diff --git a/advisories/github-reviewed/2025/04/GHSA-42fh-pvvh-999x/GHSA-42fh-pvvh-999x.json b/advisories/github-reviewed/2025/04/GHSA-42fh-pvvh-999x/GHSA-42fh-pvvh-999x.json new file mode 100644 index 00000000000..d5e4bfeeb8d --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-42fh-pvvh-999x/GHSA-42fh-pvvh-999x.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42fh-pvvh-999x", + "modified": "2025-04-16T15:33:35Z", + "published": "2025-04-16T15:33:35Z", + "aliases": [ + "CVE-2025-32783" + ], + "summary": "Unregistered users can see \"public\" messages from a closed wiki via notifications from a different wiki", + "details": "### Impact\n\nThis vulnerability impacts users of a subwiki of XWiki where Message Stream is enabled and use, if they configured their wiki to be closed by selecting \"Prevent unregistered users to view pages\" in the Administrations Rights. \n\nThe vulnerability is that any message sent in a subwiki to \"everyone\" is actually sent to the farm: any visitor of the main wiki will be able to see that message through the Dashboard, even if the subwiki is configured to be private.\n\n### Patches\n\nThis problem has not been patched and is not going to be patched in the future: Message Stream has been deprecated in XWiki 16.8.0RC1 and is not maintained anymore. \n\n### Workarounds\n\nMessage Stream is disabled by default, it's advised to keep it disabled from Administration > Social > Message Stream.\n\n### References\n\n * https://jira.xwiki.org/browse/XWIKI-17154", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-messagestream" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0" + }, + { + "last_affected": "16.7.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-42fh-pvvh-999x" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-17154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-16T15:33:35Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-f8j4-p5cr-p777/GHSA-f8j4-p5cr-p777.json b/advisories/github-reviewed/2025/04/GHSA-f8j4-p5cr-p777/GHSA-f8j4-p5cr-p777.json new file mode 100644 index 00000000000..96a63c2deaf --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-f8j4-p5cr-p777/GHSA-f8j4-p5cr-p777.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8j4-p5cr-p777", + "modified": "2025-04-16T15:34:21Z", + "published": "2025-04-16T15:34:21Z", + "aliases": [], + "summary": "Permission policy information leakage in Backstage permission system", + "details": "### Impact\n\nA vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed in the permission backend. If the permission system is not in use or if the installed permission policy does not use conditional decisions, there is no impact.\n\n### Patches\n\nThis issue has been resolved in version `0.6.0` of the permissions backend.\n\n### Workarounds\n\nAdministrators of the permission policies can ensure that they are crafted in such a way that conditional decisions do not contain any sensitive information.\n\n### References\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in the [Backstage repository](https://github.com/backstage/backstage)\nVisit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@backstage/plugin-permission-backend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.6.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/backstage/backstage/security/advisories/GHSA-f8j4-p5cr-p777" + }, + { + "type": "PACKAGE", + "url": "https://github.com/backstage/backstage" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-213" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-16T15:34:21Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-5xp9-c9vh-m53w/GHSA-5xp9-c9vh-m53w.json b/advisories/unreviewed/2022/05/GHSA-5xp9-c9vh-m53w/GHSA-5xp9-c9vh-m53w.json index ce75c75403d..9976bba007c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xp9-c9vh-m53w/GHSA-5xp9-c9vh-m53w.json +++ b/advisories/unreviewed/2022/05/GHSA-5xp9-c9vh-m53w/GHSA-5xp9-c9vh-m53w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xp9-c9vh-m53w", - "modified": "2024-04-04T01:59:10Z", + "modified": "2025-04-16T15:34:02Z", "published": "2022-05-24T16:56:39Z", "aliases": [ "CVE-2019-16693" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/phpipam/phpipam/issues/2738" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2019-16693.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-6v7c-9pxp-gfcv/GHSA-6v7c-9pxp-gfcv.json b/advisories/unreviewed/2022/05/GHSA-6v7c-9pxp-gfcv/GHSA-6v7c-9pxp-gfcv.json index 5c4c76e8944..01b15b0aab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v7c-9pxp-gfcv/GHSA-6v7c-9pxp-gfcv.json +++ b/advisories/unreviewed/2022/05/GHSA-6v7c-9pxp-gfcv/GHSA-6v7c-9pxp-gfcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v7c-9pxp-gfcv", - "modified": "2022-05-24T19:17:08Z", + "modified": "2025-04-16T15:34:03Z", "published": "2022-05-24T19:17:08Z", "aliases": [ "CVE-2021-40617" ], "details": "An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -17,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/OS4ED/openSIS-Classic/issues/192" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2021-40617.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json b/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json index 1da0c3617c1..895820fcfff 100644 --- a/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json +++ b/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88gc-h5ch-vcch", - "modified": "2022-05-24T17:23:38Z", + "modified": "2025-04-16T15:34:03Z", "published": "2022-05-24T17:23:38Z", "aliases": [ "CVE-2020-15718" ], "details": "RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -18,6 +23,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/184944" }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-15718.md" + }, { "type": "WEB", "url": "https://gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES.md" @@ -36,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fx8g-7gh6-p9vx/GHSA-fx8g-7gh6-p9vx.json b/advisories/unreviewed/2022/05/GHSA-fx8g-7gh6-p9vx/GHSA-fx8g-7gh6-p9vx.json index b8b5158af2f..b28a6684656 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx8g-7gh6-p9vx/GHSA-fx8g-7gh6-p9vx.json +++ b/advisories/unreviewed/2022/05/GHSA-fx8g-7gh6-p9vx/GHSA-fx8g-7gh6-p9vx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fx8g-7gh6-p9vx", - "modified": "2022-05-24T17:42:38Z", + "modified": "2025-04-16T15:34:03Z", "published": "2022-05-24T17:42:38Z", "aliases": [ "CVE-2019-25024" ], "details": "OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -18,6 +23,10 @@ "type": "WEB", "url": "https://github.com/OpenRepeater/openrepeater/issues/66" }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2019-25024.md" + }, { "type": "WEB", "url": "https://github.com/codexlynx/CVE-2019-25024" diff --git a/advisories/unreviewed/2022/05/GHSA-hppr-6qxj-jhgx/GHSA-hppr-6qxj-jhgx.json b/advisories/unreviewed/2022/05/GHSA-hppr-6qxj-jhgx/GHSA-hppr-6qxj-jhgx.json index cdb66051eda..d4a0330bd3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hppr-6qxj-jhgx/GHSA-hppr-6qxj-jhgx.json +++ b/advisories/unreviewed/2022/05/GHSA-hppr-6qxj-jhgx/GHSA-hppr-6qxj-jhgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hppr-6qxj-jhgx", - "modified": "2022-05-17T00:30:24Z", + "modified": "2025-04-16T15:34:02Z", "published": "2022-05-17T00:30:24Z", "aliases": [ "CVE-2017-15808" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/thorsten/phpMyFAQ/commit/a249b4645fb86f6a9fbe5d2344ab1cbdb906b75c" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2017-15808.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json b/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json index 3366897bf6c..94b7194027a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json +++ b/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mmfm-f7qp-mmv3", - "modified": "2022-05-24T17:36:40Z", + "modified": "2025-04-16T15:34:02Z", "published": "2022-05-24T17:36:40Z", "aliases": [ "CVE-2020-29607" ], "details": "A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the \"manage files\" functionality, which may result in remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -22,6 +27,10 @@ "type": "WEB", "url": "https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit" }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-29607.md" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html" diff --git a/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json b/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json index e2bbc529a72..9826afa14cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json +++ b/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wc7j-rv6h-gcx6", - "modified": "2022-05-24T17:23:38Z", + "modified": "2025-04-16T15:34:02Z", "published": "2022-05-24T17:23:38Z", "aliases": [ "CVE-2020-15716" ], "details": "RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -18,6 +23,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/184942" }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-15716.md" + }, { "type": "WEB", "url": "https://gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES.md" @@ -36,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-2pjx-v75h-827m/GHSA-2pjx-v75h-827m.json b/advisories/unreviewed/2022/12/GHSA-2pjx-v75h-827m/GHSA-2pjx-v75h-827m.json index a545d3cb44b..ba4945c877e 100644 --- a/advisories/unreviewed/2022/12/GHSA-2pjx-v75h-827m/GHSA-2pjx-v75h-827m.json +++ b/advisories/unreviewed/2022/12/GHSA-2pjx-v75h-827m/GHSA-2pjx-v75h-827m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pjx-v75h-827m", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-16T15:34:08Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29911" diff --git a/advisories/unreviewed/2022/12/GHSA-34mj-396j-93pr/GHSA-34mj-396j-93pr.json b/advisories/unreviewed/2022/12/GHSA-34mj-396j-93pr/GHSA-34mj-396j-93pr.json index 39b82b1b83b..0c810ff982d 100644 --- a/advisories/unreviewed/2022/12/GHSA-34mj-396j-93pr/GHSA-34mj-396j-93pr.json +++ b/advisories/unreviewed/2022/12/GHSA-34mj-396j-93pr/GHSA-34mj-396j-93pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34mj-396j-93pr", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22756" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3fr2-34qf-c3pm/GHSA-3fr2-34qf-c3pm.json b/advisories/unreviewed/2022/12/GHSA-3fr2-34qf-c3pm/GHSA-3fr2-34qf-c3pm.json index 621d00b103d..7fdd5d7e768 100644 --- a/advisories/unreviewed/2022/12/GHSA-3fr2-34qf-c3pm/GHSA-3fr2-34qf-c3pm.json +++ b/advisories/unreviewed/2022/12/GHSA-3fr2-34qf-c3pm/GHSA-3fr2-34qf-c3pm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fr2-34qf-c3pm", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22763" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3gfr-938g-v48x/GHSA-3gfr-938g-v48x.json b/advisories/unreviewed/2022/12/GHSA-3gfr-938g-v48x/GHSA-3gfr-938g-v48x.json index 982e595eb34..68a86a22f4d 100644 --- a/advisories/unreviewed/2022/12/GHSA-3gfr-938g-v48x/GHSA-3gfr-938g-v48x.json +++ b/advisories/unreviewed/2022/12/GHSA-3gfr-938g-v48x/GHSA-3gfr-938g-v48x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gfr-938g-v48x", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-26383" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3gq8-8fwh-fc7q/GHSA-3gq8-8fwh-fc7q.json b/advisories/unreviewed/2022/12/GHSA-3gq8-8fwh-fc7q/GHSA-3gq8-8fwh-fc7q.json index 7f890d8f644..ff2c0148b99 100644 --- a/advisories/unreviewed/2022/12/GHSA-3gq8-8fwh-fc7q/GHSA-3gq8-8fwh-fc7q.json +++ b/advisories/unreviewed/2022/12/GHSA-3gq8-8fwh-fc7q/GHSA-3gq8-8fwh-fc7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gq8-8fwh-fc7q", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:08Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29910" diff --git a/advisories/unreviewed/2022/12/GHSA-3v83-x3vq-3mmv/GHSA-3v83-x3vq-3mmv.json b/advisories/unreviewed/2022/12/GHSA-3v83-x3vq-3mmv/GHSA-3v83-x3vq-3mmv.json index 1b1689e53a8..4438a59b497 100644 --- a/advisories/unreviewed/2022/12/GHSA-3v83-x3vq-3mmv/GHSA-3v83-x3vq-3mmv.json +++ b/advisories/unreviewed/2022/12/GHSA-3v83-x3vq-3mmv/GHSA-3v83-x3vq-3mmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3v83-x3vq-3mmv", - "modified": "2023-01-04T00:30:26Z", + "modified": "2025-04-16T15:34:08Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-31738" diff --git a/advisories/unreviewed/2022/12/GHSA-3w9m-vg42-8v9h/GHSA-3w9m-vg42-8v9h.json b/advisories/unreviewed/2022/12/GHSA-3w9m-vg42-8v9h/GHSA-3w9m-vg42-8v9h.json index f42c406b254..534544ffd48 100644 --- a/advisories/unreviewed/2022/12/GHSA-3w9m-vg42-8v9h/GHSA-3w9m-vg42-8v9h.json +++ b/advisories/unreviewed/2022/12/GHSA-3w9m-vg42-8v9h/GHSA-3w9m-vg42-8v9h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w9m-vg42-8v9h", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22755" diff --git a/advisories/unreviewed/2022/12/GHSA-443j-8jp8-4xch/GHSA-443j-8jp8-4xch.json b/advisories/unreviewed/2022/12/GHSA-443j-8jp8-4xch/GHSA-443j-8jp8-4xch.json index 03cd6dd4237..a6aaf77a875 100644 --- a/advisories/unreviewed/2022/12/GHSA-443j-8jp8-4xch/GHSA-443j-8jp8-4xch.json +++ b/advisories/unreviewed/2022/12/GHSA-443j-8jp8-4xch/GHSA-443j-8jp8-4xch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-443j-8jp8-4xch", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22761" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4fpj-fh6q-hx4r/GHSA-4fpj-fh6q-hx4r.json b/advisories/unreviewed/2022/12/GHSA-4fpj-fh6q-hx4r/GHSA-4fpj-fh6q-hx4r.json index f443c7acd82..4eaf6222173 100644 --- a/advisories/unreviewed/2022/12/GHSA-4fpj-fh6q-hx4r/GHSA-4fpj-fh6q-hx4r.json +++ b/advisories/unreviewed/2022/12/GHSA-4fpj-fh6q-hx4r/GHSA-4fpj-fh6q-hx4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fpj-fh6q-hx4r", - "modified": "2022-12-31T06:30:23Z", + "modified": "2025-04-16T15:34:05Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22746" diff --git a/advisories/unreviewed/2022/12/GHSA-4hw9-gj93-w3gr/GHSA-4hw9-gj93-w3gr.json b/advisories/unreviewed/2022/12/GHSA-4hw9-gj93-w3gr/GHSA-4hw9-gj93-w3gr.json index 1c1c2623907..0af3edc3062 100644 --- a/advisories/unreviewed/2022/12/GHSA-4hw9-gj93-w3gr/GHSA-4hw9-gj93-w3gr.json +++ b/advisories/unreviewed/2022/12/GHSA-4hw9-gj93-w3gr/GHSA-4hw9-gj93-w3gr.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-640" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-557q-69q9-3wvh/GHSA-557q-69q9-3wvh.json b/advisories/unreviewed/2022/12/GHSA-557q-69q9-3wvh/GHSA-557q-69q9-3wvh.json index c0659111bc4..28962a2bb35 100644 --- a/advisories/unreviewed/2022/12/GHSA-557q-69q9-3wvh/GHSA-557q-69q9-3wvh.json +++ b/advisories/unreviewed/2022/12/GHSA-557q-69q9-3wvh/GHSA-557q-69q9-3wvh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-557q-69q9-3wvh", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:08Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29909" diff --git a/advisories/unreviewed/2022/12/GHSA-599g-72g6-j2r4/GHSA-599g-72g6-j2r4.json b/advisories/unreviewed/2022/12/GHSA-599g-72g6-j2r4/GHSA-599g-72g6-j2r4.json index 9198627bfb3..6a65c33f73d 100644 --- a/advisories/unreviewed/2022/12/GHSA-599g-72g6-j2r4/GHSA-599g-72g6-j2r4.json +++ b/advisories/unreviewed/2022/12/GHSA-599g-72g6-j2r4/GHSA-599g-72g6-j2r4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-599g-72g6-j2r4", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:05Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22751" diff --git a/advisories/unreviewed/2022/12/GHSA-5g34-x2rf-m7v6/GHSA-5g34-x2rf-m7v6.json b/advisories/unreviewed/2022/12/GHSA-5g34-x2rf-m7v6/GHSA-5g34-x2rf-m7v6.json index 8625ef35130..db4d32b804e 100644 --- a/advisories/unreviewed/2022/12/GHSA-5g34-x2rf-m7v6/GHSA-5g34-x2rf-m7v6.json +++ b/advisories/unreviewed/2022/12/GHSA-5g34-x2rf-m7v6/GHSA-5g34-x2rf-m7v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5g34-x2rf-m7v6", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-28284" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-116" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-74mv-468m-jp37/GHSA-74mv-468m-jp37.json b/advisories/unreviewed/2022/12/GHSA-74mv-468m-jp37/GHSA-74mv-468m-jp37.json index 992ac9064e8..1cfbe339220 100644 --- a/advisories/unreviewed/2022/12/GHSA-74mv-468m-jp37/GHSA-74mv-468m-jp37.json +++ b/advisories/unreviewed/2022/12/GHSA-74mv-468m-jp37/GHSA-74mv-468m-jp37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74mv-468m-jp37", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:05Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22748" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7mvx-m8hq-f37g/GHSA-7mvx-m8hq-f37g.json b/advisories/unreviewed/2022/12/GHSA-7mvx-m8hq-f37g/GHSA-7mvx-m8hq-f37g.json index 5e5638dbf9b..dd68a491a10 100644 --- a/advisories/unreviewed/2022/12/GHSA-7mvx-m8hq-f37g/GHSA-7mvx-m8hq-f37g.json +++ b/advisories/unreviewed/2022/12/GHSA-7mvx-m8hq-f37g/GHSA-7mvx-m8hq-f37g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7mvx-m8hq-f37g", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-26382" diff --git a/advisories/unreviewed/2022/12/GHSA-7qpp-mq9c-7449/GHSA-7qpp-mq9c-7449.json b/advisories/unreviewed/2022/12/GHSA-7qpp-mq9c-7449/GHSA-7qpp-mq9c-7449.json index e688fcee1a5..f9bb9c2d3fd 100644 --- a/advisories/unreviewed/2022/12/GHSA-7qpp-mq9c-7449/GHSA-7qpp-mq9c-7449.json +++ b/advisories/unreviewed/2022/12/GHSA-7qpp-mq9c-7449/GHSA-7qpp-mq9c-7449.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qpp-mq9c-7449", - "modified": "2022-12-30T00:30:43Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22759" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-83qq-799j-gmvc/GHSA-83qq-799j-gmvc.json b/advisories/unreviewed/2022/12/GHSA-83qq-799j-gmvc/GHSA-83qq-799j-gmvc.json index 09cf66278e5..b70696d563e 100644 --- a/advisories/unreviewed/2022/12/GHSA-83qq-799j-gmvc/GHSA-83qq-799j-gmvc.json +++ b/advisories/unreviewed/2022/12/GHSA-83qq-799j-gmvc/GHSA-83qq-799j-gmvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-83qq-799j-gmvc", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T15:34:04Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-0511" diff --git a/advisories/unreviewed/2022/12/GHSA-9mwr-4v4g-8w4c/GHSA-9mwr-4v4g-8w4c.json b/advisories/unreviewed/2022/12/GHSA-9mwr-4v4g-8w4c/GHSA-9mwr-4v4g-8w4c.json index 0756522402a..f6dd9d37c6e 100644 --- a/advisories/unreviewed/2022/12/GHSA-9mwr-4v4g-8w4c/GHSA-9mwr-4v4g-8w4c.json +++ b/advisories/unreviewed/2022/12/GHSA-9mwr-4v4g-8w4c/GHSA-9mwr-4v4g-8w4c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mwr-4v4g-8w4c", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:08Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-28289" diff --git a/advisories/unreviewed/2022/12/GHSA-c839-4fpv-9xp7/GHSA-c839-4fpv-9xp7.json b/advisories/unreviewed/2022/12/GHSA-c839-4fpv-9xp7/GHSA-c839-4fpv-9xp7.json index 7e3696ba6b3..6fb7256a85e 100644 --- a/advisories/unreviewed/2022/12/GHSA-c839-4fpv-9xp7/GHSA-c839-4fpv-9xp7.json +++ b/advisories/unreviewed/2022/12/GHSA-c839-4fpv-9xp7/GHSA-c839-4fpv-9xp7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c839-4fpv-9xp7", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-16T15:34:04Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2020-15685" diff --git a/advisories/unreviewed/2022/12/GHSA-cqhv-5jmg-p8jh/GHSA-cqhv-5jmg-p8jh.json b/advisories/unreviewed/2022/12/GHSA-cqhv-5jmg-p8jh/GHSA-cqhv-5jmg-p8jh.json index 03e8d6f5384..90d34e2322c 100644 --- a/advisories/unreviewed/2022/12/GHSA-cqhv-5jmg-p8jh/GHSA-cqhv-5jmg-p8jh.json +++ b/advisories/unreviewed/2022/12/GHSA-cqhv-5jmg-p8jh/GHSA-cqhv-5jmg-p8jh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqhv-5jmg-p8jh", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:05Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22749" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-cwm9-q742-vjcx/GHSA-cwm9-q742-vjcx.json b/advisories/unreviewed/2022/12/GHSA-cwm9-q742-vjcx/GHSA-cwm9-q742-vjcx.json index e1e21b5f0e2..d8c209e1764 100644 --- a/advisories/unreviewed/2022/12/GHSA-cwm9-q742-vjcx/GHSA-cwm9-q742-vjcx.json +++ b/advisories/unreviewed/2022/12/GHSA-cwm9-q742-vjcx/GHSA-cwm9-q742-vjcx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cwm9-q742-vjcx", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-26384" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-fc8f-jhcw-p24v/GHSA-fc8f-jhcw-p24v.json b/advisories/unreviewed/2022/12/GHSA-fc8f-jhcw-p24v/GHSA-fc8f-jhcw-p24v.json index be3df74a22c..710aec1ccca 100644 --- a/advisories/unreviewed/2022/12/GHSA-fc8f-jhcw-p24v/GHSA-fc8f-jhcw-p24v.json +++ b/advisories/unreviewed/2022/12/GHSA-fc8f-jhcw-p24v/GHSA-fc8f-jhcw-p24v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc8f-jhcw-p24v", - "modified": "2022-12-30T00:30:43Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22757" @@ -30,7 +30,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-345", + "CWE-346" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-fmhg-h49x-72gp/GHSA-fmhg-h49x-72gp.json b/advisories/unreviewed/2022/12/GHSA-fmhg-h49x-72gp/GHSA-fmhg-h49x-72gp.json index 72921e10c96..69ba4cdadeb 100644 --- a/advisories/unreviewed/2022/12/GHSA-fmhg-h49x-72gp/GHSA-fmhg-h49x-72gp.json +++ b/advisories/unreviewed/2022/12/GHSA-fmhg-h49x-72gp/GHSA-fmhg-h49x-72gp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmhg-h49x-72gp", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-28285" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-gm8j-qhfm-mgv8/GHSA-gm8j-qhfm-mgv8.json b/advisories/unreviewed/2022/12/GHSA-gm8j-qhfm-mgv8/GHSA-gm8j-qhfm-mgv8.json index b10493c18a7..e3d11b8149e 100644 --- a/advisories/unreviewed/2022/12/GHSA-gm8j-qhfm-mgv8/GHSA-gm8j-qhfm-mgv8.json +++ b/advisories/unreviewed/2022/12/GHSA-gm8j-qhfm-mgv8/GHSA-gm8j-qhfm-mgv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gm8j-qhfm-mgv8", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-16T15:34:09Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-31740" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-h4q8-cxvq-m2rr/GHSA-h4q8-cxvq-m2rr.json b/advisories/unreviewed/2022/12/GHSA-h4q8-cxvq-m2rr/GHSA-h4q8-cxvq-m2rr.json index 1f209ea653d..9652127e667 100644 --- a/advisories/unreviewed/2022/12/GHSA-h4q8-cxvq-m2rr/GHSA-h4q8-cxvq-m2rr.json +++ b/advisories/unreviewed/2022/12/GHSA-h4q8-cxvq-m2rr/GHSA-h4q8-cxvq-m2rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h4q8-cxvq-m2rr", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22764" @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-h4wj-cg8v-jxq5/GHSA-h4wj-cg8v-jxq5.json b/advisories/unreviewed/2022/12/GHSA-h4wj-cg8v-jxq5/GHSA-h4wj-cg8v-jxq5.json index b6025787485..6bd32c334e8 100644 --- a/advisories/unreviewed/2022/12/GHSA-h4wj-cg8v-jxq5/GHSA-h4wj-cg8v-jxq5.json +++ b/advisories/unreviewed/2022/12/GHSA-h4wj-cg8v-jxq5/GHSA-h4wj-cg8v-jxq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h4wj-cg8v-jxq5", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-26381" diff --git a/advisories/unreviewed/2022/12/GHSA-h74h-w4r7-rp9x/GHSA-h74h-w4r7-rp9x.json b/advisories/unreviewed/2022/12/GHSA-h74h-w4r7-rp9x/GHSA-h74h-w4r7-rp9x.json index 829b709dba4..469e1dd4129 100644 --- a/advisories/unreviewed/2022/12/GHSA-h74h-w4r7-rp9x/GHSA-h74h-w4r7-rp9x.json +++ b/advisories/unreviewed/2022/12/GHSA-h74h-w4r7-rp9x/GHSA-h74h-w4r7-rp9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h74h-w4r7-rp9x", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-16T15:34:08Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-31737" diff --git a/advisories/unreviewed/2022/12/GHSA-jqvp-m2qw-c439/GHSA-jqvp-m2qw-c439.json b/advisories/unreviewed/2022/12/GHSA-jqvp-m2qw-c439/GHSA-jqvp-m2qw-c439.json index e8d778091dc..2ccc09ee891 100644 --- a/advisories/unreviewed/2022/12/GHSA-jqvp-m2qw-c439/GHSA-jqvp-m2qw-c439.json +++ b/advisories/unreviewed/2022/12/GHSA-jqvp-m2qw-c439/GHSA-jqvp-m2qw-c439.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jqvp-m2qw-c439", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T15:34:04Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22745" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-m884-m9x6-6rg3/GHSA-m884-m9x6-6rg3.json b/advisories/unreviewed/2022/12/GHSA-m884-m9x6-6rg3/GHSA-m884-m9x6-6rg3.json index 63e5c163506..49f001f3fb5 100644 --- a/advisories/unreviewed/2022/12/GHSA-m884-m9x6-6rg3/GHSA-m884-m9x6-6rg3.json +++ b/advisories/unreviewed/2022/12/GHSA-m884-m9x6-6rg3/GHSA-m884-m9x6-6rg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m884-m9x6-6rg3", - "modified": "2022-12-29T18:30:25Z", + "modified": "2025-04-16T15:34:04Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22737" @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-mhvm-x9qg-34cw/GHSA-mhvm-x9qg-34cw.json b/advisories/unreviewed/2022/12/GHSA-mhvm-x9qg-34cw/GHSA-mhvm-x9qg-34cw.json index 06c50e7a9ff..03a691bd8ea 100644 --- a/advisories/unreviewed/2022/12/GHSA-mhvm-x9qg-34cw/GHSA-mhvm-x9qg-34cw.json +++ b/advisories/unreviewed/2022/12/GHSA-mhvm-x9qg-34cw/GHSA-mhvm-x9qg-34cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhvm-x9qg-34cw", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:05Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22754" diff --git a/advisories/unreviewed/2022/12/GHSA-mjpp-wxm2-vx37/GHSA-mjpp-wxm2-vx37.json b/advisories/unreviewed/2022/12/GHSA-mjpp-wxm2-vx37/GHSA-mjpp-wxm2-vx37.json index 8ec9ebc3596..99475e8ada5 100644 --- a/advisories/unreviewed/2022/12/GHSA-mjpp-wxm2-vx37/GHSA-mjpp-wxm2-vx37.json +++ b/advisories/unreviewed/2022/12/GHSA-mjpp-wxm2-vx37/GHSA-mjpp-wxm2-vx37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjpp-wxm2-vx37", - "modified": "2022-12-20T18:30:19Z", + "modified": "2025-04-16T15:34:03Z", "published": "2022-12-20T18:30:19Z", "aliases": [ "CVE-2022-3109" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00016.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KOMB6WRUC55VWV25IKJTV22KARBUGWGQ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOMB6WRUC55VWV25IKJTV22KARBUGWGQ" diff --git a/advisories/unreviewed/2022/12/GHSA-mpq8-m953-pwhf/GHSA-mpq8-m953-pwhf.json b/advisories/unreviewed/2022/12/GHSA-mpq8-m953-pwhf/GHSA-mpq8-m953-pwhf.json index 02ff8d12cb6..a62a570460d 100644 --- a/advisories/unreviewed/2022/12/GHSA-mpq8-m953-pwhf/GHSA-mpq8-m953-pwhf.json +++ b/advisories/unreviewed/2022/12/GHSA-mpq8-m953-pwhf/GHSA-mpq8-m953-pwhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mpq8-m953-pwhf", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22760" diff --git a/advisories/unreviewed/2022/12/GHSA-p6cr-3vwp-qgx2/GHSA-p6cr-3vwp-qgx2.json b/advisories/unreviewed/2022/12/GHSA-p6cr-3vwp-qgx2/GHSA-p6cr-3vwp-qgx2.json index 337d96675bf..d6a1bddd6ee 100644 --- a/advisories/unreviewed/2022/12/GHSA-p6cr-3vwp-qgx2/GHSA-p6cr-3vwp-qgx2.json +++ b/advisories/unreviewed/2022/12/GHSA-p6cr-3vwp-qgx2/GHSA-p6cr-3vwp-qgx2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-p6hc-xj9v-m5qh/GHSA-p6hc-xj9v-m5qh.json b/advisories/unreviewed/2022/12/GHSA-p6hc-xj9v-m5qh/GHSA-p6hc-xj9v-m5qh.json index b96d9647dfb..0425cfd11b2 100644 --- a/advisories/unreviewed/2022/12/GHSA-p6hc-xj9v-m5qh/GHSA-p6hc-xj9v-m5qh.json +++ b/advisories/unreviewed/2022/12/GHSA-p6hc-xj9v-m5qh/GHSA-p6hc-xj9v-m5qh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-427", "CWE-428" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-pp7m-q233-vq86/GHSA-pp7m-q233-vq86.json b/advisories/unreviewed/2022/12/GHSA-pp7m-q233-vq86/GHSA-pp7m-q233-vq86.json index f34fd28b6cc..58eea4944f1 100644 --- a/advisories/unreviewed/2022/12/GHSA-pp7m-q233-vq86/GHSA-pp7m-q233-vq86.json +++ b/advisories/unreviewed/2022/12/GHSA-pp7m-q233-vq86/GHSA-pp7m-q233-vq86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pp7m-q233-vq86", - "modified": "2022-12-30T15:30:23Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22762" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-pr6h-wqwg-8wxx/GHSA-pr6h-wqwg-8wxx.json b/advisories/unreviewed/2022/12/GHSA-pr6h-wqwg-8wxx/GHSA-pr6h-wqwg-8wxx.json index 6002604c870..9cb716237d7 100644 --- a/advisories/unreviewed/2022/12/GHSA-pr6h-wqwg-8wxx/GHSA-pr6h-wqwg-8wxx.json +++ b/advisories/unreviewed/2022/12/GHSA-pr6h-wqwg-8wxx/GHSA-pr6h-wqwg-8wxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr6h-wqwg-8wxx", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T15:34:05Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22753" diff --git a/advisories/unreviewed/2022/12/GHSA-qffr-cvph-655f/GHSA-qffr-cvph-655f.json b/advisories/unreviewed/2022/12/GHSA-qffr-cvph-655f/GHSA-qffr-cvph-655f.json index 6c5aa78b12d..3803b11b9fc 100644 --- a/advisories/unreviewed/2022/12/GHSA-qffr-cvph-655f/GHSA-qffr-cvph-655f.json +++ b/advisories/unreviewed/2022/12/GHSA-qffr-cvph-655f/GHSA-qffr-cvph-655f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qffr-cvph-655f", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-28287" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-664" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-qm5f-gm4h-wq94/GHSA-qm5f-gm4h-wq94.json b/advisories/unreviewed/2022/12/GHSA-qm5f-gm4h-wq94/GHSA-qm5f-gm4h-wq94.json index a99ed2bc021..235d5df6702 100644 --- a/advisories/unreviewed/2022/12/GHSA-qm5f-gm4h-wq94/GHSA-qm5f-gm4h-wq94.json +++ b/advisories/unreviewed/2022/12/GHSA-qm5f-gm4h-wq94/GHSA-qm5f-gm4h-wq94.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm5f-gm4h-wq94", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-28288" diff --git a/advisories/unreviewed/2022/12/GHSA-rr3f-gjw6-5522/GHSA-rr3f-gjw6-5522.json b/advisories/unreviewed/2022/12/GHSA-rr3f-gjw6-5522/GHSA-rr3f-gjw6-5522.json index b8c7fcea67b..4dd3ce4fdea 100644 --- a/advisories/unreviewed/2022/12/GHSA-rr3f-gjw6-5522/GHSA-rr3f-gjw6-5522.json +++ b/advisories/unreviewed/2022/12/GHSA-rr3f-gjw6-5522/GHSA-rr3f-gjw6-5522.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rr3f-gjw6-5522", - "modified": "2022-12-29T18:30:25Z", + "modified": "2025-04-16T15:34:04Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22738" diff --git a/advisories/unreviewed/2022/12/GHSA-vcmf-vf48-7jqp/GHSA-vcmf-vf48-7jqp.json b/advisories/unreviewed/2022/12/GHSA-vcmf-vf48-7jqp/GHSA-vcmf-vf48-7jqp.json index d56238c4c0a..f32b7f24937 100644 --- a/advisories/unreviewed/2022/12/GHSA-vcmf-vf48-7jqp/GHSA-vcmf-vf48-7jqp.json +++ b/advisories/unreviewed/2022/12/GHSA-vcmf-vf48-7jqp/GHSA-vcmf-vf48-7jqp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vcmf-vf48-7jqp", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-28283" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-552" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vr8w-grw2-mv66/GHSA-vr8w-grw2-mv66.json b/advisories/unreviewed/2022/12/GHSA-vr8w-grw2-mv66/GHSA-vr8w-grw2-mv66.json index ee4c302d9d2..b814838ed22 100644 --- a/advisories/unreviewed/2022/12/GHSA-vr8w-grw2-mv66/GHSA-vr8w-grw2-mv66.json +++ b/advisories/unreviewed/2022/12/GHSA-vr8w-grw2-mv66/GHSA-vr8w-grw2-mv66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vr8w-grw2-mv66", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-16T15:34:07Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-28286" diff --git a/advisories/unreviewed/2022/12/GHSA-w6x2-rcr6-2hh6/GHSA-w6x2-rcr6-2hh6.json b/advisories/unreviewed/2022/12/GHSA-w6x2-rcr6-2hh6/GHSA-w6x2-rcr6-2hh6.json index 04ad1fbd1c3..be6a76227ad 100644 --- a/advisories/unreviewed/2022/12/GHSA-w6x2-rcr6-2hh6/GHSA-w6x2-rcr6-2hh6.json +++ b/advisories/unreviewed/2022/12/GHSA-w6x2-rcr6-2hh6/GHSA-w6x2-rcr6-2hh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6x2-rcr6-2hh6", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-16T15:34:09Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-31739" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-73" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-x7x8-qh7j-2q6h/GHSA-x7x8-qh7j-2q6h.json b/advisories/unreviewed/2022/12/GHSA-x7x8-qh7j-2q6h/GHSA-x7x8-qh7j-2q6h.json index dc4ac24c35e..8294315b5c4 100644 --- a/advisories/unreviewed/2022/12/GHSA-x7x8-qh7j-2q6h/GHSA-x7x8-qh7j-2q6h.json +++ b/advisories/unreviewed/2022/12/GHSA-x7x8-qh7j-2q6h/GHSA-x7x8-qh7j-2q6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x7x8-qh7j-2q6h", - "modified": "2022-12-30T00:30:43Z", + "modified": "2025-04-16T15:34:06Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22758" diff --git a/advisories/unreviewed/2023/05/GHSA-ggjx-vpr3-6vwg/GHSA-ggjx-vpr3-6vwg.json b/advisories/unreviewed/2023/05/GHSA-ggjx-vpr3-6vwg/GHSA-ggjx-vpr3-6vwg.json index 7b7374632e6..8d6d2d62779 100644 --- a/advisories/unreviewed/2023/05/GHSA-ggjx-vpr3-6vwg/GHSA-ggjx-vpr3-6vwg.json +++ b/advisories/unreviewed/2023/05/GHSA-ggjx-vpr3-6vwg/GHSA-ggjx-vpr3-6vwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggjx-vpr3-6vwg", - "modified": "2024-04-04T04:18:49Z", + "modified": "2025-04-16T15:34:09Z", "published": "2023-05-23T15:30:30Z", "aliases": [ "CVE-2023-33362" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/Piwigo/Piwigo/issues/1911" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2023-33362.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json b/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json index dd6481420ab..4bada24d6d2 100644 --- a/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json +++ b/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47xj-xr7q-9hhq", - "modified": "2024-04-04T04:58:53Z", + "modified": "2025-04-16T15:34:09Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20969" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/pluck-cms/pluck/issues/86" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-20969.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-4v39-q2jh-wjrw/GHSA-4v39-q2jh-wjrw.json b/advisories/unreviewed/2023/06/GHSA-4v39-q2jh-wjrw/GHSA-4v39-q2jh-wjrw.json index 4e6eb8abfcf..113e88ea0bb 100644 --- a/advisories/unreviewed/2023/06/GHSA-4v39-q2jh-wjrw/GHSA-4v39-q2jh-wjrw.json +++ b/advisories/unreviewed/2023/06/GHSA-4v39-q2jh-wjrw/GHSA-4v39-q2jh-wjrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v39-q2jh-wjrw", - "modified": "2023-11-14T03:30:52Z", + "modified": "2025-04-16T15:34:09Z", "published": "2023-06-23T12:30:18Z", "aliases": [ "CVE-2023-30258" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://eldstal.se/advisories/230327-magnusbilling.html" }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2023-30258.md" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/175672/MagnusBilling-Remote-Command-Execution.html" diff --git a/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json b/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json index 277004510a6..ea92d8c96ac 100644 --- a/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json +++ b/advisories/unreviewed/2024/03/GHSA-23h2-xqvf-mj5r/GHSA-23h2-xqvf-mj5r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-23h2-xqvf-mj5r", - "modified": "2024-03-19T18:32:01Z", + "modified": "2025-04-16T15:34:09Z", "published": "2024-03-19T18:32:01Z", "aliases": [ "CVE-2024-27996" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/07/GHSA-w986-c9ww-hwv3/GHSA-w986-c9ww-hwv3.json b/advisories/unreviewed/2024/07/GHSA-w986-c9ww-hwv3/GHSA-w986-c9ww-hwv3.json index 2ef1a11f0d9..c92413abf07 100644 --- a/advisories/unreviewed/2024/07/GHSA-w986-c9ww-hwv3/GHSA-w986-c9ww-hwv3.json +++ b/advisories/unreviewed/2024/07/GHSA-w986-c9ww-hwv3/GHSA-w986-c9ww-hwv3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w986-c9ww-hwv3", - "modified": "2024-08-01T15:32:12Z", + "modified": "2025-04-16T15:34:13Z", "published": "2024-07-26T18:30:37Z", "aliases": [ "CVE-2024-41357" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/phpipam/phpipam/issues/4149" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2024-41357.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json b/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json index 7f43b288696..8db125d442d 100644 --- a/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json +++ b/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hmvm-6w7r-q9wr", - "modified": "2024-09-04T18:30:49Z", + "modified": "2025-04-16T15:34:13Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41358" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/phpipam/phpipam/issues/4148" + }, + { + "type": "WEB", + "url": "https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2024-41358.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-228w-3rqr-2658/GHSA-228w-3rqr-2658.json b/advisories/unreviewed/2025/04/GHSA-228w-3rqr-2658/GHSA-228w-3rqr-2658.json new file mode 100644 index 00000000000..db124013ddc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-228w-3rqr-2658/GHSA-228w-3rqr-2658.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-228w-3rqr-2658", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39560" + ], + "details": "Missing Authorization vulnerability in Shahjada Live Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Live Forms: from n/a through 4.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39560" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/liveforms/vulnerability/wordpress-live-forms-plugin-4-8-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json b/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json new file mode 100644 index 00000000000..a85475cdb49 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23cf-whmv-wf37", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22102" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix kernel panic during FW release\n\nThis fixes a kernel panic seen during release FW in a stress test\nscenario where WLAN and BT FW download occurs simultaneously, and due to\na HW bug, chip sends out only 1 bootloader signatures.\n\nWhen driver receives the bootloader signature, it enters FW download\nmode, but since no consequtive bootloader signatures seen, FW file is\nnot requested.\n\nAfter 60 seconds, when FW download times out, release_firmware causes a\nkernel panic.\n\n[ 2601.949184] Unable to handle kernel paging request at virtual address 0000312e6f006573\n[ 2601.992076] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000111802000\n[ 2601.992080] [0000312e6f006573] pgd=0000000000000000, p4d=0000000000000000\n[ 2601.992087] Internal error: Oops: 0000000096000021 [#1] PREEMPT SMP\n[ 2601.992091] Modules linked in: algif_hash algif_skcipher af_alg btnxpuart(O) pciexxx(O) mlan(O) overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce snd_soc_fsl_easrc snd_soc_fsl_asoc_card imx8_media_dev(C) snd_soc_fsl_micfil polyval_generic snd_soc_fsl_xcvr snd_soc_fsl_sai snd_soc_imx_audmux snd_soc_fsl_asrc snd_soc_imx_card snd_soc_imx_hdmi snd_soc_fsl_aud2htx snd_soc_fsl_utils imx_pcm_dma dw_hdmi_cec flexcan can_dev\n[ 2602.001825] CPU: 2 PID: 20060 Comm: hciconfig Tainted: G C O 6.6.23-lts-next-06236-gb586a521770e #1\n[ 2602.010182] Hardware name: NXP i.MX8MPlus EVK board (DT)\n[ 2602.010185] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 2602.010191] pc : _raw_spin_lock+0x34/0x68\n[ 2602.010201] lr : free_fw_priv+0x20/0xfc\n[ 2602.020561] sp : ffff800089363b30\n[ 2602.020563] x29: ffff800089363b30 x28: ffff0000d0eb5880 x27: 0000000000000000\n[ 2602.020570] x26: 0000000000000000 x25: ffff0000d728b330 x24: 0000000000000000\n[ 2602.020577] x23: ffff0000dc856f38\n[ 2602.033797] x22: ffff800089363b70 x21: ffff0000dc856000\n[ 2602.033802] x20: ff00312e6f006573 x19: ffff0000d0d9ea80 x18: 0000000000000000\n[ 2602.033809] x17: 0000000000000000 x16: 0000000000000000 x15: 0000aaaad80dd480\n[ 2602.083320] x14: 0000000000000000 x13: 00000000000001b9 x12: 0000000000000002\n[ 2602.083326] x11: 0000000000000000 x10: 0000000000000a60 x9 : ffff800089363a30\n[ 2602.083333] x8 : ffff0001793d75c0 x7 : ffff0000d6dbc400 x6 : 0000000000000000\n[ 2602.083339] x5 : 00000000410fd030 x4 : 0000000000000000 x3 : 0000000000000001\n[ 2602.083346] x2 : 0000000000000000 x1 : 0000000000000001 x0 : ff00312e6f006573\n[ 2602.083354] Call trace:\n[ 2602.083356] _raw_spin_lock+0x34/0x68\n[ 2602.083364] release_firmware+0x48/0x6c\n[ 2602.083370] nxp_setup+0x3c4/0x540 [btnxpuart]\n[ 2602.083383] hci_dev_open_sync+0xf0/0xa34\n[ 2602.083391] hci_dev_open+0xd8/0x178\n[ 2602.083399] hci_sock_ioctl+0x3b0/0x590\n[ 2602.083405] sock_do_ioctl+0x60/0x118\n[ 2602.083413] sock_ioctl+0x2f4/0x374\n[ 2602.091430] __arm64_sys_ioctl+0xac/0xf0\n[ 2602.091437] invoke_syscall+0x48/0x110\n[ 2602.091445] el0_svc_common.constprop.0+0xc0/0xe0\n[ 2602.091452] do_el0_svc+0x1c/0x28\n[ 2602.091457] el0_svc+0x40/0xe4\n[ 2602.091465] el0t_64_sync_handler+0x120/0x12c\n[ 2602.091470] el0t_64_sync+0x190/0x194", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22102" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f77c05408c96bc0b58ae476a9cadc9e5b9cfd0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6749cf49eff7ce6dadcb603c5c8db70b28079a5d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json b/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json new file mode 100644 index 00000000000..d4af65ec72c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24cr-7gmf-xxwh", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22032" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: fix kernel panic due to null pointer dereference\n\nAddress a kernel panic caused by a null pointer dereference in the\n`mt792x_rx_get_wcid` function. The issue arises because the `deflink` structure\nis not properly initialized with the `sta` context. This patch ensures that the\n`deflink` structure is correctly linked to the `sta` context, preventing the\nnull pointer dereference.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000400\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 UID: 0 PID: 470 Comm: mt76-usb-rx phy Not tainted 6.12.13-gentoo-dist #1\n Hardware name: /AMD HUDSON-M1, BIOS 4.6.4 11/15/2011\n RIP: 0010:mt792x_rx_get_wcid+0x48/0x140 [mt792x_lib]\n RSP: 0018:ffffa147c055fd98 EFLAGS: 00010202\n RAX: 0000000000000000 RBX: ffff8e9ecb652000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8e9ecb652000\n RBP: 0000000000000685 R08: ffff8e9ec6570000 R09: 0000000000000000\n R10: ffff8e9ecd2ca000 R11: ffff8e9f22a217c0 R12: 0000000038010119\n R13: 0000000080843801 R14: ffff8e9ec6570000 R15: ffff8e9ecb652000\n FS: 0000000000000000(0000) GS:ffff8e9f22a00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000400 CR3: 000000000d2ea000 CR4: 00000000000006f0\n Call Trace:\n \n ? __die_body.cold+0x19/0x27\n ? page_fault_oops+0x15a/0x2f0\n ? search_module_extables+0x19/0x60\n ? search_bpf_extables+0x5f/0x80\n ? exc_page_fault+0x7e/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? mt792x_rx_get_wcid+0x48/0x140 [mt792x_lib]\n mt7921_queue_rx_skb+0x1c6/0xaa0 [mt7921_common]\n mt76u_alloc_queues+0x784/0x810 [mt76_usb]\n ? __pfx___mt76_worker_fn+0x10/0x10 [mt76]\n __mt76_worker_fn+0x4f/0x80 [mt76]\n kthread+0xd2/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n ---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22032" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cfea60966e4b1239d20bebf02258295e189e82a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a57f8eb2a17d469d65cd1186cea26b798221d4a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adc3fd2a2277b7cc0b61692463771bf9bd298036" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/effec50381991bc067acf4b3351a57831c74d27f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json b/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json index 247fde0ed67..edc2d380dff 100644 --- a/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json +++ b/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-25fv-45mr-wm5r", - "modified": "2025-04-15T18:31:46Z", + "modified": "2025-04-16T15:34:15Z", "published": "2025-04-15T18:31:46Z", "aliases": [ "CVE-2021-27289" ], "details": "A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-294" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T18:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json b/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json new file mode 100644 index 00000000000..4c3c950a945 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2647-7h53-xfq5", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22062" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: add mutual exclusion in proc_sctp_do_udp_port()\n\nWe must serialize calls to sctp_udp_sock_stop() and sctp_udp_sock_start()\nor risk a crash as syzbot reported:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc000000000d: 0000 [#1] SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000068-0x000000000000006f]\nCPU: 1 UID: 0 PID: 6551 Comm: syz.1.44 Not tainted 6.14.0-syzkaller-g7f2ff7b62617 #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025\n RIP: 0010:kernel_sock_shutdown+0x47/0x70 net/socket.c:3653\nCall Trace:\n \n udp_tunnel_sock_release+0x68/0x80 net/ipv4/udp_tunnel_core.c:181\n sctp_udp_sock_stop+0x71/0x160 net/sctp/protocol.c:930\n proc_sctp_do_udp_port+0x264/0x450 net/sctp/sysctl.c:553\n proc_sys_call_handler+0x3d0/0x5b0 fs/proc/proc_sysctl.c:601\n iter_file_splice_write+0x91c/0x1150 fs/splice.c:738\n do_splice_from fs/splice.c:935 [inline]\n direct_splice_actor+0x18f/0x6c0 fs/splice.c:1158\n splice_direct_to_actor+0x342/0xa30 fs/splice.c:1102\n do_splice_direct_actor fs/splice.c:1201 [inline]\n do_splice_direct+0x174/0x240 fs/splice.c:1227\n do_sendfile+0xafd/0xe50 fs/read_write.c:1368\n __do_sys_sendfile64 fs/read_write.c:1429 [inline]\n __se_sys_sendfile64 fs/read_write.c:1415 [inline]\n __x64_sys_sendfile64+0x1d8/0x220 fs/read_write.c:1415\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22062" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10206302af856791fbcc27a33ed3c3eb09b2793d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3d7675d77622f6ca1aae14c51f80027b36283f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5178bfc55b3a78000f0f8298e7ade88783ce581" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efb8cb487be8f4ba6aaef616011d702d6a083ed1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-26x8-79q7-x5qq/GHSA-26x8-79q7-x5qq.json b/advisories/unreviewed/2025/04/GHSA-26x8-79q7-x5qq/GHSA-26x8-79q7-x5qq.json new file mode 100644 index 00000000000..cc5ccabe7e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-26x8-79q7-x5qq/GHSA-26x8-79q7-x5qq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26x8-79q7-x5qq", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22047" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/microcode/AMD: Fix __apply_microcode_amd()'s return value\n\nWhen verify_sha256_digest() fails, __apply_microcode_amd() should propagate\nthe failure by returning false (and not -1 which is promoted to true).