From d8de46d7228da185893b07db07c07a7d17a02333 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 23 Jul 2024 18:32:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3g6v-jwwm-8gj3.json | 2 +- .../GHSA-3j8q-j2j7-x49c.json | 2 +- .../GHSA-592c-fmq9-g63c.json | 14 ++++-- .../GHSA-5q48-pjg9-33x2.json | 2 +- .../GHSA-8xpj-rxm7-wgf9.json | 4 +- .../GHSA-9qw6-wc53-f6x9.json | 4 +- .../GHSA-v5xq-m8f8-3cc2.json | 2 +- .../GHSA-xw37-xfrp-pmwc.json | 2 +- .../GHSA-3vcc-f634-j924.json | 11 +++-- .../GHSA-5cwv-6xqx-92m5.json | 6 ++- .../GHSA-634r-qhgm-h5w5.json | 6 ++- .../GHSA-6mjp-g2rf-hh5w.json | 38 +++++++++++++++ .../GHSA-6px8-752j-c2vv.json | 35 ++++++++++++++ .../GHSA-7vfx-qp7p-vwcw.json | 9 ++-- .../GHSA-9xxq-vvgh-v3r9.json | 6 ++- .../GHSA-c2hf-vcmr-qjrf.json | 35 ++++++++++++++ .../GHSA-c2jh-qjfq-m6h4.json | 38 +++++++++++++++ .../GHSA-f2xw-g7hm-66qr.json | 11 +++-- .../GHSA-gfw8-mh94-9w58.json | 6 ++- .../GHSA-j6w5-3xwm-qv7j.json | 6 ++- .../GHSA-p622-mwq3-26f2.json | 9 ++-- .../GHSA-p742-rf2c-hvf6.json | 6 ++- .../GHSA-v3r3-642v-rqj8.json | 6 ++- .../GHSA-vq4q-wfv6-qgq8.json | 6 ++- .../GHSA-w7jq-wm3w-xhpq.json | 9 ++-- .../GHSA-x66j-2fj9-7c64.json | 46 +++++++++++++++++++ .../GHSA-xv2w-3fww-7hvf.json | 6 ++- 27 files changed, 289 insertions(+), 38 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json create mode 100644 advisories/unreviewed/2024/07/GHSA-6px8-752j-c2vv/GHSA-6px8-752j-c2vv.json create mode 100644 advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json diff --git a/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json b/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json index 49a24d8f81c..c0d63e5ee65 100644 --- a/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json +++ b/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g6v-jwwm-8gj3", - "modified": "2024-06-11T12:31:01Z", + "modified": "2024-07-23T18:31:06Z", "published": "2024-06-11T12:31:01Z", "aliases": [ "CVE-2024-35716" diff --git a/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json b/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json index 4e800f79c85..02b3f9d5cae 100644 --- a/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json +++ b/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json b/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json index 8e6d15406b4..3838972a8dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json +++ b/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-592c-fmq9-g63c", - "modified": "2024-06-21T15:31:05Z", + "modified": "2024-07-23T18:31:06Z", "published": "2024-06-05T21:31:29Z", "aliases": [ "CVE-2024-5171" ], "details": "Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers:\n\n\n * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.\n * Calling aom_img_wrap() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.\n * Calling aom_img_alloc_with_border() with a large value of the d_w, d_h, align, size_align, or border parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -33,9 +40,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-05T20:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json b/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json index d403a0f200f..64af9f68f7b 100644 --- a/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json +++ b/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json b/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json index e0f44ecdaec..89c493ff5e0 100644 --- a/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json +++ b/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xpj-rxm7-wgf9", - "modified": "2024-06-12T12:30:41Z", + "modified": "2024-07-23T18:31:06Z", "published": "2024-06-12T12:30:41Z", "aliases": [ "CVE-2024-4845" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json b/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json index 335c05df2c1..301018232af 100644 --- a/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json +++ b/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qw6-wc53-f6x9", - "modified": "2024-06-12T12:30:41Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-06-12T12:30:41Z", "aliases": [ "CVE-2024-4898" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json b/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json index 5891ed8adbc..2476dbe7e82 100644 --- a/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json +++ b/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json b/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json index fa2620c538a..033a4f6c819 100644 --- a/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json +++ b/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xw37-xfrp-pmwc", - "modified": "2024-06-11T12:31:01Z", + "modified": "2024-07-23T18:31:06Z", "published": "2024-06-11T12:31:01Z", "aliases": [ "CVE-2024-34824" diff --git a/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json b/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json index 5677bd711ee..128d4962161 100644 --- a/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json +++ b/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vcc-f634-j924", - "modified": "2024-07-16T15:30:49Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-16T15:30:49Z", "aliases": [ "CVE-2022-48850" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet-sysfs: add check for netdevice being present to speed_show\n\nWhen bringing down the netdevice or system shutdown, a panic can be\ntriggered while accessing the sysfs path because the device is already\nremoved.\n\n [ 755.549084] mlx5_core 0000:12:00.1: Shutdown was called\n [ 756.404455] mlx5_core 0000:12:00.0: Shutdown was called\n ...\n [ 757.937260] BUG: unable to handle kernel NULL pointer dereference at (null)\n [ 758.031397] IP: [] dma_pool_alloc+0x1ab/0x280\n\n crash> bt\n ...\n PID: 12649 TASK: ffff8924108f2100 CPU: 1 COMMAND: \"amsd\"\n ...\n #9 [ffff89240e1a38b0] page_fault at ffffffff8f38c778\n [exception RIP: dma_pool_alloc+0x1ab]\n RIP: ffffffff8ee11acb RSP: ffff89240e1a3968 RFLAGS: 00010046\n RAX: 0000000000000246 RBX: ffff89243d874100 RCX: 0000000000001000\n RDX: 0000000000000000 RSI: 0000000000000246 RDI: ffff89243d874090\n RBP: ffff89240e1a39c0 R8: 000000000001f080 R9: ffff8905ffc03c00\n R10: ffffffffc04680d4 R11: ffffffff8edde9fd R12: 00000000000080d0\n R13: ffff89243d874090 R14: ffff89243d874080 R15: 0000000000000000\n ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018\n #10 [ffff89240e1a39c8] mlx5_alloc_cmd_msg at ffffffffc04680f3 [mlx5_core]\n #11 [ffff89240e1a3a18] cmd_exec at ffffffffc046ad62 [mlx5_core]\n #12 [ffff89240e1a3ab8] mlx5_cmd_exec at ffffffffc046b4fb [mlx5_core]\n #13 [ffff89240e1a3ae8] mlx5_core_access_reg at ffffffffc0475434 [mlx5_core]\n #14 [ffff89240e1a3b40] mlx5e_get_fec_caps at ffffffffc04a7348 [mlx5_core]\n #15 [ffff89240e1a3bb0] get_fec_supported_advertised at ffffffffc04992bf [mlx5_core]\n #16 [ffff89240e1a3c08] mlx5e_get_link_ksettings at ffffffffc049ab36 [mlx5_core]\n #17 [ffff89240e1a3ce8] __ethtool_get_link_ksettings at ffffffff8f25db46\n #18 [ffff89240e1a3d48] speed_show at ffffffff8f277208\n #19 [ffff89240e1a3dd8] dev_attr_show at ffffffff8f0b70e3\n #20 [ffff89240e1a3df8] sysfs_kf_seq_show at ffffffff8eedbedf\n #21 [ffff89240e1a3e18] kernfs_seq_show at ffffffff8eeda596\n #22 [ffff89240e1a3e28] seq_read at ffffffff8ee76d10\n #23 [ffff89240e1a3e98] kernfs_fop_read at ffffffff8eedaef5\n #24 [ffff89240e1a3ed8] vfs_read at ffffffff8ee4e3ff\n #25 [ffff89240e1a3f08] sys_read at ffffffff8ee4f27f\n #26 [ffff89240e1a3f50] system_call_fastpath at ffffffff8f395f92\n\n crash> net_device.state ffff89443b0c0000\n state = 0x5 (__LINK_STATE_START| __LINK_STATE_NOCARRIER)\n\nTo prevent this scenario, we also make sure that the netdevice is present.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T13:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5cwv-6xqx-92m5/GHSA-5cwv-6xqx-92m5.json b/advisories/unreviewed/2024/07/GHSA-5cwv-6xqx-92m5/GHSA-5cwv-6xqx-92m5.json index b8f3ab59a95..b366aeb7288 100644 --- a/advisories/unreviewed/2024/07/GHSA-5cwv-6xqx-92m5/GHSA-5cwv-6xqx-92m5.json +++ b/advisories/unreviewed/2024/07/GHSA-5cwv-6xqx-92m5/GHSA-5cwv-6xqx-92m5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cwv-6xqx-92m5", - "modified": "2024-07-23T15:31:08Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-4467" @@ -64,6 +64,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2278875" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json b/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json index 303a05593d9..beebeaff679 100644 --- a/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json +++ b/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-634r-qhgm-h5w5", - "modified": "2024-07-22T15:32:40Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-22T15:32:40Z", "aliases": [ "CVE-2024-41315" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41315" }, + { + "type": "WEB", + "url": "https://gist.github.com/yanggao017/add8d85589614d09e3e8ccb1fb335f64" + }, { "type": "WEB", "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_4_apcli_do_enr_pin_wps/README.md" diff --git a/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json b/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json new file mode 100644 index 00000000000..9ed4046700c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mjp-g2rf-hh5w", + "modified": "2024-07-23T18:31:07Z", + "published": "2024-07-23T18:31:07Z", + "aliases": [ + "CVE-2020-11640" + ], + "details": "AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the\ncommand