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22047" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31ab12df723543047c3fc19cb8f8c4498ec6267f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/763f4d638f71cb45235395790a46e9f9e84227fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f705a45f130a85fbf31c2abdc999c65644c8307" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ada88219d5315fc13f2910fe278c7112d8d68889" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d295c58fad1d5ab987a81f139dd21498732c4f13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json b/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json new file mode 100644 index 00000000000..7bafee6dd1e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2788-7prj-r2qv", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22031" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/bwctrl: Fix NULL pointer dereference on bus number exhaustion\n\nWhen BIOS neglects to assign bus numbers to PCI bridges, the kernel\nattempts to correct that during PCI device enumeration. If it runs out\nof bus numbers, no pci_bus is allocated and the \"subordinate\" pointer in\nthe bridge's pci_dev remains NULL.\n\nThe PCIe bandwidth controller erroneously does not check for a NULL\nsubordinate pointer and dereferences it on probe.\n\nBandwidth control of unusable devices below the bridge is of questionable\nutility, so simply error out instead. This mirrors what PCIe hotplug does\nsince commit 62e4492c3063 (\"PCI: Prevent NULL dereference during pciehp\nprobe\").\n\nThe PCI core emits a message with KERN_INFO severity if it has run out of\nbus numbers. PCIe hotplug emits an additional message with KERN_ERR\nseverity to inform the user that hotplug functionality is disabled at the\nbridge. A similar message for bandwidth control does not seem merited,\ngiven that its only purpose so far is to expose an up-to-date link speed\nin sysfs and throttle the link speed on certain laptops with limited\nThermal Design Power. So error out silently.\n\nUser-visible messages:\n\n pci 0000:16:02.0: bridge configuration invalid ([bus 00-00]), reconfiguring\n [...]\n pci_bus 0000:45: busn_res: [bus 45-74] end is updated to 74\n pci 0000:16:02.0: devices behind bridge are unusable because [bus 45-74] cannot be assigned for them\n [...]\n pcieport 0000:16:02.0: pciehp: Hotplug bridge without secondary bus, ignoring\n [...]\n BUG: kernel NULL pointer dereference\n RIP: pcie_update_link_speed\n pcie_bwnotif_enable\n pcie_bwnotif_probe\n pcie_port_probe_service\n really_probe", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22031" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1181924af78e5299ddec6e457789c02dd5966559" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/667f053b05f00a007738cd7ed6fa1901de19dc7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d93d309013e89631630a12b1770d27e4be78362a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2879-fhf4-rjj6/GHSA-2879-fhf4-rjj6.json b/advisories/unreviewed/2025/04/GHSA-2879-fhf4-rjj6/GHSA-2879-fhf4-rjj6.json new file mode 100644 index 00000000000..aebc29cedb9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2879-fhf4-rjj6/GHSA-2879-fhf4-rjj6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2879-fhf4-rjj6", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22094" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/perf: Fix ref-counting on the PMU 'vpa_pmu'\n\nCommit 176cda0619b6 (\"powerpc/perf: Add perf interface to expose vpa\ncounters\") introduced 'vpa_pmu' to expose Book3s-HV nested APIv2 provided\nL1<->L2 context switch latency counters to L1 user-space via\nperf-events. However the newly introduced PMU named 'vpa_pmu' doesn't\nassign ownership of the PMU to the module 'vpa_pmu'. Consequently the\nmodule 'vpa_pmu' can be unloaded while one of the perf-events are still\nactive, which can lead to kernel oops and panic of the form below on a\nPseries-LPAR:\n\nBUG: Kernel NULL pointer dereference on read at 0x00000058\n\n NIP [c000000000506cb8] event_sched_out+0x40/0x258\n LR [c00000000050e8a4] __perf_remove_from_context+0x7c/0x2b0\n Call Trace:\n [c00000025fc3fc30] [c00000025f8457a8] 0xc00000025f8457a8 (unreliable)\n [c00000025fc3fc80] [fffffffffffffee0] 0xfffffffffffffee0\n [c00000025fc3fcd0] [c000000000501e70] event_function+0xa8/0x120\n\n Kernel panic - not syncing: Aiee, killing interrupt handler!\n\nFix this by adding the module ownership to 'vpa_pmu' so that the module\n'vpa_pmu' is ref-counted and prevented from being unloaded when perf-events\nare initialized.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22094" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6cf045b51e2c5721db7e55305f09ee32741e00f9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70ea7c5189197c6f5acdcfd8a2651be2c41e2faa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff99d5b6a246715f2257123cdf6c4a29cb33aa78" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2cqv-6948-3374/GHSA-2cqv-6948-3374.json b/advisories/unreviewed/2025/04/GHSA-2cqv-6948-3374/GHSA-2cqv-6948-3374.json new file mode 100644 index 00000000000..8227c67c1b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cqv-6948-3374/GHSA-2cqv-6948-3374.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cqv-6948-3374", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22029" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexec: fix the racy usage of fs_struct->in_exec\n\ncheck_unsafe_exec() sets fs->in_exec under cred_guard_mutex, then execve()\npaths clear fs->in_exec lockless. This is fine if exec succeeds, but if it\nfails we have the following race:\n\n\tT1 sets fs->in_exec = 1, fails, drops cred_guard_mutex\n\n\tT2 sets fs->in_exec = 1\n\n\tT1 clears fs->in_exec\n\n\tT2 continues with fs->in_exec == 0\n\nChange fs/exec.c to clear fs->in_exec with cred_guard_mutex held.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22029" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/753a620a7f8e134b444f89fe90873234e894e21a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6b5070721503fb6021ebed51c925ffc66b1c5ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af7bb0d2ca459f15cb5ca604dab5d9af103643f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b519f2e5800fe2391b7545ba6889df795828e885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2d8e7bd3314485e0b3b08380c659b3d1d67ed6a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2gxm-8qch-c9vg/GHSA-2gxm-8qch-c9vg.json b/advisories/unreviewed/2025/04/GHSA-2gxm-8qch-c9vg/GHSA-2gxm-8qch-c9vg.json new file mode 100644 index 00000000000..b3f009bf617 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2gxm-8qch-c9vg/GHSA-2gxm-8qch-c9vg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gxm-8qch-c9vg", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22113" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid journaling sb update on error if journal is destroying\n\nPresently we always BUG_ON if trying to start a transaction on a journal marked\nwith JBD2_UNMOUNT, since this should never happen. However, while ltp running\nstress tests, it was observed that in case of some error handling paths, it is\npossible for update_super_work to start a transaction after the journal is\ndestroyed eg:\n\n(umount)\next4_kill_sb\n kill_block_super\n generic_shutdown_super\n sync_filesystem /* commits all txns */\n evict_inodes\n /* might start a new txn */\n ext4_put_super\n\tflush_work(&sbi->s_sb_upd_work) /* flush the workqueue */\n jbd2_journal_destroy\n journal_kill_thread\n journal->j_flags |= JBD2_UNMOUNT;\n jbd2_journal_commit_transaction\n jbd2_journal_get_descriptor_buffer\n jbd2_journal_bmap\n ext4_journal_bmap\n ext4_map_blocks\n ...\n ext4_inode_error\n ext4_handle_error\n schedule_work(&sbi->s_sb_upd_work)\n\n /* work queue kicks in */\n update_super_work\n jbd2_journal_start\n start_this_handle\n BUG_ON(journal->j_flags &\n JBD2_UNMOUNT)\n\nHence, introduce a new mount flag to indicate journal is destroying and only do\na journaled (and deferred) update of sb if this flag is not set. Otherwise, just\nfallback to an un-journaled commit.\n\nFurther, in the journal destroy path, we have the following sequence:\n\n 1. Set mount flag indicating journal is destroying\n 2. force a commit and wait for it\n 3. flush pending sb updates\n\nThis sequence is important as it ensures that, after this point, there is no sb\nupdate that might be journaled so it is safe to update the sb outside the\njournal. (To avoid race discussed in 2d01ddc86606)\n\nAlso, we don't need a similar check in ext4_grp_locked_error since it is only\ncalled from mballoc and AFAICT it would be always valid to schedule work here.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22113" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce2f26e73783b4a7c46a86e3af5b5c8de0971790" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db05767b5bc307143d99fe2afd8c43af58d2ebef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2jfh-4hc8-cjjm/GHSA-2jfh-4hc8-cjjm.json b/advisories/unreviewed/2025/04/GHSA-2jfh-4hc8-cjjm/GHSA-2jfh-4hc8-cjjm.json new file mode 100644 index 00000000000..28c6e1dc923 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2jfh-4hc8-cjjm/GHSA-2jfh-4hc8-cjjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jfh-4hc8-cjjm", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39529" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robin Cornett Scriptless Social Sharing allows Stored XSS. This issue affects Scriptless Social Sharing: from n/a through 3.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39529" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scriptless-social-sharing/vulnerability/wordpress-scriptless-social-sharing-3-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2q2c-9vgr-84gw/GHSA-2q2c-9vgr-84gw.json b/advisories/unreviewed/2025/04/GHSA-2q2c-9vgr-84gw/GHSA-2q2c-9vgr-84gw.json new file mode 100644 index 00000000000..38234892e38 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2q2c-9vgr-84gw/GHSA-2q2c-9vgr-84gw.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q2c-9vgr-84gw", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22086" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow\n\nWhen cur_qp isn't NULL, in order to avoid fetching the QP from\nthe radix tree again we check if the next cqe QP is identical to\nthe one we already have.\n\nThe bug however is that we are checking if the QP is identical by\nchecking the QP number inside the CQE against the QP number inside the\nmlx5_ib_qp, but that's wrong since the QP number from the CQE is from\nFW so it should be matched against mlx5_core_qp which is our FW QP\nnumber.\n\nOtherwise we could use the wrong QP when handling a CQE which could\ncause the kernel trace below.\n\nThis issue is mainly noticeable over QPs 0 & 1, since for now they are\nthe only QPs in our driver whereas the QP number inside mlx5_ib_qp\ndoesn't match the QP number inside mlx5_core_qp.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000012\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] SMP\n CPU: 0 UID: 0 PID: 7927 Comm: kworker/u62:1 Not tainted 6.14.0-rc3+ #189\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n Workqueue: ib-comp-unb-wq ib_cq_poll_work [ib_core]\n RIP: 0010:mlx5_ib_poll_cq+0x4c7/0xd90 [mlx5_ib]\n Code: 03 00 00 8d 58 ff 21 cb 66 39 d3 74 39 48 c7 c7 3c 89 6e a0 0f b7 db e8 b7 d2 b3 e0 49 8b 86 60 03 00 00 48 c7 c7 4a 89 6e a0 <0f> b7 5c 98 02 e8 9f d2 b3 e0 41 0f b7 86 78 03 00 00 83 e8 01 21\n RSP: 0018:ffff88810511bd60 EFLAGS: 00010046\n RAX: 0000000000000010 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffff88885fa1b3c0 RDI: ffffffffa06e894a\n RBP: 00000000000000b0 R08: 0000000000000000 R09: ffff88810511bc10\n R10: 0000000000000001 R11: 0000000000000001 R12: ffff88810d593000\n R13: ffff88810e579108 R14: ffff888105146000 R15: 00000000000000b0\n FS: 0000000000000000(0000) GS:ffff88885fa00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000012 CR3: 00000001077e6001 CR4: 0000000000370eb0\n Call Trace:\n \n ? __die+0x20/0x60\n ? page_fault_oops+0x150/0x3e0\n ? exc_page_fault+0x74/0x130\n ? asm_exc_page_fault+0x22/0x30\n ? mlx5_ib_poll_cq+0x4c7/0xd90 [mlx5_ib]\n __ib_process_cq+0x5a/0x150 [ib_core]\n ib_cq_poll_work+0x31/0x90 [ib_core]\n process_one_work+0x169/0x320\n worker_thread+0x288/0x3a0\n ? work_busy+0xb0/0xb0\n kthread+0xd7/0x1f0\n ? kthreads_online_cpu+0x130/0x130\n ? kthreads_online_cpu+0x130/0x130\n ret_from_fork+0x2d/0x50\n ? kthreads_online_cpu+0x130/0x130\n ret_from_fork_asm+0x11/0x20\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22086" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b97d77049856865ac5ce8ffbc6e716928310f7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55c65a64aefa6267b964d90e9a4039cb68ec73a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ed3b0cb3f827072e93b4c5b6e2b8106fd7cccbd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c51a6964b45b6d40027abd77e89cef30d26dc5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/856d9e5d72dc44eca6d5a153581c58fbd84e92e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cad677085274ecf9c7565b5bfc5d2e49acbf174c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d52636eb13ccba448a752964cc6fc49970912874" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc7139b7031d877acd73d7eff55670f22f48cd5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0447ceb8a31d79bee7144f98f9a13f765531e1a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2q7g-23rp-fjwm/GHSA-2q7g-23rp-fjwm.json b/advisories/unreviewed/2025/04/GHSA-2q7g-23rp-fjwm/GHSA-2q7g-23rp-fjwm.json new file mode 100644 index 00000000000..42da48b87b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2q7g-23rp-fjwm/GHSA-2q7g-23rp-fjwm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q7g-23rp-fjwm", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22104" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Use kernel helpers for hex dumps\n\nPreviously, when the driver was printing hex dumps, the buffer was cast\nto an 8 byte long and printed using string formatters. If the buffer\nsize was not a multiple of 8 then a read buffer overflow was possible.\n\nTherefore, create a new ibmvnic function that loops over a buffer and\ncalls hex_dump_to_buffer instead.\n\nThis patch address KASAN reports like the one below:\n ibmvnic 30000003 env3: Login Buffer:\n ibmvnic 30000003 env3: 01000000af000000\n <...>\n ibmvnic 30000003 env3: 2e6d62692e736261\n ibmvnic 30000003 env3: 65050003006d6f63\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]\n Read of size 8 at addr c0000001331a9aa8 by task ip/17681\n <...>\n Allocated by task 17681:\n <...>\n ibmvnic_login+0x2f0/0xffc [ibmvnic]\n ibmvnic_open+0x148/0x308 [ibmvnic]\n __dev_open+0x1ac/0x304\n <...>\n The buggy address is located 168 bytes inside of\n allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)\n <...>\n =================================================================\n ibmvnic 30000003 env3: 000000000033766e", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22104" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae6b1d6c1acee3a2000394d83ec9f1028321e207" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d93a6caab5d7d9b5ce034d75b1e1e993338e3852" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2w3p-68xj-4hh5/GHSA-2w3p-68xj-4hh5.json b/advisories/unreviewed/2025/04/GHSA-2w3p-68xj-4hh5/GHSA-2w3p-68xj-4hh5.json new file mode 100644 index 00000000000..c0f4cee1b99 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2w3p-68xj-4hh5/GHSA-2w3p-68xj-4hh5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w3p-68xj-4hh5", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-22128" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: Clear affinity hint before calling ath12k_pci_free_irq() in error path\n\nIf a shared IRQ is used by the driver due to platform limitation, then the\nIRQ affinity hint is set right after the allocation of IRQ vectors in\nath12k_pci_msi_alloc(). This does no harm unless one of the functions\nrequesting the IRQ fails and attempt to free the IRQ.\n\nThis may end up with a warning from the IRQ core that is expecting the\naffinity hint to be cleared before freeing the IRQ:\n\nkernel/irq/manage.c:\n\n\t/* make sure affinity_hint is cleaned up */\n\tif (WARN_ON_ONCE(desc->affinity_hint))\n\t\tdesc->affinity_hint = NULL;\n\nSo to fix this issue, clear the IRQ affinity hint before calling\nath12k_pci_free_irq() in the error path. The affinity will be cleared once\nagain further down the error path due to code organization, but that does\nno harm.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22128" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35b33ba76765ce9e72949d957f3cf1feafd2955c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b43b1e2c52db77c872bd60d30cdcc72c47df70c7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3299-q63p-824w/GHSA-3299-q63p-824w.json b/advisories/unreviewed/2025/04/GHSA-3299-q63p-824w/GHSA-3299-q63p-824w.json new file mode 100644 index 00000000000..8ea3754d787 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3299-q63p-824w/GHSA-3299-q63p-824w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3299-q63p-824w", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23131" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: prevent NPD when writing a positive value to event_done\n\ndo_uevent returns the value written to event_done. In case it is a\npositive value, new_lockspace would undo all the work, and lockspace\nwould not be set. __dlm_new_lockspace, however, would treat that\npositive value as a success due to commit 8511a2728ab8 (\"dlm: fix use\ncount with multiple joins\").\n\nDown the line, device_create_lockspace would pass that NULL lockspace to\ndlm_find_lockspace_local, leading to a NULL pointer dereference.\n\nTreating such positive values as successes prevents the problem. Given\nthis has been broken for so long, this is unlikely to break userspace\nexpectations.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23131" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e2bad543eca5c25cd02cbc63d72557934d45f13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b73c4ad4d387fe5bc988145bd9f1bc0de76afd5c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-35r5-x2r5-c49q/GHSA-35r5-x2r5-c49q.json b/advisories/unreviewed/2025/04/GHSA-35r5-x2r5-c49q/GHSA-35r5-x2r5-c49q.json new file mode 100644 index 00000000000..8116825aa2d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35r5-x2r5-c49q/GHSA-35r5-x2r5-c49q.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35r5-x2r5-c49q", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22043" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add bounds check for durable handle context\n\nAdd missing bounds check for durable handle context.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22043" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1107b9ed92194603593c51829a3887812ae9e806" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/29b946714d6aa77de54c71243bba39469ac43ef2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/542027e123fc0bfd61dd59e21ae0ee4ef2101b29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d4848c45943c9cf5e86142fd7347efa97f497db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0db3d9d416e332a0d6f045a1509539d3a4cd898" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3ggp-43f5-88mv/GHSA-3ggp-43f5-88mv.json b/advisories/unreviewed/2025/04/GHSA-3ggp-43f5-88mv/GHSA-3ggp-43f5-88mv.json new file mode 100644 index 00000000000..d9cfb35e6c3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3ggp-43f5-88mv/GHSA-3ggp-43f5-88mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ggp-43f5-88mv", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39574" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UIUX Lab Uix Shortcodes allows Stored XSS. This issue affects Uix Shortcodes: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39574" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uix-shortcodes/vulnerability/wordpress-uix-shortcodes-2-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3vmv-8wv7-jffx/GHSA-3vmv-8wv7-jffx.json b/advisories/unreviewed/2025/04/GHSA-3vmv-8wv7-jffx/GHSA-3vmv-8wv7-jffx.json new file mode 100644 index 00000000000..b353eb702f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3vmv-8wv7-jffx/GHSA-3vmv-8wv7-jffx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vmv-8wv7-jffx", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39516" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alan Petersen Author WIP Progress Bar allows DOM-Based XSS. This issue affects Author WIP Progress Bar: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39516" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/author-work-in-progress-bar/vulnerability/wordpress-author-wip-progress-bar-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3w79-f82r-vfcx/GHSA-3w79-f82r-vfcx.json b/advisories/unreviewed/2025/04/GHSA-3w79-f82r-vfcx/GHSA-3w79-f82r-vfcx.json new file mode 100644 index 00000000000..e80c65f77b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w79-f82r-vfcx/GHSA-3w79-f82r-vfcx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w79-f82r-vfcx", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22103" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix NULL pointer dereference in l3mdev_l3_rcv\n\nWhen delete l3s ipvlan:\n\n ip link del link eth0 ipvlan1 type ipvlan mode l3s\n\nThis may cause a null pointer dereference:\n\n Call trace:\n ip_rcv_finish+0x48/0xd0\n ip_rcv+0x5c/0x100\n __netif_receive_skb_one_core+0x64/0xb0\n __netif_receive_skb+0x20/0x80\n process_backlog+0xb4/0x204\n napi_poll+0xe8/0x294\n net_rx_action+0xd8/0x22c\n __do_softirq+0x12c/0x354\n\nThis is because l3mdev_l3_rcv() visit dev->l3mdev_ops after\nipvlan_l3s_unregister() assign the dev->l3mdev_ops to NULL. The process\nlike this:\n\n (CPU1) | (CPU2)\n l3mdev_l3_rcv() |\n check dev->priv_flags: |\n master = skb->dev; |\n |\n | ipvlan_l3s_unregister()\n | set dev->priv_flags\n | dev->l3mdev_ops = NULL;\n |\n visit master->l3mdev_ops |\n\nTo avoid this by do not set dev->l3mdev_ops when unregister l3s ipvlan.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22103" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0032c99e83b9ce6d5995d65900aa4b6ffb501cce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9dff65140efc289f01bcf39c3ca66a8806b6132" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3w95-jpf5-784j/GHSA-3w95-jpf5-784j.json b/advisories/unreviewed/2025/04/GHSA-3w95-jpf5-784j/GHSA-3w95-jpf5-784j.json new file mode 100644 index 00000000000..af27c0fe654 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w95-jpf5-784j/GHSA-3w95-jpf5-784j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w95-jpf5-784j", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39570" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcom-member/vulnerability/wordpress-wpcom-member-1-7-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3wj6-wmrj-4chx/GHSA-3wj6-wmrj-4chx.json b/advisories/unreviewed/2025/04/GHSA-3wj6-wmrj-4chx/GHSA-3wj6-wmrj-4chx.json new file mode 100644 index 00000000000..4a8f06e6967 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3wj6-wmrj-4chx/GHSA-3wj6-wmrj-4chx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wj6-wmrj-4chx", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39522" + ], + "details": "Missing Authorization vulnerability in Sebastian Lee Dynamic Post allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Dynamic Post: from n/a through 4.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39522" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dynamic-post/vulnerability/wordpress-dynamic-post-4-10-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3wr8-w2fq-6q7v/GHSA-3wr8-w2fq-6q7v.json b/advisories/unreviewed/2025/04/GHSA-3wr8-w2fq-6q7v/GHSA-3wr8-w2fq-6q7v.json new file mode 100644 index 00000000000..a4f46c5ddfe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3wr8-w2fq-6q7v/GHSA-3wr8-w2fq-6q7v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wr8-w2fq-6q7v", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-22125" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1,raid10: don't ignore IO flags\n\nIf blk-wbt is enabled by default, it's found that raid write performance\nis quite bad because all IO are throttled by wbt of underlying disks,\ndue to flag REQ_IDLE is ignored. And turns out this behaviour exist since\nblk-wbt is introduced.\n\nOther than REQ_IDLE, other flags should not be ignored as well, for\nexample REQ_META can be set for filesystems, clearing it can cause priority\nreverse problems; And REQ_NOWAIT should not be cleared as well, because\nio will wait instead of failing directly in underlying disks.\n\nFix those problems by keep IO flags from master bio.\n\nFises: f51d46d0e7cb (\"md: add support for REQ_NOWAIT\")", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22125" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a0adf3d778c4a0893c6d34a9e1b0082a6f1c495" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e879a0d9cb086c8e52ce6c04e5bfa63825a6213c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4297-r96p-57pp/GHSA-4297-r96p-57pp.json b/advisories/unreviewed/2025/04/GHSA-4297-r96p-57pp/GHSA-4297-r96p-57pp.json new file mode 100644 index 00000000000..85c3459e082 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4297-r96p-57pp/GHSA-4297-r96p-57pp.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4297-r96p-57pp", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22034" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs\n\nPatch series \"mm: fixes for device-exclusive entries (hmm)\", v2.\n\nDiscussing the PageTail() call in make_device_exclusive_range() with\nWilly, I recently discovered [1] that device-exclusive handling does not\nproperly work with THP, making the hmm-tests selftests fail if THPs are\nenabled on the system.\n\nLooking into more details, I found that hugetlb is not properly fenced,\nand I realized that something that was bugging me for longer -- how\ndevice-exclusive entries interact with mapcounts -- completely breaks\nmigration/swapout/split/hwpoison handling of these folios while they have\ndevice-exclusive PTEs.\n\nThe program below can be used to allocate 1 GiB worth of pages and making\nthem device-exclusive on a kernel with CONFIG_TEST_HMM.\n\nOnce they are device-exclusive, these folios cannot get swapped out\n(proc$pid/smaps_rollup will always indicate 1 GiB RSS no matter how much\none forces memory reclaim), and when having a memory block onlined to\nZONE_MOVABLE, trying to offline it will loop forever and complain about\nfailed migration of a page that should be movable.\n\n# echo offline > /sys/devices/system/memory/memory136/state\n# echo online_movable > /sys/devices/system/memory/memory136/state\n# ./hmm-swap &\n... wait until everything is device-exclusive\n# echo offline > /sys/devices/system/memory/memory136/state\n[ 285.193431][T14882] page: refcount:2 mapcount:0 mapping:0000000000000000\n index:0x7f20671f7 pfn:0x442b6a\n[ 285.196618][T14882] memcg:ffff888179298000\n[ 285.198085][T14882] anon flags: 0x5fff0000002091c(referenced|uptodate|\n dirty|active|owner_2|swapbacked|node=1|zone=3|lastcpupid=0x7ff)\n[ 285.201734][T14882] raw: ...\n[ 285.204464][T14882] raw: ...\n[ 285.207196][T14882] page dumped because: migration failure\n[ 285.209072][T14882] page_owner tracks the page as allocated\n[ 285.210915][T14882] page last allocated via order 0, migratetype\n Movable, gfp_mask 0x140dca(GFP_HIGHUSER_MOVABLE|__GFP_COMP|__GFP_ZERO),\n id 14926, tgid 14926 (hmm-swap), ts 254506295376, free_ts 227402023774\n[ 285.216765][T14882] post_alloc_hook+0x197/0x1b0\n[ 285.218874][T14882] get_page_from_freelist+0x76e/0x3280\n[ 285.220864][T14882] __alloc_frozen_pages_noprof+0x38e/0x2740\n[ 285.223302][T14882] alloc_pages_mpol+0x1fc/0x540\n[ 285.225130][T14882] folio_alloc_mpol_noprof+0x36/0x340\n[ 285.227222][T14882] vma_alloc_folio_noprof+0xee/0x1a0\n[ 285.229074][T14882] __handle_mm_fault+0x2b38/0x56a0\n[ 285.230822][T14882] handle_mm_fault+0x368/0x9f0\n...\n\nThis series fixes all issues I found so far. There is no easy way to fix\nwithout a bigger rework/cleanup. I have a bunch of cleanups on top (some\nprevious sent, some the result of the discussion in v1) that I will send\nout separately once this landed and I get to it.\n\nI wish we could just use some special present PROT_NONE PTEs instead of\nthese (non-present, non-none) fake-swap entries; but that just results in\nthe same problem we keep having (lack of spare PTE bits), and staring at\nother similar fake-swap entries, that ship has sailed.\n\nWith this series, make_device_exclusive() doesn't actually belong into\nmm/rmap.c anymore, but I'll leave moving that for another day.\n\nI only tested this series with the hmm-tests selftests due to lack of HW,\nso I'd appreciate some testing, especially if the interaction between two\nGPUs wanting a device-exclusive entry works as expected.\n\n\n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n\n#define HMM_DMIRROR_EXCLUSIVE _IOWR('H', 0x05, struct hmm_dmirror_cmd)\n\nstruct hmm_dmirror_cmd {\n\t__u64 addr;\n\t__u64 ptr;\n\t__u64 npages;\n\t__u64 cpages;\n\t__u64 faults;\n};\n\nconst size_t size = 1 * 1024 * 1024 * 1024ul;\nconst size_t chunk_size = 2 * 1024 * 1024ul;\n\nint m\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22034" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e877ff3492267def06dd50cb165dc9ab8838e7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48d28417c66cce2f3b0ba773fcb6695a56eff220" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8977752c8056a6a094a279004a49722da15bace3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd900832e8440046627b60697687ab5d04398008" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-45jg-8873-4f8h/GHSA-45jg-8873-4f8h.json b/advisories/unreviewed/2025/04/GHSA-45jg-8873-4f8h/GHSA-45jg-8873-4f8h.json new file mode 100644 index 00000000000..bf5b56a59b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-45jg-8873-4f8h/GHSA-45jg-8873-4f8h.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45jg-8873-4f8h", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22078" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: vchiq_arm: Fix possible NPR of keep-alive thread\n\nIn case vchiq_platform_conn_state_changed() is never called or fails before\ndriver removal, ka_thread won't be a valid pointer to a task_struct. So\ndo the necessary checks before calling kthread_stop to avoid a crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22078" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1817c4b85011998604e5ff9a80a6e01adb7e7e81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3db89bc6d973e2bcaa852f6409c98c228f39a926" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a915c896f95a989a7759a73f8c064f5dc3775175" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd38395b901327f77a82112f006240de22cf2ceb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-48f7-49jv-jj2v/GHSA-48f7-49jv-jj2v.json b/advisories/unreviewed/2025/04/GHSA-48f7-49jv-jj2v/GHSA-48f7-49jv-jj2v.json new file mode 100644 index 00000000000..79e957187e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-48f7-49jv-jj2v/GHSA-48f7-49jv-jj2v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48f7-49jv-jj2v", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22124" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb\n\nIn clustermd, separate write-intent-bitmaps are used for each cluster\nnode:\n\n0 4k 8k 12k\n-------------------------------------------------------------------\n| idle | md super | bm super [0] + bits |\n| bm bits[0, contd] | bm super[1] + bits | bm bits[1, contd] |\n| bm super[2] + bits | bm bits [2, contd] | bm super[3] + bits |\n| bm bits [3, contd] | | |\n\nSo in node 1, pg_index in __write_sb_page() could equal to\nbitmap->storage.file_pages. Then bitmap_limit will be calculated to\n0. md_super_write() will be called with 0 size.\nThat means the first 4k sb area of node 1 will never be updated\nthrough filemap_write_page().\nThis bug causes hang of mdadm/clustermd_tests/01r1_Grow_resize.\n\nHere use (pg_index % bitmap->storage.file_pages) to make calculation\nof bitmap_limit correct.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22124" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6130825f34d41718c98a9b1504a79a23e379701e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc3a9788961631359527763d7e1fcf26554c7cb1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json b/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json new file mode 100644 index 00000000000..cc864ccdf3d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hwj-3ppp-cx8v", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22036" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix random stack corruption after get_block\n\nWhen get_block is called with a buffer_head allocated on the stack, such\nas do_mpage_readpage, stack corruption due to buffer_head UAF may occur in\nthe following race condition situation.\n\n \nmpage_read_folio\n <>\n do_mpage_readpage\n exfat_get_block\n bh_read\n __bh_read\n\t get_bh(bh)\n submit_bh\n wait_on_buffer\n ...\n end_buffer_read_sync\n __end_buffer_read_notouch\n unlock_buffer\n <>\n ...\n ...\n ...\n ...\n<>\n .\n .\nanother_function\n <>\n put_bh(bh)\n atomic_dec(bh->b_count)\n * stack corruption here *\n\nThis patch returns -EAGAIN if a folio does not have buffers when bh_read\nneeds to be called. By doing this, the caller can fallback to functions\nlike block_read_full_folio(), create a buffer_head in the folio, and then\ncall get_block again.\n\nLet's do not call bh_read() with on-stack buffer_head.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22036" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bb7ff4204b6d4927e982cd256286c09ed4fd8ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49b0a6ab8e528a0c1c50e37cef9b9c7c121365f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7447286363dc1e410bf30b87d75168f3519f9cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f807a6bf2005740fa26b4f59c4a003dc966b9afd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4vfw-gvwq-xw7v/GHSA-4vfw-gvwq-xw7v.json b/advisories/unreviewed/2025/04/GHSA-4vfw-gvwq-xw7v/GHSA-4vfw-gvwq-xw7v.json new file mode 100644 index 00000000000..ff2e9397bef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4vfw-gvwq-xw7v/GHSA-4vfw-gvwq-xw7v.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vfw-gvwq-xw7v", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22048" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Don't override subprog's return value\n\nThe verifier test `calls: div by 0 in subprog` triggers a panic at the\nld.bu instruction. The ld.bu insn is trying to load byte from memory\naddress returned by the subprog. The subprog actually set the correct\naddress at the a5 register (dedicated register for BPF return values).\nBut at commit 73c359d1d356 (\"LoongArch: BPF: Sign-extend return values\")\nwe also sign extended a5 to the a0 register (return value in LoongArch).\nFor function call insn, we later propagate the a0 register back to a5\nregister. This is right for native calls but wrong for bpf2bpf calls\nwhich expect zero-extended return value in a5 register. So only move a0\nto a5 for native calls (i.e. non-BPF_PSEUDO_CALL).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22048" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/223d565d8892481684091cfbaf3466f2b0e289d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60f3caff1492e5b8616b9578c4bedb5c0a88ed14" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/780628a780b622759d9e5adc76d15432144da1a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7df2696256a034405d3c5a71b3a4c54725de4404" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/996e90ab446641553e8e21707b38b9709605e0e0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-526j-rpwr-89fg/GHSA-526j-rpwr-89fg.json b/advisories/unreviewed/2025/04/GHSA-526j-rpwr-89fg/GHSA-526j-rpwr-89fg.json new file mode 100644 index 00000000000..50aa083f12d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-526j-rpwr-89fg/GHSA-526j-rpwr-89fg.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-526j-rpwr-89fg", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22090" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range()\n\nIf track_pfn_copy() fails, we already added the dst VMA to the maple\ntree. As fork() fails, we'll cleanup the maple tree, and stumble over\nthe dst VMA for which we neither performed any reservation nor copied\nany page tables.\n\nConsequently untrack_pfn() will see VM_PAT and try obtaining the\nPAT information from the page table -- which fails because the page\ntable was not copied.\n\nThe easiest fix would be to simply clear the VM_PAT flag of the dst VMA\nif track_pfn_copy() fails. However, the whole thing is about \"simply\"\nclearing the VM_PAT flag is shaky as well: if we passed track_pfn_copy()\nand performed a reservation, but copying the page tables fails, we'll\nsimply clear the VM_PAT flag, not properly undoing the reservation ...\nwhich is also wrong.\n\nSo let's fix it properly: set the VM_PAT flag only if the reservation\nsucceeded (leaving it clear initially), and undo the reservation if\nanything goes wrong while copying the page tables: clearing the VM_PAT\nflag after undoing the reservation.\n\nNote that any copied page table entries will get zapped when the VMA will\nget removed later, after copy_page_range() succeeded; as VM_PAT is not set\nthen, we won't try cleaning VM_PAT up once more and untrack_pfn() will be\nhappy. Note that leaving these page tables in place without a reservation\nis not a problem, as we are aborting fork(); this process will never run.\n\nA reproducer can trigger this usually at the first try:\n\n https://gitlab.com/davidhildenbrand/scratchspace/-/raw/main/reproducers/pat_fork.c\n\n WARNING: CPU: 26 PID: 11650 at arch/x86/mm/pat/memtype.c:983 get_pat_info+0xf6/0x110\n Modules linked in: ...\n CPU: 26 UID: 0 PID: 11650 Comm: repro3 Not tainted 6.12.0-rc5+ #92\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\n RIP: 0010:get_pat_info+0xf6/0x110\n ...\n Call Trace:\n \n ...\n untrack_pfn+0x52/0x110\n unmap_single_vma+0xa6/0xe0\n unmap_vmas+0x105/0x1f0\n exit_mmap+0xf6/0x460\n __mmput+0x4b/0x120\n copy_process+0x1bf6/0x2aa0\n kernel_clone+0xab/0x440\n __do_sys_clone+0x66/0x90\n do_syscall_64+0x95/0x180\n\nLikely this case was missed in:\n\n d155df53f310 (\"x86/mm/pat: clear VM_PAT if copy_p4d_range failed\")\n\n... and instead of undoing the reservation we simply cleared the VM_PAT flag.\n\nKeep the documentation of these functions in include/linux/pgtable.h,\none place is more than sufficient -- we should clean that up for the other\nfunctions like track_pfn_remap/untrack_pfn separately.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22090" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d6373f83f367dbed316ddeb178130a3a64b5b67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b07398e8a5da517083f5c3f2daa8f6681b48ab28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da381c33f3aa6406406c9fdf07b8b0b63e0ce722" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc84bc2aba85a1508f04a936f9f9a15f64ebfb31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de6185b8892d88142ef69768fe4077cbf40109c0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-558x-x2cc-cqp6/GHSA-558x-x2cc-cqp6.json b/advisories/unreviewed/2025/04/GHSA-558x-x2cc-cqp6/GHSA-558x-x2cc-cqp6.json new file mode 100644 index 00000000000..c34bbfea2a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-558x-x2cc-cqp6/GHSA-558x-x2cc-cqp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-558x-x2cc-cqp6", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39572" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Checkout for PayPal allows Stored XSS. This issue affects Checkout for PayPal: from n/a through 1.0.38.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39572" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/checkout-for-paypal/vulnerability/wordpress-checkout-for-paypal-1-0-38-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json b/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json new file mode 100644 index 00000000000..1bb1b50f7a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5659-626r-mfvx", + "modified": "2025-04-16T15:34:47Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23136" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: int340x: Add NULL check for adev\n\nNot all devices have an ACPI companion fwnode, so adev might be NULL.\nThis is similar to the commit cd2fd6eab480\n(\"platform/x86: int3472: Check for adev == NULL\").\n\nAdd a check for adev not being set and return -ENODEV in that case to\navoid a possible NULL pointer deref in int3402_thermal_probe().\n\nNote, under the same directory, int3400_thermal_probe() has such a\ncheck.\n\n[ rjw: Subject edit, added Fixes: ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23136" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c49f12c77b77a706fd41370c11910635e491845" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2542a3f70e563a9e70e7ded314286535a3321bdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3155d5261b518776d1b807d9d922669991bbee56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a810c462f099353e908c70619638884cb82229c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e8f1ddf4186731649df8bc9646017369eb19186" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/953d28a4f459fcbde2d08f51aeca19d6b0f179f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac2eb7378319e3836cdf3a2c15a0bdf04c50e81d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc7b5f782d28942dbdfda70df30ce132694a06de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0d21c8e44216fa9afdb3809edf213f3c0a8c060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59g4-mvcc-7p3x/GHSA-59g4-mvcc-7p3x.json b/advisories/unreviewed/2025/04/GHSA-59g4-mvcc-7p3x/GHSA-59g4-mvcc-7p3x.json new file mode 100644 index 00000000000..3abab8ab76c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59g4-mvcc-7p3x/GHSA-59g4-mvcc-7p3x.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59g4-mvcc-7p3x", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22053" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ibmveth: make veth_pool_store stop hanging\n\nv2:\n- Created a single error handling unlock and exit in veth_pool_store\n- Greatly expanded commit message with previous explanatory-only text\n\nSummary: Use rtnl_mutex to synchronize veth_pool_store with itself,\nibmveth_close and ibmveth_open, preventing multiple calls in a row to\nnapi_disable.\n\nBackground: Two (or more) threads could call veth_pool_store through\nwriting to /sys/devices/vio/30000002/pool*/*. You can do this easily\nwith a little shell script. This causes a hang.\n\nI configured LOCKDEP, compiled ibmveth.c with DEBUG, and built a new\nkernel. I ran this test again and saw:\n\n Setting pool0/active to 0\n Setting pool1/active to 1\n [ 73.911067][ T4365] ibmveth 30000002 eth0: close starting\n Setting pool1/active to 1\n Setting pool1/active to 0\n [ 73.911367][ T4366] ibmveth 30000002 eth0: close starting\n [ 73.916056][ T4365] ibmveth 30000002 eth0: close complete\n [ 73.916064][ T4365] ibmveth 30000002 eth0: open starting\n [ 110.808564][ T712] systemd-journald[712]: Sent WATCHDOG=1 notification.\n [ 230.808495][ T712] systemd-journald[712]: Sent WATCHDOG=1 notification.\n [ 243.683786][ T123] INFO: task stress.sh:4365 blocked for more than 122 seconds.\n [ 243.683827][ T123] Not tainted 6.14.0-01103-g2df0c02dab82-dirty #8\n [ 243.683833][ T123] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n [ 243.683838][ T123] task:stress.sh state:D stack:28096 pid:4365 tgid:4365 ppid:4364 task_flags:0x400040 flags:0x00042000\n [ 243.683852][ T123] Call Trace:\n [ 243.683857][ T123] [c00000000c38f690] [0000000000000001] 0x1 (unreliable)\n [ 243.683868][ T123] [c00000000c38f840] [c00000000001f908] __switch_to+0x318/0x4e0\n [ 243.683878][ T123] [c00000000c38f8a0] [c000000001549a70] __schedule+0x500/0x12a0\n [ 243.683888][ T123] [c00000000c38f9a0] [c00000000154a878] schedule+0x68/0x210\n [ 243.683896][ T123] [c00000000c38f9d0] [c00000000154ac80] schedule_preempt_disabled+0x30/0x50\n [ 243.683904][ T123] [c00000000c38fa00] [c00000000154dbb0] __mutex_lock+0x730/0x10f0\n [ 243.683913][ T123] [c00000000c38fb10] [c000000001154d40] napi_enable+0x30/0x60\n [ 243.683921][ T123] [c00000000c38fb40] [c000000000f4ae94] ibmveth_open+0x68/0x5dc\n [ 243.683928][ T123] [c00000000c38fbe0] [c000000000f4aa20] veth_pool_store+0x220/0x270\n [ 243.683936][ T123] [c00000000c38fc70] [c000000000826278] sysfs_kf_write+0x68/0xb0\n [ 243.683944][ T123] [c00000000c38fcb0] [c0000000008240b8] kernfs_fop_write_iter+0x198/0x2d0\n [ 243.683951][ T123] [c00000000c38fd00] [c00000000071b9ac] vfs_write+0x34c/0x650\n [ 243.683958][ T123] [c00000000c38fdc0] [c00000000071bea8] ksys_write+0x88/0x150\n [ 243.683966][ T123] [c00000000c38fe10] [c0000000000317f4] system_call_exception+0x124/0x340\n [ 243.683973][ T123] [c00000000c38fe50] [c00000000000d05c] system_call_vectored_common+0x15c/0x2ec\n ...\n [ 243.684087][ T123] Showing all locks held in the system:\n [ 243.684095][ T123] 1 lock held by khungtaskd/123:\n [ 243.684099][ T123] #0: c00000000278e370 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x50/0x248\n [ 243.684114][ T123] 4 locks held by stress.sh/4365:\n [ 243.684119][ T123] #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150\n [ 243.684132][ T123] #1: c000000041aea888 (&of->mutex#2){+.+.}-{3:3}, at: kernfs_fop_write_iter+0x154/0x2d0\n [ 243.684143][ T123] #2: c0000000366fb9a8 (kn->active#64){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x160/0x2d0\n [ 243.684155][ T123] #3: c000000035ff4cb8 (&dev->lock){+.+.}-{3:3}, at: napi_enable+0x30/0x60\n [ 243.684166][ T123] 5 locks held by stress.sh/4366:\n [ 243.684170][ T123] #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150\n [ 243.\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22053" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/053f3ff67d7feefc75797863f3d84b47ad47086f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a2470e3ecde64fc7e3781dc474923193621ae67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e458c292f4c687dcf5aad32dd4836d03cd2191f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86cc70f5c85dc09bf7f3e1eee380eefe73c90765" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a88bb092f4208355880b9fdcc69d491aa297595" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5fx5-c375-9927/GHSA-5fx5-c375-9927.json b/advisories/unreviewed/2025/04/GHSA-5fx5-c375-9927/GHSA-5fx5-c375-9927.json new file mode 100644 index 00000000000..444b976b0a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5fx5-c375-9927/GHSA-5fx5-c375-9927.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fx5-c375-9927", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23133" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: update channel list in reg notifier instead reg worker\n\nCurrently when ath11k gets a new channel list, it will be processed\naccording to the following steps:\n1. update new channel list to cfg80211 and queue reg_work.\n2. cfg80211 handles new channel list during reg_work.\n3. update cfg80211's handled channel list to firmware by\nath11k_reg_update_chan_list().\n\nBut ath11k will immediately execute step 3 after reg_work is just\nqueued. Since step 2 is asynchronous, cfg80211 may not have completed\nhandling the new channel list, which may leading to an out-of-bounds\nwrite error:\nBUG: KASAN: slab-out-of-bounds in ath11k_reg_update_chan_list\nCall Trace:\n ath11k_reg_update_chan_list+0xbfe/0xfe0 [ath11k]\n kfree+0x109/0x3a0\n ath11k_regd_update+0x1cf/0x350 [ath11k]\n ath11k_regd_update_work+0x14/0x20 [ath11k]\n process_one_work+0xe35/0x14c0\n\nShould ensure step 2 is completely done before executing step 3. Thus\nWen raised patch[1]. When flag NL80211_REGDOM_SET_BY_DRIVER is set,\ncfg80211 will notify ath11k after step 2 is done.\n\nSo enable the flag NL80211_REGDOM_SET_BY_DRIVER then cfg80211 will\nnotify ath11k after step 2 is done. At this time, there will be no\nKASAN bug during the execution of the step 3.\n\n[1] https://patchwork.kernel.org/project/linux-wireless/patch/20230201065313.27203-1-quic_wgong@quicinc.com/\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23133" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/933ab187e679e6fbdeea1835ae39efcc59c022d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f952fb83c9c6f908d27500764c4aee1df04b9d3f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5g5j-4w29-mr24/GHSA-5g5j-4w29-mr24.json b/advisories/unreviewed/2025/04/GHSA-5g5j-4w29-mr24/GHSA-5g5j-4w29-mr24.json new file mode 100644 index 00000000000..a3e6c197ff1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5g5j-4w29-mr24/GHSA-5g5j-4w29-mr24.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g5j-4w29-mr24", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22097" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vkms: Fix use after free and double free on init error\n\nIf the driver initialization fails, the vkms_exit() function might\naccess an uninitialized or freed default_config pointer and it might\ndouble free it.\n\nFix both possible errors by initializing default_config only when the\ndriver initialization succeeded.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22097" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f68f1cf09d06061eb549726ff8339e064eddebd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49a69f67f53518bdd9b7eeebf019a2da6cc0e954" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/561fc0c5cf41f646f3e9e61784cbc0fc832fb936" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79d138d137b80eeb0a83244d1cff29e64cf91067" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8a18bb53e06d6d3c1fd03d12533d6e333ba8853" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5eb8e347905ab17788a7903fa1d3d06747355f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed15511a773df86205bda66c37193569575ae828" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5h75-5c4v-wwm8/GHSA-5h75-5c4v-wwm8.json b/advisories/unreviewed/2025/04/GHSA-5h75-5c4v-wwm8/GHSA-5h75-5c4v-wwm8.json new file mode 100644 index 00000000000..5d22c3a79d7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5h75-5c4v-wwm8/GHSA-5h75-5c4v-wwm8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h75-5c4v-wwm8", + "modified": "2025-04-16T15:34:47Z", + "published": "2025-04-16T15:34:47Z", + "aliases": [ + "CVE-2025-3696" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /search/search_stock. php. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3696" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/sql_inject_in_search.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304984" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304984" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553579" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5mmh-2695-w96v/GHSA-5mmh-2695-w96v.json b/advisories/unreviewed/2025/04/GHSA-5mmh-2695-w96v/GHSA-5mmh-2695-w96v.json index f2485a9e06e..41bdf364881 100644 --- a/advisories/unreviewed/2025/04/GHSA-5mmh-2695-w96v/GHSA-5mmh-2695-w96v.json +++ b/advisories/unreviewed/2025/04/GHSA-5mmh-2695-w96v/GHSA-5mmh-2695-w96v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-5q5m-hp58-38wm/GHSA-5q5m-hp58-38wm.json b/advisories/unreviewed/2025/04/GHSA-5q5m-hp58-38wm/GHSA-5q5m-hp58-38wm.json new file mode 100644 index 00000000000..0b9b8a9d57d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5q5m-hp58-38wm/GHSA-5q5m-hp58-38wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q5m-hp58-38wm", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39576" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts allows Stored XSS. This issue affects WPAdverts: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpadverts/vulnerability/wordpress-wpadverts-2-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json b/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json new file mode 100644 index 00000000000..dfbb4fd9756 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v57-87fw-9gxc", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22033" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: Don't call NULL in do_compat_alignment_fixup()\n\ndo_alignment_t32_to_handler() only fixes up alignment faults for\nspecific instructions; it returns NULL otherwise (e.g. LDREX). When\nthat's the case, signal to the caller that it needs to proceed with the\nregular alignment fault handling (i.e. SIGBUS). Without this patch, the\nkernel panics:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Mem abort info:\n ESR = 0x0000000086000006\n EC = 0x21: IABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x06: level 2 translation fault\n user pgtable: 4k pages, 48-bit VAs, pgdp=00000800164aa000\n [0000000000000000] pgd=0800081fdbd22003, p4d=0800081fdbd22003, pud=08000815d51c6003, pmd=0000000000000000\n Internal error: Oops: 0000000086000006 [#1] SMP\n Modules linked in: cfg80211 rfkill xt_nat xt_tcpudp xt_conntrack nft_chain_nat xt_MASQUERADE nf_nat nf_conntrack_netlink nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xfrm_user xfrm_algo xt_addrtype nft_compat br_netfilter veth nvme_fa>\n libcrc32c crc32c_generic raid0 multipath linear dm_mod dax raid1 md_mod xhci_pci nvme xhci_hcd nvme_core t10_pi usbcore igb crc64_rocksoft crc64 crc_t10dif crct10dif_generic crct10dif_ce crct10dif_common usb_common i2c_algo_bit i2c>\n CPU: 2 PID: 3932954 Comm: WPEWebProcess Not tainted 6.1.0-31-arm64 #1 Debian 6.1.128-1\n Hardware name: GIGABYTE MP32-AR1-00/MP32-AR1-00, BIOS F18v (SCP: 1.08.20211002) 12/01/2021\n pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : 0x0\n lr : do_compat_alignment_fixup+0xd8/0x3dc\n sp : ffff80000f973dd0\n x29: ffff80000f973dd0 x28: ffff081b42526180 x27: 0000000000000000\n x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n x23: 0000000000000004 x22: 0000000000000000 x21: 0000000000000001\n x20: 00000000e8551f00 x19: ffff80000f973eb0 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : ffffaebc949bc488\n x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000400000 x4 : 0000fffffffffffe x3 : 0000000000000000\n x2 : ffff80000f973eb0 x1 : 00000000e8551f00 x0 : 0000000000000001\n Call trace:\n 0x0\n do_alignment_fault+0x40/0x50\n do_mem_abort+0x4c/0xa0\n el0_da+0x48/0xf0\n el0t_32_sync_handler+0x110/0x140\n el0t_32_sync+0x190/0x194\n Code: bad PC value\n ---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22033" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2df8ee605eb6806cd41c2095306db05206633a08" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/617a4b0084a547917669fef2b54253cc9c064990" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c28f31deeacda307acfee2f18c0ad904e5123aac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf187601053ecaf671ae645edb898901f81d03e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecf798573bbe0805803f7764e12a34b4bcc65074" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa2a9f625f185c6acb4ee5be8d71359a567afac9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vc9-m9gx-8qqw/GHSA-5vc9-m9gx-8qqw.json b/advisories/unreviewed/2025/04/GHSA-5vc9-m9gx-8qqw/GHSA-5vc9-m9gx-8qqw.json new file mode 100644 index 00000000000..4fa974ed213 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5vc9-m9gx-8qqw/GHSA-5vc9-m9gx-8qqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vc9-m9gx-8qqw", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39549" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in whiletrue Most And Least Read Posts Widget allows Stored XSS. This issue affects Most And Least Read Posts Widget: from n/a through 2.5.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/most-and-least-read-posts-widget/vulnerability/wordpress-most-and-least-read-posts-widget-2-5-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vpj-4f48-j8qc/GHSA-5vpj-4f48-j8qc.json b/advisories/unreviewed/2025/04/GHSA-5vpj-4f48-j8qc/GHSA-5vpj-4f48-j8qc.json new file mode 100644 index 00000000000..60d49250e26 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5vpj-4f48-j8qc/GHSA-5vpj-4f48-j8qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vpj-4f48-j8qc", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39514" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Forum allows Stored XSS. This issue affects Asgaros Forum: from n/a through 3.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/asgaros-forum/vulnerability/wordpress-asgaros-forum-3-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vwg-96q8-mm82/GHSA-5vwg-96q8-mm82.json b/advisories/unreviewed/2025/04/GHSA-5vwg-96q8-mm82/GHSA-5vwg-96q8-mm82.json new file mode 100644 index 00000000000..8e8e8c08d26 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5vwg-96q8-mm82/GHSA-5vwg-96q8-mm82.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vwg-96q8-mm82", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22068" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk: make sure ubq->canceling is set when queue is frozen\n\nNow ublk driver depends on `ubq->canceling` for deciding if the request\ncan be dispatched via uring_cmd & io_uring_cmd_complete_in_task().\n\nOnce ubq->canceling is set, the uring_cmd can be done via ublk_cancel_cmd()\nand io_uring_cmd_done().\n\nSo set ubq->canceling when queue is frozen, this way makes sure that the\nflag can be observed from ublk_queue_rq() reliably, and avoids\nuse-after-free on uring_cmd.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22068" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5491400589e7572c2d2627ed6384302f7672aa1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e3497d7dacb5aee69dd9be842b778083cae0e75" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8741d0737921ec1c03cf59aebf4d01400c2b461a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9158359015f0eda00e521e35b7bc7ebce176aebf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5wc9-7mc8-3qmr/GHSA-5wc9-7mc8-3qmr.json b/advisories/unreviewed/2025/04/GHSA-5wc9-7mc8-3qmr/GHSA-5wc9-7mc8-3qmr.json new file mode 100644 index 00000000000..1701f424b72 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5wc9-7mc8-3qmr/GHSA-5wc9-7mc8-3qmr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wc9-7mc8-3qmr", + "modified": "2025-04-16T15:34:33Z", + "published": "2025-04-16T15:34:33Z", + "aliases": [ + "CVE-2025-1983" + ], + "details": "A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1983" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://ready-os.com/pl" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-62fp-h6c8-g6f9/GHSA-62fp-h6c8-g6f9.json b/advisories/unreviewed/2025/04/GHSA-62fp-h6c8-g6f9/GHSA-62fp-h6c8-g6f9.json new file mode 100644 index 00000000000..4fc0cffc8ca --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-62fp-h6c8-g6f9/GHSA-62fp-h6c8-g6f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62fp-h6c8-g6f9", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39538" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search allows Upload a Web Shell to a Web Server. This issue affects WP-Advanced-Search: from n/a through 3.3.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-advanced-search/vulnerability/wordpress-wp-advanced-search-3-3-9-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-646x-rjhr-jf76/GHSA-646x-rjhr-jf76.json b/advisories/unreviewed/2025/04/GHSA-646x-rjhr-jf76/GHSA-646x-rjhr-jf76.json new file mode 100644 index 00000000000..8a3f0982296 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-646x-rjhr-jf76/GHSA-646x-rjhr-jf76.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-646x-rjhr-jf76", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22106" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmxnet3: unregister xdp rxq info in the reset path\n\nvmxnet3 does not unregister xdp rxq info in the\nvmxnet3_reset_work() code path as vmxnet3_rq_destroy()\nis not invoked in this code path. So, we get below message with a\nbacktrace.\n\nMissing unregister, handled but fix driver\nWARNING: CPU:48 PID: 500 at net/core/xdp.c:182\n__xdp_rxq_info_reg+0x93/0xf0\n\nThis patch fixes the problem by moving the unregister\ncode of XDP from vmxnet3_rq_destroy() to vmxnet3_rq_cleanup().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22106" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0dd765fae295832934bf28e45dd5a355e0891ed4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9908541a9e235b7c5e2fbdd59910eaf9c32c3075" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-65j3-jrj3-4mgp/GHSA-65j3-jrj3-4mgp.json b/advisories/unreviewed/2025/04/GHSA-65j3-jrj3-4mgp/GHSA-65j3-jrj3-4mgp.json new file mode 100644 index 00000000000..3dc87792e25 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-65j3-jrj3-4mgp/GHSA-65j3-jrj3-4mgp.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65j3-jrj3-4mgp", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22044" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nacpi: nfit: fix narrowing conversion in acpi_nfit_ctl\n\nSyzkaller has reported a warning in to_nfit_bus_uuid(): \"only secondary\nbus families can be translated\". This warning is emited if the argument\nis equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first\nverifies that a user-provided value call_pkg->nd_family of type u64 is\nnot equal to 0. Then the value is converted to int, and only after that\nis compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid\nargument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while\nthe lower 32 bits are zero.\n\nFurthermore, it is best to return EINVAL immediately upon seeing the\ninvalid user input. The WARNING is insufficient to prevent further\nundefined behavior based on other invalid user input.\n\nAll checks of the input value should be applied to the original variable\ncall_pkg->nd_family.\n\n[iweiny: update commit message]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22044" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ff0e408db36c21ed3fa5e3c1e0e687c82cf132f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b65cff06a004ac54f6ea8886060f0d07b1ca055" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73851cfceb00cc77d7a0851bc10f2263394c3e87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85f11291658ab907c4294319c8102450cc75bb96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92ba06aef65522483784dcbd6697629ddbd4c4f9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bae5b55e0f327102e78f6a66fb127275e9bc91b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c90402d2a226ff7afbe1d0650bee8ecc15a91049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e71a57c5aaa389d4c3c82f920761262efdd18d38" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6c74-8p8j-4qv8/GHSA-6c74-8p8j-4qv8.json b/advisories/unreviewed/2025/04/GHSA-6c74-8p8j-4qv8/GHSA-6c74-8p8j-4qv8.json new file mode 100644 index 00000000000..ba928286689 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6c74-8p8j-4qv8/GHSA-6c74-8p8j-4qv8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c74-8p8j-4qv8", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22076" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix missing shutdown check\n\nxfstests generic/730 test failed because after deleting the device\nthat still had dirty data, the file could still be read without\nreturning an error. The reason is the missing shutdown check in\n->read_iter.\n\nI also noticed that shutdown checks were missing from ->write_iter,\n->splice_read, and ->mmap. This commit adds shutdown checks to all\nof them.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22076" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47e35366bc6fa3cf189a8305bce63992495f3efa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a9595eb024b8319957c178be3cdeed613ac0795" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/539147585ca453db6e3d7a5cf3b9c9690513762d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e41e33eb795cb9c1ead6ac627d8710546fac6e81" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6cvc-553h-v3j8/GHSA-6cvc-553h-v3j8.json b/advisories/unreviewed/2025/04/GHSA-6cvc-553h-v3j8/GHSA-6cvc-553h-v3j8.json new file mode 100644 index 00000000000..b7125cc5dd9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6cvc-553h-v3j8/GHSA-6cvc-553h-v3j8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cvc-553h-v3j8", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22024" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix management of listener transports\n\nCurrently, when no active threads are running, a root user using nfsdctl\ncommand can try to remove a particular listener from the list of previously\nadded ones, then start the server by increasing the number of threads,\nit leads to the following problem:\n\n[ 158.835354] refcount_t: addition on 0; use-after-free.\n[ 158.835603] WARNING: CPU: 2 PID: 9145 at lib/refcount.c:25 refcount_warn_saturate+0x160/0x1a0\n[ 158.836017] Modules linked in: rpcrdma rdma_cm iw_cm ib_cm ib_core nfsd auth_rpcgss nfs_acl lockd grace overlay isofs uinput snd_seq_dummy snd_hrtimer nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables qrtr sunrpc vfat fat uvcvideo videobuf2_vmalloc videobuf2_memops uvc videobuf2_v4l2 videodev videobuf2_common snd_hda_codec_generic mc e1000e snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_seq snd_seq_device snd_pcm snd_timer snd soundcore sg loop dm_multipath dm_mod nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs libcrc32c crct10dif_ce ghash_ce vmwgfx sha2_ce sha256_arm64 sr_mod sha1_ce cdrom nvme drm_client_lib drm_ttm_helper ttm nvme_core drm_kms_helper nvme_auth drm fuse\n[ 158.840093] CPU: 2 UID: 0 PID: 9145 Comm: nfsd Kdump: loaded Tainted: G B W 6.13.0-rc6+ #7\n[ 158.840624] Tainted: [B]=BAD_PAGE, [W]=WARN\n[ 158.840802] Hardware name: VMware, Inc. VMware20,1/VBSA, BIOS VMW201.00V.24006586.BA64.2406042154 06/04/2024\n[ 158.841220] pstate: 61400005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[ 158.841563] pc : refcount_warn_saturate+0x160/0x1a0\n[ 158.841780] lr : refcount_warn_saturate+0x160/0x1a0\n[ 158.842000] sp : ffff800089be7d80\n[ 158.842147] x29: ffff800089be7d80 x28: ffff00008e68c148 x27: ffff00008e68c148\n[ 158.842492] x26: ffff0002e3b5c000 x25: ffff600011cd1829 x24: ffff00008653c010\n[ 158.842832] x23: ffff00008653c000 x22: 1fffe00011cd1829 x21: ffff00008653c028\n[ 158.843175] x20: 0000000000000002 x19: ffff00008653c010 x18: 0000000000000000\n[ 158.843505] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n[ 158.843836] x14: 0000000000000000 x13: 0000000000000001 x12: ffff600050a26493\n[ 158.844143] x11: 1fffe00050a26492 x10: ffff600050a26492 x9 : dfff800000000000\n[ 158.844475] x8 : 00009fffaf5d9b6e x7 : ffff000285132493 x6 : 0000000000000001\n[ 158.844823] x5 : ffff000285132490 x4 : ffff600050a26493 x3 : ffff8000805e72bc\n[ 158.845174] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000098588000\n[ 158.845528] Call trace:\n[ 158.845658] refcount_warn_saturate+0x160/0x1a0 (P)\n[ 158.845894] svc_recv+0x58c/0x680 [sunrpc]\n[ 158.846183] nfsd+0x1fc/0x348 [nfsd]\n[ 158.846390] kthread+0x274/0x2f8\n[ 158.846546] ret_from_fork+0x10/0x20\n[ 158.846714] ---[ end trace 0000000000000000 ]---\n\nnfsd_nl_listener_set_doit() would manipulate the list of transports of\nserver's sv_permsocks and close the specified listener but the other\nlist of transports (server's sp_xprts list) would not be changed leading\nto the problem above.\n\nInstead, determined if the nfsdctl is trying to remove a listener, in\nwhich case, delete all the existing listener transports and re-create\nall-but-the-removed ones.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22024" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/052a34f093fb940a145493d1438e7abbfe507cdd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f42df0ab2b11ea6b2884bdaf6dbc3be6dde7e82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a84c80515ca8a0cdf6d06f1b6ca721224b08453e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d093c90892607be505e801469d6674459e69ab89" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6hqx-m227-83p9/GHSA-6hqx-m227-83p9.json b/advisories/unreviewed/2025/04/GHSA-6hqx-m227-83p9/GHSA-6hqx-m227-83p9.json new file mode 100644 index 00000000000..e77cf2e84e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6hqx-m227-83p9/GHSA-6hqx-m227-83p9.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hqx-m227-83p9", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22095" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: brcmstb: Fix error path after a call to regulator_bulk_get()\n\nIf the regulator_bulk_get() returns an error and no regulators\nare created, we need to set their number to zero.\n\nIf we don't do this and the PCIe link up fails, a call to the\nregulator_bulk_free() will result in a kernel panic.\n\nWhile at it, print the error value, as we cannot return an error\nupwards as the kernel will WARN() on an error from add_bus().\n\n[kwilczynski: commit log, use comma in the message to match style with\nother similar messages]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22095" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3651ad5249c51cf7eee078e12612557040a6bdb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f44e1fdb006db61394aa4d4c25728ada00842e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7842e842a9bf6bd5866c84f588353711d131ab1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99a0efba9f903acbdece548862b6b4cbe7d999e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df63321a40cc98e52313cffbff376b8ae9ceffa7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eedd054834930b8d678f0776cd4b091b8fffbb4a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json b/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json new file mode 100644 index 00000000000..3bd1399a829 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pg5-wf6r-xvh8", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22054" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narcnet: Add NULL check in com20020pci_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\ncom20020pci_probe() does not check for this case, which results in a\nNULL pointer dereference.\n\nAdd NULL check after devm_kasprintf() to prevent this issue and ensure\nno resources are left allocated.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22054" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/661cf5d102949898c931e81fd4e1c773afcdeafa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/887226163504494ea7e58033a97c2d2ab12e05d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/905a34dc1ad9a53a8aaaf8a759ea5dbaaa30418d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a654f31b33515d39bb56c75fd8b26bef025ced7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be8a0decd0b59a52a07276f9ef3b33ef820b2179" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ebebeb58d48e25525fa654f2c53a24713fe141c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ececf8eff6c25acc239fa8f0fd837c76bc770547" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef8b29398ea6061ac8257f3e45c9be45cc004ce2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fda8c491db2a90ff3e6fbbae58e495b4ddddeca3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6rvr-95xv-gjrq/GHSA-6rvr-95xv-gjrq.json b/advisories/unreviewed/2025/04/GHSA-6rvr-95xv-gjrq/GHSA-6rvr-95xv-gjrq.json new file mode 100644 index 00000000000..144ea83de82 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6rvr-95xv-gjrq/GHSA-6rvr-95xv-gjrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rvr-95xv-gjrq", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39552" + ], + "details": "Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.200.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zephyr-project-manager/vulnerability/wordpress-zephyr-project-manager-3-3-200-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-727c-882c-j5hc/GHSA-727c-882c-j5hc.json b/advisories/unreviewed/2025/04/GHSA-727c-882c-j5hc/GHSA-727c-882c-j5hc.json new file mode 100644 index 00000000000..d3ec274c731 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-727c-882c-j5hc/GHSA-727c-882c-j5hc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-727c-882c-j5hc", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22118" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: validate queue quanta parameters to prevent OOB access\n\nAdd queue wraparound prevention in quanta configuration.\nEnsure end_qid does not overflow by validating start_qid and num_queues.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22118" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4161cf3f4c11006507f4e02bedc048a215a4b81a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2f7d3f7331b92cb820da23e8c45133305da1e63" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-73pc-m2pm-2mr8/GHSA-73pc-m2pm-2mr8.json b/advisories/unreviewed/2025/04/GHSA-73pc-m2pm-2mr8/GHSA-73pc-m2pm-2mr8.json new file mode 100644 index 00000000000..5b22cd56a44 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-73pc-m2pm-2mr8/GHSA-73pc-m2pm-2mr8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73pc-m2pm-2mr8", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22084" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nw1: fix NULL pointer dereference in probe\n\nThe w1_uart_probe() function calls w1_uart_serdev_open() (which includes\ndevm_serdev_device_open()) before setting the client ops via\nserdev_device_set_client_ops(). This ordering can trigger a NULL pointer\ndereference in the serdev controller's receive_buf handler, as it assumes\nserdev->ops is valid when SERPORT_ACTIVE is set.\n\nThis is similar to the issue fixed in commit 5e700b384ec1\n(\"platform/chrome: cros_ec_uart: properly fix race condition\") where\ndevm_serdev_device_open() was called before fully initializing the\ndevice.\n\nFix the race by ensuring client ops are set before enabling the port via\nw1_uart_serdev_open().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22084" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0dd6770a72f138dabea9eae87f3da6ffa68f0d06" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f750b84628080ff0d67bf1af67a4967b740acf2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/64ab50577c59bb7049bec6b5c42d1c38e4029f29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc6b0ec7cccbf66ef3621e9e93296b7bd1f52298" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-748f-j47f-m54j/GHSA-748f-j47f-m54j.json b/advisories/unreviewed/2025/04/GHSA-748f-j47f-m54j/GHSA-748f-j47f-m54j.json new file mode 100644 index 00000000000..c4d03d72ad2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-748f-j47f-m54j/GHSA-748f-j47f-m54j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-748f-j47f-m54j", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39518" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb BMA Lite allows SQL Injection. This issue affects BMA Lite: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bma-lite-appointment-booking-and-scheduling/vulnerability/wordpress-bma-lite-1-4-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-76xf-w35q-qjmg/GHSA-76xf-w35q-qjmg.json b/advisories/unreviewed/2025/04/GHSA-76xf-w35q-qjmg/GHSA-76xf-w35q-qjmg.json new file mode 100644 index 00000000000..564c77b0de4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-76xf-w35q-qjmg/GHSA-76xf-w35q-qjmg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76xf-w35q-qjmg", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22117" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix using untrusted value of pkt_len in ice_vc_fdir_parse_raw()\n\nFix using the untrusted value of proto->raw.pkt_len in function\nice_vc_fdir_parse_raw() by verifying if it does not exceed the\nVIRTCHNL_MAX_SIZE_RAW_PACKET value.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22117" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1388dd564183a5a18ec4a966748037736b5653c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/362f704ba73a359db9cded567e891d9a8f081875" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-798j-54v2-vw4x/GHSA-798j-54v2-vw4x.json b/advisories/unreviewed/2025/04/GHSA-798j-54v2-vw4x/GHSA-798j-54v2-vw4x.json new file mode 100644 index 00000000000..196e71709e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-798j-54v2-vw4x/GHSA-798j-54v2-vw4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-798j-54v2-vw4x", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39524" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in bPlugins Html5 Audio Player allows Stored XSS. This issue affects Html5 Audio Player: from n/a through 2.2.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39524" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/html5-audio-player/vulnerability/wordpress-html5-audio-player-2-2-28-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7c8w-c4x7-8gxf/GHSA-7c8w-c4x7-8gxf.json b/advisories/unreviewed/2025/04/GHSA-7c8w-c4x7-8gxf/GHSA-7c8w-c4x7-8gxf.json new file mode 100644 index 00000000000..d59ec5726e1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7c8w-c4x7-8gxf/GHSA-7c8w-c4x7-8gxf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c8w-c4x7-8gxf", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22100" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix race condition when gathering fdinfo group samples\n\nCommit e16635d88fa0 (\"drm/panthor: add DRM fdinfo support\") failed to\nprotect access to groups with an xarray lock, which could lead to\nuse-after-free errors.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22100" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0590c94c3596d6c1a3d549ae611366f2ad4e1d8d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d98c83ad67e7bd86a47494fd6c3863e7bb26db9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9d45f42a64a400adba59ee83d03e6db662530b4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7gf2-qgvm-6qgh/GHSA-7gf2-qgvm-6qgh.json b/advisories/unreviewed/2025/04/GHSA-7gf2-qgvm-6qgh/GHSA-7gf2-qgvm-6qgh.json new file mode 100644 index 00000000000..0ab1531247f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7gf2-qgvm-6qgh/GHSA-7gf2-qgvm-6qgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gf2-qgvm-6qgh", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39525" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Logo Carousel Slider allows Stored XSS. This issue affects Logo Carousel Slider: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39525" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/logo-carousel-slider/vulnerability/wordpress-logo-carousel-slider-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7gv9-65q7-v834/GHSA-7gv9-65q7-v834.json b/advisories/unreviewed/2025/04/GHSA-7gv9-65q7-v834/GHSA-7gv9-65q7-v834.json new file mode 100644 index 00000000000..db8ad1394b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7gv9-65q7-v834/GHSA-7gv9-65q7-v834.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gv9-65q7-v834", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39565" + ], + "details": "Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security allows Object Injection. This issue affects MelaPress Login Security: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39565" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/melapress-login-security/vulnerability/wordpress-melapress-login-security-2-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7jvh-56fg-c3rv/GHSA-7jvh-56fg-c3rv.json b/advisories/unreviewed/2025/04/GHSA-7jvh-56fg-c3rv/GHSA-7jvh-56fg-c3rv.json index 41107420a5e..6a23a73bbe5 100644 --- a/advisories/unreviewed/2025/04/GHSA-7jvh-56fg-c3rv/GHSA-7jvh-56fg-c3rv.json +++ b/advisories/unreviewed/2025/04/GHSA-7jvh-56fg-c3rv/GHSA-7jvh-56fg-c3rv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7jww-p4g2-4fpv/GHSA-7jww-p4g2-4fpv.json b/advisories/unreviewed/2025/04/GHSA-7jww-p4g2-4fpv/GHSA-7jww-p4g2-4fpv.json index 52f385f1f9d..97515832bf7 100644 --- a/advisories/unreviewed/2025/04/GHSA-7jww-p4g2-4fpv/GHSA-7jww-p4g2-4fpv.json +++ b/advisories/unreviewed/2025/04/GHSA-7jww-p4g2-4fpv/GHSA-7jww-p4g2-4fpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jww-p4g2-4fpv", - "modified": "2025-04-15T21:31:43Z", + "modified": "2025-04-16T15:34:16Z", "published": "2025-04-15T21:31:43Z", "aliases": [ "CVE-2025-22900" ], "details": "Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T19:16:06Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7m6p-mvhj-8v99/GHSA-7m6p-mvhj-8v99.json b/advisories/unreviewed/2025/04/GHSA-7m6p-mvhj-8v99/GHSA-7m6p-mvhj-8v99.json new file mode 100644 index 00000000000..e3904aaf623 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7m6p-mvhj-8v99/GHSA-7m6p-mvhj-8v99.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m6p-mvhj-8v99", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22030" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: zswap: fix crypto_free_acomp() deadlock in zswap_cpu_comp_dead()\n\nCurrently, zswap_cpu_comp_dead() calls crypto_free_acomp() while holding\nthe per-CPU acomp_ctx mutex. crypto_free_acomp() then holds scomp_lock\n(through crypto_exit_scomp_ops_async()).\n\nOn the other hand, crypto_alloc_acomp_node() holds the scomp_lock (through\ncrypto_scomp_init_tfm()), and then allocates memory. If the allocation\nresults in reclaim, we may attempt to hold the per-CPU acomp_ctx mutex.\n\nThe above dependencies can cause an ABBA deadlock. For example in the\nfollowing scenario:\n\n(1) Task A running on CPU #1:\n crypto_alloc_acomp_node()\n Holds scomp_lock\n Enters reclaim\n Reads per_cpu_ptr(pool->acomp_ctx, 1)\n\n(2) Task A is descheduled\n\n(3) CPU #1 goes offline\n zswap_cpu_comp_dead(CPU #1)\n Holds per_cpu_ptr(pool->acomp_ctx, 1))\n Calls crypto_free_acomp()\n Waits for scomp_lock\n\n(4) Task A running on CPU #2:\n Waits for per_cpu_ptr(pool->acomp_ctx, 1) // Read on CPU #1\n DEADLOCK\n\nSince there is no requirement to call crypto_free_acomp() with the per-CPU\nacomp_ctx mutex held in zswap_cpu_comp_dead(), move it after the mutex is\nunlocked. Also move the acomp_request_free() and kfree() calls for\nconsistency and to avoid any potential sublte locking dependencies in the\nfuture.\n\nWith this, only setting acomp_ctx fields to NULL occurs with the mutex\nheld. This is similar to how zswap_cpu_comp_prepare() only initializes\nacomp_ctx fields with the mutex held, after performing all allocations\nbefore holding the mutex.\n\nOpportunistically, move the NULL check on acomp_ctx so that it takes place\nbefore the mutex dereference.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22030" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/717d9c35deff6c33235693171bacbb03e9643fa4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/747e3eec1d7d124ea90ed3d7b85369df8b4e36d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8d18000e9d2d97aaf105f5f9b3b0e8a6fbf8b96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c11bcbc0a517acf69282c8225059b2a8ac5fe628" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json b/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json new file mode 100644 index 00000000000..9d31da339a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mx5-64fm-676w", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22056" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_tunnel: fix geneve_opt type confusion addition\n\nWhen handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the\nparsing logic should place every geneve_opt structure one by one\ncompactly. Hence, when deciding the next geneve_opt position, the\npointer addition should be in units of char *.\n\nHowever, the current implementation erroneously does type conversion\nbefore the addition, which will lead to heap out-of-bounds write.\n\n[ 6.989857] ==================================================================\n[ 6.990293] BUG: KASAN: slab-out-of-bounds in nft_tunnel_obj_init+0x977/0xa70\n[ 6.990725] Write of size 124 at addr ffff888005f18974 by task poc/178\n[ 6.991162]\n[ 6.991259] CPU: 0 PID: 178 Comm: poc-oob-write Not tainted 6.1.132 #1\n[ 6.991655] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n[ 6.992281] Call Trace:\n[ 6.992423] \n[ 6.992586] dump_stack_lvl+0x44/0x5c\n[ 6.992801] print_report+0x184/0x4be\n[ 6.993790] kasan_report+0xc5/0x100\n[ 6.994252] kasan_check_range+0xf3/0x1a0\n[ 6.994486] memcpy+0x38/0x60\n[ 6.994692] nft_tunnel_obj_init+0x977/0xa70\n[ 6.995677] nft_obj_init+0x10c/0x1b0\n[ 6.995891] nf_tables_newobj+0x585/0x950\n[ 6.996922] nfnetlink_rcv_batch+0xdf9/0x1020\n[ 6.998997] nfnetlink_rcv+0x1df/0x220\n[ 6.999537] netlink_unicast+0x395/0x530\n[ 7.000771] netlink_sendmsg+0x3d0/0x6d0\n[ 7.001462] __sock_sendmsg+0x99/0xa0\n[ 7.001707] ____sys_sendmsg+0x409/0x450\n[ 7.002391] ___sys_sendmsg+0xfd/0x170\n[ 7.003145] __sys_sendmsg+0xea/0x170\n[ 7.004359] do_syscall_64+0x5e/0x90\n[ 7.005817] entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n[ 7.006127] RIP: 0033:0x7ec756d4e407\n[ 7.006339] Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 faf\n[ 7.007364] RSP: 002b:00007ffed5d46760 EFLAGS: 00000202 ORIG_RAX: 000000000000002e\n[ 7.007827] RAX: ffffffffffffffda RBX: 00007ec756cc4740 RCX: 00007ec756d4e407\n[ 7.008223] RDX: 0000000000000000 RSI: 00007ffed5d467f0 RDI: 0000000000000003\n[ 7.008620] RBP: 00007ffed5d468a0 R08: 0000000000000000 R09: 0000000000000000\n[ 7.009039] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000\n[ 7.009429] R13: 00007ffed5d478b0 R14: 00007ec756ee5000 R15: 00005cbd4e655cb8\n\nFix this bug with correct pointer addition and conversion in parse\nand dump code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22056" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a93a710d6df334b828ea064c6d39fda34f901dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b755d8eb1ace3870789d48fbd94f386ad6e30be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28d88ee1e1cc8ac2d79aeb112717b97c5c833d43" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31d49eb436f2da61280508d7adf8c9b473b967aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/446d94898c560ed2f61e26ae445858a4c4830762" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/708e268acb3a446ad2a8a3d2e9bd41cc23660cd6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a263d31c8c92e5919d41af57d9479cfb66323782" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca2adfc03cd6273f0b589fe65afc6f75e0fe116e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7q75-pggr-8c64/GHSA-7q75-pggr-8c64.json b/advisories/unreviewed/2025/04/GHSA-7q75-pggr-8c64/GHSA-7q75-pggr-8c64.json new file mode 100644 index 00000000000..b43b354bf2e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7q75-pggr-8c64/GHSA-7q75-pggr-8c64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q75-pggr-8c64", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39593" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in EverAccounting Ever Accounting allows Cross Site Request Forgery. This issue affects Ever Accounting: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39593" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ever-accounting/vulnerability/wordpress-ever-accounting-2-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rq4-gjpx-jq6g/GHSA-7rq4-gjpx-jq6g.json b/advisories/unreviewed/2025/04/GHSA-7rq4-gjpx-jq6g/GHSA-7rq4-gjpx-jq6g.json new file mode 100644 index 00000000000..f90e1a50a26 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rq4-gjpx-jq6g/GHSA-7rq4-gjpx-jq6g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rq4-gjpx-jq6g", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22114" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't clobber ret in btrfs_validate_super()\n\nCommit 2a9bb78cfd36 (\"btrfs: validate system chunk array at\nbtrfs_validate_super()\") introduces a call to validate_sys_chunk_array()\nin btrfs_validate_super(), which clobbers the value of ret set earlier.