queue can use it to launch an attack by running any executable on the AdvaBuild node. The\nexecutables that can be run are not limited to AdvaBuild specific executables. \n\nImproper Privilege Management vulnerability in ABB Advant MOD 300 AdvaBuild.This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11640" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=3BUA003421&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.200044199.882581162.1721753430-284724496.1718609177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6px8-752j-c2vv/GHSA-6px8-752j-c2vv.json b/advisories/unreviewed/2024/07/GHSA-6px8-752j-c2vv/GHSA-6px8-752j-c2vv.json new file mode 100644 index 00000000000..f066f4c7e3b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6px8-752j-c2vv/GHSA-6px8-752j-c2vv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6px8-752j-c2vv", + "modified": "2024-07-23T18:31:07Z", + "published": "2024-07-23T18:31:07Z", + "aliases": [ + "CVE-2024-39702" + ], + "details": "In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of service with relatively few incoming requests. This vulnerability only exists in the OpenResty fork in the openresty/luajit2 GitHub repository. The LuaJIT/LuaJIT epository. is unaffected/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39702" + }, + { + "type": "WEB", + "url": "https://openresty.org/en/ann-1025003002.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json b/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json index 6ec08c227a3..1be9bbc16f1 100644 --- a/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json +++ b/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vfx-qp7p-vwcw", - "modified": "2024-07-16T15:30:49Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-16T15:30:49Z", "aliases": [ "CVE-2022-48849" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: bypass tiling flag check in virtual display case (v2)\n\nvkms leverages common amdgpu framebuffer creation, and\nalso as it does not support FB modifier, there is no need\nto check tiling flags when initing framebuffer when virtual\ndisplay is enabled.\n\nThis can fix below calltrace:\n\namdgpu 0000:00:08.0: GFX9+ requires FB check based on format modifier\nWARNING: CPU: 0 PID: 1023 at drivers/gpu/drm/amd/amdgpu/amdgpu_display.c:1150 amdgpu_display_framebuffer_init+0x8e7/0xb40 [amdgpu]\n\nv2: check adev->enable_virtual_display instead as vkms can be\n\tenabled in bare metal as well.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T13:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json b/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json index d94d91e0e86..b7ef24b1921 100644 --- a/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json +++ b/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xxq-vvgh-v3r9", - "modified": "2024-07-23T15:31:09Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-1737" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/rrset-limits-in-zones" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json b/advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json new file mode 100644 index 00000000000..6b305b0fb94 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2hf-vcmr-qjrf", + "modified": "2024-07-23T18:31:07Z", + "published": "2024-07-23T18:31:07Z", + "aliases": [ + "CVE-2024-41178" + ], + "details": "Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. \n\nOn certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithWebIdentity.html . This allows someone with access to the logs to impersonate that identity, including performing their own calls to AssumeRoleWithWebIdentity, until the OIDC token expires. Typically OIDC tokens are valid for up to an hour, although this will vary depending on the issuer.\n\nUsers are recommended to use a different AWS authentication mechanism, disable logging or upgrade to version 0.10.2, which fixes this issue.\n\nDetails:\n\nWhen using AWS WebIdentityTokens with the object_store crate, in the event of a failure and automatic retry, the underlying reqwest error, including the full URL with the credentials, potentially in the parameters, is written to the logs. \n\nThanks to Paul Hatcherian for reporting this vulnerability", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41178" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/3t0povdppnt2czv6crlsqhvyko93kcrg" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json b/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json new file mode 100644 index 00000000000..7b13853abdd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2jh-qjfq-m6h4", + "modified": "2024-07-23T18:31:07Z", + "published": "2024-07-23T18:31:07Z", + "aliases": [ + "CVE-2020-11639" + ], + "details": "An attacker could exploit the vulnerability by\ninjecting garbage data or specially crafted data. Depending on the data injected each process might be\naffected differently. The process could crash or cause communication issues on the affected node, effectively causing a denial-of-service attack. The attacker could tamper with the data transmitted, causing\nthe product to store wrong information or act on wrong data or display wrong information.