\nThis has the effect of negating the validity checks done earlier, making\nit so btrfs could potentially try to mount invalid filesystems.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22114" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9db9c7dd5b4e1d3205137a094805980082c37716" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef6800a2015e706e9852a5ec15263fec9990d012" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-83hg-h5qp-3qr9/GHSA-83hg-h5qp-3qr9.json b/advisories/unreviewed/2025/04/GHSA-83hg-h5qp-3qr9/GHSA-83hg-h5qp-3qr9.json new file mode 100644 index 00000000000..3bf0a975569 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-83hg-h5qp-3qr9/GHSA-83hg-h5qp-3qr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83hg-h5qp-3qr9", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39581" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Shortcodes allows Stored XSS. This issue affects Themify Shortcodes: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39581" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themify-shortcodes/vulnerability/wordpress-themify-shortcodes-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-83jq-f5p9-r6x4/GHSA-83jq-f5p9-r6x4.json b/advisories/unreviewed/2025/04/GHSA-83jq-f5p9-r6x4/GHSA-83jq-f5p9-r6x4.json new file mode 100644 index 00000000000..a4cf8f43377 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-83jq-f5p9-r6x4/GHSA-83jq-f5p9-r6x4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83jq-f5p9-r6x4", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22092" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Fix NULL dereference in SR-IOV VF creation error path\n\nClean up when virtfn setup fails to prevent NULL pointer dereference\nduring device removal. The kernel oops below occurred due to incorrect\nerror handling flow when pci_setup_device() fails.\n\nAdd pci_iov_scan_device(), which handles virtfn allocation and setup and\ncleans up if pci_setup_device() fails, so pci_iov_add_virtfn() doesn't need\nto call pci_stop_and_remove_bus_device(). This prevents accessing\npartially initialized virtfn devices during removal.\n\n BUG: kernel NULL pointer dereference, address: 00000000000000d0\n RIP: 0010:device_del+0x3d/0x3d0\n Call Trace:\n pci_remove_bus_device+0x7c/0x100\n pci_iov_add_virtfn+0xfa/0x200\n sriov_enable+0x208/0x420\n mlx5_core_sriov_configure+0x6a/0x160 [mlx5_core]\n sriov_numvfs_store+0xae/0x1a0\n\n[bhelgaas: commit log, return ERR_PTR(-ENOMEM) directly]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22092" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04d50d953ab46d96b0b32d5ad955fceaa28622db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c67a233834b778b8c78f8b62c072ccf87a9eb6d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef421b4d206f0d3681804b8f94f06a8458a53aaf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json b/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json new file mode 100644 index 00000000000..e4c624c8e34 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-843p-6jf4-c3r6", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23137" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update\n\nCheck if policy is NULL before dereferencing it in amd_pstate_update.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23137" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/426db24d4db2e4f0d6720aeb7795eafcb9e82640" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b99c1c63d88c75a4dc5487c3696cda38697b8d35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-84v5-fhgf-rr93/GHSA-84v5-fhgf-rr93.json b/advisories/unreviewed/2025/04/GHSA-84v5-fhgf-rr93/GHSA-84v5-fhgf-rr93.json new file mode 100644 index 00000000000..156405ae26e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-84v5-fhgf-rr93/GHSA-84v5-fhgf-rr93.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84v5-fhgf-rr93", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39544" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Path Traversal. This issue affects WP Tools: from n/a through 5.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wptools/vulnerability/wordpress-wp-tools-plugin-5-18-csrf-to-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-855g-gqf8-49xq/GHSA-855g-gqf8-49xq.json b/advisories/unreviewed/2025/04/GHSA-855g-gqf8-49xq/GHSA-855g-gqf8-49xq.json new file mode 100644 index 00000000000..01c56e9cf49 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-855g-gqf8-49xq/GHSA-855g-gqf8-49xq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-855g-gqf8-49xq", + "modified": "2025-04-16T15:34:47Z", + "published": "2025-04-16T15:34:47Z", + "aliases": [ + "CVE-2025-3697" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-product.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3697" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/sql_inject_in_edit.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304985" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304985" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553624" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-879f-fp4c-q873/GHSA-879f-fp4c-q873.json b/advisories/unreviewed/2025/04/GHSA-879f-fp4c-q873/GHSA-879f-fp4c-q873.json new file mode 100644 index 00000000000..94bf0a825f6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-879f-fp4c-q873/GHSA-879f-fp4c-q873.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-879f-fp4c-q873", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22061" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: airoha: Fix qid report in airoha_tc_get_htb_get_leaf_queue()\n\nFix the following kernel warning deleting HTB offloaded leafs and/or root\nHTB qdisc in airoha_eth driver properly reporting qid in\nairoha_tc_get_htb_get_leaf_queue routine.\n\n$tc qdisc replace dev eth1 root handle 10: htb offload\n$tc class add dev eth1 arent 10: classid 10:4 htb rate 100mbit ceil 100mbit\n$tc qdisc replace dev eth1 parent 10:4 handle 4: ets bands 8 \\\n quanta 1514 3028 4542 6056 7570 9084 10598 12112\n$tc qdisc del dev eth1 root\n\n[ 55.827864] ------------[ cut here ]------------\n[ 55.832493] WARNING: CPU: 3 PID: 2678 at 0xffffffc0798695a4\n[ 55.956510] CPU: 3 PID: 2678 Comm: tc Tainted: G O 6.6.71 #0\n[ 55.963557] Hardware name: Airoha AN7581 Evaluation Board (DT)\n[ 55.969383] pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 55.976344] pc : 0xffffffc0798695a4\n[ 55.979851] lr : 0xffffffc079869a20\n[ 55.983358] sp : ffffffc0850536a0\n[ 55.986665] x29: ffffffc0850536a0 x28: 0000000000000024 x27: 0000000000000001\n[ 55.993800] x26: 0000000000000000 x25: ffffff8008b19000 x24: ffffff800222e800\n[ 56.000935] x23: 0000000000000001 x22: 0000000000000000 x21: ffffff8008b19000\n[ 56.008071] x20: ffffff8002225800 x19: ffffff800379d000 x18: 0000000000000000\n[ 56.015206] x17: ffffffbf9ea59000 x16: ffffffc080018000 x15: 0000000000000000\n[ 56.022342] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000001\n[ 56.029478] x11: ffffffc081471008 x10: ffffffc081575a98 x9 : 0000000000000000\n[ 56.036614] x8 : ffffffc08167fd40 x7 : ffffffc08069e104 x6 : ffffff8007f86000\n[ 56.043748] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000001\n[ 56.050884] x2 : 0000000000000000 x1 : 0000000000000250 x0 : ffffff800222c000\n[ 56.058020] Call trace:\n[ 56.060459] 0xffffffc0798695a4\n[ 56.063618] 0xffffffc079869a20\n[ 56.066777] __qdisc_destroy+0x40/0xa0\n[ 56.070528] qdisc_put+0x54/0x6c\n[ 56.073748] qdisc_graft+0x41c/0x648\n[ 56.077324] tc_get_qdisc+0x168/0x2f8\n[ 56.080978] rtnetlink_rcv_msg+0x230/0x330\n[ 56.085076] netlink_rcv_skb+0x5c/0x128\n[ 56.088913] rtnetlink_rcv+0x14/0x1c\n[ 56.092490] netlink_unicast+0x1e0/0x2c8\n[ 56.096413] netlink_sendmsg+0x198/0x3c8\n[ 56.100337] ____sys_sendmsg+0x1c4/0x274\n[ 56.104261] ___sys_sendmsg+0x7c/0xc0\n[ 56.107924] __sys_sendmsg+0x44/0x98\n[ 56.111492] __arm64_sys_sendmsg+0x20/0x28\n[ 56.115580] invoke_syscall.constprop.0+0x58/0xfc\n[ 56.120285] do_el0_svc+0x3c/0xbc\n[ 56.123592] el0_svc+0x18/0x4c\n[ 56.126647] el0t_64_sync_handler+0x118/0x124\n[ 56.131005] el0t_64_sync+0x150/0x154\n[ 56.134660] ---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22061" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57b290d97c6150774bf929117ca737a26d8fc33d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7f76197e49e46a8c082a6fededaa8a07e69a860" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-88gp-q3v3-9qmm/GHSA-88gp-q3v3-9qmm.json b/advisories/unreviewed/2025/04/GHSA-88gp-q3v3-9qmm/GHSA-88gp-q3v3-9qmm.json new file mode 100644 index 00000000000..ff8f98e05fe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-88gp-q3v3-9qmm/GHSA-88gp-q3v3-9qmm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88gp-q3v3-9qmm", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-3691" + ], + "details": "A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3691" + }, + { + "type": "WEB", + "url": "https://github.com/KKDT12138/CVE/blob/main/cve2.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304980" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304980" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-89pr-66m5-4vwv/GHSA-89pr-66m5-4vwv.json b/advisories/unreviewed/2025/04/GHSA-89pr-66m5-4vwv/GHSA-89pr-66m5-4vwv.json new file mode 100644 index 00000000000..849b0dcd152 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89pr-66m5-4vwv/GHSA-89pr-66m5-4vwv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89pr-66m5-4vwv", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22087" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix array bounds error with may_goto\n\nmay_goto uses an additional 8 bytes on the stack, which causes the\ninterpreters[] array to go out of bounds when calculating index by\nstack_size.\n\n1. If a BPF program is rewritten, re-evaluate the stack size. For non-JIT\ncases, reject loading directly.\n\n2. For non-JIT cases, calculating interpreters[idx] may still cause\nout-of-bounds array access, and just warn about it.\n\n3. For jit_requested cases, the execution of bpf_func also needs to be\nwarned. So move the definition of function __bpf_prog_ret0_warn out of\nthe macro definition CONFIG_BPF_JIT_ALWAYS_ON.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22087" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19e6817f84000d0b06f09fd69ebd56217842c122" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a86ae57b2600e5749f5f674e9d4296ac00c69a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4524b7febdd55fb99ae2e1f48db64019fa69e643" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ebc5030e0c5a698f1dd9a6684cddf6ccaed64a0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8f89-67pg-r2cq/GHSA-8f89-67pg-r2cq.json b/advisories/unreviewed/2025/04/GHSA-8f89-67pg-r2cq/GHSA-8f89-67pg-r2cq.json new file mode 100644 index 00000000000..db21931343d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8f89-67pg-r2cq/GHSA-8f89-67pg-r2cq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f89-67pg-r2cq", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39577" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive allows Stored XSS. This issue affects PropertyHive: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39577" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/propertyhive/vulnerability/wordpress-propertyhive-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json b/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json new file mode 100644 index 00000000000..e2fb7975b0b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fp6-f772-8g6x", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22088" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Prevent use-after-free in erdma_accept_newconn()\n\nAfter the erdma_cep_put(new_cep) being called, new_cep will be freed,\nand the following dereference will cause a UAF problem. Fix this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22088" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/667a628ab67d359166799fad89b3c6909599558a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78411a133312ce7d8a3239c76a8fd85bca1cc10f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7aa6bb5276d9fec98deb05615a086eeb893854ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83437689249e6a17b25e27712fbee292e42e7855" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a114d25d584c14019d31dbf2163780c47415a187" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc1db4d8f1b0dc480d7d745a60a8cc94ce2badd4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8m3h-2pfc-jv58/GHSA-8m3h-2pfc-jv58.json b/advisories/unreviewed/2025/04/GHSA-8m3h-2pfc-jv58/GHSA-8m3h-2pfc-jv58.json new file mode 100644 index 00000000000..05b28aac0e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8m3h-2pfc-jv58/GHSA-8m3h-2pfc-jv58.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m3h-2pfc-jv58", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22081" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fix a couple integer overflows on 32bit systems\n\nOn 32bit systems the \"off + sizeof(struct NTFS_DE)\" addition can\nhave an integer wrapping issue. Fix it by using size_add().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22081" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0538f52410b619737e663167b6a2b2d0bc1a589d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0922d86a7a6032cb1694eab0b44b861bd33ba8d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0dfe700fbd3525f30a36ffbe390a5b9319bd009a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a14e9718a19d2e88de004a1360bfd7a86ed1395" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/284c9549386e9883855fb82b730303bb2edea9de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d0f4f42922a832388a0c2fe5204c0a1037ff786" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ad414f4df2294b28836b5b7b69787659d6aa708" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json b/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json new file mode 100644 index 00000000000..3010f429aae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xw7-j864-h87q", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22038" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate zero num_subauth before sub_auth is accessed\n\nAccess psid->sub_auth[psid->num_subauth - 1] without checking\nif num_subauth is non-zero leads to an out-of-bounds read.\nThis patch adds a validation step to ensure num_subauth != 0\nbefore sub_auth is accessed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22038" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e36a3e080d6d8bd7a34e089345d043da4ac8283" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ac65de111c686c95316ade660f8ba7aea3cd3cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56de7778a48560278c334077ace7b9ac4bfb2fd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68c6c3142bfcdb049839d40a9a59ebe8ea865002" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf21e29d78cd2c2371023953d9c82dfef82ebb36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8bfe1954a0b89e7b29b3a3e7f4c5e0ebd295e20" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-92m7-rr4r-78cq/GHSA-92m7-rr4r-78cq.json b/advisories/unreviewed/2025/04/GHSA-92m7-rr4r-78cq/GHSA-92m7-rr4r-78cq.json new file mode 100644 index 00000000000..b637b479bec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-92m7-rr4r-78cq/GHSA-92m7-rr4r-78cq.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92m7-rr4r-78cq", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22073" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix a leak on spufs_new_file() failure\n\nIt's called from spufs_fill_dir(), and caller of that will do\nspufs_rmdir() in case of failure. That does remove everything\nwe'd managed to create, but... the problem dentry is still\nnegative. IOW, it needs to be explicitly dropped.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22073" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bd56e4e72c354b65c0a7e5ac1c09eca81949d5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/132925bd6772d7614340fb755ac5415462ac8edd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35f789ccebd69f6f9a1e0a9b85435003b2450065" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53b189651c33b5f1fb3b755e6a37a8206978514e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90d1b276d1b1379d20ad27d1f6349ba9f44a2e00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96de7fbdc2dcadeebc17c3cb89e7cdab487bfce0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1eef06d10c1a9848e3a762919bbbe315a0a7cb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1ca8698ca1332625d83ea0d753747be66f9906d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d791985ceeb081155b4e96d314ca54c7605dcbe0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-94gr-3chc-756r/GHSA-94gr-3chc-756r.json b/advisories/unreviewed/2025/04/GHSA-94gr-3chc-756r/GHSA-94gr-3chc-756r.json new file mode 100644 index 00000000000..9871191dcd4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-94gr-3chc-756r/GHSA-94gr-3chc-756r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94gr-3chc-756r", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham Checkout Files Upload for WooCommerce allows Stored XSS. This issue affects Checkout Files Upload for WooCommerce: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/checkout-files-upload-woocommerce/vulnerability/wordpress-checkout-files-upload-for-woocommerce-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-96f3-qv87-v4w6/GHSA-96f3-qv87-v4w6.json b/advisories/unreviewed/2025/04/GHSA-96f3-qv87-v4w6/GHSA-96f3-qv87-v4w6.json new file mode 100644 index 00000000000..78b94ebc8d4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-96f3-qv87-v4w6/GHSA-96f3-qv87-v4w6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96f3-qv87-v4w6", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22110" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error\n\nIt is possible that ctx in nfqnl_build_packet_message() could be used\nbefore it is properly initialize, which is only initialized\nby nfqnl_get_sk_secctx().\n\nThis patch corrects this problem by initializing the lsmctx to a safe\nvalue when it is declared.\n\nThis is similar to the commit 35fcac7a7c25\n(\"audit: Initialize lsmctx to avoid memory allocation error\").", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22110" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/778b09d91baafb13408470c721d034d6515cfa5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddbf7e1d82a1d0c1d3425931a6cb1b83f8454759" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-97x7-5rrp-gxxp/GHSA-97x7-5rrp-gxxp.json b/advisories/unreviewed/2025/04/GHSA-97x7-5rrp-gxxp/GHSA-97x7-5rrp-gxxp.json new file mode 100644 index 00000000000..328d26f41c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-97x7-5rrp-gxxp/GHSA-97x7-5rrp-gxxp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97x7-5rrp-gxxp", + "modified": "2025-04-16T15:34:32Z", + "published": "2025-04-16T15:34:32Z", + "aliases": [ + "CVE-2025-1981" + ], + "details": "Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1981" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://ready-os.com/pl" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json b/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json index 632442d32f2..000eb1d9961 100644 --- a/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json +++ b/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98g5-ch9p-4pc6", - "modified": "2025-04-15T18:31:47Z", + "modified": "2025-04-16T15:34:15Z", "published": "2025-04-15T18:31:47Z", "aliases": [ "CVE-2025-28100" ], "details": "A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the \"operateOrder.php\" id parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T18:15:51Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9ccw-6g9x-96r5/GHSA-9ccw-6g9x-96r5.json b/advisories/unreviewed/2025/04/GHSA-9ccw-6g9x-96r5/GHSA-9ccw-6g9x-96r5.json new file mode 100644 index 00000000000..bae36338088 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9ccw-6g9x-96r5/GHSA-9ccw-6g9x-96r5.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ccw-6g9x-96r5", + "modified": "2025-04-16T15:34:47Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23138" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatch_queue: fix pipe accounting mismatch\n\nCurrently, watch_queue_set_size() modifies the pipe buffers charged to\nuser->pipe_bufs without updating the pipe->nr_accounted on the pipe\nitself, due to the if (!pipe_has_watch_queue()) test in\npipe_resize_ring(). This means that when the pipe is ultimately freed,\nwe decrement user->pipe_bufs by something other than what than we had\ncharged to it, potentially leading to an underflow. This in turn can\ncause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM.\n\nTo remedy this, explicitly account for the pipe usage in\nwatch_queue_set_size() to match the number set via account_pipe_buffers()\n\n(It's unclear why watch_queue_set_size() does not update nr_accounted;\nit may be due to intentional overprovisioning in watch_queue_set_size()?)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23138" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/205028ebba838938d3b264dda1d0708fa7fe1ade" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d680b988656bb556c863d8b46d9b9096842bf3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/471c89b7d4f58bd6082f7c1fe14d4ca15c7f1284" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56ec918e6c86c1536870e4373e91eddd0c44245f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dafa27764183738dc5368b669b71e3d0d154f12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8658c75343ed00e5e154ebbe24335f51ba8db547" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d40e3537265dea9e3c33021874437ff26dc18787" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f13abc1e8e1a3b7455511c4e122750127f6bc9b0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9fpp-56h8-w47g/GHSA-9fpp-56h8-w47g.json b/advisories/unreviewed/2025/04/GHSA-9fpp-56h8-w47g/GHSA-9fpp-56h8-w47g.json index 4991cd0ce56..7dffdc1d021 100644 --- a/advisories/unreviewed/2025/04/GHSA-9fpp-56h8-w47g/GHSA-9fpp-56h8-w47g.json +++ b/advisories/unreviewed/2025/04/GHSA-9fpp-56h8-w47g/GHSA-9fpp-56h8-w47g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-9gvx-7g99-qp7r/GHSA-9gvx-7g99-qp7r.json b/advisories/unreviewed/2025/04/GHSA-9gvx-7g99-qp7r/GHSA-9gvx-7g99-qp7r.json new file mode 100644 index 00000000000..b773bbad2f6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gvx-7g99-qp7r/GHSA-9gvx-7g99-qp7r.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gvx-7g99-qp7r", + "modified": "2025-04-16T15:34:42Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22067" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence: Fix out-of-bounds array access in cdns_mrvl_xspi_setup_clock()\n\nIf requested_clk > 128, cdns_mrvl_xspi_setup_clock() iterates over the\nentire cdns_mrvl_xspi_clk_div_list array without breaking out early,\ncausing 'i' to go beyond the array bounds.\n\nFix that by stopping the loop when it gets to the last entry, clamping\nthe clock to the minimum 6.25 MHz.\n\nFixes the following warning with an UBSAN kernel:\n\n vmlinux.o: warning: objtool: cdns_mrvl_xspi_setup_clock: unexpected end of section .text.cdns_mrvl_xspi_setup_clock", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22067" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/645f1813fe0dc96381c36b834131e643b798fd73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ba0847fa1c22e7801cebfe5f7b75aee4fae317e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1fb84e274cb6a2bce6ba5e65116c06e0b3ab275" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e50781bf7accc75883cb8a6a9921fb4e2fa8cca4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9mf7-6xj9-h3r8/GHSA-9mf7-6xj9-h3r8.json b/advisories/unreviewed/2025/04/GHSA-9mf7-6xj9-h3r8/GHSA-9mf7-6xj9-h3r8.json index f6bcd6d3a3f..c3ffb15f107 100644 --- a/advisories/unreviewed/2025/04/GHSA-9mf7-6xj9-h3r8/GHSA-9mf7-6xj9-h3r8.json +++ b/advisories/unreviewed/2025/04/GHSA-9mf7-6xj9-h3r8/GHSA-9mf7-6xj9-h3r8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-9q65-f9rx-r8m2/GHSA-9q65-f9rx-r8m2.json b/advisories/unreviewed/2025/04/GHSA-9q65-f9rx-r8m2/GHSA-9q65-f9rx-r8m2.json new file mode 100644 index 00000000000..3f73d188beb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9q65-f9rx-r8m2/GHSA-9q65-f9rx-r8m2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q65-f9rx-r8m2", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22028" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vimc: skip .s_stream() for stopped entities\n\nSyzbot reported [1] a warning prompted by a check in call_s_stream()\nthat checks whether .s_stream() operation is warranted for unstarted\nor stopped subdevs.\n\nAdd a simple fix in vimc_streamer_pipeline_terminate() ensuring that\nentities skip a call to .s_stream() unless they have been previously\nproperly started.\n\n[1] Syzbot report:\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 5933 at drivers/media/v4l2-core/v4l2-subdev.c:460 call_s_stream+0x2df/0x350 drivers/media/v4l2-core/v4l2-subdev.c:460\nModules linked in:\nCPU: 0 UID: 0 PID: 5933 Comm: syz-executor330 Not tainted 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67 #0\n...\nCall Trace:\n \n vimc_streamer_pipeline_terminate+0x218/0x320 drivers/media/test-drivers/vimc/vimc-streamer.c:62\n vimc_streamer_pipeline_init drivers/media/test-drivers/vimc/vimc-streamer.c:101 [inline]\n vimc_streamer_s_stream+0x650/0x9a0 drivers/media/test-drivers/vimc/vimc-streamer.c:203\n vimc_capture_start_streaming+0xa1/0x130 drivers/media/test-drivers/vimc/vimc-capture.c:256\n vb2_start_streaming+0x15f/0x5a0 drivers/media/common/videobuf2/videobuf2-core.c:1789\n vb2_core_streamon+0x2a7/0x450 drivers/media/common/videobuf2/videobuf2-core.c:2348\n vb2_streamon drivers/media/common/videobuf2/videobuf2-v4l2.c:875 [inline]\n vb2_ioctl_streamon+0xf4/0x170 drivers/media/common/videobuf2/videobuf2-v4l2.c:1118\n __video_do_ioctl+0xaf0/0xf00 drivers/media/v4l2-core/v4l2-ioctl.c:3122\n video_usercopy+0x4d2/0x1620 drivers/media/v4l2-core/v4l2-ioctl.c:3463\n v4l2_ioctl+0x1ba/0x250 drivers/media/v4l2-core/v4l2-dev.c:366\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl fs/ioctl.c:892 [inline]\n __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f2b85c01b19\n...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22028" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36cef585e2a31e4ddf33a004b0584a7a572246de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f6064dab4dcfb7e34a395040a0c9dc22cc8765d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a58d4c4cf8ff60ab1f93399deefaf6057da91c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/845e9286ff99ee88cfdeb2b748f730003a512190" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9v7w-mq26-j739/GHSA-9v7w-mq26-j739.json b/advisories/unreviewed/2025/04/GHSA-9v7w-mq26-j739/GHSA-9v7w-mq26-j739.json new file mode 100644 index 00000000000..40d09e9026e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9v7w-mq26-j739/GHSA-9v7w-mq26-j739.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v7w-mq26-j739", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39545" + ], + "details": "Missing Authorization vulnerability in miniOrange WordPress REST API Authentication allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress REST API Authentication: from n/a through 3.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39545" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-rest-api-authentication/vulnerability/wordpress-wordpress-rest-api-authentication-3-6-3-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9vh4-w78f-qwqw/GHSA-9vh4-w78f-qwqw.json b/advisories/unreviewed/2025/04/GHSA-9vh4-w78f-qwqw/GHSA-9vh4-w78f-qwqw.json new file mode 100644 index 00000000000..bd6eb4d0b42 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9vh4-w78f-qwqw/GHSA-9vh4-w78f-qwqw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vh4-w78f-qwqw", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22120" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: goto right label 'out_mmap_sem' in ext4_setattr()\n\nOtherwise, if ext4_inode_attach_jinode() fails, a hung task will\nhappen because filemap_invalidate_unlock() isn't called to unlock\nmapping->invalidate_lock. Like this:\n\nEXT4-fs error (device sda) in ext4_setattr:5557: Out of memory\nINFO: task fsstress:374 blocked for more than 122 seconds.\n Not tainted 6.14.0-rc1-next-20250206-xfstests-dirty #726\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:fsstress state:D stack:0 pid:374 tgid:374 ppid:373\n task_flags:0x440140 flags:0x00000000\nCall Trace:\n \n __schedule+0x2c9/0x7f0\n schedule+0x27/0xa0\n schedule_preempt_disabled+0x15/0x30\n rwsem_down_read_slowpath+0x278/0x4c0\n down_read+0x59/0xb0\n page_cache_ra_unbounded+0x65/0x1b0\n filemap_get_pages+0x124/0x3e0\n filemap_read+0x114/0x3d0\n vfs_read+0x297/0x360\n ksys_read+0x6c/0xe0\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22120" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32d872e3905746ff1048078256cb00f946b97d8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e91ae31e2d264155dfd102101afc2de7bd74a64" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9wvw-xgvm-jmjr/GHSA-9wvw-xgvm-jmjr.json b/advisories/unreviewed/2025/04/GHSA-9wvw-xgvm-jmjr/GHSA-9wvw-xgvm-jmjr.json new file mode 100644 index 00000000000..3e534e935ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9wvw-xgvm-jmjr/GHSA-9wvw-xgvm-jmjr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wvw-xgvm-jmjr", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-3692" + ], + "details": "A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3692" + }, + { + "type": "WEB", + "url": "https://github.com/vulnofound/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304981" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304981" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553520" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9x7h-v87g-j6jw/GHSA-9x7h-v87g-j6jw.json b/advisories/unreviewed/2025/04/GHSA-9x7h-v87g-j6jw/GHSA-9x7h-v87g-j6jw.json new file mode 100644 index 00000000000..e60631e581e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9x7h-v87g-j6jw/GHSA-9x7h-v87g-j6jw.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x7h-v87g-j6jw", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22042" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add bounds check for create lease context\n\nAdd missing bounds check for create lease context.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22042" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60b7207893a8a06c78441934931a08fdad63f18e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/629dd37acc336ad778979361c351e782053ea284" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/800c482c9ef5910f05e3a713943c67cc6c1d4939" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a1b6ea955e6c7b29939a6d98701202f9d9644ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a41cd52f00907a040ca22c73d4805bb79b0d0972" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bab703ed8472aa9d109c5f8c1863921533363dae" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c3xr-4rp5-847c/GHSA-c3xr-4rp5-847c.json b/advisories/unreviewed/2025/04/GHSA-c3xr-4rp5-847c/GHSA-c3xr-4rp5-847c.json new file mode 100644 index 00000000000..79467806b9f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c3xr-4rp5-847c/GHSA-c3xr-4rp5-847c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3xr-4rp5-847c", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39578" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks allows Stored XSS. This issue affects Responsive Blocks: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsive-block-editor-addons/vulnerability/wordpress-responsive-blocks-2-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c43m-gvgr-chxv/GHSA-c43m-gvgr-chxv.json b/advisories/unreviewed/2025/04/GHSA-c43m-gvgr-chxv/GHSA-c43m-gvgr-chxv.json new file mode 100644 index 00000000000..5ad46f8dba2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c43m-gvgr-chxv/GHSA-c43m-gvgr-chxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c43m-gvgr-chxv", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-39599" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Webilia Inc. Listdom allows Phishing. This issue affects Listdom: from n/a through 4.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39599" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/listdom/vulnerability/wordpress-listdom-4-0-0-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c4fx-3whg-2g7m/GHSA-c4fx-3whg-2g7m.json b/advisories/unreviewed/2025/04/GHSA-c4fx-3whg-2g7m/GHSA-c4fx-3whg-2g7m.json new file mode 100644 index 00000000000..d8b7a910f9d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c4fx-3whg-2g7m/GHSA-c4fx-3whg-2g7m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4fx-3whg-2g7m", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22108" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Mask the bd_cnt field in the TX BD properly\n\nThe bd_cnt field in the TX BD specifies the total number of BDs for\nthe TX packet. The bd_cnt field has 5 bits and the maximum number\nsupported is 32 with the value 0.\n\nCONFIG_MAX_SKB_FRAGS can be modified and the total number of SKB\nfragments can approach or exceed the maximum supported by the chip.\nAdd a macro to properly mask the bd_cnt field so that the value 32\nwill be properly masked and set to 0 in the bd_cnd field.\n\nWithout this patch, the out-of-range bd_cnt value will corrupt the\nTX BD and may cause TX timeout.\n\nThe next patch will check for values exceeding 32.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22108" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/107b25db61122d8f990987895c2912927b8b6e3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f60b41b815826f15c4d0323f923f398c423178d0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json b/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json new file mode 100644 index 00000000000..4e1afde0cfa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8pq-47pf-5pgc", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22051" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gpib: Fix Oops after disconnect in agilent usb\n\nIf the agilent usb dongle is disconnected subsequent calls to the\ndriver cause a NULL dereference Oops as the bus_interface\nis set to NULL on disconnect.\n\nThis problem was introduced by setting usb_dev from the bus_interface\nfor dev_xxx messages.\n\nPreviously bus_interface was checked for NULL only in the functions\ndirectly calling usb_fill_bulk_urb or usb_control_msg.\n\nCheck for valid bus_interface on all interface entry points\nand return -ENODEV if it is NULL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22051" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50ef6e45bec79da4c5a01fad4dc23466ba255099" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8491e73a5223acb0a4b4d78c3f8b96aa9c5e774d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e88633705078f40391a9afc6cc8ea3025e6f692b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cc5p-3rfr-2p84/GHSA-cc5p-3rfr-2p84.json b/advisories/unreviewed/2025/04/GHSA-cc5p-3rfr-2p84/GHSA-cc5p-3rfr-2p84.json new file mode 100644 index 00000000000..4a4e298449f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cc5p-3rfr-2p84/GHSA-cc5p-3rfr-2p84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc5p-3rfr-2p84", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39515" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tnomi Attendance Manager allows Stored XSS. This issue affects Attendance Manager: from n/a through 0.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39515" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/attendance-manager/vulnerability/wordpress-attendance-manager-0-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfp7-5h7h-9vxv/GHSA-cfp7-5h7h-9vxv.json b/advisories/unreviewed/2025/04/GHSA-cfp7-5h7h-9vxv/GHSA-cfp7-5h7h-9vxv.json index 0d44c6493dc..636de73c51e 100644 --- a/advisories/unreviewed/2025/04/GHSA-cfp7-5h7h-9vxv/GHSA-cfp7-5h7h-9vxv.json +++ b/advisories/unreviewed/2025/04/GHSA-cfp7-5h7h-9vxv/GHSA-cfp7-5h7h-9vxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfp7-5h7h-9vxv", - "modified": "2025-04-16T03:30:25Z", + "modified": "2025-04-16T15:34:29Z", "published": "2025-04-16T03:30:25Z", "aliases": [ "CVE-2025-3664" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3664" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setWiFiEasyGuestCfg-1cb53a41781f805f9ee3f1b2d362d3f2" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setWiFiEasyGuestCfg-1cb53a41781f805f9ee3f1b2d362d3f2?pvs=4" diff --git a/advisories/unreviewed/2025/04/GHSA-ch3q-jhhp-7w44/GHSA-ch3q-jhhp-7w44.json b/advisories/unreviewed/2025/04/GHSA-ch3q-jhhp-7w44/GHSA-ch3q-jhhp-7w44.json new file mode 100644 index 00000000000..65b165d9f94 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ch3q-jhhp-7w44/GHSA-ch3q-jhhp-7w44.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch3q-jhhp-7w44", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23129" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path\n\nIf a shared IRQ is used by the driver due to platform limitation, then the\nIRQ affinity hint is set right after the allocation of IRQ vectors in\nath11k_pci_alloc_msi(). This does no harm unless one of the functions\nrequesting the IRQ fails and attempt to free the IRQ. This results in the\nbelow warning:\n\nWARNING: CPU: 7 PID: 349 at kernel/irq/manage.c:1929 free_irq+0x278/0x29c\nCall trace:\n free_irq+0x278/0x29c\n ath11k_pcic_free_irq+0x70/0x10c [ath11k]\n ath11k_pci_probe+0x800/0x820 [ath11k_pci]\n local_pci_probe+0x40/0xbc\n\nThe warning is due to not clearing the affinity hint before freeing the\nIRQs.\n\nSo to fix this issue, clear the IRQ affinity hint before calling\nath11k_pcic_free_irq() in the error path. The affinity will be cleared once\nagain further down the error path due to code organization, but that does\nno harm.\n\nTested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-05266-QCAHSTSWPLZ_V2_TO_X86-1", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23129" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3fc42cfcc6e336f25dee79b34e57c4a63cd652a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68410c5bd381a81bcc92b808e7dc4e6b9ed25d11" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chm6-426c-783j/GHSA-chm6-426c-783j.json b/advisories/unreviewed/2025/04/GHSA-chm6-426c-783j/GHSA-chm6-426c-783j.json new file mode 100644 index 00000000000..e169748b5eb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chm6-426c-783j/GHSA-chm6-426c-783j.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chm6-426c-783j", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22055" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix geneve_opt length integer overflow\n\nstruct geneve_opt uses 5 bit length for each single option, which\nmeans every vary size option should be smaller than 128 bytes.\n\nHowever, all current related Netlink policies cannot promise this\nlength condition and the attacker can exploit a exact 128-byte size\noption to *fake* a zero length option and confuse the parsing logic,\nfurther achieve heap out-of-bounds read.\n\nOne example crash log is like below:\n\n[ 3.905425] ==================================================================\n[ 3.905925] BUG: KASAN: slab-out-of-bounds in nla_put+0xa9/0xe0\n[ 3.906255] Read of size 124 at addr ffff888005f291cc by task poc/177\n[ 3.906646]\n[ 3.906775] CPU: 0 PID: 177 Comm: poc-oob-read Not tainted 6.1.132 #1\n[ 3.907131] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n[ 3.907784] Call Trace:\n[ 3.907925] \n[ 3.908048] dump_stack_lvl+0x44/0x5c\n[ 3.908258] print_report+0x184/0x4be\n[ 3.909151] kasan_report+0xc5/0x100\n[ 3.909539] kasan_check_range+0xf3/0x1a0\n[ 3.909794] memcpy+0x1f/0x60\n[ 3.909968] nla_put+0xa9/0xe0\n[ 3.910147] tunnel_key_dump+0x945/0xba0\n[ 3.911536] tcf_action_dump_1+0x1c1/0x340\n[ 3.912436] tcf_action_dump+0x101/0x180\n[ 3.912689] tcf_exts_dump+0x164/0x1e0\n[ 3.912905] fw_dump+0x18b/0x2d0\n[ 3.913483] tcf_fill_node+0x2ee/0x460\n[ 3.914778] tfilter_notify+0xf4/0x180\n[ 3.915208] tc_new_tfilter+0xd51/0x10d0\n[ 3.918615] rtnetlink_rcv_msg+0x4a2/0x560\n[ 3.919118] netlink_rcv_skb+0xcd/0x200\n[ 3.919787] netlink_unicast+0x395/0x530\n[ 3.921032] netlink_sendmsg+0x3d0/0x6d0\n[ 3.921987] __sock_sendmsg+0x99/0xa0\n[ 3.922220] __sys_sendto+0x1b7/0x240\n[ 3.922682] __x64_sys_sendto+0x72/0x90\n[ 3.922906] do_syscall_64+0x5e/0x90\n[ 3.923814] entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n[ 3.924122] RIP: 0033:0x7e83eab84407\n[ 3.924331] Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 faf\n[ 3.925330] RSP: 002b:00007ffff505e370 EFLAGS: 00000202 ORIG_RAX: 000000000000002c\n[ 3.925752] RAX: ffffffffffffffda RBX: 00007e83eaafa740 RCX: 00007e83eab84407\n[ 3.926173] RDX: 00000000000001a8 RSI: 00007ffff505e3c0 RDI: 0000000000000003\n[ 3.926587] RBP: 00007ffff505f460 R08: 00007e83eace1000 R09: 000000000000000c\n[ 3.926977] R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffff505f3c0\n[ 3.927367] R13: 00007ffff505f5c8 R14: 00007e83ead1b000 R15: 00005d4fbbe6dcb8\n\nFix these issues by enforing correct length condition in related\npolicies.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22055" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21748669c5825761cbbf47cbeeb01387ddccc8cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2952776c69a1a551649ed770bf22e3f691f6ec65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d606069bdd3c76f8ab1f06796c97ef7f4746807" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a2976cc4d9c36ff58a0f10e35ce4283cbaa9c0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/738ae5712215fe9181587d582b23333f02c62ca6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2cb85f989e2074e2f392e00188c438cab3de088" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b27055a08ad4b415dcf15b63034f9cb236f7fb40" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4513ad0f391871d3feee8ddf535609a3aabeeac" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json b/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json new file mode 100644 index 00000000000..7377daa46df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjw9-x8qr-5wpf", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22122" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix adding folio to bio\n\n>4GB folio is possible on some ARCHs, such as aarch64, 16GB hugepage\nis supported, then 'offset' of folio can't be held in 'unsigned int',\ncause warning in bio_add_folio_nofail() and IO failure.\n\nFix it by adjusting 'page' & trimming 'offset' so that `->bi_offset` won't\nbe overflow, and folio can be added to bio successfully.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22122" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26064d3e2b4d9a14df1072980e558c636fb023ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b96e0af1b1c99cb7e6188b6fa4963a4e47beb01e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxcw-75qj-r943/GHSA-cxcw-75qj-r943.json b/advisories/unreviewed/2025/04/GHSA-cxcw-75qj-r943/GHSA-cxcw-75qj-r943.json new file mode 100644 index 00000000000..542a546ab95 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxcw-75qj-r943/GHSA-cxcw-75qj-r943.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxcw-75qj-r943", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2024-58095" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before txBeginAnon() call\n\nAdded a read-only check before calling `txBeginAnon` in `extAlloc`\nand `extRecord`. This prevents modification attempts on a read-only\nmounted filesystem, avoiding potential errors or crashes.\n\nCall trace:\n txBeginAnon+0xac/0x154\n extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78\n jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248\n __block_write_begin_int+0x580/0x166c fs/buffer.c:2128\n __block_write_begin fs/buffer.c:2177 [inline]\n block_write_begin+0x98/0x11c fs/buffer.c:2236\n jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58095" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0176e69743ecc02961f2ae1ea42439cd2bf9ed58" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15469c408af2d7a52fb186a92f2f091b0f13b1fb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxj5-mwc8-g86c/GHSA-cxj5-mwc8-g86c.json b/advisories/unreviewed/2025/04/GHSA-cxj5-mwc8-g86c/GHSA-cxj5-mwc8-g86c.json new file mode 100644 index 00000000000..0adb1359dac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxj5-mwc8-g86c/GHSA-cxj5-mwc8-g86c.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxj5-mwc8-g86c", + "modified": "2025-04-16T15:34:32Z", + "published": "2025-04-16T15:34:32Z", + "aliases": [ + "CVE-2025-1980" + ], + "details": "The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If the server is misconfigured, as it was by default when installed at the turn of 2021 and 2022, it can result in Remote Code Execution. Refer to the Required Configuration for Exposure section for more information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://ready-os.com/pl" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f42j-5x72-52wf/GHSA-f42j-5x72-52wf.json b/advisories/unreviewed/2025/04/GHSA-f42j-5x72-52wf/GHSA-f42j-5x72-52wf.json new file mode 100644 index 00000000000..6d039a4b04f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f42j-5x72-52wf/GHSA-f42j-5x72-52wf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f42j-5x72-52wf", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22119" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: init wiphy_work before allocating rfkill fails\n\nsyzbort reported a uninitialize wiphy_work_lock in cfg80211_dev_free. [1]\n\nAfter rfkill allocation fails, the wiphy release process will be performed,\nwhich will cause cfg80211_dev_free to access the uninitialized wiphy_work\nrelated data.\n\nMove the initialization of wiphy_work to before rfkill initialization to\navoid this issue.\n\n[1]\nINFO: trying to register non-static key.\nThe code is fine but needs lockdep annotation, or maybe\nyou didn't initialize this object before use?\nturning off the locking correctness validator.\nCPU: 0 UID: 0 PID: 5935 Comm: syz-executor550 Not tainted 6.14.0-rc6-syzkaller-00103-g4003c9e78778 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n assign_lock_key kernel/locking/lockdep.c:983 [inline]\n register_lock_class+0xc39/0x1240 kernel/locking/lockdep.c:1297\n __lock_acquire+0x135/0x3c40 kernel/locking/lockdep.c:5103\n lock_acquire.part.0+0x11b/0x380 kernel/locking/lockdep.c:5851\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0x3a/0x60 kernel/locking/spinlock.c:162\n cfg80211_dev_free+0x30/0x3d0 net/wireless/core.c:1196\n device_release+0xa1/0x240 drivers/base/core.c:2568\n kobject_cleanup lib/kobject.c:689 [inline]\n kobject_release lib/kobject.c:720 [inline]\n kref_put include/linux/kref.h:65 [inline]\n kobject_put+0x1e4/0x5a0 lib/kobject.c:737\n put_device+0x1f/0x30 drivers/base/core.c:3774\n wiphy_free net/wireless/core.c:1224 [inline]\n wiphy_new_nm+0x1c1f/0x2160 net/wireless/core.c:562\n ieee80211_alloc_hw_nm+0x1b7a/0x2260 net/mac80211/main.c:835\n mac80211_hwsim_new_radio+0x1d6/0x54e0 drivers/net/wireless/virtual/mac80211_hwsim.c:5185\n hwsim_new_radio_nl+0xb42/0x12b0 drivers/net/wireless/virtual/mac80211_hwsim.c:6242\n genl_family_rcv_msg_doit+0x202/0x2f0 net/netlink/genetlink.c:1115\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x565/0x800 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x16b/0x440 net/netlink/af_netlink.c:2533\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1312 [inline]\n netlink_unicast+0x53c/0x7f0 net/netlink/af_netlink.c:1338\n netlink_sendmsg+0x8b8/0xd70 net/netlink/af_netlink.c:1882\n sock_sendmsg_nosec net/socket.c:718 [inline]\n __sock_sendmsg net/socket.c:733 [inline]\n ____sys_sendmsg+0xaaf/0xc90 net/socket.c:2573\n ___sys_sendmsg+0x135/0x1e0 net/socket.c:2627\n __sys_sendmsg+0x16e/0x220 net/socket.c:2659\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n\nClose: https://syzkaller.appspot.com/bug?extid=aaf0488c83d1d5f4f029", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22119" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2617f60c3613ef105b8db2d514d2cac2a1836f7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc88dee89d7b63eeb17699393eb659aadf9d9b7c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f5rg-cp58-cwjr/GHSA-f5rg-cp58-cwjr.json b/advisories/unreviewed/2025/04/GHSA-f5rg-cp58-cwjr/GHSA-f5rg-cp58-cwjr.json new file mode 100644 index 00000000000..0353201ee93 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f5rg-cp58-cwjr/GHSA-f5rg-cp58-cwjr.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5rg-cp58-cwjr", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22060" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: Prevent parser TCAM memory corruption\n\nProtect the parser TCAM/SRAM memory, and the cached (shadow) SRAM\ninformation, from concurrent modifications.\n\nBoth the TCAM and SRAM tables are indirectly accessed by configuring\nan index register that selects the row to read or write to. This means\nthat operations must be atomic in order to, e.g., avoid spreading\nwrites across multiple rows. Since the shadow SRAM array is used to\nfind free rows in the hardware table, it must also be protected in\norder to avoid TOCTOU errors where multiple cores allocate the same\nrow.\n\nThis issue was detected in a situation where `mvpp2_set_rx_mode()` ran\nconcurrently on two CPUs. In this particular case the\nMVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the\nclassifier unit to drop all incoming unicast - indicated by the\n`rx_classifier_drops` counter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22060" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46c1e23e34c9d1eaadf37f88216d9d8ce0d0bcee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b0ae1723a7d9574ae1aee7d9cf9757a30069865" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96844075226b49af25a69a1d084b648ec2d9b08d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3f48a41a00d6d8d9c6fe09ae47dd21c8c1c8b03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3711163d14d02af9005e4cdad30899c565f13fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e64e9b6e86b39db3baa576fd73da73533b54cb2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcbfb54a0269875cf3cd6a2bff4f85a2e0a0b552" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f6x4-fwp3-vv23/GHSA-f6x4-fwp3-vv23.json b/advisories/unreviewed/2025/04/GHSA-f6x4-fwp3-vv23/GHSA-f6x4-fwp3-vv23.json new file mode 100644 index 00000000000..887c3cbf524 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f6x4-fwp3-vv23/GHSA-f6x4-fwp3-vv23.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6x4-fwp3-vv23", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22057" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: decrease cached dst counters in dst_release\n\nUpstream fix ac888d58869b (\"net: do not delay dst_entries_add() in\ndst_release()\") moved decrementing the dst count from dst_destroy to\ndst_release to avoid accessing already freed data in case of netns\ndismantle. However in case CONFIG_DST_CACHE is enabled and OvS+tunnels\nare used, this fix is incomplete as the same issue will be seen for\ncached dsts:\n\n Unable to handle kernel paging request at virtual address ffff5aabf6b5c000\n Call trace:\n percpu_counter_add_batch+0x3c/0x160 (P)\n dst_release+0xec/0x108\n dst_cache_destroy+0x68/0xd8\n dst_destroy+0x13c/0x168\n dst_destroy_rcu+0x1c/0xb0\n rcu_do_batch+0x18c/0x7d0\n rcu_core+0x174/0x378\n rcu_core_si+0x18/0x30\n\nFix this by invalidating the cache, and thus decrementing cached dst\ncounters, in dst_release too.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22057" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a0a3ff6593d670af2451ec363ccb7b18aec0c0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/836415a8405c9665ae55352fc5ba865c242f5e4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92a5c18513117be69bc00419dd1724c1940f8fcd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccc331fd5bcae131d2627d5ef099d4a1f6540aea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e833e7ad64eb2f63867f65303be49ca30ee8819e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc2r-93rp-39pp/GHSA-fc2r-93rp-39pp.json b/advisories/unreviewed/2025/04/GHSA-fc2r-93rp-39pp/GHSA-fc2r-93rp-39pp.json new file mode 100644 index 00000000000..8f600961391 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc2r-93rp-39pp/GHSA-fc2r-93rp-39pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc2r-93rp-39pp", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39517" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Basic Interactive World Map allows Cross Site Request Forgery. This issue affects Basic Interactive World Map: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39517" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/basic-interactive-world-map/vulnerability/wordpress-basic-interactive-world-map-plugin-2-7-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc7v-mg36-xxcw/GHSA-fc7v-mg36-xxcw.json b/advisories/unreviewed/2025/04/GHSA-fc7v-mg36-xxcw/GHSA-fc7v-mg36-xxcw.json new file mode 100644 index 00000000000..58b5c0be90c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc7v-mg36-xxcw/GHSA-fc7v-mg36-xxcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc7v-mg36-xxcw", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39566" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel allows Blind SQL Injection. This issue affects Hostel: from n/a through 1.1.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39566" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hostel/vulnerability/wordpress-hostel-1-1-5-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fcc8-29wg-87m4/GHSA-fcc8-29wg-87m4.json b/advisories/unreviewed/2025/04/GHSA-fcc8-29wg-87m4/GHSA-fcc8-29wg-87m4.json new file mode 100644 index 00000000000..cb0974a80c5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fcc8-29wg-87m4/GHSA-fcc8-29wg-87m4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcc8-29wg-87m4", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39547" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser allows Stored XSS. This issue affects Internal Link Optimiser: from n/a through 5.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/internal-link-finder/vulnerability/wordpress-internal-link-optimiser-plugin-5-1-3-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ff4q-6fcm-f22c/GHSA-ff4q-6fcm-f22c.json b/advisories/unreviewed/2025/04/GHSA-ff4q-6fcm-f22c/GHSA-ff4q-6fcm-f22c.json new file mode 100644 index 00000000000..305b71ad9be --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ff4q-6fcm-f22c/GHSA-ff4q-6fcm-f22c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff4q-6fcm-f22c", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39528" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS. This issue affects Rescue Shortcodes: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39528" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rescue-shortcodes/vulnerability/wordpress-rescue-shortcodes-plugin-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json b/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json new file mode 100644 index 00000000000..cafe57e7500 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq4p-236v-8g34", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22123" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid accessing uninitialized curseg\n\nsyzbot reports a f2fs bug as below:\n\nF2FS-fs (loop3): Stopped filesystem due to reason: 7\nkworker/u8:7: attempt to access beyond end of device\nBUG: unable to handle page fault for address: ffffed1604ea3dfa\nRIP: 0010:get_ckpt_valid_blocks fs/f2fs/segment.h:361 [inline]\nRIP: 0010:has_curseg_enough_space fs/f2fs/segment.h:570 [inline]\nRIP: 0010:__get_secs_required fs/f2fs/segment.h:620 [inline]\nRIP: 0010:has_not_enough_free_secs fs/f2fs/segment.h:633 [inline]\nRIP: 0010:has_enough_free_secs+0x575/0x1660 fs/f2fs/segment.h:649\n \n f2fs_is_checkpoint_ready fs/f2fs/segment.h:671 [inline]\n f2fs_write_inode+0x425/0x540 fs/f2fs/inode.c:791\n write_inode fs/fs-writeback.c:1525 [inline]\n __writeback_single_inode+0x708/0x10d0 fs/fs-writeback.c:1745\n writeback_sb_inodes+0x820/0x1360 fs/fs-writeback.c:1976\n wb_writeback+0x413/0xb80 fs/fs-writeback.c:2156\n wb_do_writeback fs/fs-writeback.c:2303 [inline]\n wb_workfn+0x410/0x1080 fs/fs-writeback.c:2343\n process_one_work kernel/workqueue.c:3236 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3317\n worker_thread+0x870/0xd30 kernel/workqueue.c:3398\n kthread+0x7a9/0x920 kernel/kthread.c:464\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nCommit 8b10d3653735 (\"f2fs: introduce FAULT_NO_SEGMENT\") allows to trigger\nno free segment fault in allocator, then it will update curseg->segno to\nNULL_SEGNO, though, CP_ERROR_FLAG has been set, f2fs_write_inode() missed\nto check the flag, and access invalid curseg->segno directly in below call\npath, then resulting in panic:\n\n- f2fs_write_inode\n - f2fs_is_checkpoint_ready\n - has_enough_free_secs\n - has_not_enough_free_secs\n - __get_secs_required\n - has_curseg_enough_space\n - get_ckpt_valid_blocks\n : access invalid curseg->segno\n\nTo avoid this issue, let's:\n- check CP_ERROR_FLAG flag in prior to f2fs_is_checkpoint_ready() in\nf2fs_write_inode().\n- in has_curseg_enough_space(), save curseg->segno into a temp variable,\nand verify its validation before use.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22123" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f90e5d423cd2d4c74b2abb527872f335108637f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/986c50f6bca109c6cf362b4e2babcb85aba958f6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g5f8-w583-m28g/GHSA-g5f8-w583-m28g.json b/advisories/unreviewed/2025/04/GHSA-g5f8-w583-m28g/GHSA-g5f8-w583-m28g.json new file mode 100644 index 00000000000..ab31ed3296a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g5f8-w583-m28g/GHSA-g5f8-w583-m28g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5f8-w583-m28g", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39579" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce allows DOM-Based XSS. This issue affects Membership For WooCommerce: from n/a through 2.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/membership-for-woocommerce/vulnerability/wordpress-membership-for-woocommerce-2-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json b/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json index 81f587f35ba..3b459555ef9 100644 --- a/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json +++ b/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-gg64-46cm-rj5f/GHSA-gg64-46cm-rj5f.json b/advisories/unreviewed/2025/04/GHSA-gg64-46cm-rj5f/GHSA-gg64-46cm-rj5f.json index 218e41b1709..725bf64f6b9 100644 --- a/advisories/unreviewed/2025/04/GHSA-gg64-46cm-rj5f/GHSA-gg64-46cm-rj5f.json +++ b/advisories/unreviewed/2025/04/GHSA-gg64-46cm-rj5f/GHSA-gg64-46cm-rj5f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-ghq9-g65f-2r4v/GHSA-ghq9-g65f-2r4v.json b/advisories/unreviewed/2025/04/GHSA-ghq9-g65f-2r4v/GHSA-ghq9-g65f-2r4v.json new file mode 100644 index 00000000000..160702c1ee5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghq9-g65f-2r4v/GHSA-ghq9-g65f-2r4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghq9-g65f-2r4v", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39563" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Payments for WooCommerce allows Cross Site Request Forgery. This issue affects Conditional Payments for WooCommerce: from n/a through 3.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/conditional-payments-for-woocommerce/vulnerability/wordpress-conditional-payments-for-woocommerce-3-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gj5h-7fq5-56p5/GHSA-gj5h-7fq5-56p5.json b/advisories/unreviewed/2025/04/GHSA-gj5h-7fq5-56p5/GHSA-gj5h-7fq5-56p5.json new file mode 100644 index 00000000000..42d2f65335a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gj5h-7fq5-56p5/GHSA-gj5h-7fq5-56p5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj5h-7fq5-56p5", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-22127" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadloop in prepare_compress_overwrite()\n\nJan Prusakowski reported a kernel hang issue as below:\n\nWhen running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I\nencountered a problem in generic/475 test where fsstress process\ngets blocked in __f2fs_write_data_pages() and the test hangs.\nThe options I used are:\n\nMKFS_OPTIONS -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc\nMOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc\n\nINFO: task kworker/u8:0:11 blocked for more than 122 seconds.\n Not tainted 6.14.0-rc3-xfstests-lockdep #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:0 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208160 flags:0x00004000\nWorkqueue: writeback wb_workfn (flush-253:0)\nCall Trace:\n \n __schedule+0x309/0x8e0\n schedule+0x3a/0x100\n schedule_preempt_disabled+0x15/0x30\n __mutex_lock+0x59a/0xdb0\n __f2fs_write_data_pages+0x3ac/0x400\n do_writepages+0xe8/0x290\n __writeback_single_inode+0x5c/0x360\n writeback_sb_inodes+0x22f/0x570\n wb_writeback+0xb0/0x410\n wb_do_writeback+0x47/0x2f0\n wb_workfn+0x5a/0x1c0\n process_one_work+0x223/0x5b0\n worker_thread+0x1d5/0x3c0\n kthread+0xfd/0x230\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n \n\nThe root cause is: once generic/475 starts toload error table to dm\ndevice, f2fs_prepare_compress_overwrite() will loop reading compressed\ncluster pages due to IO error, meanwhile it has held .writepages lock,\nit can block all other writeback tasks.\n\nLet's fix this issue w/ below changes:\n- add f2fs_handle_page_eio() in prepare_compress_overwrite() to\ndetect IO error.\n- detect cp_error earler in f2fs_read_multi_pages().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22127" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3147ee567dd9004a49826ddeaf0a4b12865d4409" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7215cf8ef54bdc9082dffac4662416d54961e258" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json b/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json new file mode 100644 index 00000000000..3c2c5e3adb4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj89-4h85-hv53", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22041" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in ksmbd_sessions_deregister()\n\nIn multichannel mode, UAF issue can occur in session_deregister\nwhen the second channel sets up a session through the connection of\nthe first channel. session that is freed through the global session\ntable can be accessed again through ->sessions of connection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22041" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15a9605f8d69dc85005b1a00c31a050b8625e1aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33cc29e221df7a3085ae413e8c26c4e81a151153" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ed0e9d2f410f63525afb8351181eea36c80bcf1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8a8ae303a8395cbac270b5b404d85df6ec788f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca042cc0e4f9e0d2c8f86dd67e4b22f30a516a9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0eb3f575138b816da74697bd506682574742fcd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gjjg-hhwj-9mvj/GHSA-gjjg-hhwj-9mvj.json b/advisories/unreviewed/2025/04/GHSA-gjjg-hhwj-9mvj/GHSA-gjjg-hhwj-9mvj.json new file mode 100644 index 00000000000..e0eda7d9174 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gjjg-hhwj-9mvj/GHSA-gjjg-hhwj-9mvj.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjjg-hhwj-9mvj", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22093" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: avoid NPD when ASIC does not support DMUB\n\nctx->dmub_srv will de NULL if the ASIC does not support DMUB, which is\ntested in dm_dmub_sw_init.\n\nHowever, it will be dereferenced in dmub_hw_lock_mgr_cmd if\nshould_use_dmub_lock returns true.\n\nThis has been the case since dmub support has been added for PSR1.\n\nFix this by checking for dmub_srv in should_use_dmub_lock.\n\n[ 37.440832] BUG: kernel NULL pointer dereference, address: 0000000000000058\n[ 37.447808] #PF: supervisor read access in kernel mode\n[ 37.452959] #PF: error_code(0x0000) - not-present page\n[ 37.458112] PGD 0 P4D 0\n[ 37.460662] Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ 37.465553] CPU: 2 UID: 1000 PID: 1745 Comm: DrmThread Not tainted 6.14.0-rc1-00003-gd62e938120f0 #23 99720e1cb1e0fc4773b8513150932a07de3c6e88\n[ 37.478324] Hardware name: Google Morphius/Morphius, BIOS Google_Morphius.13434.858.0 10/26/2023\n[ 37.487103] RIP: 0010:dmub_hw_lock_mgr_cmd+0x77/0xb0\n[ 37.492074] Code: 44 24 0e 00 00 00 00 48 c7 04 24 45 00 00 0c 40 88 74 24 0d 0f b6 02 88 44 24 0c 8b 01 89 44 24 08 85 f6 75 05 c6 44 24 0e 01 <48> 8b 7f 58 48 89 e6 ba 01 00 00 00 e8 08 3c 2a 00 65 48 8b 04 5\n[ 37.510822] RSP: 0018:ffff969442853300 EFLAGS: 00010202\n[ 37.516052] RAX: 0000000000000000 RBX: ffff92db03000000 RCX: ffff969442853358\n[ 37.523185] RDX: ffff969442853368 RSI: 0000000000000001 RDI: 0000000000000000\n[ 37.530322] RBP: 0000000000000001 R08: 00000000000004a7 R09: 00000000000004a5\n[ 37.537453] R10: 0000000000000476 R11: 0000000000000062 R12: ffff92db0ade8000\n[ 37.544589] R13: ffff92da01180ae0 R14: ffff92da011802a8 R15: ffff92db03000000\n[ 37.551725] FS: 0000784a9cdfc6c0(0000) GS:ffff92db2af00000(0000) knlGS:0000000000000000\n[ 37.559814] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 37.565562] CR2: 0000000000000058 CR3: 0000000112b1c000 CR4: 00000000003506f0\n[ 37.572697] Call Trace:\n[ 37.575152] \n[ 37.577258] ? __die_body+0x66/0xb0\n[ 37.580756] ? page_fault_oops+0x3e7/0x4a0\n[ 37.584861] ? exc_page_fault+0x3e/0xe0\n[ 37.588706] ? exc_page_fault+0x5c/0xe0\n[ 37.592550] ? asm_exc_page_fault+0x22/0x30\n[ 37.596742] ? dmub_hw_lock_mgr_cmd+0x77/0xb0\n[ 37.601107] dcn10_cursor_lock+0x1e1/0x240\n[ 37.605211] program_cursor_attributes+0x81/0x190\n[ 37.609923] commit_planes_for_stream+0x998/0x1ef0\n[ 37.614722] update_planes_and_stream_v2+0x41e/0x5c0\n[ 37.619703] dc_update_planes_and_stream+0x78/0x140\n[ 37.624588] amdgpu_dm_atomic_commit_tail+0x4362/0x49f0\n[ 37.629832] ? srso_return_thunk+0x5/0x5f\n[ 37.633847] ? mark_held_locks+0x6d/0xd0\n[ 37.637774] ? _raw_spin_unlock_irq+0x24/0x50\n[ 37.642135] ? srso_return_thunk+0x5/0x5f\n[ 37.646148] ? lockdep_hardirqs_on+0x95/0x150\n[ 37.650510] ? srso_return_thunk+0x5/0x5f\n[ 37.654522] ? _raw_spin_unlock_irq+0x2f/0x50\n[ 37.658883] ? srso_return_thunk+0x5/0x5f\n[ 37.662897] ? wait_for_common+0x186/0x1c0\n[ 37.666998] ? srso_return_thunk+0x5/0x5f\n[ 37.671009] ? drm_crtc_next_vblank_start+0xc3/0x170\n[ 37.675983] commit_tail+0xf5/0x1c0\n[ 37.679478] drm_atomic_helper_commit+0x2a2/0x2b0\n[ 37.684186] drm_atomic_commit+0xd6/0x100\n[ 37.688199] ? __cfi___drm_printfn_info+0x10/0x10\n[ 37.692911] drm_atomic_helper_update_plane+0xe5/0x130\n[ 37.698054] drm_mode_cursor_common+0x501/0x670\n[ 37.702600] ? __cfi_drm_mode_cursor_ioctl+0x10/0x10\n[ 37.707572] drm_mode_cursor_ioctl+0x48/0x70\n[ 37.711851] drm_ioctl_kernel+0xf2/0x150\n[ 37.715781] drm_ioctl+0x363/0x590\n[ 37.719189] ? __cfi_drm_mode_cursor_ioctl+0x10/0x10\n[ 37.724165] amdgpu_drm_ioctl+0x41/0x80\n[ 37.728013] __se_sys_ioctl+0x7f/0xd0\n[ 37.731685] do_syscall_64+0x87/0x100\n[ 37.735355] ? vma_end_read+0x12/0xe0\n[ 37.739024] ? srso_return_thunk+0x5/0x5f\n[ 37.743041] ? find_held_lock+0x47/0xf0\n[ 37.746884] ? vma_end_read+0x12/0xe0\n[ 37.750552] ? srso_return_thunk+0x5/0\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22093" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3453bcaf2ca92659346bf8504c2b52b3993fbd79" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35ad39afd007eddf34b3307bebb715c26891cc96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42d9d7bed270247f134190ba0cb05bbd072f58c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e4b1e04740cdb28de189285007366d99a92f1ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3a93a2407ad23c8d5bacabaf7cecbb4c6cdd461" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d953e2cd59ab466569c6f9da460e01caf1c83559" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json b/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json new file mode 100644 index 00000000000..9b4c1e147d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjvw-2pj9-fgr6", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22052" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gpib: Fix Oops after disconnect in ni_usb\n\nIf the usb dongle is disconnected subsequent calls to the\ndriver cause a NULL dereference Oops as the bus_interface\nis set to NULL on disconnect.\n\nThis problem was introduced by setting usb_dev from the bus_interface\nfor dev_xxx messages.\n\nPreviously bus_interface was checked for NULL only in the the functions\ndirectly calling usb_fill_bulk_urb or usb_control_msg.\n\nCheck for valid bus_interface on all interface entry points\nand return -ENODEV if it is NULL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22052" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dc98ba6f7304c188b267ef481281849638447bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a239c6e91b665f1837cf57b97fe638ef1baf2e78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2d8d7959077c5d4b11d0dc6bd2167791fd1c72e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-grxg-qf98-pfw3/GHSA-grxg-qf98-pfw3.json b/advisories/unreviewed/2025/04/GHSA-grxg-qf98-pfw3/GHSA-grxg-qf98-pfw3.json index b657e6e6f9b..18555ef8759 100644 --- a/advisories/unreviewed/2025/04/GHSA-grxg-qf98-pfw3/GHSA-grxg-qf98-pfw3.json +++ b/advisories/unreviewed/2025/04/GHSA-grxg-qf98-pfw3/GHSA-grxg-qf98-pfw3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-gv9h-c7qr-5qwc/GHSA-gv9h-c7qr-5qwc.json b/advisories/unreviewed/2025/04/GHSA-gv9h-c7qr-5qwc/GHSA-gv9h-c7qr-5qwc.json new file mode 100644 index 00000000000..110eb52ef77 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gv9h-c7qr-5qwc/GHSA-gv9h-c7qr-5qwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv9h-c7qr-5qwc", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39571" + ], + "details": "Missing Authorization vulnerability in WPXPO WowStore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WowStore: from n/a through 4.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39571" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-blocks/vulnerability/wordpress-wowstore-4-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json b/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json new file mode 100644 index 00000000000..be6b8431753 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvg4-xh6r-ggrp", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22037" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request. ksmbd return error\nresponse. Subsequently, the client can send smb2 session setup even\nthought conn->preauth_info is not allocated.\nThis patch add KSMBD_SESS_NEED_SETUP status of connection to ignore\nsession setup request if smb2 negotiate phase is not complete.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22037" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8eb243e670ecf30e91524dd12f7260dac07d335" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gwgr-4p4p-9w6m/GHSA-gwgr-4p4p-9w6m.json b/advisories/unreviewed/2025/04/GHSA-gwgr-4p4p-9w6m/GHSA-gwgr-4p4p-9w6m.json new file mode 100644 index 00000000000..a0273e123ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwgr-4p4p-9w6m/GHSA-gwgr-4p4p-9w6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwgr-4p4p-9w6m", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39543" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a through 1.3.977.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/royal-elementor-addons/vulnerability/wordpress-royal-elementor-addons-plugin-1-3-977-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json b/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json new file mode 100644 index 00000000000..c9db4a3764f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxg5-6xg7-gc7q", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23134" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: Don't take register_mutex with copy_from/to_user()\n\nThe infamous mmap_lock taken in copy_from/to_user() can be often\nproblematic when it's called inside another mutex, as they might lead\nto deadlocks.\n\nIn the case of ALSA timer code, the bad pattern is with\nguard(mutex)(®ister_mutex) that covers copy_from/to_user() -- which\nwas mistakenly introduced at converting to guard(), and it had been\ncarefully worked around in the past.\n\nThis patch fixes those pieces simply by moving copy_from/to_user() out\nof the register mutex lock again.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23134" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15291b561d8cc835a2eea76b394070cf8e072771" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/296f7a9e15aab276db11206cbc1e2ae1215d7862" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3424c8f53bc63c87712a7fc22dc13d0cc85fb0d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b074f47e55df93832bbbca1b524c501e6fea1c0d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gxqc-9w8x-48v5/GHSA-gxqc-9w8x-48v5.json b/advisories/unreviewed/2025/04/GHSA-gxqc-9w8x-48v5/GHSA-gxqc-9w8x-48v5.json new file mode 100644 index 00000000000..757a465375f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gxqc-9w8x-48v5/GHSA-gxqc-9w8x-48v5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxqc-9w8x-48v5", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39597" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings allows Phishing. This issue affects Fast eBay Listings: from n/a through 2.12.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39597" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fast-ebay-listings/vulnerability/wordpress-fast-ebay-listings-2-12-15-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h26m-qmpx-mvhh/GHSA-h26m-qmpx-mvhh.json b/advisories/unreviewed/2025/04/GHSA-h26m-qmpx-mvhh/GHSA-h26m-qmpx-mvhh.json new file mode 100644 index 00000000000..90f0d36e83b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h26m-qmpx-mvhh/GHSA-h26m-qmpx-mvhh.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h26m-qmpx-mvhh", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22059" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: Fix multiple wraparounds of sk->sk_rmem_alloc.\n\n__udp_enqueue_schedule_skb() has the following condition:\n\n if (atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf)\n goto drop;\n\nsk->sk_rcvbuf is initialised by net.core.rmem_default and later can\nbe configured by SO_RCVBUF, which is limited by net.core.rmem_max,\nor SO_RCVBUFFORCE.\n\nIf we set INT_MAX to sk->sk_rcvbuf, the condition is always false\nas sk->sk_rmem_alloc is also signed int.\n\nThen, the size of the incoming skb is added to sk->sk_rmem_alloc\nunconditionally.\n\nThis results in integer overflow (possibly multiple times) on\nsk->sk_rmem_alloc and allows a single socket to have skb up to\nnet.core.udp_mem[1].\n\nFor example, if we set a large value to udp_mem[1] and INT_MAX to\nsk->sk_rcvbuf and flood packets to the socket, we can see multiple\noverflows:\n\n # cat /proc/net/sockstat | grep UDP:\n UDP: inuse 3 mem 7956736 <-- (7956736 << 12) bytes > INT_MAX * 15\n ^- PAGE_SHIFT\n # ss -uam\n State Recv-Q ...\n UNCONN -1757018048 ... <-- flipping the sign repeatedly\n skmem:(r2537949248,rb2147483646,t0,tb212992,f1984,w0,o0,bl0,d0)\n\nPreviously, we had a boundary check for INT_MAX, which was removed by\ncommit 6a1f12dd85a8 (\"udp: relax atomic operation on sk->sk_rmem_alloc\").\n\nA complete fix would be to revert it and cap the right operand by\nINT_MAX:\n\n rmem = atomic_add_return(size, &sk->sk_rmem_alloc);\n if (rmem > min(size + (unsigned int)sk->sk_rcvbuf, INT_MAX))\n goto uncharge_drop;\n\nbut we do not want to add the expensive atomic_add_return() back just\nfor the corner case.\n\nCasting rmem to unsigned int prevents multiple wraparounds, but we still\nallow a single wraparound.\n\n # cat /proc/net/sockstat | grep UDP:\n UDP: inuse 3 mem 524288 <-- (INT_MAX + 1) >> 12\n\n # ss -uam\n State Recv-Q ...\n UNCONN -2147482816 ... <-- INT_MAX + 831 bytes\n skmem:(r2147484480,rb2147483646,t0,tb212992,f3264,w0,o0,bl0,d14468947)\n\nSo, let's define rmem and rcvbuf as unsigned int and check skb->truesize\nonly when rcvbuf is large enough to lower the overflow possibility.\n\nNote that we still have a small chance to see overflow if multiple skbs\nto the same socket are processed on different core at the same time and\neach size does not exceed the limit but the total size does.\n\nNote also that we must ignore skb->truesize for a small buffer as\nexplained in commit 363dc73acacb (\"udp: be less conservative with\nsock rmem accounting\").", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22059" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f529988efe9870db802cb79d01d8f473099b4d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a465a0da13ee9fbd7d3cd0b2893309b0fe4b7e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7571aadd20289e9ea10ebfed0986f39ed8b3c16b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94d5ad7b41122be33ebc2a6830fe710cba1ecd75" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h52v-87c4-f7qg/GHSA-h52v-87c4-f7qg.json b/advisories/unreviewed/2025/04/GHSA-h52v-87c4-f7qg/GHSA-h52v-87c4-f7qg.json new file mode 100644 index 00000000000..ac7b4cd93bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h52v-87c4-f7qg/GHSA-h52v-87c4-f7qg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h52v-87c4-f7qg", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22115" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix block group refcount race in btrfs_create_pending_block_groups()\n\nBlock group creation is done in two phases, which results in a slightly\nunintuitive property: a block group can be allocated/deallocated from\nafter btrfs_make_block_group() adds it to the space_info with\nbtrfs_add_bg_to_space_info(), but before creation is completely completed\nin btrfs_create_pending_block_groups(). As a result, it is possible for a\nblock group to go unused and have 'btrfs_mark_bg_unused' called on it\nconcurrently with 'btrfs_create_pending_block_groups'. This causes a\nnumber of issues, which were fixed with the block group flag\n'BLOCK_GROUP_FLAG_NEW'.\n\nHowever, this fix is not quite complete. Since it does not use the\nunused_bg_lock, it is possible for the following race to occur:\n\nbtrfs_create_pending_block_groups btrfs_mark_bg_unused\n if list_empty // false\n list_del_init\n clear_bit\n else if (test_bit) // true\n list_move_tail\n\nAnd we get into the exact same broken ref count and invalid new_bgs\nstate for transaction cleanup that BLOCK_GROUP_FLAG_NEW was designed to\nprevent.\n\nThe broken refcount aspect will result in a warning like:\n\n [1272.943527] refcount_t: underflow; use-after-free.\n [1272.943967] WARNING: CPU: 1 PID: 61 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110\n [1272.944731] Modules linked in: btrfs virtio_net xor zstd_compress raid6_pq null_blk [last unloaded: btrfs]\n [1272.945550] CPU: 1 UID: 0 PID: 61 Comm: kworker/u32:1 Kdump: loaded Tainted: G W 6.14.0-rc5+ #108\n [1272.946368] Tainted: [W]=WARN\n [1272.946585] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n [1272.947273] Workqueue: btrfs_discard btrfs_discard_workfn [btrfs]\n [1272.947788] RIP: 0010:refcount_warn_saturate+0xba/0x110\n [1272.949532] RSP: 0018:ffffbf1200247df0 EFLAGS: 00010282\n [1272.949901] RAX: 0000000000000000 RBX: ffffa14b00e3f800 RCX: 0000000000000000\n [1272.950437] RDX: 0000000000000000 RSI: ffffbf1200247c78 RDI: 00000000ffffdfff\n [1272.950986] RBP: ffffa14b00dc2860 R08: 00000000ffffdfff R09: ffffffff90526268\n [1272.951512] R10: ffffffff904762c0 R11: 0000000063666572 R12: ffffa14b00dc28c0\n [1272.952024] R13: 0000000000000000 R14: ffffa14b00dc2868 R15: 000001285dcd12c0\n [1272.952850] FS: 0000000000000000(0000) GS:ffffa14d33c40000(0000) knlGS:0000000000000000\n [1272.953458] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [1272.953931] CR2: 00007f838cbda000 CR3: 000000010104e000 CR4: 00000000000006f0\n [1272.954474] Call Trace:\n [1272.954655] \n [1272.954812] ? refcount_warn_saturate+0xba/0x110\n [1272.955173] ? __warn.cold+0x93/0xd7\n [1272.955487] ? refcount_warn_saturate+0xba/0x110\n [1272.955816] ? report_bug+0xe7/0x120\n [1272.956103] ? handle_bug+0x53/0x90\n [1272.956424] ? exc_invalid_op+0x13/0x60\n [1272.956700] ? asm_exc_invalid_op+0x16/0x20\n [1272.957011] ? refcount_warn_saturate+0xba/0x110\n [1272.957399] btrfs_discard_cancel_work.cold+0x26/0x2b [btrfs]\n [1272.957853] btrfs_put_block_group.cold+0x5d/0x8e [btrfs]\n [1272.958289] btrfs_discard_workfn+0x194/0x380 [btrfs]\n [1272.958729] process_one_work+0x130/0x290\n [1272.959026] worker_thread+0x2ea/0x420\n [1272.959335] ? __pfx_worker_thread+0x10/0x10\n [1272.959644] kthread+0xd7/0x1c0\n [1272.959872] ? __pfx_kthread+0x10/0x10\n [1272.960172] ret_from_fork+0x30/0x50\n [1272.960474] ? __pfx_kthread+0x10/0x10\n [1272.960745] ret_from_fork_asm+0x1a/0x30\n [1272.961035] \n [1272.961238] ---[ end trace 0000000000000000 ]---\n\nThough we have seen them in the async discard workfn as well. It is\nmost likely to happen after a relocation finishes which cancels discard,\ntears down the block group, etc.\n\nFix this fully by taking the lock arou\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22115" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d8e5168d48a91e7a802d3003e72afb4304bebfa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d383a6fc59271aaaf07a33b23b2eac5b9268b7a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8h5-wj84-22hp/GHSA-h8h5-wj84-22hp.json b/advisories/unreviewed/2025/04/GHSA-h8h5-wj84-22hp/GHSA-h8h5-wj84-22hp.json new file mode 100644 index 00000000000..aa9174fc344 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h8h5-wj84-22hp/GHSA-h8h5-wj84-22hp.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8h5-wj84-22hp", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22079" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate l_tree_depth to avoid out-of-bounds access\n\nThe l_tree_depth field is 16-bit (__le16), but the actual maximum depth is\nlimited to OCFS2_MAX_PATH_DEPTH.\n\nAdd a check to prevent out-of-bounds access if l_tree_depth has an invalid\nvalue, which may occur when reading from a corrupted mounted disk [1].", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22079" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11e24802e73362aa2948ee16b8fb4e32635d5b2a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17c99ab3db2ba74096d36c69daa6e784e98fc0b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d012ba4404a0bb517658699ba85e6abda386dc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49d2a2ea9d30991bae82107f9523915b91637683" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/538ed8b049ef801a86c543433e5061a91cc106e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a406aff8c05115119127c962cbbbbd202e1973ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b942f88fe7d2d789e51c5c30a675fa1c126f5a6d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e95d97c9c8cd0c239b7b59c79be0f6a9dcf7905c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef34840bda333fe99bafbd2d73b70ceaaf9eba66" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json b/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json index 8512629e515..3d7f329d35c 100644 --- a/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json +++ b/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h9jw-jhh5-8664/GHSA-h9jw-jhh5-8664.json b/advisories/unreviewed/2025/04/GHSA-h9jw-jhh5-8664/GHSA-h9jw-jhh5-8664.json new file mode 100644 index 00000000000..9b9933efe46 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h9jw-jhh5-8664/GHSA-h9jw-jhh5-8664.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9jw-jhh5-8664", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39590" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS. This issue affects Essential Addons for Elementor: from n/a through 6.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39590" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-addons-for-elementor-lite/vulnerability/wordpress-essential-addons-for-elementor-6-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hcw2-w33p-f795/GHSA-hcw2-w33p-f795.json b/advisories/unreviewed/2025/04/GHSA-hcw2-w33p-f795/GHSA-hcw2-w33p-f795.json new file mode 100644 index 00000000000..1e898ccd18d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hcw2-w33p-f795/GHSA-hcw2-w33p-f795.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcw2-w33p-f795", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-3689" + ], + "details": "A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-customer-detailed.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3689" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyao-i03i/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304978" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304978" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553500" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hh43-6g5g-5cr9/GHSA-hh43-6g5g-5cr9.json b/advisories/unreviewed/2025/04/GHSA-hh43-6g5g-5cr9/GHSA-hh43-6g5g-5cr9.json new file mode 100644 index 00000000000..a434d132ae4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hh43-6g5g-5cr9/GHSA-hh43-6g5g-5cr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh43-6g5g-5cr9", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39555" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin allows Stored XSS. This issue affects Church Admin: from n/a through 5.0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/church-admin/vulnerability/wordpress-church-admin-plugin-5-0-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hm8c-g4h4-r6v4/GHSA-hm8c-g4h4-r6v4.json b/advisories/unreviewed/2025/04/GHSA-hm8c-g4h4-r6v4/GHSA-hm8c-g4h4-r6v4.json new file mode 100644 index 00000000000..7016fe16f74 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hm8c-g4h4-r6v4/GHSA-hm8c-g4h4-r6v4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm8c-g4h4-r6v4", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39585" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Travelfic Toolkit allows Stored XSS. This issue affects Travelfic Toolkit: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/travelfic-toolkit/vulnerability/wordpress-travelfic-toolkit-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hp5m-j8j6-v9gj/GHSA-hp5m-j8j6-v9gj.json b/advisories/unreviewed/2025/04/GHSA-hp5m-j8j6-v9gj/GHSA-hp5m-j8j6-v9gj.json new file mode 100644 index 00000000000..66199040df7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hp5m-j8j6-v9gj/GHSA-hp5m-j8j6-v9gj.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp5m-j8j6-v9gj", + "modified": "2025-04-16T15:34:32Z", + "published": "2025-04-16T15:34:32Z", + "aliases": [ + "CVE-2024-46915" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46915" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hp7g-8x4v-4c78/GHSA-hp7g-8x4v-4c78.json b/advisories/unreviewed/2025/04/GHSA-hp7g-8x4v-4c78/GHSA-hp7g-8x4v-4c78.json index 8973c46778a..5e2b1ce2bcb 100644 --- a/advisories/unreviewed/2025/04/GHSA-hp7g-8x4v-4c78/GHSA-hp7g-8x4v-4c78.json +++ b/advisories/unreviewed/2025/04/GHSA-hp7g-8x4v-4c78/GHSA-hp7g-8x4v-4c78.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-hp93-7vpr-rjwq/GHSA-hp93-7vpr-rjwq.json b/advisories/unreviewed/2025/04/GHSA-hp93-7vpr-rjwq/GHSA-hp93-7vpr-rjwq.json new file mode 100644 index 00000000000..c58d2fc5d3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hp93-7vpr-rjwq/GHSA-hp93-7vpr-rjwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp93-7vpr-rjwq", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-39602" + ], + "details": "Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Product Table Lite: from n/a through 3.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39602" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-product-table-lite/vulnerability/wordpress-woocommerce-product-table-lite-plugin-3-9-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hppm-5frr-q754/GHSA-hppm-5frr-q754.json b/advisories/unreviewed/2025/04/GHSA-hppm-5frr-q754/GHSA-hppm-5frr-q754.json new file mode 100644 index 00000000000..51855478214 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hppm-5frr-q754/GHSA-hppm-5frr-q754.