\n\n\nThis issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.\n\n\n\n\nFor an attack to be successful, the attacker must have local access to a node in the system and be able to\nstart a specially crafted application that disrupts the communication.\nAn attacker who successfully exploited the vulnerability would be able to manipulate the data in such\nway as allowing reads and writes to the controllers or cause Windows processes in 800xA for MOD 300\nand AdvaBuild to crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11639" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=3BUA003421&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.200044199.882581162.1721753430-284724496.1718609177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-924" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json b/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json index 982bd6e8755..9c211b13a91 100644 --- a/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json +++ b/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2xw-g7hm-66qr", - "modified": "2024-07-16T15:30:49Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-16T15:30:49Z", "aliases": [ "CVE-2022-48851" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gdm724x: fix use after free in gdm_lte_rx()\n\nThe netif_rx_ni() function frees the skb so we can't dereference it to\nsave the skb->len.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T13:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json b/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json index 5b97df83cf9..6a56eb8192d 100644 --- a/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json +++ b/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfw8-mh94-9w58", - "modified": "2024-07-23T15:31:09Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-4076" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2024-4076" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json b/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json index 482d6a4771b..b6c8fc3159d 100644 --- a/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json +++ b/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6w5-3xwm-qv7j", - "modified": "2024-07-22T15:32:40Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-22T15:32:40Z", "aliases": [ "CVE-2024-41314" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41314" }, + { + "type": "WEB", + "url": "https://gist.github.com/yanggao017/8593748d4e2de1582344b4035b2456c6" + }, { "type": "WEB", "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_1_vif_disable/README.md" diff --git a/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json b/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json index 3a0b30f48b1..2a385f34233 100644 --- a/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json +++ b/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p622-mwq3-26f2", - "modified": "2024-07-16T15:30:50Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-16T15:30:49Z", "aliases": [ "CVE-2022-48853" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nswiotlb: fix info leak with DMA_FROM_DEVICE\n\nThe problem I'm addressing was discovered by the LTP test covering\ncve-2018-1000204.\n\nA short description of what happens follows:\n1) The test case issues a command code 00 (TEST UNIT READY) via the SG_IO\n interface with: dxfer_len == 524288, dxdfer_dir == SG_DXFER_FROM_DEV\n and a corresponding dxferp. The peculiar thing about this is that TUR\n is not reading from the device.\n2) In sg_start_req() the invocation of blk_rq_map_user() effectively\n bounces the user-space buffer. As if the device was to transfer into\n it. Since commit a45b599ad808 (\"scsi: sg: allocate with __GFP_ZERO in\n sg_build_indirect()\") we make sure this first bounce buffer is\n allocated with GFP_ZERO.\n3) For the rest of the story we keep ignoring that we have a TUR, so the\n device won't touch the buffer we prepare as if the we had a\n DMA_FROM_DEVICE type of situation. My setup uses a virtio-scsi device\n and the buffer allocated by SG is mapped by the function\n virtqueue_add_split() which uses DMA_FROM_DEVICE for the \"in\" sgs (here\n scatter-gather and not scsi generics). This mapping involves bouncing\n via the swiotlb (we need swiotlb to do virtio in protected guest like\n s390 Secure Execution, or AMD SEV).