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hppm-5frr-q754", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39592" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unlock Lite allows PHP Local File Inclusion. This issue affects Subscribe to Unlock Lite: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39592" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subscribe-to-unlock-lite/vulnerability/wordpress-subscribe-to-unlock-lite-1-3-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json b/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json new file mode 100644 index 00000000000..de5885a4db8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2pm-rwgr-r5gf", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22085" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix use-after-free when rename device name\n\nSyzbot reported a slab-use-after-free with the following call trace:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in nla_put+0xd3/0x150 lib/nlattr.c:1099\nRead of size 5 at addr ffff888140ea1c60 by task syz.0.988/10025\n\nCPU: 0 UID: 0 PID: 10025 Comm: syz.0.988\nNot tainted 6.14.0-rc4-syzkaller-00859-gf77f12010f67 #0\nHardware name: Google Compute Engine, BIOS Google 02/12/2025\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:408 [inline]\n print_report+0x16e/0x5b0 mm/kasan/report.c:521\n kasan_report+0x143/0x180 mm/kasan/report.c:634\n kasan_check_range+0x282/0x290 mm/kasan/generic.c:189\n __asan_memcpy+0x29/0x70 mm/kasan/shadow.c:105\n nla_put+0xd3/0x150 lib/nlattr.c:1099\n nla_put_string include/net/netlink.h:1621 [inline]\n fill_nldev_handle+0x16e/0x200 drivers/infiniband/core/nldev.c:265\n rdma_nl_notify_event+0x561/0xef0 drivers/infiniband/core/nldev.c:2857\n ib_device_notify_register+0x22/0x230 drivers/infiniband/core/device.c:1344\n ib_register_device+0x1292/0x1460 drivers/infiniband/core/device.c:1460\n rxe_register_device+0x233/0x350 drivers/infiniband/sw/rxe/rxe_verbs.c:1540\n rxe_net_add+0x74/0xf0 drivers/infiniband/sw/rxe/rxe_net.c:550\n rxe_newlink+0xde/0x1a0 drivers/infiniband/sw/rxe/rxe.c:212\n nldev_newlink+0x5ea/0x680 drivers/infiniband/core/nldev.c:1795\n rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]\n rdma_nl_rcv+0x6dd/0x9e0 drivers/infiniband/core/netlink.c:259\n netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1339\n netlink_sendmsg+0x8de/0xcb0 net/netlink/af_netlink.c:1883\n sock_sendmsg_nosec net/socket.c:709 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:724\n ____sys_sendmsg+0x53a/0x860 net/socket.c:2564\n ___sys_sendmsg net/socket.c:2618 [inline]\n __sys_sendmsg+0x269/0x350 net/socket.c:2650\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f42d1b8d169\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 ...\nRSP: 002b:00007f42d2960038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f42d1da6320 RCX: 00007f42d1b8d169\nRDX: 0000000000000000 RSI: 00004000000002c0 RDI: 000000000000000c\nRBP: 00007f42d1c0e2a0 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f42d1da6320 R15: 00007ffe399344a8\n \n\nAllocated by task 10025:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4294 [inline]\n __kmalloc_node_track_caller_noprof+0x28b/0x4c0 mm/slub.c:4313\n __kmemdup_nul mm/util.c:61 [inline]\n kstrdup+0x42/0x100 mm/util.c:81\n kobject_set_name_vargs+0x61/0x120 lib/kobject.c:274\n dev_set_name+0xd5/0x120 drivers/base/core.c:3468\n assign_name drivers/infiniband/core/device.c:1202 [inline]\n ib_register_device+0x178/0x1460 drivers/infiniband/core/device.c:1384\n rxe_register_device+0x233/0x350 drivers/infiniband/sw/rxe/rxe_verbs.c:1540\n rxe_net_add+0x74/0xf0 drivers/infiniband/sw/rxe/rxe_net.c:550\n rxe_newlink+0xde/0x1a0 drivers/infiniband/sw/rxe/rxe.c:212\n nldev_newlink+0x5ea/0x680 drivers/infiniband/core/nldev.c:1795\n rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]\n rdma_nl_rcv+0x6dd/0x9e0 drivers/infiniband/core/netlink.c:259\n netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1339\n netlink_sendmsg+0x8de/0xcb0 net\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22085" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d6460b9d2a3ee380940bdf47680751ef91cb88e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d6a9e7449e2a0c1e2934eee7880ba8bd1e464cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56ec8580be5174b2b9774066e60f1aad56d201db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/edf6b543e81ba68c6dbac2499ab362098a5a9716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7vf-7m65-7hhr/GHSA-j7vf-7m65-7hhr.json b/advisories/unreviewed/2025/04/GHSA-j7vf-7m65-7hhr/GHSA-j7vf-7m65-7hhr.json new file mode 100644 index 00000000000..cdc337e6096 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j7vf-7m65-7hhr/GHSA-j7vf-7m65-7hhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7vf-7m65-7hhr", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39556" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel allows Retrieve Embedded Sensitive Data. This issue affects Mediavine Control Panel: from n/a through 2.10.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mediavine-control-panel/vulnerability/wordpress-mediavine-control-panel-plugin-2-10-6-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jch8-hv9x-vvc6/GHSA-jch8-hv9x-vvc6.json b/advisories/unreviewed/2025/04/GHSA-jch8-hv9x-vvc6/GHSA-jch8-hv9x-vvc6.json new file mode 100644 index 00000000000..e1c9125597b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jch8-hv9x-vvc6/GHSA-jch8-hv9x-vvc6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jch8-hv9x-vvc6", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22111" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF.\n\nSIOCBRDELIF is passed to dev_ioctl() first and later forwarded to\nbr_ioctl_call(), which causes unnecessary RTNL dance and the splat\nbelow [0] under RTNL pressure.\n\nLet's say Thread A is trying to detach a device from a bridge and\nThread B is trying to remove the bridge.\n\nIn dev_ioctl(), Thread A bumps the bridge device's refcnt by\nnetdev_hold() and releases RTNL because the following br_ioctl_call()\nalso re-acquires RTNL.\n\nIn the race window, Thread B could acquire RTNL and try to remove\nthe bridge device. Then, rtnl_unlock() by Thread B will release RTNL\nand wait for netdev_put() by Thread A.\n\nThread A, however, must hold RTNL after the unlock in dev_ifsioc(),\nwhich may take long under RTNL pressure, resulting in the splat by\nThread B.\n\n Thread A (SIOCBRDELIF) Thread B (SIOCBRDELBR)\n ---------------------- ----------------------\n sock_ioctl sock_ioctl\n `- sock_do_ioctl `- br_ioctl_call\n `- dev_ioctl `- br_ioctl_stub\n |- rtnl_lock |\n |- dev_ifsioc '\n ' |- dev = __dev_get_by_name(...)\n |- netdev_hold(dev, ...) .\n / |- rtnl_unlock ------. |\n | |- br_ioctl_call `---> |- rtnl_lock\n Race | | `- br_ioctl_stub |- br_del_bridge\n Window | | | |- dev = __dev_get_by_name(...)\n | | | May take long | `- br_dev_delete(dev, ...)\n | | | under RTNL pressure | `- unregister_netdevice_queue(dev, ...)\n | | | | `- rtnl_unlock\n \\ | |- rtnl_lock <-' `- netdev_run_todo\n | |- ... `- netdev_run_todo\n | `- rtnl_unlock |- __rtnl_unlock\n | |- netdev_wait_allrefs_any\n |- netdev_put(dev, ...) <----------------'\n Wait refcnt decrement\n and log splat below\n\nTo avoid blocking SIOCBRDELBR unnecessarily, let's not call\ndev_ioctl() for SIOCBRADDIF and SIOCBRDELIF.\n\nIn the dev_ioctl() path, we do the following:\n\n 1. Copy struct ifreq by get_user_ifreq in sock_do_ioctl()\n 2. Check CAP_NET_ADMIN in dev_ioctl()\n 3. Call dev_load() in dev_ioctl()\n 4. Fetch the master dev from ifr.ifr_name in dev_ifsioc()\n\n3. can be done by request_module() in br_ioctl_call(), so we move\n1., 2., and 4. to br_ioctl_stub().\n\nNote that 2. is also checked later in add_del_if(), but it's better\nperformed before RTNL.\n\nSIOCBRADDIF and SIOCBRDELIF have been processed in dev_ioctl() since\nthe pre-git era, and there seems to be no specific reason to process\nthem there.\n\n[0]:\nunregister_netdevice: waiting for wpan3 to become free. Usage count = 2\nref_tracker: wpan3@ffff8880662d8608 has 1/1 users at\n __netdev_tracker_alloc include/linux/netdevice.h:4282 [inline]\n netdev_hold include/linux/netdevice.h:4311 [inline]\n dev_ifsioc+0xc6a/0x1160 net/core/dev_ioctl.c:624\n dev_ioctl+0x255/0x10c0 net/core/dev_ioctl.c:826\n sock_do_ioctl+0x1ca/0x260 net/socket.c:1213\n sock_ioctl+0x23a/0x6c0 net/socket.c:1318\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl fs/ioctl.c:892 [inline]\n __x64_sys_ioctl+0x1a4/0x210 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcb/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22111" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00fe0ac64efd1f5373b3dd9f1f84b19235371e39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed3ba9b6e280e14cc3148c1b226ba453f02fa76c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jprx-mprp-6qvx/GHSA-jprx-mprp-6qvx.json b/advisories/unreviewed/2025/04/GHSA-jprx-mprp-6qvx/GHSA-jprx-mprp-6qvx.json new file mode 100644 index 00000000000..1cd2093903c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jprx-mprp-6qvx/GHSA-jprx-mprp-6qvx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jprx-mprp-6qvx", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22070" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/9p: fix NULL pointer dereference on mkdir\n\nWhen a 9p tree was mounted with option 'posixacl', parent directory had a\ndefault ACL set for its subdirectories, e.g.:\n\n setfacl -m default:group:simpsons:rwx parentdir\n\nthen creating a subdirectory crashed 9p client, as v9fs_fid_add() call in\nfunction v9fs_vfs_mkdir_dotl() sets the passed 'fid' pointer to NULL\n(since dafbe689736) even though the subsequent v9fs_set_create_acl() call\nexpects a valid non-NULL 'fid' pointer:\n\n [ 37.273191] BUG: kernel NULL pointer dereference, address: 0000000000000000\n ...\n [ 37.322338] Call Trace:\n [ 37.323043] \n [ 37.323621] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n [ 37.324448] ? page_fault_oops (arch/x86/mm/fault.c:714)\n [ 37.325532] ? search_module_extables (kernel/module/main.c:3733)\n [ 37.326742] ? p9_client_walk (net/9p/client.c:1165) 9pnet\n [ 37.328006] ? search_bpf_extables (kernel/bpf/core.c:804)\n [ 37.329142] ? exc_page_fault (./arch/x86/include/asm/paravirt.h:686 arch/x86/mm/fault.c:1488 arch/x86/mm/fault.c:1538)\n [ 37.330196] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:574)\n [ 37.331330] ? p9_client_walk (net/9p/client.c:1165) 9pnet\n [ 37.332562] ? v9fs_fid_xattr_get (fs/9p/xattr.c:30) 9p\n [ 37.333824] v9fs_fid_xattr_set (fs/9p/fid.h:23 fs/9p/xattr.c:121) 9p\n [ 37.335077] v9fs_set_acl (fs/9p/acl.c:276) 9p\n [ 37.336112] v9fs_set_create_acl (fs/9p/acl.c:307) 9p\n [ 37.337326] v9fs_vfs_mkdir_dotl (fs/9p/vfs_inode_dotl.c:411) 9p\n [ 37.338590] vfs_mkdir (fs/namei.c:4313)\n [ 37.339535] do_mkdirat (fs/namei.c:4336)\n [ 37.340465] __x64_sys_mkdir (fs/namei.c:4354)\n [ 37.341455] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n [ 37.342447] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nFix this by simply swapping the sequence of these two calls in\nv9fs_vfs_mkdir_dotl(), i.e. calling v9fs_set_create_acl() before\nv9fs_fid_add().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22070" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2139dea5c53e3bb63ac49a6901c85e525a80ee8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f61ac7c65bdb26accb52f9db66313597e759821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6517b395cb1e43fbf3962dd93e6fb4a5e5ab100e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8522051c58d68146b93e8a5ba9987e83b3d64e7b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jr2f-554p-cmvr/GHSA-jr2f-554p-cmvr.json b/advisories/unreviewed/2025/04/GHSA-jr2f-554p-cmvr/GHSA-jr2f-554p-cmvr.json new file mode 100644 index 00000000000..187dcbf39a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jr2f-554p-cmvr/GHSA-jr2f-554p-cmvr.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr2f-554p-cmvr", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22025" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: put dl_stid if fail to queue dl_recall\n\nBefore calling nfsd4_run_cb to queue dl_recall to the callback_wq, we\nincrement the reference count of dl_stid.\nWe expect that after the corresponding work_struct is processed, the\nreference count of dl_stid will be decremented through the callback\nfunction nfsd4_cb_recall_release.\nHowever, if the call to nfsd4_run_cb fails, the incremented reference\ncount of dl_stid will not be decremented correspondingly, leading to the\nfollowing nfs4_stid leak:\nunreferenced object 0xffff88812067b578 (size 344):\n comm \"nfsd\", pid 2761, jiffies 4295044002 (age 5541.241s)\n hex dump (first 32 bytes):\n 01 00 00 00 6b 6b 6b 6b b8 02 c0 e2 81 88 ff ff ....kkkk........\n 00 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 ad 4e ad de .kkkkkkk.....N..\n backtrace:\n kmem_cache_alloc+0x4b9/0x700\n nfsd4_process_open1+0x34/0x300\n nfsd4_open+0x2d1/0x9d0\n nfsd4_proc_compound+0x7a2/0xe30\n nfsd_dispatch+0x241/0x3e0\n svc_process_common+0x5d3/0xcc0\n svc_process+0x2a3/0x320\n nfsd+0x180/0x2e0\n kthread+0x199/0x1d0\n ret_from_fork+0x30/0x50\n ret_from_fork_asm+0x1b/0x30\nunreferenced object 0xffff8881499f4d28 (size 368):\n comm \"nfsd\", pid 2761, jiffies 4295044005 (age 5541.239s)\n hex dump (first 32 bytes):\n 01 00 00 00 00 00 00 00 30 4d 9f 49 81 88 ff ff ........0M.I....\n 30 4d 9f 49 81 88 ff ff 20 00 00 00 01 00 00 00 0M.I.... .......\n backtrace:\n kmem_cache_alloc+0x4b9/0x700\n nfs4_alloc_stid+0x29/0x210\n alloc_init_deleg+0x92/0x2e0\n nfs4_set_delegation+0x284/0xc00\n nfs4_open_delegation+0x216/0x3f0\n nfsd4_process_open2+0x2b3/0xee0\n nfsd4_open+0x770/0x9d0\n nfsd4_proc_compound+0x7a2/0xe30\n nfsd_dispatch+0x241/0x3e0\n svc_process_common+0x5d3/0xcc0\n svc_process+0x2a3/0x320\n nfsd+0x180/0x2e0\n kthread+0x199/0x1d0\n ret_from_fork+0x30/0x50\n ret_from_fork_asm+0x1b/0x30\nFix it by checking the result of nfsd4_run_cb and call nfs4_put_stid if\nfail to queue dl_recall.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22025" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/133f5e2a37ce08c82d24e8fba65e0a81deae4609" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/230ca758453c63bd38e4d9f4a21db698f7abada8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63b91c8ff4589f5263873b24c052447a28e10ef7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a81cde8c7ce65dd90fb47ceea93a45fc1a2fbd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b874cdef4e67e5150e07eff0eae1cbb21fb92da1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cad3479b63661a399c9df1d0b759e1806e2df3c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdb796137c57e68ca34518d53be53b679351eb86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d96587cc93ec369031bcd7658c6adc719873c9fd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json b/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json new file mode 100644 index 00000000000..ace58fd261f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrxv-vv4v-jrrh", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22035" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix use-after-free in print_graph_function_flags during tracer switching\n\nKairui reported a UAF issue in print_graph_function_flags() during\nftrace stress testing [1]. This issue can be reproduced if puting a\n'mdelay(10)' after 'mutex_unlock(&trace_types_lock)' in s_start(),\nand executing the following script:\n\n $ echo function_graph > current_tracer\n $ cat trace > /dev/null &\n $ sleep 5 # Ensure the 'cat' reaches the 'mdelay(10)' point\n $ echo timerlat > current_tracer\n\nThe root cause lies in the two calls to print_graph_function_flags\nwithin print_trace_line during each s_show():\n\n * One through 'iter->trace->print_line()';\n * Another through 'event->funcs->trace()', which is hidden in\n print_trace_fmt() before print_trace_line returns.\n\nTracer switching only updates the former, while the latter continues\nto use the print_line function of the old tracer, which in the script\nabove is print_graph_function_flags.\n\nMoreover, when switching from the 'function_graph' tracer to the\n'timerlat' tracer, s_start only calls graph_trace_close of the\n'function_graph' tracer to free 'iter->private', but does not set\nit to NULL. This provides an opportunity for 'event->funcs->trace()'\nto use an invalid 'iter->private'.\n\nTo fix this issue, set 'iter->private' to NULL immediately after\nfreeing it in graph_trace_close(), ensuring that an invalid pointer\nis not passed to other tracers. Additionally, clean up the unnecessary\n'iter->private = NULL' during each 'cat trace' when using wakeup and\nirqsoff tracers.\n\n [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22035" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/099ef3385800828b74933a96c117574637c3fb3a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42561fe62c3628ea3bc9623f64f047605e98857f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70be951bc01e4a0e10d443f3510bb17426f257fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f81f27b1093e4895e87b74143c59c055c3b1906" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81a85b12132c8ffe98f5ddbdc185481790aeaa1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2cce54c1748216535dda02e185d07a084be837e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c85efe6e13743cac6ba4ccf144cb91f44c86231a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de7b309139f862a44379ecd96e93c9133c69f813" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f14752d66056d0c7bffe5092130409417d3baa70" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jv3r-47pw-5225/GHSA-jv3r-47pw-5225.json b/advisories/unreviewed/2025/04/GHSA-jv3r-47pw-5225/GHSA-jv3r-47pw-5225.json new file mode 100644 index 00000000000..46f2f45f8df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jv3r-47pw-5225/GHSA-jv3r-47pw-5225.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv3r-47pw-5225", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22027" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: streamzap: fix race between device disconnection and urb callback\n\nSyzkaller has reported a general protection fault at function\nir_raw_event_store_with_filter(). This crash is caused by a NULL pointer\ndereference of dev->raw pointer, even though it is checked for NULL in\nthe same function, which means there is a race condition. It occurs due\nto the incorrect order of actions in the streamzap_disconnect() function:\nrc_unregister_device() is called before usb_kill_urb(). The dev->raw\npointer is freed and set to NULL in rc_unregister_device(), and only\nafter that usb_kill_urb() waits for in-progress requests to finish.\n\nIf rc_unregister_device() is called while streamzap_callback() handler is\nnot finished, this can lead to accessing freed resources. Thus\nrc_unregister_device() should be called after usb_kill_urb().\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22027" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15483afb930fc2f883702dc96f80efbe4055235e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30ef7cfee752ca318d5902cb67b60d9797ccd378" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4db62b60af2ccdea6ac5452fd20e29587ed85f57" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8760da4b9d44c36b93b6e4cf401ec7fe520015bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adf0ddb914c9e5b3e50da4c97959e82de2df75c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f656cfbc7a293a039d6a0c7100e1c846845148c1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxcg-xjhx-339v/GHSA-jxcg-xjhx-339v.json b/advisories/unreviewed/2025/04/GHSA-jxcg-xjhx-339v/GHSA-jxcg-xjhx-339v.json new file mode 100644 index 00000000000..8626f0e7d7b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jxcg-xjhx-339v/GHSA-jxcg-xjhx-339v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxcg-xjhx-339v", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-39601" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP allows Remote Code Inclusion. This issue affects Custom CSS, JS & PHP: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39601" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-css/vulnerability/wordpress-custom-css-js-php-plugin-2-4-1-csrf-to-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxfc-qg7h-gw67/GHSA-jxfc-qg7h-gw67.json b/advisories/unreviewed/2025/04/GHSA-jxfc-qg7h-gw67/GHSA-jxfc-qg7h-gw67.json new file mode 100644 index 00000000000..0bb6b79abfc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jxfc-qg7h-gw67/GHSA-jxfc-qg7h-gw67.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxfc-qg7h-gw67", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22069" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler\n\nNaresh Kamboju reported a \"Bad frame pointer\" kernel warning while\nrunning LTP trace ftrace_stress_test.sh in riscv. We can reproduce the\nsame issue with the following command:\n\n```\n$ cd /sys/kernel/debug/tracing\n$ echo 'f:myprobe do_nanosleep%return args1=$retval' > dynamic_events\n$ echo 1 > events/fprobes/enable\n$ echo 1 > tracing_on\n$ sleep 1\n```\n\nAnd we can get the following kernel warning:\n\n[ 127.692888] ------------[ cut here ]------------\n[ 127.693755] Bad frame pointer: expected ff2000000065be50, received ba34c141e9594000\n[ 127.693755] from func do_nanosleep return to ffffffff800ccb16\n[ 127.698699] WARNING: CPU: 1 PID: 129 at kernel/trace/fgraph.c:755 ftrace_return_to_handler+0x1b2/0x1be\n[ 127.699894] Modules linked in:\n[ 127.700908] CPU: 1 UID: 0 PID: 129 Comm: sleep Not tainted 6.14.0-rc3-g0ab191c74642 #32\n[ 127.701453] Hardware name: riscv-virtio,qemu (DT)\n[ 127.701859] epc : ftrace_return_to_handler+0x1b2/0x1be\n[ 127.702032] ra : ftrace_return_to_handler+0x1b2/0x1be\n[ 127.702151] epc : ffffffff8013b5e0 ra : ffffffff8013b5e0 sp : ff2000000065bd10\n[ 127.702221] gp : ffffffff819c12f8 tp : ff60000080853100 t0 : 6e00000000000000\n[ 127.702284] t1 : 0000000000000020 t2 : 6e7566206d6f7266 s0 : ff2000000065bd80\n[ 127.702346] s1 : ff60000081262000 a0 : 000000000000007b a1 : ffffffff81894f20\n[ 127.702408] a2 : 0000000000000010 a3 : fffffffffffffffe a4 : 0000000000000000\n[ 127.702470] a5 : 0000000000000000 a6 : 0000000000000008 a7 : 0000000000000038\n[ 127.702530] s2 : ba34c141e9594000 s3 : 0000000000000000 s4 : ff2000000065bdd0\n[ 127.702591] s5 : 00007fff8adcf400 s6 : 000055556dc1d8c0 s7 : 0000000000000068\n[ 127.702651] s8 : 00007fff8adf5d10 s9 : 000000000000006d s10: 0000000000000001\n[ 127.702710] s11: 00005555737377c8 t3 : ffffffff819d899e t4 : ffffffff819d899e\n[ 127.702769] t5 : ffffffff819d89a0 t6 : ff2000000065bb18\n[ 127.702826] status: 0000000200000120 badaddr: 0000000000000000 cause: 0000000000000003\n[ 127.703292] [] ftrace_return_to_handler+0x1b2/0x1be\n[ 127.703760] [] return_to_handler+0x16/0x26\n[ 127.704009] [] return_to_handler+0x0/0x26\n[ 127.704057] [] common_nsleep+0x42/0x54\n[ 127.704117] [] __riscv_sys_clock_nanosleep+0xba/0x10a\n[ 127.704176] [] do_trap_ecall_u+0x188/0x218\n[ 127.704295] [] handle_exception+0x14a/0x156\n[ 127.705436] ---[ end trace 0000000000000000 ]---\n\nThe reason is that the stack layout for constructing argument for the\nftrace_return_to_handler in the return_to_handler does not match the\n__arch_ftrace_regs structure of riscv, leading to unexpected results.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22069" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67a5ba8f742f247bc83e46dd2313c142b1383276" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78b39c587b8f6c69140177108f9c08a75b1c7c37" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m322-h5v9-h9fc/GHSA-m322-h5v9-h9fc.json b/advisories/unreviewed/2025/04/GHSA-m322-h5v9-h9fc/GHSA-m322-h5v9-h9fc.json new file mode 100644 index 00000000000..59bef94d32b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m322-h5v9-h9fc/GHSA-m322-h5v9-h9fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m322-h5v9-h9fc", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39546" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in quomodosoft ElementsReady Addons for Elementor allows Cross Site Request Forgery. This issue affects ElementsReady Addons for Elementor: from n/a through 6.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/element-ready-lite/vulnerability/wordpress-elementsready-addons-for-elementor-6-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m3w4-4fpp-54xg/GHSA-m3w4-4fpp-54xg.json b/advisories/unreviewed/2025/04/GHSA-m3w4-4fpp-54xg/GHSA-m3w4-4fpp-54xg.json index aba110a8797..1aa1e24adab 100644 --- a/advisories/unreviewed/2025/04/GHSA-m3w4-4fpp-54xg/GHSA-m3w4-4fpp-54xg.json +++ b/advisories/unreviewed/2025/04/GHSA-m3w4-4fpp-54xg/GHSA-m3w4-4fpp-54xg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-m587-7hw6-635x/GHSA-m587-7hw6-635x.json b/advisories/unreviewed/2025/04/GHSA-m587-7hw6-635x/GHSA-m587-7hw6-635x.json new file mode 100644 index 00000000000..42b79c2e38e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m587-7hw6-635x/GHSA-m587-7hw6-635x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m587-7hw6-635x", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22082" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: backend: make sure to NULL terminate stack buffer\n\nMake sure to NULL terminate the buffer in\niio_backend_debugfs_write_reg() before passing it to sscanf(). It is a\nstack variable so we should not assume it will 0 initialized.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/035b4989211dc1c8626e186d655ae8ca5141bb73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04271a4d2740f98bbe36f82cd3d74677a839d1eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df3892e5e861c43d5612728ed259634675b8a71f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd791c81f410ab1c554686a6f486dc7a176dfe35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m83v-mmqj-7jrm/GHSA-m83v-mmqj-7jrm.json b/advisories/unreviewed/2025/04/GHSA-m83v-mmqj-7jrm/GHSA-m83v-mmqj-7jrm.json new file mode 100644 index 00000000000..c4e36d96e14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m83v-mmqj-7jrm/GHSA-m83v-mmqj-7jrm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m83v-mmqj-7jrm", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2024-58248" + ], + "details": "nopCommerce before 4.80.0 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58248" + }, + { + "type": "WEB", + "url": "https://github.com/nopSolutions/nopCommerce/issues/7325" + }, + { + "type": "WEB", + "url": "https://www.nopcommerce.com/en/release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mfp5-c75h-8m74/GHSA-mfp5-c75h-8m74.json b/advisories/unreviewed/2025/04/GHSA-mfp5-c75h-8m74/GHSA-mfp5-c75h-8m74.json index b5422338f08..57c3891b929 100644 --- a/advisories/unreviewed/2025/04/GHSA-mfp5-c75h-8m74/GHSA-mfp5-c75h-8m74.json +++ b/advisories/unreviewed/2025/04/GHSA-mfp5-c75h-8m74/GHSA-mfp5-c75h-8m74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfp5-c75h-8m74", - "modified": "2025-04-16T09:32:13Z", + "modified": "2025-04-16T15:34:30Z", "published": "2025-04-16T09:32:13Z", "aliases": [ "CVE-2025-3674" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3674" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setUrlFilterRules-1cb53a41781f808f9547da7748580914" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setUrlFilterRules-1cb53a41781f808f9547da7748580914?pvs=4" diff --git a/advisories/unreviewed/2025/04/GHSA-mg7c-mfqw-jg72/GHSA-mg7c-mfqw-jg72.json b/advisories/unreviewed/2025/04/GHSA-mg7c-mfqw-jg72/GHSA-mg7c-mfqw-jg72.json new file mode 100644 index 00000000000..986d6aae21b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mg7c-mfqw-jg72/GHSA-mg7c-mfqw-jg72.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg7c-mfqw-jg72", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-22126" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: fix mddev uaf while iterating all_mddevs list\n\nWhile iterating all_mddevs list from md_notify_reboot() and md_exit(),\nlist_for_each_entry_safe is used, and this can race with deletint the\nnext mddev, causing UAF:\n\nt1:\nspin_lock\n//list_for_each_entry_safe(mddev, n, ...)\n mddev_get(mddev1)\n // assume mddev2 is the next entry\n spin_unlock\n t2:\n //remove mddev2\n ...\n mddev_free\n spin_lock\n list_del\n spin_unlock\n kfree(mddev2)\n mddev_put(mddev1)\n spin_lock\n //continue dereference mddev2->all_mddevs\n\nThe old helper for_each_mddev() actually grab the reference of mddev2\nwhile holding the lock, to prevent from being freed. This problem can be\nfixed the same way, however, the code will be complex.\n\nHence switch to use list_for_each_entry, in this case mddev_put() can free\nthe mddev1 and it's not safe as well. Refer to md_seq_show(), also factor\nout a helper mddev_put_locked() to fix this problem.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22126" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5462544ccbad3fc938a71b01fa5bd3a0dc2b750a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8542870237c3a48ff049b6c5df5f50c8728284fa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mh27-4q3p-7mc8/GHSA-mh27-4q3p-7mc8.json b/advisories/unreviewed/2025/04/GHSA-mh27-4q3p-7mc8/GHSA-mh27-4q3p-7mc8.json new file mode 100644 index 00000000000..0a582696c8a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mh27-4q3p-7mc8/GHSA-mh27-4q3p-7mc8.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh27-4q3p-7mc8", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22089" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Don't expose hw_counters outside of init net namespace\n\nCommit 467f432a521a (\"RDMA/core: Split port and device counter sysfs\nattributes\") accidentally almost exposed hw counters to non-init net\nnamespaces. It didn't expose them fully, as an attempt to read any of\nthose counters leads to a crash like this one:\n\n[42021.807566] BUG: kernel NULL pointer dereference, address: 0000000000000028\n[42021.814463] #PF: supervisor read access in kernel mode\n[42021.819549] #PF: error_code(0x0000) - not-present page\n[42021.824636] PGD 0 P4D 0\n[42021.827145] Oops: 0000 [#1] SMP PTI\n[42021.830598] CPU: 82 PID: 2843922 Comm: switchto-defaul Kdump: loaded Tainted: G S W I XXX\n[42021.841697] Hardware name: XXX\n[42021.849619] RIP: 0010:hw_stat_device_show+0x1e/0x40 [ib_core]\n[42021.855362] Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 49 89 d0 4c 8b 5e 20 48 8b 8f b8 04 00 00 48 81 c7 f0 fa ff ff <48> 8b 41 28 48 29 ce 48 83 c6 d0 48 c1 ee 04 69 d6 ab aa aa aa 48\n[42021.873931] RSP: 0018:ffff97fe90f03da0 EFLAGS: 00010287\n[42021.879108] RAX: ffff9406988a8c60 RBX: ffff940e1072d438 RCX: 0000000000000000\n[42021.886169] RDX: ffff94085f1aa000 RSI: ffff93c6cbbdbcb0 RDI: ffff940c7517aef0\n[42021.893230] RBP: ffff97fe90f03e70 R08: ffff94085f1aa000 R09: 0000000000000000\n[42021.900294] R10: ffff94085f1aa000 R11: ffffffffc0775680 R12: ffffffff87ca2530\n[42021.907355] R13: ffff940651602840 R14: ffff93c6cbbdbcb0 R15: ffff94085f1aa000\n[42021.914418] FS: 00007fda1a3b9700(0000) GS:ffff94453fb80000(0000) knlGS:0000000000000000\n[42021.922423] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[42021.928130] CR2: 0000000000000028 CR3: 00000042dcfb8003 CR4: 00000000003726f0\n[42021.935194] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[42021.942257] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[42021.949324] Call Trace:\n[42021.951756] \n[42021.953842] [] ? show_regs+0x64/0x70\n[42021.959030] [] ? __die+0x78/0xc0\n[42021.963874] [] ? page_fault_oops+0x2b5/0x3b0\n[42021.969749] [] ? exc_page_fault+0x1a2/0x3c0\n[42021.975549] [] ? asm_exc_page_fault+0x26/0x30\n[42021.981517] [] ? __pfx_show_hw_stats+0x10/0x10 [ib_core]\n[42021.988482] [] ? hw_stat_device_show+0x1e/0x40 [ib_core]\n[42021.995438] [] dev_attr_show+0x1e/0x50\n[42022.000803] [] sysfs_kf_seq_show+0x81/0xe0\n[42022.006508] [] seq_read_iter+0xf4/0x410\n[42022.011954] [] vfs_read+0x16e/0x2f0\n[42022.017058] [] ksys_read+0x6e/0xe0\n[42022.022073] [] do_syscall_64+0x6a/0xa0\n[42022.027441] [] entry_SYSCALL_64_after_hwframe+0x78/0xe2\n\nThe problem can be reproduced using the following steps:\n ip netns add foo\n ip netns exec foo bash\n cat /sys/class/infiniband/mlx4_0/hw_counters/*\n\nThe panic occurs because of casting the device pointer into an\nib_device pointer using container_of() in hw_stat_device_show() is\nwrong and leads to a memory corruption.\n\nHowever the real problem is that hw counters should never been exposed\noutside of the non-init net namespace.\n\nFix this by saving the index of the corresponding attribute group\n(it might be 1 or 2 depending on the presence of driver-specific\nattributes) and zeroing the pointer to hw_counters group for compat\ndevices during the initialization.\n\nWith this fix applied hw_counters are not available in a non-init\nnet namespace:\n find /sys/class/infiniband/mlx4_0/ -name hw_counters\n /sys/class/infiniband/mlx4_0/ports/1/hw_counters\n /sys/class/infiniband/mlx4_0/ports/2/hw_counters\n /sys/class/infiniband/mlx4_0/hw_counters\n\n ip netns add foo\n ip netns exec foo bash\n find /sys/class/infiniband/mlx4_0/ -name hw_counters", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22089" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cf80f924aecb5b2bebd4f4ad11b2efc676a0b78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6682da5d8fd578a5068531d01633c9d2e4c8f12b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a5b7f8842a90a5e6eeff37f9f6d814e61ea3529" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1ecb30f90856b0be4168ad51b8875148e285c1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c14d9704f5d77a7c7fa46e2114b64a4f75b64e17" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5212b99649c5740154f307e9e3d7fee9bf62773" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df45ae2a4f1cdfda00c032839e12092e1f32c05e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mpfh-94p7-8328/GHSA-mpfh-94p7-8328.json b/advisories/unreviewed/2025/04/GHSA-mpfh-94p7-8328/GHSA-mpfh-94p7-8328.json new file mode 100644 index 00000000000..0ab77829a81 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mpfh-94p7-8328/GHSA-mpfh-94p7-8328.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpfh-94p7-8328", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2024-58097" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix RCU stall while reaping monitor destination ring\n\nWhile processing the monitor destination ring, MSDUs are reaped from the\nlink descriptor based on the corresponding buf_id.\n\nHowever, sometimes the driver cannot obtain a valid buffer corresponding\nto the buf_id received from the hardware. This causes an infinite loop\nin the destination processing, resulting in a kernel crash.\n\nkernel log:\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\n\nFix this by skipping the problematic buf_id and reaping the next entry,\nreplacing the break with the next MSDU processing.\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58097" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16c6c35c03ea73054a1f6d3302a4ce4a331b427d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4991fc41745645f8050506f5a8578bd11e6b378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mq3f-36rm-5qp5/GHSA-mq3f-36rm-5qp5.json b/advisories/unreviewed/2025/04/GHSA-mq3f-36rm-5qp5/GHSA-mq3f-36rm-5qp5.json new file mode 100644 index 00000000000..4ac20727a1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mq3f-36rm-5qp5/GHSA-mq3f-36rm-5qp5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq3f-36rm-5qp5", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22112" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: fix out-of-range access of vnic_info array\n\nThe bnxt_queue_{start | stop}() access vnic_info as much as allocated,\nwhich indicates bp->nr_vnics.\nSo, it should not reach bp->vnic_info[bp->nr_vnics].", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22112" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/919f9f497dbcee75d487400e8f9815b74a6a37df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1e081d331ab3a0dea25425f2b6ddeb365fc9d22" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrcw-4q3q-p9vg/GHSA-mrcw-4q3q-p9vg.json b/advisories/unreviewed/2025/04/GHSA-mrcw-4q3q-p9vg/GHSA-mrcw-4q3q-p9vg.json index 3a45e14a050..03fac1a0e64 100644 --- a/advisories/unreviewed/2025/04/GHSA-mrcw-4q3q-p9vg/GHSA-mrcw-4q3q-p9vg.json +++ b/advisories/unreviewed/2025/04/GHSA-mrcw-4q3q-p9vg/GHSA-mrcw-4q3q-p9vg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mx69-4qpq-mvf3/GHSA-mx69-4qpq-mvf3.json b/advisories/unreviewed/2025/04/GHSA-mx69-4qpq-mvf3/GHSA-mx69-4qpq-mvf3.json index 111627f5574..35e4467221e 100644 --- a/advisories/unreviewed/2025/04/GHSA-mx69-4qpq-mvf3/GHSA-mx69-4qpq-mvf3.json +++ b/advisories/unreviewed/2025/04/GHSA-mx69-4qpq-mvf3/GHSA-mx69-4qpq-mvf3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json b/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json index ca8f335369c..a4cbb36ebbe 100644 --- a/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json +++ b/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mxvx-cwcc-38xf/GHSA-mxvx-cwcc-38xf.json b/advisories/unreviewed/2025/04/GHSA-mxvx-cwcc-38xf/GHSA-mxvx-cwcc-38xf.json new file mode 100644 index 00000000000..1903c0a9b05 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mxvx-cwcc-38xf/GHSA-mxvx-cwcc-38xf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxvx-cwcc-38xf", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-3693" + ], + "details": "A vulnerability was found in Tenda W12 3.0.0.5. It has been rated as critical. Affected by this issue is the function cgiWifiRadioSet of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3693" + }, + { + "type": "WEB", + "url": "https://github.com/02Tn/vul/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304982" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304982" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553526" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2v4-fw4j-mfg2/GHSA-p2v4-fw4j-mfg2.json b/advisories/unreviewed/2025/04/GHSA-p2v4-fw4j-mfg2/GHSA-p2v4-fw4j-mfg2.json new file mode 100644 index 00000000000..2513f0c517a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2v4-fw4j-mfg2/GHSA-p2v4-fw4j-mfg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2v4-fw4j-mfg2", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39548" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban allows Stored XSS. This issue affects Right Click Disable OR Ban: from n/a through 1.1.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/right-click-disable-or-ban/vulnerability/wordpress-right-click-disable-or-ban-plugin-1-1-17-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2xc-pjjh-xj6w/GHSA-p2xc-pjjh-xj6w.json b/advisories/unreviewed/2025/04/GHSA-p2xc-pjjh-xj6w/GHSA-p2xc-pjjh-xj6w.json index 30eb27eaa75..5faaf1891c9 100644 --- a/advisories/unreviewed/2025/04/GHSA-p2xc-pjjh-xj6w/GHSA-p2xc-pjjh-xj6w.json +++ b/advisories/unreviewed/2025/04/GHSA-p2xc-pjjh-xj6w/GHSA-p2xc-pjjh-xj6w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-p48m-987f-62rc/GHSA-p48m-987f-62rc.json b/advisories/unreviewed/2025/04/GHSA-p48m-987f-62rc/GHSA-p48m-987f-62rc.json index 8e12fa55c06..e52de87d9e5 100644 --- a/advisories/unreviewed/2025/04/GHSA-p48m-987f-62rc/GHSA-p48m-987f-62rc.json +++ b/advisories/unreviewed/2025/04/GHSA-p48m-987f-62rc/GHSA-p48m-987f-62rc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-p54p-8qp2-pc9m/GHSA-p54p-8qp2-pc9m.json b/advisories/unreviewed/2025/04/GHSA-p54p-8qp2-pc9m/GHSA-p54p-8qp2-pc9m.json new file mode 100644 index 00000000000..e3bbbd0cec8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p54p-8qp2-pc9m/GHSA-p54p-8qp2-pc9m.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p54p-8qp2-pc9m", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22074" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix r_count dec/increment mismatch\n\nr_count is only increased when there is an oplock break wait,\nso r_count inc/decrement are not paired. This can cause r_count\nto become negative, which can lead to a problem where the ksmbd\nthread does not terminate.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22074" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20378cf48359f39dee0ef9b61470ebe77bd49c0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/457db486203c90e10c3efc87fd45cc7000b1cd36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4790bcb269e5d6d88200a67c54ae6d627332a3be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2ec33d46b4d1c8085dab5d02e00b21f4f0fb8a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddb7ea36ba7129c2ed107e2186591128618864e1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p55c-m7rf-5552/GHSA-p55c-m7rf-5552.json b/advisories/unreviewed/2025/04/GHSA-p55c-m7rf-5552/GHSA-p55c-m7rf-5552.json new file mode 100644 index 00000000000..763a61a7074 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p55c-m7rf-5552/GHSA-p55c-m7rf-5552.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p55c-m7rf-5552", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2024-58094" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before truncation in jfs_truncate_nolock()\n\nAdded a check for \"read-only\" mode in the `jfs_truncate_nolock`\nfunction to avoid errors related to writing to a read-only\nfilesystem.\n\nCall stack:\n\nblock_write_begin() {\n jfs_write_failed() {\n jfs_truncate() {\n jfs_truncate_nolock() {\n txEnd() {\n ...\n log = JFS_SBI(tblk->sb)->log;\n // (log == NULL)\n\nIf the `isReadOnly(ip)` condition is triggered in\n`jfs_truncate_nolock`, the function execution will stop, and no\nfurther data modification will occur. Instead, the `xtTruncate`\nfunction will be called with the \"COMMIT_WMAP\" flag, preventing\nmodifications in \"read-only\" mode.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58094" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5799dd77054c1ec49b0088b006c9908e256843b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f605bc3e162f5c6faa9bd3602ce496053d06a4bb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p6rr-cjxp-fjgr/GHSA-p6rr-cjxp-fjgr.json b/advisories/unreviewed/2025/04/GHSA-p6rr-cjxp-fjgr/GHSA-p6rr-cjxp-fjgr.json new file mode 100644 index 00000000000..0d59356d297 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p6rr-cjxp-fjgr/GHSA-p6rr-cjxp-fjgr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rr-cjxp-fjgr", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39598" + ], + "details": "Path Traversal vulnerability in Quý Lê 91 Administrator Z allows Path Traversal. This issue affects Administrator Z: from n/a through 2025.03.