\n4) When the SCSI TUR is done, we first copy back the content of the second\n (that is swiotlb) bounce buffer (which most likely contains some\n previous IO data), to the first bounce buffer, which contains all\n zeros. Then we copy back the content of the first bounce buffer to\n the user-space buffer.\n5) The test case detects that the buffer, which it zero-initialized,\n ain't all zeros and fails.\n\nOne can argue that this is an swiotlb problem, because without swiotlb\nwe leak all zeros, and the swiotlb should be transparent in a sense that\nit does not affect the outcome (if all other participants are well\nbehaved).\n\nCopying the content of the original buffer into the swiotlb buffer is\nthe only way I can think of to make swiotlb transparent in such\nscenarios. So let's do just that if in doubt, but allow the driver\nto tell us that the whole mapped buffer is going to be overwritten,\nin which case we can preserve the old behavior and avoid the performance\nimpact of the extra bounce.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T13:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json b/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json index b3c5d5bd5f4..a713b9c65f0 100644 --- a/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json +++ b/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p742-rf2c-hvf6", - "modified": "2024-07-22T15:32:40Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-22T15:32:40Z", "aliases": [ "CVE-2024-41316" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41316" }, + { + "type": "WEB", + "url": "https://gist.github.com/yanggao017/690f3e4b5045bbdf1209baa30fb53065" + }, { "type": "WEB", "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_2_apcli_cancel_wps/README.md" diff --git a/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json b/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json index f9b6c14bfbe..beb8550c66e 100644 --- a/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json +++ b/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3r3-642v-rqj8", - "modified": "2024-07-23T15:31:09Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-0760" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2024-0760" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json b/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json index ba2c40cd650..1227a3260bf 100644 --- a/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json +++ b/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vq4q-wfv6-qgq8", - "modified": "2024-07-22T15:32:40Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-22T15:32:40Z", "aliases": [ "CVE-2024-41317" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41317" }, + { + "type": "WEB", + "url": "https://gist.github.com/yanggao017/8b7a567996f1986ac9fb3ab427c59227" + }, { "type": "WEB", "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_3_apcli_do_enr_pbc_wps/README.md" diff --git a/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json b/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json index 63f51e7ef87..3d97d851a49 100644 --- a/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json +++ b/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7jq-wm3w-xhpq", - "modified": "2024-07-16T15:30:49Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-16T15:30:49Z", "aliases": [ "CVE-2022-48852" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: hdmi: Unregister codec device on unbind\n\nOn bind we will register the HDMI codec device but we don't unregister\nit on unbind, leading to a device leakage. Unregister our device at\nunbind.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T13:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json b/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json new file mode 100644 index 00000000000..bdded9a4c03 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x66j-2fj9-7c64", + "modified": "2024-07-23T18:31:07Z", + "published": "2024-07-23T18:31:07Z", + "aliases": [ + "CVE-2024-6714" + ], + "details": "An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6714" + }, + { + "type": "WEB", + "url": "https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-6714" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json b/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json index 3f68dfa0a56..db82dc5a079 100644 --- a/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json +++ b/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv2w-3fww-7hvf", - "modified": "2024-07-23T15:31:09Z", + "modified": "2024-07-23T18:31:07Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-1975" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2024-1975" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" } ], "database_specific": {