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39598" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/administrator-z/vulnerability/wordpress-administrator-z-2025-03-28-directory-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pcj7-8ccj-92x9/GHSA-pcj7-8ccj-92x9.json b/advisories/unreviewed/2025/04/GHSA-pcj7-8ccj-92x9/GHSA-pcj7-8ccj-92x9.json new file mode 100644 index 00000000000..2b0e85035bb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pcj7-8ccj-92x9/GHSA-pcj7-8ccj-92x9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcj7-8ccj-92x9", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22075" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtnetlink: Allocate vfinfo size for VF GUIDs when supported\n\nCommit 30aad41721e0 (\"net/core: Add support for getting VF GUIDs\")\nadded support for getting VF port and node GUIDs in netlink ifinfo\nmessages, but their size was not taken into consideration in the\nfunction that allocates the netlink message, causing the following\nwarning when a netlink message is filled with many VF port and node\nGUIDs:\n # echo 64 > /sys/bus/pci/devices/0000\\:08\\:00.0/sriov_numvfs\n # ip link show dev ib0\n RTNETLINK answers: Message too long\n Cannot send link get request: Message too long\n\nKernel warning:\n\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 1930 at net/core/rtnetlink.c:4151 rtnl_getlink+0x586/0x5a0\n Modules linked in: xt_conntrack xt_MASQUERADE nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter overlay mlx5_ib macsec mlx5_core tls rpcrdma rdma_ucm ib_uverbs ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm iw_cm ib_ipoib fuse ib_cm ib_core\n CPU: 2 UID: 0 PID: 1930 Comm: ip Not tainted 6.14.0-rc2+ #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n RIP: 0010:rtnl_getlink+0x586/0x5a0\n Code: cb 82 e8 3d af 0a 00 4d 85 ff 0f 84 08 ff ff ff 4c 89 ff 41 be ea ff ff ff e8 66 63 5b ff 49 c7 07 80 4f cb 82 e9 36 fc ff ff <0f> 0b e9 16 fe ff ff e8 de a0 56 00 66 66 2e 0f 1f 84 00 00 00 00\n RSP: 0018:ffff888113557348 EFLAGS: 00010246\n RAX: 00000000ffffffa6 RBX: ffff88817e87aa34 RCX: dffffc0000000000\n RDX: 0000000000000003 RSI: 0000000000000000 RDI: ffff88817e87afb8\n RBP: 0000000000000009 R08: ffffffff821f44aa R09: 0000000000000000\n R10: ffff8881260f79a8 R11: ffff88817e87af00 R12: ffff88817e87aa00\n R13: ffffffff8563d300 R14: 00000000ffffffa6 R15: 00000000ffffffff\n FS: 00007f63a5dbf280(0000) GS:ffff88881ee00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f63a5ba4493 CR3: 00000001700fe002 CR4: 0000000000772eb0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __warn+0xa5/0x230\n ? rtnl_getlink+0x586/0x5a0\n ? report_bug+0x22d/0x240\n ? handle_bug+0x53/0xa0\n ? exc_invalid_op+0x14/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_trim+0x6a/0x80\n ? rtnl_getlink+0x586/0x5a0\n ? __pfx_rtnl_getlink+0x10/0x10\n ? rtnetlink_rcv_msg+0x1e5/0x860\n ? __pfx___mutex_lock+0x10/0x10\n ? rcu_is_watching+0x34/0x60\n ? __pfx_lock_acquire+0x10/0x10\n ? stack_trace_save+0x90/0xd0\n ? filter_irq_stacks+0x1d/0x70\n ? kasan_save_stack+0x30/0x40\n ? kasan_save_stack+0x20/0x40\n ? kasan_save_track+0x10/0x30\n rtnetlink_rcv_msg+0x21c/0x860\n ? entry_SYSCALL_64_after_hwframe+0x76/0x7e\n ? __pfx_rtnetlink_rcv_msg+0x10/0x10\n ? arch_stack_walk+0x9e/0xf0\n ? rcu_is_watching+0x34/0x60\n ? lock_acquire+0xd5/0x410\n ? rcu_is_watching+0x34/0x60\n netlink_rcv_skb+0xe0/0x210\n ? __pfx_rtnetlink_rcv_msg+0x10/0x10\n ? __pfx_netlink_rcv_skb+0x10/0x10\n ? rcu_is_watching+0x34/0x60\n ? __pfx___netlink_lookup+0x10/0x10\n ? lock_release+0x62/0x200\n ? netlink_deliver_tap+0xfd/0x290\n ? rcu_is_watching+0x34/0x60\n ? lock_release+0x62/0x200\n ? netlink_deliver_tap+0x95/0x290\n netlink_unicast+0x31f/0x480\n ? __pfx_netlink_unicast+0x10/0x10\n ? rcu_is_watching+0x34/0x60\n ? lock_acquire+0xd5/0x410\n netlink_sendmsg+0x369/0x660\n ? lock_release+0x62/0x200\n ? __pfx_netlink_sendmsg+0x10/0x10\n ? import_ubuf+0xb9/0xf0\n ? __import_iovec+0x254/0x2b0\n ? lock_release+0x62/0x200\n ? __pfx_netlink_sendmsg+0x10/0x10\n ____sys_sendmsg+0x559/0x5a0\n ? __pfx_____sys_sendmsg+0x10/0x10\n ? __pfx_copy_msghdr_from_user+0x10/0x10\n ? rcu_is_watching+0x34/0x60\n ? do_read_fault+0x213/0x4a0\n ? rcu_is_watching+0x34/0x60\n ___sys_sendmsg+0xe4/0x150\n ? __pfx____sys_sendmsg+0x10/0x10\n ? do_fault+0x2cc/0x6f0\n ? handle_pte_fault+0x2e3/0x3d0\n ? __pfx_handle_pte_fault+0x10/0x10\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22075" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f5489707cf528f9df2f39a3045c1ee713ec90e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15f150771e0ec97f8ab1657e7d2568e593c7fa04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23f00807619d15063d676218f36c5dfeda1eb420" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28b21ee8e8fb326ba961a4bbce04ec04c65e705a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/365c1ae819455561d4746aafabad673e4bcb0163" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f39454468329bb7fc7fc4895a6ba6ae3b95027e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fed5f6de3cf734b231a11775748a6871ee3020f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb7bdf636cef74cdd7a7d548bdc7457ae161f617" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pf5r-v475-xg7p/GHSA-pf5r-v475-xg7p.json b/advisories/unreviewed/2025/04/GHSA-pf5r-v475-xg7p/GHSA-pf5r-v475-xg7p.json new file mode 100644 index 00000000000..0510d533457 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pf5r-v475-xg7p/GHSA-pf5r-v475-xg7p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf5r-v475-xg7p", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22096" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/gem: Fix error code msm_parse_deps()\n\nThe SUBMIT_ERROR() macro turns the error code negative. This extra '-'\noperation turns it back to positive EINVAL again. The error code is\npassed to ERR_PTR() and since positive values are not an IS_ERR() it\neventually will lead to an oops. Delete the '-'.\n\nPatchwork: https://patchwork.freedesktop.org/patch/637625/", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22096" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b305b7cadce835505bd93183a599acb1f800a05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efe759dcf3352d8379a1adad7b4d14044a4c41a7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pghg-fxcf-g9f9/GHSA-pghg-fxcf-g9f9.json b/advisories/unreviewed/2025/04/GHSA-pghg-fxcf-g9f9/GHSA-pghg-fxcf-g9f9.json new file mode 100644 index 00000000000..b46b6210db3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pghg-fxcf-g9f9/GHSA-pghg-fxcf-g9f9.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pghg-fxcf-g9f9", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22045" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Fix flush_tlb_range() when used for zapping normal PMDs\n\nOn the following path, flush_tlb_range() can be used for zapping normal\nPMD entries (PMD entries that point to page tables) together with the PTE\nentries in the pointed-to page table:\n\n collapse_pte_mapped_thp\n pmdp_collapse_flush\n flush_tlb_range\n\nThe arm64 version of flush_tlb_range() has a comment describing that it can\nbe used for page table removal, and does not use any last-level\ninvalidation optimizations. Fix the X86 version by making it behave the\nsame way.\n\nCurrently, X86 only uses this information for the following two purposes,\nwhich I think means the issue doesn't have much impact:\n\n - In native_flush_tlb_multi() for checking if lazy TLB CPUs need to be\n IPI'd to avoid issues with speculative page table walks.\n - In Hyper-V TLB paravirtualization, again for lazy TLB stuff.\n\nThe patch \"x86/mm: only invalidate final translations with INVLPGB\" which\nis currently under review (see\n)\nwould probably be making the impact of this a lot worse.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22045" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0708fd6bd8161871bfbadced2ca4319b84ab44fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a8f806ea6b5dd64b3d1f05ff774817d5f7ddbd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/320ac1af4c0bdb92c864dc9250d1329234820edf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ef938c3503563bfc2ac15083557f880d29c2e64" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/556d446068f90981e5d71ca686bdaccdd545d491" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/618d5612ecb7bfc1c85342daafeb2b47e29e77a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7085895c59e4057ffae17f58990ccb630087d0d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78d6f9a9eb2a5da6fcbd76d6191d24b0dcc321be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93224deb50a8d20df3884f3672ce9f982129aa50" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json b/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json index d40ae9df76a..26c7c691aa1 100644 --- a/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json +++ b/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prv3-9p5f-cqv2", - "modified": "2025-04-15T18:31:47Z", + "modified": "2025-04-16T15:34:16Z", "published": "2025-04-15T18:31:46Z", "aliases": [ "CVE-2024-50960" ], "details": "A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T18:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pxc5-947h-65gr/GHSA-pxc5-947h-65gr.json b/advisories/unreviewed/2025/04/GHSA-pxc5-947h-65gr/GHSA-pxc5-947h-65gr.json index 3998adf0ce9..4b874312f83 100644 --- a/advisories/unreviewed/2025/04/GHSA-pxc5-947h-65gr/GHSA-pxc5-947h-65gr.json +++ b/advisories/unreviewed/2025/04/GHSA-pxc5-947h-65gr/GHSA-pxc5-947h-65gr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-q76c-5fh5-v6x4/GHSA-q76c-5fh5-v6x4.json b/advisories/unreviewed/2025/04/GHSA-q76c-5fh5-v6x4/GHSA-q76c-5fh5-v6x4.json new file mode 100644 index 00000000000..325b358b4f8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q76c-5fh5-v6x4/GHSA-q76c-5fh5-v6x4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q76c-5fh5-v6x4", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-39600" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks allows Cross Site Request Forgery. This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39600" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-woocommerce-quickbooks/vulnerability/wordpress-integration-for-woocommerce-and-quickbooks-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q8p5-jh8j-ww29/GHSA-q8p5-jh8j-ww29.json b/advisories/unreviewed/2025/04/GHSA-q8p5-jh8j-ww29/GHSA-q8p5-jh8j-ww29.json new file mode 100644 index 00000000000..ab3c960915f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q8p5-jh8j-ww29/GHSA-q8p5-jh8j-ww29.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8p5-jh8j-ww29", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22049" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Increase ARCH_DMA_MINALIGN up to 16\n\nARCH_DMA_MINALIGN is 1 by default, but some LoongArch-specific devices\n(such as APBDMA) require 16 bytes alignment. When the data buffer length\nis too small, the hardware may make an error writing cacheline. Thus, it\nis dangerous to allocate a small memory buffer for DMA. It's always safe\nto define ARCH_DMA_MINALIGN as L1_CACHE_BYTES but unnecessary (kmalloc()\nneed small memory objects). Therefore, just increase it to 16.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d0def2d1658666ec1f32c9495df60e7411e3c82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/279ec25c2df49fba1cd9488f2ddd045d9cb2112e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4103cfe9dcb88010ae4911d3ff417457d1b6a720" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b82aea3666f8f2c78f86148d78aea99c46e0f82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bfff341cac7c650e6ca8d10503725992f5564d0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f39af67f03b564b763b06e44cb960c10a382d54a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json b/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json new file mode 100644 index 00000000000..bc6e66e91c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9qg-fj9x-mqhg", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22040" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix session use-after-free in multichannel connection\n\nThere is a race condition between session setup and\nksmbd_sessions_deregister. The session can be freed before the connection\nis added to channel list of session.\nThis patch check reference count of session before freeing it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22040" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3980770cb1470054e6400fd97668665975726737" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/596407adb9af1ee75fe7c7529607783d31b66e7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7dfbd4c43eed91dd2548a95236908025707a8dfd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9069939d762138e232a6f79e3e1462682ed6a17d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94c281721d4ed2d972232414b91d98a6f5bdb16b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa4cdb8cbca7d6cb6aa13e4d8d83d1103f6345db" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qc4q-4qwh-7cc2/GHSA-qc4q-4qwh-7cc2.json b/advisories/unreviewed/2025/04/GHSA-qc4q-4qwh-7cc2/GHSA-qc4q-4qwh-7cc2.json new file mode 100644 index 00000000000..d434e916944 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qc4q-4qwh-7cc2/GHSA-qc4q-4qwh-7cc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc4q-4qwh-7cc2", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39584" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39584" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-4-0-25-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json b/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json new file mode 100644 index 00000000000..3eb5f4caf96 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgrf-8g4m-4v9p", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2025-3690" + ], + "details": "A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-services.php. The manipulation of the argument cost leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3690" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyao-i03i/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304979" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304979" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qh2m-xfgm-crh8/GHSA-qh2m-xfgm-crh8.json b/advisories/unreviewed/2025/04/GHSA-qh2m-xfgm-crh8/GHSA-qh2m-xfgm-crh8.json new file mode 100644 index 00000000000..c3550d5633c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qh2m-xfgm-crh8/GHSA-qh2m-xfgm-crh8.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh2m-xfgm-crh8", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22058" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: Fix memory accounting leak.\n\nMatt Dowling reported a weird UDP memory usage issue.\n\nUnder normal operation, the UDP memory usage reported in /proc/net/sockstat\nremains close to zero. However, it occasionally spiked to 524,288 pages\nand never dropped. Moreover, the value doubled when the application was\nterminated. Finally, it caused intermittent packet drops.\n\nWe can reproduce the issue with the script below [0]:\n\n 1. /proc/net/sockstat reports 0 pages\n\n # cat /proc/net/sockstat | grep UDP:\n UDP: inuse 1 mem 0\n\n 2. Run the script till the report reaches 524,288\n\n # python3 test.py & sleep 5\n # cat /proc/net/sockstat | grep UDP:\n UDP: inuse 3 mem 524288 <-- (INT_MAX + 1) >> PAGE_SHIFT\n\n 3. Kill the socket and confirm the number never drops\n\n # pkill python3 && sleep 5\n # cat /proc/net/sockstat | grep UDP:\n UDP: inuse 1 mem 524288\n\n 4. (necessary since v6.0) Trigger proto_memory_pcpu_drain()\n\n # python3 test.py & sleep 1 && pkill python3\n\n 5. The number doubles\n\n # cat /proc/net/sockstat | grep UDP:\n UDP: inuse 1 mem 1048577\n\nThe application set INT_MAX to SO_RCVBUF, which triggered an integer\noverflow in udp_rmem_release().\n\nWhen a socket is close()d, udp_destruct_common() purges its receive\nqueue and sums up skb->truesize in the queue. This total is calculated\nand stored in a local unsigned integer variable.\n\nThe total size is then passed to udp_rmem_release() to adjust memory\naccounting. However, because the function takes a signed integer\nargument, the total size can wrap around, causing an overflow.\n\nThen, the released amount is calculated as follows:\n\n 1) Add size to sk->sk_forward_alloc.\n 2) Round down sk->sk_forward_alloc to the nearest lower multiple of\n PAGE_SIZE and assign it to amount.\n 3) Subtract amount from sk->sk_forward_alloc.\n 4) Pass amount >> PAGE_SHIFT to __sk_mem_reduce_allocated().\n\nWhen the issue occurred, the total in udp_destruct_common() was 2147484480\n(INT_MAX + 833), which was cast to -2147482816 in udp_rmem_release().\n\nAt 1) sk->sk_forward_alloc is changed from 3264 to -2147479552, and\n2) sets -2147479552 to amount. 3) reverts the wraparound, so we don't\nsee a warning in inet_sock_destruct(). However, udp_memory_allocated\nends up doubling at 4).\n\nSince commit 3cd3399dd7a8 (\"net: implement per-cpu reserves for\nmemory_allocated\"), memory usage no longer doubles immediately after\na socket is close()d because __sk_mem_reduce_allocated() caches the\namount in udp_memory_per_cpu_fw_alloc. However, the next time a UDP\nsocket receives a packet, the subtraction takes effect, causing UDP\nmemory usage to double.\n\nThis issue makes further memory allocation fail once the socket's\nsk->sk_rmem_alloc exceeds net.ipv4.udp_rmem_min, resulting in packet\ndrops.\n\nTo prevent this issue, let's use unsigned int for the calculation and\ncall sk_forward_alloc_add() only once for the small delta.\n\nNote that first_packet_length() also potentially has the same problem.\n\n[0]:\nfrom socket import *\n\nSO_RCVBUFFORCE = 33\nINT_MAX = (2 ** 31) - 1\n\ns = socket(AF_INET, SOCK_DGRAM)\ns.bind(('', 0))\ns.setsockopt(SOL_SOCKET, SO_RCVBUFFORCE, INT_MAX)\n\nc = socket(AF_INET, SOCK_DGRAM)\nc.connect(s.getsockname())\n\ndata = b'a' * 100\n\nwhile True:\n c.send(data)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22058" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3836029448e76c1e6f77cc5fe0adc09b018b5fa8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9122fec396950cc866137af7154b1d0d989be52e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a116b271bf3cb72c8155b6b7f39083c1b80dcd00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aeef6456692c6f11ae53d278df64f1316a2a405a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4bac6c398118fba79e32b1cd01db22dbfe29fbf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df207de9d9e7a4d92f8567e2c539d9c8c12fd99d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qj48-g5ch-7g59/GHSA-qj48-g5ch-7g59.json b/advisories/unreviewed/2025/04/GHSA-qj48-g5ch-7g59/GHSA-qj48-g5ch-7g59.json new file mode 100644 index 00000000000..1cf443464ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qj48-g5ch-7g59/GHSA-qj48-g5ch-7g59.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj48-g5ch-7g59", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23130" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid panic once fallocation fails for pinfile\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/segment.c:2746!\nCPU: 0 UID: 0 PID: 5323 Comm: syz.0.0 Not tainted 6.13.0-rc2-syzkaller-00018-g7cb1b4663150 #0\nRIP: 0010:get_new_segment fs/f2fs/segment.c:2746 [inline]\nRIP: 0010:new_curseg+0x1f52/0x1f70 fs/f2fs/segment.c:2876\nCall Trace:\n \n __allocate_new_segment+0x1ce/0x940 fs/f2fs/segment.c:3210\n f2fs_allocate_new_section fs/f2fs/segment.c:3224 [inline]\n f2fs_allocate_pinning_section+0xfa/0x4e0 fs/f2fs/segment.c:3238\n f2fs_expand_inode_data+0x696/0xca0 fs/f2fs/file.c:1830\n f2fs_fallocate+0x537/0xa10 fs/f2fs/file.c:1940\n vfs_fallocate+0x569/0x6e0 fs/open.c:327\n do_vfs_ioctl+0x258c/0x2e40 fs/ioctl.c:885\n __do_sys_ioctl fs/ioctl.c:904 [inline]\n __se_sys_ioctl+0x80/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nConcurrent pinfile allocation may run out of free section, result in\npanic in get_new_segment(), let's expand pin_sem lock coverage to\ninclude f2fs_gc(), so that we can make sure to reclaim enough free\nspace for following allocation.\n\nIn addition, do below changes to enhance error path handling:\n- call f2fs_bug_on() only in non-pinfile allocation path in\nget_new_segment().\n- call reset_curseg_fields() to reset all fields of curseg in\nnew_curseg()", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23130" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48ea8b200414ac69ea96f4c231f5c7ef1fbeffef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9392862608d081a8346a3b841f862d732fce954b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qjgh-6vq4-q6jf/GHSA-qjgh-6vq4-q6jf.json b/advisories/unreviewed/2025/04/GHSA-qjgh-6vq4-q6jf/GHSA-qjgh-6vq4-q6jf.json index ab9fff9b4f7..36b519560ae 100644 --- a/advisories/unreviewed/2025/04/GHSA-qjgh-6vq4-q6jf/GHSA-qjgh-6vq4-q6jf.json +++ b/advisories/unreviewed/2025/04/GHSA-qjgh-6vq4-q6jf/GHSA-qjgh-6vq4-q6jf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qpr8-8f95-6w4h/GHSA-qpr8-8f95-6w4h.json b/advisories/unreviewed/2025/04/GHSA-qpr8-8f95-6w4h/GHSA-qpr8-8f95-6w4h.json index 2cb66ea0b59..3c8bca447ac 100644 --- a/advisories/unreviewed/2025/04/GHSA-qpr8-8f95-6w4h/GHSA-qpr8-8f95-6w4h.json +++ b/advisories/unreviewed/2025/04/GHSA-qpr8-8f95-6w4h/GHSA-qpr8-8f95-6w4h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qq66-993w-2v7r/GHSA-qq66-993w-2v7r.json b/advisories/unreviewed/2025/04/GHSA-qq66-993w-2v7r/GHSA-qq66-993w-2v7r.json new file mode 100644 index 00000000000..e8be895d6c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qq66-993w-2v7r/GHSA-qq66-993w-2v7r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq66-993w-2v7r", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-3694" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the component Login Handler. The manipulation of the argument login_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3694" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/sql_inject_in_session_email.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304983" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304983" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553568" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qwxj-4879-p647/GHSA-qwxj-4879-p647.json b/advisories/unreviewed/2025/04/GHSA-qwxj-4879-p647/GHSA-qwxj-4879-p647.json index 197da5bac1d..b43888e1302 100644 --- a/advisories/unreviewed/2025/04/GHSA-qwxj-4879-p647/GHSA-qwxj-4879-p647.json +++ b/advisories/unreviewed/2025/04/GHSA-qwxj-4879-p647/GHSA-qwxj-4879-p647.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qwxj-4879-p647", - "modified": "2025-04-16T03:30:24Z", + "modified": "2025-04-16T15:34:29Z", "published": "2025-04-16T03:30:24Z", "aliases": [ "CVE-2025-3698" ], "details": "Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T03:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qx79-q87h-mhp6/GHSA-qx79-q87h-mhp6.json b/advisories/unreviewed/2025/04/GHSA-qx79-q87h-mhp6/GHSA-qx79-q87h-mhp6.json new file mode 100644 index 00000000000..f05d0773e6f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qx79-q87h-mhp6/GHSA-qx79-q87h-mhp6.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx79-q87h-mhp6", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22080" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Prevent integer overflow in hdr_first_de()\n\nThe \"de_off\" and \"used\" variables come from the disk so they both need to\ncheck. The problem is that on 32bit systems if they're both greater than\nUINT_MAX - 16 then the check does work as intended because of an integer\noverflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22080" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/201a2bdda13b619c4927700ffe47d387a30ced50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bb81b94f7a9cba6bde9a905cef52a65317a8b04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85615aa442830027923fc690390fa74d17b36ae1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9982065b82b4177ba3a7a72ce18c84921f7494d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6d44b1aa46d317e52c21fb9314cfb20dd69e7b0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r24q-wpfh-2vqx/GHSA-r24q-wpfh-2vqx.json b/advisories/unreviewed/2025/04/GHSA-r24q-wpfh-2vqx/GHSA-r24q-wpfh-2vqx.json new file mode 100644 index 00000000000..25a163d8bcd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r24q-wpfh-2vqx/GHSA-r24q-wpfh-2vqx.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r24q-wpfh-2vqx", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22071" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix a leak in spufs_create_context()\n\nLeak fixes back in 2008 missed one case - if we are trying to set affinity\nand spufs_mkdir() fails, we need to drop the reference to neighbor.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22071" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f5cce3fc55b08ee4da3372baccf4bcd36a98396" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/239ea3c34673b3244a499fd65771c47e5bffcbb0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/410c787d89c92df4215d7b1a338e2c1a8aba6b9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a7448c83e117ed68597952ecaede1cebc4427a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a90b699844a5bb96961e5892e51cc59255444a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/829bd6139968e2e759f3928cf65ad0db1e302fe3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a333f223e555d27609f8b45d75a08e8e1d36c432" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4e72a0d75442237b6f3bcca10a7d81b89376d16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d04600f43569d48262e1328eaa1592fcefa2c19c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r2hv-pfm6-9m75/GHSA-r2hv-pfm6-9m75.json b/advisories/unreviewed/2025/04/GHSA-r2hv-pfm6-9m75/GHSA-r2hv-pfm6-9m75.json index ceb3a16e1c6..ea77839f794 100644 --- a/advisories/unreviewed/2025/04/GHSA-r2hv-pfm6-9m75/GHSA-r2hv-pfm6-9m75.json +++ b/advisories/unreviewed/2025/04/GHSA-r2hv-pfm6-9m75/GHSA-r2hv-pfm6-9m75.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-r2xg-g23x-9jj5/GHSA-r2xg-g23x-9jj5.json b/advisories/unreviewed/2025/04/GHSA-r2xg-g23x-9jj5/GHSA-r2xg-g23x-9jj5.json new file mode 100644 index 00000000000..abdf0b7865e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r2xg-g23x-9jj5/GHSA-r2xg-g23x-9jj5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2xg-g23x-9jj5", + "modified": "2025-04-16T15:34:42Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22065" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix adapter NULL pointer dereference on reboot\n\nWith SRIOV enabled, idpf ends up calling into idpf_remove() twice.\nFirst via idpf_shutdown() and then again when idpf_remove() calls into\nsriov_disable(), because the VF devices use the idpf driver, hence the\nsame remove routine. When that happens, it is possible for the adapter\nto be NULL from the first call to idpf_remove(), leading to a NULL\npointer dereference.\n\necho 1 > /sys/class/net//device/sriov_numvfs\nreboot\n\nBUG: kernel NULL pointer dereference, address: 0000000000000020\n...\nRIP: 0010:idpf_remove+0x22/0x1f0 [idpf]\n...\n? idpf_remove+0x22/0x1f0 [idpf]\n? idpf_remove+0x1e4/0x1f0 [idpf]\npci_device_remove+0x3f/0xb0\ndevice_release_driver_internal+0x19f/0x200\npci_stop_bus_device+0x6d/0x90\npci_stop_and_remove_bus_device+0x12/0x20\npci_iov_remove_virtfn+0xbe/0x120\nsriov_disable+0x34/0xe0\nidpf_sriov_configure+0x58/0x140 [idpf]\nidpf_remove+0x1b9/0x1f0 [idpf]\nidpf_shutdown+0x12/0x30 [idpf]\npci_device_shutdown+0x35/0x60\ndevice_shutdown+0x156/0x200\n...\n\nReplace the direct idpf_remove() call in idpf_shutdown() with\nidpf_vc_core_deinit() and idpf_deinit_dflt_mbx(), which perform\nthe bulk of the cleanup, such as stopping the init task, freeing IRQs,\ndestroying the vports and freeing the mailbox. This avoids the calls to\nsriov_disable() in addition to a small netdev cleanup, and destroying\nworkqueues, which don't seem to be required on shutdown.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22065" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c9106f4906a85f6b13542d862e423bcdc118cc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79618e952ef4dfa1a17ee0631d5549603fab58d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88a6d562e92a295648f8636acf2a6aa714241771" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fc9b3dc0d0c189ed205acf1e5fbd73e0becc4d6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r428-mj5m-mqvq/GHSA-r428-mj5m-mqvq.json b/advisories/unreviewed/2025/04/GHSA-r428-mj5m-mqvq/GHSA-r428-mj5m-mqvq.json new file mode 100644 index 00000000000..4a50d6cc990 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r428-mj5m-mqvq/GHSA-r428-mj5m-mqvq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r428-mj5m-mqvq", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22099" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: xlnx: zynqmp_dpsub: Add NULL check in zynqmp_audio_init\n\ndevm_kasprintf() calls can return null pointers on failure.\nBut some return values were not checked in zynqmp_audio_init().\n\nAdd NULL check in zynqmp_audio_init(), avoid referencing null\npointers in the subsequent code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22099" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/066d6f22e7d84953db6bbf2dae507401157660c6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0660f9c588a1246a1a543c91a1e3cad910237da" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r4f3-r23x-xm4q/GHSA-r4f3-r23x-xm4q.json b/advisories/unreviewed/2025/04/GHSA-r4f3-r23x-xm4q/GHSA-r4f3-r23x-xm4q.json new file mode 100644 index 00000000000..f954eb4f79b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r4f3-r23x-xm4q/GHSA-r4f3-r23x-xm4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4f3-r23x-xm4q", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39557" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Upload a Web Shell to a Web Server. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39557" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-14-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r4vm-3mc7-prgx/GHSA-r4vm-3mc7-prgx.json b/advisories/unreviewed/2025/04/GHSA-r4vm-3mc7-prgx/GHSA-r4vm-3mc7-prgx.json new file mode 100644 index 00000000000..4de631f425a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r4vm-3mc7-prgx/GHSA-r4vm-3mc7-prgx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4vm-3mc7-prgx", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22105" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: check xdp prog when set bond mode\n\nFollowing operations can trigger a warning[1]:\n\n ip netns add ns1\n ip netns exec ns1 ip link add bond0 type bond mode balance-rr\n ip netns exec ns1 ip link set dev bond0 xdp obj af_xdp_kern.o sec xdp\n ip netns exec ns1 ip link set bond0 type bond mode broadcast\n ip netns del ns1\n\nWhen delete the namespace, dev_xdp_uninstall() is called to remove xdp\nprogram on bond dev, and bond_xdp_set() will check the bond mode. If bond\nmode is changed after attaching xdp program, the warning may occur.\n\nSome bond modes (broadcast, etc.) do not support native xdp. Set bond mode\nwith xdp program attached is not good. Add check for xdp program when set\nbond mode.\n\n [1]\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 11 at net/core/dev.c:9912 unregister_netdevice_many_notify+0x8d9/0x930\n Modules linked in:\n CPU: 0 UID: 0 PID: 11 Comm: kworker/u4:0 Not tainted 6.14.0-rc4 #107\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014\n Workqueue: netns cleanup_net\n RIP: 0010:unregister_netdevice_many_notify+0x8d9/0x930\n Code: 00 00 48 c7 c6 6f e3 a2 82 48 c7 c7 d0 b3 96 82 e8 9c 10 3e ...\n RSP: 0018:ffffc90000063d80 EFLAGS: 00000282\n RAX: 00000000ffffffa1 RBX: ffff888004959000 RCX: 00000000ffffdfff\n RDX: 0000000000000000 RSI: 00000000ffffffea RDI: ffffc90000063b48\n RBP: ffffc90000063e28 R08: ffffffff82d39b28 R09: 0000000000009ffb\n R10: 0000000000000175 R11: ffffffff82d09b40 R12: ffff8880049598e8\n R13: 0000000000000001 R14: dead000000000100 R15: ffffc90000045000\n FS: 0000000000000000(0000) GS:ffff888007a00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000d406b60 CR3: 000000000483e000 CR4: 00000000000006f0\n Call Trace:\n \n ? __warn+0x83/0x130\n ? unregister_netdevice_many_notify+0x8d9/0x930\n ? report_bug+0x18e/0x1a0\n ? handle_bug+0x54/0x90\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? unregister_netdevice_many_notify+0x8d9/0x930\n ? bond_net_exit_batch_rtnl+0x5c/0x90\n cleanup_net+0x237/0x3d0\n process_one_work+0x163/0x390\n worker_thread+0x293/0x3b0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xec/0x1e0\n ? __pfx_kthread+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2f/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n ---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22105" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/094ee6017ea09c11d6af187935a949df32803ce0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0dd4fac43bdea23cfe4bb2a3eabb76d752ac32fb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json b/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json new file mode 100644 index 00000000000..0b48d50c28d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r764-27jf-q424", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22063" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets\n\nWhen calling netlbl_conn_setattr(), addr->sa_family is used\nto determine the function behavior. If sk is an IPv4 socket,\nbut the connect function is called with an IPv6 address,\nthe function calipso_sock_setattr() is triggered.\nInside this function, the following code is executed:\n\nsk_fullsock(__sk) ? inet_sk(__sk)->pinet6 : NULL;\n\nSince sk is an IPv4 socket, pinet6 is NULL, leading to a\nnull pointer dereference.\n\nThis patch fixes the issue by checking if inet6_sk(sk)\nreturns a NULL pointer before accessing pinet6.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22063" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/078aabd567de3d63d37d7673f714e309d369e6e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/172a8a996a337206970467e871dd995ac07640b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1927d0bcd5b81e80971bf6b8eba267508bd1c78b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ad9166cab6a0f5c0b10344a97bdf749ae11dcbf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e38f7a6cdd68377f8a4189b2fbaec14a6dd5152" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ba9cf69de50e8abed32b448616c313baa4c5712" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/797e5371cf55463b4530bab3fef5f27f7c6657a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fe3839588db7519030377b7dee3f165e654f6c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7e89541d05b98c79a51c0f95df020f8e82b62ed" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r89q-j67g-cqcj/GHSA-r89q-j67g-cqcj.json b/advisories/unreviewed/2025/04/GHSA-r89q-j67g-cqcj/GHSA-r89q-j67g-cqcj.json new file mode 100644 index 00000000000..5d54652f107 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r89q-j67g-cqcj/GHSA-r89q-j67g-cqcj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r89q-j67g-cqcj", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23135" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRISC-V: KVM: Teardown riscv specific bits after kvm_exit\n\nDuring a module removal, kvm_exit invokes arch specific disable\ncall which disables AIA. However, we invoke aia_exit before kvm_exit\nresulting in the following warning. KVM kernel module can't be inserted\nafterwards due to inconsistent state of IRQ.\n\n[25469.031389] percpu IRQ 31 still enabled on CPU0!\n[25469.031732] WARNING: CPU: 3 PID: 943 at kernel/irq/manage.c:2476 __free_percpu_irq+0xa2/0x150\n[25469.031804] Modules linked in: kvm(-)\n[25469.031848] CPU: 3 UID: 0 PID: 943 Comm: rmmod Not tainted 6.14.0-rc5-06947-g91c763118f47-dirty #2\n[25469.031905] Hardware name: riscv-virtio,qemu (DT)\n[25469.031928] epc : __free_percpu_irq+0xa2/0x150\n[25469.031976] ra : __free_percpu_irq+0xa2/0x150\n[25469.032197] epc : ffffffff8007db1e ra : ffffffff8007db1e sp : ff2000000088bd50\n[25469.032241] gp : ffffffff8131cef8 tp : ff60000080b96400 t0 : ff2000000088baf8\n[25469.032285] t1 : fffffffffffffffc t2 : 5249207570637265 s0 : ff2000000088bd90\n[25469.032329] s1 : ff60000098b21080 a0 : 037d527a15eb4f00 a1 : 037d527a15eb4f00\n[25469.032372] a2 : 0000000000000023 a3 : 0000000000000001 a4 : ffffffff8122dbf8\n[25469.032410] a5 : 0000000000000fff a6 : 0000000000000000 a7 : ffffffff8122dc10\n[25469.032448] s2 : ff60000080c22eb0 s3 : 0000000200000022 s4 : 000000000000001f\n[25469.032488] s5 : ff60000080c22e00 s6 : ffffffff80c351c0 s7 : 0000000000000000\n[25469.032582] s8 : 0000000000000003 s9 : 000055556b7fb490 s10: 00007ffff0e12fa0\n[25469.032621] s11: 00007ffff0e13e9a t3 : ffffffff81354ac7 t4 : ffffffff81354ac7\n[25469.032664] t5 : ffffffff81354ac8 t6 : ffffffff81354ac7\n[25469.032698] status: 0000000200000100 badaddr: ffffffff8007db1e cause: 0000000000000003\n[25469.032738] [] __free_percpu_irq+0xa2/0x150\n[25469.032797] [] free_percpu_irq+0x30/0x5e\n[25469.032856] [] kvm_riscv_aia_exit+0x40/0x42 [kvm]\n[25469.033947] [] cleanup_module+0x10/0x32 [kvm]\n[25469.035300] [] __riscv_sys_delete_module+0x18e/0x1fc\n[25469.035374] [] syscall_handler+0x3a/0x46\n[25469.035456] [] do_trap_ecall_u+0x72/0x134\n[25469.035536] [] handle_exception+0x148/0x156\n\nInvoke aia_exit and other arch specific cleanup functions after kvm_exit\nso that disable gets a chance to be called first before exit.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23135" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1521cc04f0b6e737ff30105aa57fa9dde8493231" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1edb2de48616b11ee05e9a65d74c70abcb6d9939" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d117e67f318303f6ab699a5511d1fac3f170545" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rgv7-v2jh-pv8v/GHSA-rgv7-v2jh-pv8v.json b/advisories/unreviewed/2025/04/GHSA-rgv7-v2jh-pv8v/GHSA-rgv7-v2jh-pv8v.json new file mode 100644 index 00000000000..c6cd9dc6782 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rgv7-v2jh-pv8v/GHSA-rgv7-v2jh-pv8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgv7-v2jh-pv8v", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39564" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce allows Cross Site Request Forgery. This issue affects Conditional Shipping for WooCommerce: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/conditional-shipping-for-woocommerce/vulnerability/wordpress-conditional-shipping-for-woocommerce-3-4-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rgvr-pr7c-x97v/GHSA-rgvr-pr7c-x97v.json b/advisories/unreviewed/2025/04/GHSA-rgvr-pr7c-x97v/GHSA-rgvr-pr7c-x97v.json new file mode 100644 index 00000000000..fe9a73d10fd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rgvr-pr7c-x97v/GHSA-rgvr-pr7c-x97v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgvr-pr7c-x97v", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22109" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Remove broken autobind\n\nBinding AX25 socket by using the autobind feature leads to memory leaks\nin ax25_connect() and also refcount leaks in ax25_release(). Memory\nleak was detected with kmemleak:\n\n================================================================\nunreferenced object 0xffff8880253cd680 (size 96):\nbacktrace:\n__kmalloc_node_track_caller_noprof (./include/linux/kmemleak.h:43)\nkmemdup_noprof (mm/util.c:136)\nax25_rt_autobind (net/ax25/ax25_route.c:428)\nax25_connect (net/ax25/af_ax25.c:1282)\n__sys_connect_file (net/socket.c:2045)\n__sys_connect (net/socket.c:2064)\n__x64_sys_connect (net/socket.c:2067)\ndo_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n================================================================\n\nWhen socket is bound, refcounts must be incremented the way it is done\nin ax25_bind() and ax25_setsockopt() (SO_BINDTODEVICE). In case of\nautobind, the refcounts are not incremented.\n\nThis bug leads to the following issue reported by Syzkaller:\n\n================================================================\nax25_connect(): syz-executor318 uses autobind, please contact jreuter@yaina.de\n------------[ cut here ]------------\nrefcount_t: decrement hit 0; leaking memory.\nWARNING: CPU: 0 PID: 5317 at lib/refcount.c:31 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31\nModules linked in:\nCPU: 0 UID: 0 PID: 5317 Comm: syz-executor318 Not tainted 6.14.0-rc4-syzkaller-00278-gece144f151ac #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31\n...\nCall Trace:\n \n __refcount_dec include/linux/refcount.h:336 [inline]\n refcount_dec include/linux/refcount.h:351 [inline]\n ref_tracker_free+0x6af/0x7e0 lib/ref_tracker.c:236\n netdev_tracker_free include/linux/netdevice.h:4302 [inline]\n netdev_put include/linux/netdevice.h:4319 [inline]\n ax25_release+0x368/0x960 net/ax25/af_ax25.c:1080\n __sock_release net/socket.c:647 [inline]\n sock_close+0xbc/0x240 net/socket.c:1398\n __fput+0x3e9/0x9f0 fs/file_table.c:464\n __do_sys_close fs/open.c:1580 [inline]\n __se_sys_close fs/open.c:1565 [inline]\n __x64_sys_close+0x7f/0x110 fs/open.c:1565\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n ...\n \n================================================================\n\nConsidering the issues above and the comments left in the code that say:\n\"check if we can remove this feature. It is broken.\"; \"autobinding in this\nmay or may not work\"; - it is better to completely remove this feature than\nto fix it because it is broken and leads to various kinds of memory bugs.\n\nNow calling connect() without first binding socket will result in an\nerror (-EINVAL). Userspace software that relies on the autobind feature\nmight get broken. However, this feature does not seem widely used with\nthis specific driver as it was not reliable at any point of time, and it\nis already broken anyway. E.g. ax25-tools and ax25-apps packages for\npopular distributions do not use the autobind feature for AF_AX25.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22109" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f6efbabceb6b2914ee9bafb86d9a51feae9cce8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61203fdd3e35519db9a98b6ff8983c620ffc4696" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rxxj-rv84-8c37/GHSA-rxxj-rv84-8c37.json b/advisories/unreviewed/2025/04/GHSA-rxxj-rv84-8c37/GHSA-rxxj-rv84-8c37.json new file mode 100644 index 00000000000..bcb3409f072 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rxxj-rv84-8c37/GHSA-rxxj-rv84-8c37.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxxj-rv84-8c37", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22091" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix page_size variable overflow\n\nChange all variables storing mlx5_umem_mkc_find_best_pgsz() result to\nunsigned long to support values larger than 31 and avoid overflow.\n\nFor example: If we try to register 4GB of memory that is contiguous in\nphysical memory, the driver will optimize the page_size and try to use\nan mkey with 4GB entity size. The 'unsigned int' page_size variable will\noverflow to '0' and we'll hit the WARN_ON() in alloc_cacheable_mr().\n\nWARNING: CPU: 2 PID: 1203 at drivers/infiniband/hw/mlx5/mr.c:1124 alloc_cacheable_mr+0x22/0x580 [mlx5_ib]\nModules linked in: mlx5_ib mlx5_core bonding ip6_gre ip6_tunnel tunnel6 ip_gre gre rdma_rxe rdma_ucm ib_uverbs ib_ipoib ib_umad rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm fuse ib_core [last unloaded: mlx5_core]\nCPU: 2 UID: 70878 PID: 1203 Comm: rdma_resource_l Tainted: G W 6.14.0-rc4-dirty #43\nTainted: [W]=WARN\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:alloc_cacheable_mr+0x22/0x580 [mlx5_ib]\nCode: 90 90 90 90 90 90 90 90 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 41 55 41 54 41 52 53 48 83 ec 30 f6 46 28 04 4c 8b 77 08 75 21 <0f> 0b 49 c7 c2 ea ff ff ff 48 8d 65 d0 4c 89 d0 5b 41 5a 41 5c 41\nRSP: 0018:ffffc900006ffac8 EFLAGS: 00010246\nRAX: 0000000004c0d0d0 RBX: ffff888217a22000 RCX: 0000000000100001\nRDX: 00007fb7ac480000 RSI: ffff8882037b1240 RDI: ffff8882046f0600\nRBP: ffffc900006ffb28 R08: 0000000000000001 R09: 0000000000000000\nR10: 00000000000007e0 R11: ffffea0008011d40 R12: ffff8882037b1240\nR13: ffff8882046f0600 R14: ffff888217a22000 R15: ffffc900006ffe00\nFS: 00007fb7ed013340(0000) GS:ffff88885fd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fb7ed1d8000 CR3: 00000001fd8f6006 CR4: 0000000000772eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? __warn+0x81/0x130\n ? alloc_cacheable_mr+0x22/0x580 [mlx5_ib]\n ? report_bug+0xfc/0x1e0\n ? handle_bug+0x55/0x90\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? alloc_cacheable_mr+0x22/0x580 [mlx5_ib]\n create_real_mr+0x54/0x150 [mlx5_ib]\n ib_uverbs_reg_mr+0x17f/0x2a0 [ib_uverbs]\n ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0xca/0x140 [ib_uverbs]\n ib_uverbs_run_method+0x6d0/0x780 [ib_uverbs]\n ? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs]\n ib_uverbs_cmd_verbs+0x19b/0x360 [ib_uverbs]\n ? walk_system_ram_range+0x79/0xd0\n ? ___pte_offset_map+0x1b/0x110\n ? __pte_offset_map_lock+0x80/0x100\n ib_uverbs_ioctl+0xac/0x110 [ib_uverbs]\n __x64_sys_ioctl+0x94/0xb0\n do_syscall_64+0x50/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7fb7ecf0737b\nCode: ff ff ff 85 c0 79 9b 49 c7 c4 ff ff ff ff 5b 5d 4c 89 e0 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 7d 2a 0f 00 f7 d8 64 89 01 48\nRSP: 002b:00007ffdbe03ecc8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007ffdbe03edb8 RCX: 00007fb7ecf0737b\nRDX: 00007ffdbe03eda0 RSI: 00000000c0181b01 RDI: 0000000000000003\nRBP: 00007ffdbe03ed80 R08: 00007fb7ecc84010 R09: 00007ffdbe03eed4\nR10: 0000000000000009 R11: 0000000000000246 R12: 00007ffdbe03eed4\nR13: 000000000000000c R14: 000000000000000c R15: 00007fb7ecc84150\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01fd737776ca0f17a96d83cd7f0840ce130b9a02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05b215d5e219c0228b9c7082ba9bcf176c576646" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0c09f639ca0e102f250df8787740c2013e9d1b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0c2427412b43cdf1b7b0944749ea17ddb97d5a5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v2fq-g4g9-h8q9/GHSA-v2fq-g4g9-h8q9.json b/advisories/unreviewed/2025/04/GHSA-v2fq-g4g9-h8q9/GHSA-v2fq-g4g9-h8q9.json new file mode 100644 index 00000000000..e8259291c17 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v2fq-g4g9-h8q9/GHSA-v2fq-g4g9-h8q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2fq-g4g9-h8q9", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39591" + ], + "details": "Missing Authorization vulnerability in WP Shuffle WP Subscription Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Subscription Forms: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39591" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-subscription-forms/vulnerability/wordpress-wp-subscription-forms-1-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v2jc-6pmq-v2wf/GHSA-v2jc-6pmq-v2wf.json b/advisories/unreviewed/2025/04/GHSA-v2jc-6pmq-v2wf/GHSA-v2jc-6pmq-v2wf.json new file mode 100644 index 00000000000..fbc8a0b5a3a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v2jc-6pmq-v2wf/GHSA-v2jc-6pmq-v2wf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2jc-6pmq-v2wf", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39512" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Yuya Hoshino Bulk Term Editor allows Cross Site Request Forgery. This issue affects Bulk Term Editor: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39512" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-term-editor/vulnerability/wordpress-bulk-term-editor-1-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v3c9-cxr8-9vgg/GHSA-v3c9-cxr8-9vgg.json b/advisories/unreviewed/2025/04/GHSA-v3c9-cxr8-9vgg/GHSA-v3c9-cxr8-9vgg.json new file mode 100644 index 00000000000..4d60617cc3e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v3c9-cxr8-9vgg/GHSA-v3c9-cxr8-9vgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3c9-cxr8-9vgg", + "modified": "2025-04-16T15:34:36Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39573" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Posts Carousel allows Stored XSS. This issue affects WP Posts Carousel: from n/a through 1.3.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39573" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-posts-carousel/vulnerability/wordpress-wp-posts-carousel-1-3-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v43g-xqqr-j4r8/GHSA-v43g-xqqr-j4r8.json b/advisories/unreviewed/2025/04/GHSA-v43g-xqqr-j4r8/GHSA-v43g-xqqr-j4r8.json new file mode 100644 index 00000000000..3d509fb3055 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v43g-xqqr-j4r8/GHSA-v43g-xqqr-j4r8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v43g-xqqr-j4r8", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22107" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry()\n\nThere are actually 2 problems:\n- deleting the last element doesn't require the memmove of elements\n [i + 1, end) over it. Actually, element i+1 is out of bounds.\n- The memmove itself should move size - i - 1 elements, because the last\n element is out of bounds.\n\nThe out-of-bounds element still remains out of bounds after being\naccessed, so the problem is only that we touch it, not that it becomes\nin active use. But I suppose it can lead to issues if the out-of-bounds\nelement is part of an unmapped page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22107" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59b97641de03c081f26b3a8876628c765b5faa25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f2b28b79d2d1946ee36ad8b3dc0066f73c90481" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v4w6-p754-7g2j/GHSA-v4w6-p754-7g2j.json b/advisories/unreviewed/2025/04/GHSA-v4w6-p754-7g2j/GHSA-v4w6-p754-7g2j.json new file mode 100644 index 00000000000..0cd2d91aec1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v4w6-p754-7g2j/GHSA-v4w6-p754-7g2j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4w6-p754-7g2j", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:46Z", + "aliases": [ + "CVE-2025-23132" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: quota: fix to avoid warning in dquot_writeback_dquots()\n\nF2FS-fs (dm-59): checkpoint=enable has some unwritten data.\n\n------------[ cut here ]------------\nWARNING: CPU: 6 PID: 8013 at fs/quota/dquot.c:691 dquot_writeback_dquots+0x2fc/0x308\npc : dquot_writeback_dquots+0x2fc/0x308\nlr : f2fs_quota_sync+0xcc/0x1c4\nCall trace:\ndquot_writeback_dquots+0x2fc/0x308\nf2fs_quota_sync+0xcc/0x1c4\nf2fs_write_checkpoint+0x3d4/0x9b0\nf2fs_issue_checkpoint+0x1bc/0x2c0\nf2fs_sync_fs+0x54/0x150\nf2fs_do_sync_file+0x2f8/0x814\n__f2fs_ioctl+0x1960/0x3244\nf2fs_ioctl+0x54/0xe0\n__arm64_sys_ioctl+0xa8/0xe4\ninvoke_syscall+0x58/0x114\n\ncheckpoint and f2fs_remount may race as below, resulting triggering warning\nin dquot_writeback_dquots().\n\natomic write remount\n - do_remount\n - down_write(&sb->s_umount);\n - f2fs_remount\n- ioctl\n - f2fs_do_sync_file\n - f2fs_sync_fs\n - f2fs_write_checkpoint\n - block_operations\n - locked = down_read_trylock(&sbi->sb->s_umount)\n : fail to lock due to the write lock was held by remount\n - up_write(&sb->s_umount);\n - f2fs_quota_sync\n - dquot_writeback_dquots\n - WARN_ON_ONCE(!rwsem_is_locked(&sb->s_umount))\n : trigger warning because s_umount lock was unlocked by remount\n\nIf checkpoint comes from mount/umount/remount/freeze/quotactl, caller of\ncheckpoint has already held s_umount lock, calling dquot_writeback_dquots()\nin the context should be safe.\n\nSo let's record task to sbi->umount_lock_holder, so that checkpoint can\nknow whether the lock has held in the context or not by checking current\nw/ it.\n\nIn addition, in order to not misrepresent caller of checkpoint, we should\nnot allow to trigger async checkpoint for those callers: mount/umount/remount/\nfreeze/quotactl.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23132" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7acf0a6c87aa282c86a36dbaa2f92fda88c5884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb85c2410d6f581e957cd03a644ff6ddbe592af9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v6rx-qqxh-7pj6/GHSA-v6rx-qqxh-7pj6.json b/advisories/unreviewed/2025/04/GHSA-v6rx-qqxh-7pj6/GHSA-v6rx-qqxh-7pj6.json new file mode 100644 index 00000000000..763fa885d39 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v6rx-qqxh-7pj6/GHSA-v6rx-qqxh-7pj6.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6rx-qqxh-7pj6", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22072" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix gang directory lifetimes\n\nprior to \"[POWERPC] spufs: Fix gang destroy leaks\" we used to have\na problem with gang lifetimes - creation of a gang returns opened\ngang directory, which normally gets removed when that gets closed,\nbut if somebody has created a context belonging to that gang and\nkept it alive until the gang got closed, removal failed and we\nended up with a leak.\n\nUnfortunately, it had been fixed the wrong way. Dentry of gang\ndirectory was no longer pinned, and rmdir on close was gone.\nOne problem was that failure of open kept calling simple_rmdir()\nas cleanup, which meant an unbalanced dput(). Another bug was\nin the success case - gang creation incremented link count on\nroot directory, but that was no longer undone when gang got\ndestroyed.\n\nFix consists of\n\t* reverting the commit in question\n\t* adding a counter to gang, protected by ->i_rwsem\nof gang directory inode.\n\t* having it set to 1 at creation time, dropped\nin both spufs_dir_close() and spufs_gang_close() and bumped\nin spufs_create_context(), provided that it's not 0.\n\t* using simple_recursive_removal() to take the gang\ndirectory out when counter reaches zero.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22072" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/029d8c711f5e5fe8cf63e8a4a1a140a06e224e45" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/324f280806aab28ef757aecc18df419676c10ef8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/880e7b3da2e765c1f90c94c0539be039e96c7062" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/903733782f3ae28a2f7fe4dfb47c7fe3e079a528" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c134deabf4784e155d360744d4a6a835b9de4dd4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc646a6c6d14b5d581f162a7e32999f789e3a3ac" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vc4w-2h5w-x28j/GHSA-vc4w-2h5w-x28j.json b/advisories/unreviewed/2025/04/GHSA-vc4w-2h5w-x28j/GHSA-vc4w-2h5w-x28j.json new file mode 100644 index 00000000000..0425c4efbaf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vc4w-2h5w-x28j/GHSA-vc4w-2h5w-x28j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc4w-2h5w-x28j", + "modified": "2025-04-16T15:34:34Z", + "published": "2025-04-16T15:34:34Z", + "aliases": [ + "CVE-2025-39513" + ], + "details": "Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects ActiveDEMAND: from n/a through 0.2.46.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39513" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/activedemand/vulnerability/wordpress-activedemand-0-2-46-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vcjc-q999-g4p2/GHSA-vcjc-q999-g4p2.json b/advisories/unreviewed/2025/04/GHSA-vcjc-q999-g4p2/GHSA-vcjc-q999-g4p2.json new file mode 100644 index 00000000000..4011eb78c1b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vcjc-q999-g4p2/GHSA-vcjc-q999-g4p2.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcjc-q999-g4p2", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22083" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint\n\nIf vhost_scsi_set_endpoint is called multiple times without a\nvhost_scsi_clear_endpoint between them, we can hit multiple bugs\nfound by Haoran Zhang:\n\n1. Use-after-free when no tpgs are found:\n\nThis fixes a use after free that occurs when vhost_scsi_set_endpoint is\ncalled more than once and calls after the first call do not find any\ntpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds\ntpgs to add to the vs_tpg array match=true, so we will do:\n\nvhost_vq_set_backend(vq, vs_tpg);\n...\n\nkfree(vs->vs_tpg);\nvs->vs_tpg = vs_tpg;\n\nIf vhost_scsi_set_endpoint is called again and no tpgs are found\nmatch=false so we skip the vhost_vq_set_backend call leaving the\npointer to the vs_tpg we then free via:\n\nkfree(vs->vs_tpg);\nvs->vs_tpg = vs_tpg;\n\nIf a scsi request is then sent we do:\n\nvhost_scsi_handle_vq -> vhost_scsi_get_req -> vhost_vq_get_backend\n\nwhich sees the vs_tpg we just did a kfree on.\n\n2. Tpg dir removal hang:\n\nThis patch fixes an issue where we cannot remove a LIO/target layer\ntpg (and structs above it like the target) dir due to the refcount\ndropping to -1.\n\nThe problem is that if vhost_scsi_set_endpoint detects a tpg is already\nin the vs->vs_tpg array or if the tpg has been removed so\ntarget_depend_item fails, the undepend goto handler will do\ntarget_undepend_item on all tpgs in the vs_tpg array dropping their\nrefcount to 0. At this time vs_tpg contains both the tpgs we have added\nin the current vhost_scsi_set_endpoint call as well as tpgs we added in\nprevious calls which are also in vs->vs_tpg.\n\nLater, when vhost_scsi_clear_endpoint runs it will do\ntarget_undepend_item on all the tpgs in the vs->vs_tpg which will drop\ntheir refcount to -1. Userspace will then not be able to remove the tpg\nand will hang when it tries to do rmdir on the tpg dir.\n\n3. Tpg leak:\n\nThis fixes a bug where we can leak tpgs and cause them to be\nun-removable because the target name is overwritten when\nvhost_scsi_set_endpoint is called multiple times but with different\ntarget names.\n\nThe bug occurs if a user has called VHOST_SCSI_SET_ENDPOINT and setup\na vhost-scsi device to target/tpg mapping, then calls\nVHOST_SCSI_SET_ENDPOINT again with a new target name that has tpgs we\nhaven't seen before (target1 has tpg1 but target2 has tpg2). When this\nhappens we don't teardown the old target tpg mapping and just overwrite\nthe target name and the vs->vs_tpg array. Later when we do\nvhost_scsi_clear_endpoint, we are passed in either target1 or target2's\nname and we will only match that target's tpgs when we loop over the\nvs->vs_tpg. We will then return from the function without doing\ntarget_undepend_item on the tpgs.\n\nBecause of all these bugs, it looks like being able to call\nvhost_scsi_set_endpoint multiple times was never supported. The major\nuser, QEMU, already has checks to prevent this use case. So to fix the\nissues, this patch prevents vhost_scsi_set_endpoint from being called\nif it's already successfully added tpgs. To add, remove or change the\ntpg config or target name, you must do a vhost_scsi_clear_endpoint\nfirst.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22083" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b34bdc42df047794542f3e220fe989124e4499a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a19eb3d9818e28f14c818a18dc913344a52ca92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3fd054baf382a426bbf5135ede0fc5673db74d3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dd639a1646ef5fe8f4bf270fad47c5c3755b9b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63b449f73ab0dcc0ba11ceaa4c5c70bc86ccf03c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vgw5-6pvc-ccx5/GHSA-vgw5-6pvc-ccx5.json b/advisories/unreviewed/2025/04/GHSA-vgw5-6pvc-ccx5/GHSA-vgw5-6pvc-ccx5.json index c8f2a513ea4..47024ece72b 100644 --- a/advisories/unreviewed/2025/04/GHSA-vgw5-6pvc-ccx5/GHSA-vgw5-6pvc-ccx5.json +++ b/advisories/unreviewed/2025/04/GHSA-vgw5-6pvc-ccx5/GHSA-vgw5-6pvc-ccx5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vgw5-6pvc-ccx5", - "modified": "2025-04-15T21:31:43Z", + "modified": "2025-04-16T15:34:16Z", "published": "2025-04-15T21:31:43Z", "aliases": [ "CVE-2025-28399" ], "details": "An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T19:16:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w6v4-56gc-2jmg/GHSA-w6v4-56gc-2jmg.json b/advisories/unreviewed/2025/04/GHSA-w6v4-56gc-2jmg/GHSA-w6v4-56gc-2jmg.json new file mode 100644 index 00000000000..9684ec5e0c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w6v4-56gc-2jmg/GHSA-w6v4-56gc-2jmg.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6v4-56gc-2jmg", + "modified": "2025-04-16T15:34:41Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22050" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet:fix NPE during rx_complete\n\nMissing usbnet_going_away Check in Critical Path.\nThe usb_submit_urb function lacks a usbnet_going_away\nvalidation, whereas __usbnet_queue_skb includes this check.\n\nThis inconsistency creates a race condition where:\nA URB request may succeed, but the corresponding SKB data\nfails to be queued.\n\nSubsequent processes:\n(e.g., rx_complete → defer_bh → __skb_unlink(skb, list))\nattempt to access skb->next, triggering a NULL pointer\ndereference (Kernel Panic).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22050" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c30988588b28393e3e8873d5654f910e86391ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f10f83acfd619e13c64d6705908dfd792f19544" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51de3600093429e3b712e5f091d767babc5dd6df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95789c2f94fd29dce8759f9766baa333f749287c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acacd48a37b52fc95f621765762c04152b58d642" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d689645cd1594ea1d13cb0c404f8ad1011353e0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd9ee3f0d6a53844f65efde581c91bbb0ff749ac" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wfg7-fvvf-v737/GHSA-wfg7-fvvf-v737.json b/advisories/unreviewed/2025/04/GHSA-wfg7-fvvf-v737/GHSA-wfg7-fvvf-v737.json new file mode 100644 index 00000000000..c94d3f632f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wfg7-fvvf-v737/GHSA-wfg7-fvvf-v737.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfg7-fvvf-v737", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39582" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Passionate Programmer Peter WP Data Access allows DOM-Based XSS. This issue affects WP Data Access: from n/a through 5.5.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-data-access/vulnerability/wordpress-wp-data-access-5-5-36-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wg8c-ghqw-wq88/GHSA-wg8c-ghqw-wq88.json b/advisories/unreviewed/2025/04/GHSA-wg8c-ghqw-wq88/GHSA-wg8c-ghqw-wq88.json new file mode 100644 index 00000000000..2767eb84614 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wg8c-ghqw-wq88/GHSA-wg8c-ghqw-wq88.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg8c-ghqw-wq88", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22098" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: zynqmp_dp: Fix a deadlock in zynqmp_dp_ignore_hpd_set()\n\nInstead of attempting the same mutex twice, lock and unlock it.\n\nThis bug has been detected by the Clang thread-safety analyzer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22098" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f988cd2f65175e79349961a43a9deb115174784" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a8d53aa5b7d2a89cda598239d08423bd66920f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f887685ee0eb4ef716391355568181230338f6eb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wgqx-9hcf-wpvq/GHSA-wgqx-9hcf-wpvq.json b/advisories/unreviewed/2025/04/GHSA-wgqx-9hcf-wpvq/GHSA-wgqx-9hcf-wpvq.json new file mode 100644 index 00000000000..dab6aded998 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wgqx-9hcf-wpvq/GHSA-wgqx-9hcf-wpvq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgqx-9hcf-wpvq", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2024-58096" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode\n\nath11k_hal_srng_* should be used with srng->lock to protect srng data.\n\nFor ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(),\nthey use ath11k_hal_srng_* for many times but never call srng->lock.\n\nSo when running (full) monitor mode, warning will occur:\nRIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]\nCall Trace:\n ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]\n ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k]\n ? idr_alloc_u32+0x97/0xd0\n ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k]\n ath11k_dp_service_srng+0x289/0x5a0 [ath11k]\n ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k]\n __napi_poll+0x30/0x1f0\n net_rx_action+0x198/0x320\n __do_softirq+0xdd/0x319\n\nSo add srng->lock for them to avoid such warnings.\n\nInorder to fetch the srng->lock, should change srng's definition from\n'void' to 'struct hal_srng'. And initialize them elsewhere to prevent\none line of code from being too long. This is consistent with other ring\nprocess functions, such as ath11k_dp_process_rx().\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58096" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63b7af49496d0e32f7a748b6af3361ec138b1bd3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b85758e76b6452740fc2a08ced6759af64c0d59a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-whxm-hh66-2gfx/GHSA-whxm-hh66-2gfx.json b/advisories/unreviewed/2025/04/GHSA-whxm-hh66-2gfx/GHSA-whxm-hh66-2gfx.json new file mode 100644 index 00000000000..d9e2eee4b95 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-whxm-hh66-2gfx/GHSA-whxm-hh66-2gfx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whxm-hh66-2gfx", + "modified": "2025-04-16T15:34:45Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22116" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: check error for register_netdev() on init\n\nCurrent init logic ignores the error code from register_netdev(),\nwhich will cause WARN_ON() on attempt to unregister it, if there was one,\nand there is no info for the user that the creation of the netdev failed.\n\nWARNING: CPU: 89 PID: 6902 at net/core/dev.c:11512 unregister_netdevice_many_notify+0x211/0x1a10\n...\n[ 3707.563641] unregister_netdev+0x1c/0x30\n[ 3707.563656] idpf_vport_dealloc+0x5cf/0xce0 [idpf]\n[ 3707.563684] idpf_deinit_task+0xef/0x160 [idpf]\n[ 3707.563712] idpf_vc_core_deinit+0x84/0x320 [idpf]\n[ 3707.563739] idpf_remove+0xbf/0x780 [idpf]\n[ 3707.563769] pci_device_remove+0xab/0x1e0\n[ 3707.563786] device_release_driver_internal+0x371/0x530\n[ 3707.563803] driver_detach+0xbf/0x180\n[ 3707.563816] bus_remove_driver+0x11b/0x2a0\n[ 3707.563829] pci_unregister_driver+0x2a/0x250\n\nIntroduce an error check and log the vport number and error code.\nOn removal make sure to check VPORT_REG_NETDEV flag prior to calling\nunregister and free on the netdev.\n\nAdd local variables for idx, vport_config and netdev for readability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22116" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/680811c67906191b237bbafe7dabbbad64649b39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/89768e33752211b2240ec4c34138170c95f11f97" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wjf2-jp32-r3w3/GHSA-wjf2-jp32-r3w3.json b/advisories/unreviewed/2025/04/GHSA-wjf2-jp32-r3w3/GHSA-wjf2-jp32-r3w3.json index d8424da542b..675cdab6499 100644 --- a/advisories/unreviewed/2025/04/GHSA-wjf2-jp32-r3w3/GHSA-wjf2-jp32-r3w3.json +++ b/advisories/unreviewed/2025/04/GHSA-wjf2-jp32-r3w3/GHSA-wjf2-jp32-r3w3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-wqf7-x4xg-j697/GHSA-wqf7-x4xg-j697.json b/advisories/unreviewed/2025/04/GHSA-wqf7-x4xg-j697/GHSA-wqf7-x4xg-j697.json new file mode 100644 index 00000000000..74fc6fcddf3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wqf7-x4xg-j697/GHSA-wqf7-x4xg-j697.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqf7-x4xg-j697", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22046" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes/x86: Harden uretprobe syscall trampoline check\n\nJann reported a possible issue when trampoline_check_ip returns\naddress near the bottom of the address space that is allowed to\ncall into the syscall if uretprobes are not set up:\n\n https://lore.kernel.org/bpf/202502081235.5A6F352985@keescook/T/#m9d416df341b8fbc11737dacbcd29f0054413cbbf\n\nThough the mmap minimum address restrictions will typically prevent\ncreating mappings there, let's make sure uretprobe syscall checks\nfor that.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22046" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0065d712049c87e1994c6eac00c6a637e39b325" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c35771342e47d58ab9433f3be1c3c30f2c5fa4f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4e48b8d59fe162938a5004ace698c847e6a3207" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa6192adc32f4fdfe5b74edd5b210e12afd6ecc0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wqh9-5q54-mhg8/GHSA-wqh9-5q54-mhg8.json b/advisories/unreviewed/2025/04/GHSA-wqh9-5q54-mhg8/GHSA-wqh9-5q54-mhg8.json new file mode 100644 index 00000000000..e52efc12f52 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wqh9-5q54-mhg8/GHSA-wqh9-5q54-mhg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqh9-5q54-mhg8", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:37Z", + "aliases": [ + "CVE-2025-39589" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Essential Addons for Elementor: from n/a through 6.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39589" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-addons-for-elementor-lite/vulnerability/wordpress-essential-addons-for-elementor-6-1-9-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wv2q-ghh7-v3v5/GHSA-wv2q-ghh7-v3v5.json b/advisories/unreviewed/2025/04/GHSA-wv2q-ghh7-v3v5/GHSA-wv2q-ghh7-v3v5.json new file mode 100644 index 00000000000..f9eb8b2a4cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wv2q-ghh7-v3v5/GHSA-wv2q-ghh7-v3v5.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv2q-ghh7-v3v5", + "modified": "2025-04-16T15:34:42Z", + "published": "2025-04-16T15:34:41Z", + "aliases": [ + "CVE-2025-22064" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: don't unregister hook when table is dormant\n\nWhen nf_tables_updchain encounters an error, hook registration needs to\nbe rolled back.\n\nThis should only be done if the hook has been registered, which won't\nhappen when the table is flagged as dormant (inactive).\n\nJust move the assignment into the registration block.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22064" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03d1fb457b696c18fe15661440c4f052b2374e7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6134d1ea1e1408e8e7c8c26545b3b301cbdf1eda" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/688c15017d5cd5aac882400782e7213d40dc3556" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce571eba07d54e3637bf334bc48376fbfa55defe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/feb1fa2a03a27fec7001e93e4223be4120d1784b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wv58-fx9p-fw8m/GHSA-wv58-fx9p-fw8m.json b/advisories/unreviewed/2025/04/GHSA-wv58-fx9p-fw8m/GHSA-wv58-fx9p-fw8m.json new file mode 100644 index 00000000000..e09e391a158 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wv58-fx9p-fw8m/GHSA-wv58-fx9p-fw8m.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv58-fx9p-fw8m", + "modified": "2025-04-16T15:34:33Z", + "published": "2025-04-16T15:34:33Z", + "aliases": [ + "CVE-2025-1982" + ], + "details": "Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be use to read content of system files.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1982" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/04/CVE-2025-1980" + }, + { + "type": "WEB", + "url": "https://ready-os.com/pl" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x48v-wjg9-grxf/GHSA-x48v-wjg9-grxf.json b/advisories/unreviewed/2025/04/GHSA-x48v-wjg9-grxf/GHSA-x48v-wjg9-grxf.json new file mode 100644 index 00000000000..fccd14441cf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x48v-wjg9-grxf/GHSA-x48v-wjg9-grxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x48v-wjg9-grxf", + "modified": "2025-04-16T15:34:37Z", + "published": "2025-04-16T15:34:36Z", + "aliases": [ + "CVE-2025-39575" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa allows Stored XSS. This issue affects WPCasa: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcasa/vulnerability/wordpress-wpcasa-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x5m7-q3w6-xq5p/GHSA-x5m7-q3w6-xq5p.json b/advisories/unreviewed/2025/04/GHSA-x5m7-q3w6-xq5p/GHSA-x5m7-q3w6-xq5p.json new file mode 100644 index 00000000000..ac53d248e0c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x5m7-q3w6-xq5p/GHSA-x5m7-q3w6-xq5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5m7-q3w6-xq5p", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39531" + ], + "details": "Missing Authorization vulnerability in slazzercom Slazzer Background Changer allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Slazzer Background Changer: from n/a through 3.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39531" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/slazzer-background-changer/vulnerability/wordpress-slazzer-background-changer-3-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x8hg-f9pc-8q66/GHSA-x8hg-f9pc-8q66.json b/advisories/unreviewed/2025/04/GHSA-x8hg-f9pc-8q66/GHSA-x8hg-f9pc-8q66.json new file mode 100644 index 00000000000..4717faaf356 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x8hg-f9pc-8q66/GHSA-x8hg-f9pc-8q66.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8hg-f9pc-8q66", + "modified": "2025-04-16T15:34:44Z", + "published": "2025-04-16T15:34:44Z", + "aliases": [ + "CVE-2025-22101" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: libwx: fix Tx L4 checksum\n\nThe hardware only supports L4 checksum offload for TCP/UDP/SCTP protocol.\nThere was a bug to set Tx checksum flag for the other protocol that results\nin Tx ring hang. Fix to compute software checksum for these packets.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22101" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f583e059eced1857f41e221ef5951e029e632bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7d82913d5f9e97860772ee4051eaa66b56a6273" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xcjf-5v2r-gvc9/GHSA-xcjf-5v2r-gvc9.json b/advisories/unreviewed/2025/04/GHSA-xcjf-5v2r-gvc9/GHSA-xcjf-5v2r-gvc9.json new file mode 100644 index 00000000000..3fb92656045 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xcjf-5v2r-gvc9/GHSA-xcjf-5v2r-gvc9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcjf-5v2r-gvc9", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2024-58093" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/ASPM: Fix link state exit during switch upstream function removal\n\nBefore 456d8aa37d0f (\"PCI/ASPM: Disable ASPM on MFD function removal to\navoid use-after-free\"), we would free the ASPM link only after the last\nfunction on the bus pertaining to the given link was removed.\n\nThat was too late. If function 0 is removed before sibling function,\nlink->downstream would point to free'd memory after.\n\nAfter above change, we freed the ASPM parent link state upon any function\nremoval on the bus pertaining to a given link.\n\nThat is too early. If the link is to a PCIe switch with MFD on the upstream\nport, then removing functions other than 0 first would free a link which\nstill remains parent_link to the remaining downstream ports.\n\nThe resulting GPFs are especially frequent during hot-unplug, because\npciehp removes devices on the link bus in reverse order.\n\nOn that switch, function 0 is the virtual P2P bridge to the internal bus.\nFree exactly when function 0 is removed -- before the parent link is\nobsolete, but after all subordinate links are gone.\n\n[kwilczynski: commit log]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58093" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbf937dcadfd571a434f8074d057b32cd14fbea5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xhq9-9h5f-jcjw/GHSA-xhq9-9h5f-jcjw.json b/advisories/unreviewed/2025/04/GHSA-xhq9-9h5f-jcjw/GHSA-xhq9-9h5f-jcjw.json new file mode 100644 index 00000000000..1c09787b734 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xhq9-9h5f-jcjw/GHSA-xhq9-9h5f-jcjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhq9-9h5f-jcjw", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39540" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP Flipclock allows DOM-Based XSS. This issue affects WP Flipclock: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-flipclock/vulnerability/wordpress-wp-flipclock-plugin-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xjrj-hm29-qrjc/GHSA-xjrj-hm29-qrjc.json b/advisories/unreviewed/2025/04/GHSA-xjrj-hm29-qrjc/GHSA-xjrj-hm29-qrjc.json new file mode 100644 index 00000000000..d838b5814a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjrj-hm29-qrjc/GHSA-xjrj-hm29-qrjc.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjrj-hm29-qrjc", + "modified": "2025-04-16T15:34:43Z", + "published": "2025-04-16T15:34:43Z", + "aliases": [ + "CVE-2025-22077" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix netns refcount imbalance causing leaks and use-after-free\n\nCommit ef7134c7fc48 (\"smb: client: Fix use-after-free of network\nnamespace.\") attempted to fix a netns use-after-free issue by manually\nadjusting reference counts via sk->sk_net_refcnt and sock_inuse_add().\n\nHowever, a later commit e9f2517a3e18 (\"smb: client: fix TCP timers deadlock\nafter rmmod\") pointed out that the approach of manually setting\nsk->sk_net_refcnt in the first commit was technically incorrect, as\nsk->sk_net_refcnt should only be set for user sockets. It led to issues\nlike TCP timers not being cleared properly on close. The second commit\nmoved to a model of just holding an extra netns reference for\nserver->ssocket using get_net(), and dropping it when the server is torn\ndown.\n\nBut there remain some gaps in the get_net()/put_net() balancing added by\nthese commits. The incomplete reference handling in these fixes results\nin two issues:\n\n1. Netns refcount leaks[1]\n\nThe problem process is as follows:\n\n```\nmount.cifs cifsd\n\ncifs_do_mount\n cifs_mount\n cifs_mount_get_session\n cifs_get_tcp_session\n get_net() /* First get net. */\n ip_connect\n generic_ip_connect /* Try port 445 */\n get_net()\n ->connect() /* Failed */\n put_net()\n generic_ip_connect /* Try port 139 */\n get_net() /* Missing matching put_net() for this get_net().*/\n cifs_get_smb_ses\n cifs_negotiate_protocol\n smb2_negotiate\n SMB2_negotiate\n cifs_send_recv\n wait_for_response\n cifs_demultiplex_thread\n cifs_read_from_socket\n cifs_readv_from_socket\n cifs_reconnect\n cifs_abort_connection\n sock_release();\n server->ssocket = NULL;\n /* Missing put_net() here. */\n generic_ip_connect\n get_net()\n ->connect() /* Failed */\n put_net()\n sock_release();\n server->ssocket = NULL;\n free_rsp_buf\n ...\n clean_demultiplex_info\n /* It's only called once here. */\n put_net()\n```\n\nWhen cifs_reconnect() is triggered, the server->ssocket is released\nwithout a corresponding put_net() for the reference acquired in\ngeneric_ip_connect() before. it ends up calling generic_ip_connect()\nagain to retry get_net(). After that, server->ssocket is set to NULL\nin the error path of generic_ip_connect(), and the net count cannot be\nreleased in the final clean_demultiplex_info() function.\n\n2. Potential use-after-free\n\nThe current refcounting scheme can lead to a potential use-after-free issue\nin the following scenario:\n\n```\n cifs_do_mount\n cifs_mount\n cifs_mount_get_session\n cifs_get_tcp_session\n get_net() /* First get net */\n ip_connect\n generic_ip_connect\n get_net()\n bind_socket\n\t kernel_bind /* failed */\n put_net()\n /* after out_err_crypto_release label */\n put_net()\n /* after out_err label */\n put_net()\n```\n\nIn the exception handling process where binding the socket fails, the\nget_net() and put_net() calls are unbalanced, which may cause the\nserver->net reference count to drop to zero and be prematurely released.\n\nTo address both issues, this patch ties the netns reference counti\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22077" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/476617a4ca0123f0df677d547a82a110c27c8c74" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e7f1644f2ac6d01dc584f6301c3b1d5aac4eaef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d8dfc27d90d41627c0d6ada97ed0ab57b3dae25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/961755d0055e0e96d1849cc0425da966c8a64e53" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6b6b8dcef4adf8ee4e439bb97e74106096c71b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xm3p-r4jv-jxcf/GHSA-xm3p-r4jv-jxcf.json b/advisories/unreviewed/2025/04/GHSA-xm3p-r4jv-jxcf/GHSA-xm3p-r4jv-jxcf.json new file mode 100644 index 00000000000..62da00bdc59 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xm3p-r4jv-jxcf/GHSA-xm3p-r4jv-jxcf.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm3p-r4jv-jxcf", + "modified": "2025-04-16T15:34:40Z", + "published": "2025-04-16T15:34:40Z", + "aliases": [ + "CVE-2025-22039" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix overflow in dacloffset bounds check\n\nThe dacloffset field was originally typed as int and used in an\nunchecked addition, which could overflow and bypass the existing\nbounds check in both smb_check_perm_dacl() and smb_inherit_dacl().\n\nThis could result in out-of-bounds memory access and a kernel crash\nwhen dereferencing the DACL pointer.\n\nThis patch converts dacloffset to unsigned int and uses\ncheck_add_overflow() to validate access to the DACL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22039" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/443b373a4df5a2cb9f7b8c4658b2afedeb16397f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b8d379048b168a0dff5ab1acb975b933f368514" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmgf-j324-j5xq/GHSA-xmgf-j324-j5xq.json b/advisories/unreviewed/2025/04/GHSA-xmgf-j324-j5xq/GHSA-xmgf-j324-j5xq.json new file mode 100644 index 00000000000..39858f9de7b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xmgf-j324-j5xq/GHSA-xmgf-j324-j5xq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmgf-j324-j5xq", + "modified": "2025-04-16T15:34:46Z", + "published": "2025-04-16T15:34:45Z", + "aliases": [ + "CVE-2025-22121" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()\n\nThere's issue as follows:\nBUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790\nRead of size 4 at addr ffff88807b003000 by task syz-executor.0/15172\n\nCPU: 3 PID: 15172 Comm: syz-executor.0\nCall Trace:\n __dump_stack lib/dump_stack.c:82 [inline]\n dump_stack+0xbe/0xfd lib/dump_stack.c:123\n print_address_description.constprop.0+0x1e/0x280 mm/kasan/report.c:400\n __kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560\n kasan_report+0x3a/0x50 mm/kasan/report.c:585\n ext4_xattr_inode_dec_ref_all+0x6ff/0x790 fs/ext4/xattr.c:1137\n ext4_xattr_delete_inode+0x4c7/0xda0 fs/ext4/xattr.c:2896\n ext4_evict_inode+0xb3b/0x1670 fs/ext4/inode.c:323\n evict+0x39f/0x880 fs/inode.c:622\n iput_final fs/inode.c:1746 [inline]\n iput fs/inode.c:1772 [inline]\n iput+0x525/0x6c0 fs/inode.c:1758\n ext4_orphan_cleanup fs/ext4/super.c:3298 [inline]\n ext4_fill_super+0x8c57/0xba40 fs/ext4/super.c:5300\n mount_bdev+0x355/0x410 fs/super.c:1446\n legacy_get_tree+0xfe/0x220 fs/fs_context.c:611\n vfs_get_tree+0x8d/0x2f0 fs/super.c:1576\n do_new_mount fs/namespace.c:2983 [inline]\n path_mount+0x119a/0x1ad0 fs/namespace.c:3316\n do_mount+0xfc/0x110 fs/namespace.c:3329\n __do_sys_mount fs/namespace.c:3540 [inline]\n __se_sys_mount+0x219/0x2e0 fs/namespace.c:3514\n do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nMemory state around the buggy address:\n ffff88807b002f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ffff88807b002f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n>ffff88807b003000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ^\n ffff88807b003080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ffff88807b003100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n\nAbove issue happens as ext4_xattr_delete_inode() isn't check xattr\nis valid if xattr is in inode.\nTo solve above issue call xattr_check_inode() check if xattr if valid\nin inode. In fact, we can directly verify in ext4_iget_extra_inode(),\nso that there is no divergent verification.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22121" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c8fbb6ffb3c8f5164572ca88e4ccb6cd6a41ca8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5701875f9609b000d91351eaa6bfd97fe2f157f4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xph3-px55-p2mg/GHSA-xph3-px55-p2mg.json b/advisories/unreviewed/2025/04/GHSA-xph3-px55-p2mg/GHSA-xph3-px55-p2mg.json new file mode 100644 index 00000000000..4f446cba9e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xph3-px55-p2mg/GHSA-xph3-px55-p2mg.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xph3-px55-p2mg", + "modified": "2025-04-16T15:34:38Z", + "published": "2025-04-16T15:34:38Z", + "aliases": [ + "CVE-2023-53034" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans\n\nThere is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and\nsize. This would make xlate_pos negative.\n\n[ 23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000\n[ 23.734158] ================================================================================\n[ 23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7\n[ 23.734418] shift exponent -1 is negative\n\nEnsuring xlate_pos is a positive or zero before BIT.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53034" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2429bdf26a0f3950fdd996861e9c1a3873af1dbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36d32cfb00d42e865396424bb5d340fc0a28870d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b6857bb3bfb0dae17fab1e42c1e82c204a508b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ed22f8d8be26225a78cf5e85b2036421a6bf2d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c61a3f2df162ba424be0141649a9ef5f28eaccc1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb153bdc1812a3375639ed6ca5f147eaefb65349" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de203da734fae00e75be50220ba5391e7beecdf9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f56951f211f181410a383d305e8d370993e45294" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xpqh-2w77-cvcv/GHSA-xpqh-2w77-cvcv.json b/advisories/unreviewed/2025/04/GHSA-xpqh-2w77-cvcv/GHSA-xpqh-2w77-cvcv.json new file mode 100644 index 00000000000..2cd86caa0a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xpqh-2w77-cvcv/GHSA-xpqh-2w77-cvcv.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpqh-2w77-cvcv", + "modified": "2025-04-16T15:34:42Z", + "published": "2025-04-16T15:34:42Z", + "aliases": [ + "CVE-2025-22066" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: imx-card: Add NULL check in imx_card_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\nimx_card_probe() does not check for this case, which results in a NULL\npointer dereference.\n\nAdd NULL check after devm_kasprintf() to prevent this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22066" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/018e6cf2503e60087747b0ebc190e18b3640766f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38253922a89a742e7e622f626b41c64388367361" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d8458e48ff135bddc402ad79821dc058ea163d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93d34608fd162f725172e780b1c60cc93a920719" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b01700e08be99e3842570142ec5973ccd7e73eaf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd2bbb9564d0d24a2643ad90008a79840368c4b4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e283a5bf4337a7300ac5e6ae363cc8b242a0b4b7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xrr8-p4pf-hfwr/GHSA-xrr8-p4pf-hfwr.json b/advisories/unreviewed/2025/04/GHSA-xrr8-p4pf-hfwr/GHSA-xrr8-p4pf-hfwr.json new file mode 100644 index 00000000000..c86b6f15099 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xrr8-p4pf-hfwr/GHSA-xrr8-p4pf-hfwr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrr8-p4pf-hfwr", + "modified": "2025-04-16T15:34:39Z", + "published": "2025-04-16T15:34:39Z", + "aliases": [ + "CVE-2025-22026" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: don't ignore the return code of svc_proc_register()\n\nCurrently, nfsd_proc_stat_init() ignores the return value of\nsvc_proc_register(). If the procfile creation fails, then the kernel\nwill WARN when it tries to remove the entry later.\n\nFix nfsd_proc_stat_init() to return the same type of pointer as\nsvc_proc_register(), and fix up nfsd_net_init() to check that and fail\nthe nfsd_net construction if it occurs.\n\nsvc_proc_register() can fail if the dentry can't be allocated, or if an\nidentical dentry already exists. The second case is pretty unlikely in\nthe nfsd_net construction codepath, so if this happens, return -ENOMEM.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22026" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/930b64ca0c511521f0abdd1d57ce52b2a6e3476b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d9456185fd5f1891c74354ee297f19538141ead" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xvgw-45wp-xpq2/GHSA-xvgw-45wp-xpq2.json b/advisories/unreviewed/2025/04/GHSA-xvgw-45wp-xpq2/GHSA-xvgw-45wp-xpq2.json new file mode 100644 index 00000000000..257a22cb049 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xvgw-45wp-xpq2/GHSA-xvgw-45wp-xpq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvgw-45wp-xpq2", + "modified": "2025-04-16T15:34:35Z", + "published": "2025-04-16T15:34:35Z", + "aliases": [ + "CVE-2025-39530" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 allows Stored XSS. This issue affects Site Search 360: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39530" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-search-360/vulnerability/wordpress-site-search-360-plugin-2-1-7-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xw4f-22g6-wrgg/GHSA-xw4f-22g6-wrgg.json b/advisories/unreviewed/2025/04/GHSA-xw4f-22g6-wrgg/GHSA-xw4f-22g6-wrgg.json index aaee57db0fd..d09297d0cda 100644 --- a/advisories/unreviewed/2025/04/GHSA-xw4f-22g6-wrgg/GHSA-xw4f-22g6-wrgg.json +++ b/advisories/unreviewed/2025/04/GHSA-xw4f-22g6-wrgg/GHSA-xw4f-22g6-wrgg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null,