From df20203274df4ea038645f1f0743646c6fa9deec Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 28 Feb 2025 00:32:45 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-79mw-p7qm-h4wp.json | 2 +- .../GHSA-7vf7-cqc9-qxj2.json | 4 +- .../GHSA-w6r8-2m56-2cwg.json | 4 +- .../GHSA-79xc-34g5-49p2.json | 15 +++++-- .../GHSA-gvgx-pcvr-3pc4.json | 15 +++++-- .../GHSA-mccq-9gc6-hm85.json | 15 +++++-- .../GHSA-qv7c-pjpr-grqx.json | 15 +++++-- .../GHSA-wm8x-c4gv-vvw5.json | 15 +++++-- .../GHSA-xf3h-rpgf-fmvp.json | 15 +++++-- .../GHSA-24v3-p69g-7cx6.json | 15 +++++-- .../GHSA-2gpq-mc93-wwwp.json | 15 +++++-- .../GHSA-5m3g-gpvq-34jp.json | 15 +++++-- .../GHSA-6w8c-3g24-p9jh.json | 15 +++++-- .../GHSA-7qcm-45jm-fj5g.json | 15 +++++-- .../GHSA-94vx-hxvv-26m7.json | 15 +++++-- .../GHSA-v3qj-q3px-pcxw.json | 15 +++++-- .../GHSA-vrx4-x92w-9vhv.json | 15 +++++-- .../GHSA-wgq7-x72m-hm6h.json | 15 +++++-- .../GHSA-3qf8-ww35-9vjg.json | 29 ++++++++++++ .../GHSA-53j9-5hmj-8v9f.json | 29 ++++++++++++ .../GHSA-5xc2-vwvc-458q.json | 44 +++++++++++++++++++ .../GHSA-8vc4-8cgc-2m74.json | 29 ++++++++++++ .../GHSA-9c2w-rfmh-q65f.json | 29 ++++++++++++ .../GHSA-cx33-wwv9-rm3j.json | 44 +++++++++++++++++++ .../GHSA-g4v7-6h28-6phm.json | 29 ++++++++++++ .../GHSA-h33c-355w-g26q.json | 29 ++++++++++++ .../GHSA-jf75-x4f2-r8c9.json | 29 ++++++++++++ .../GHSA-jv4p-6m84-hhpv.json | 29 ++++++++++++ .../GHSA-m73p-w5w2-3m5h.json | 29 ++++++++++++ .../GHSA-p2c8-vcc7-q39q.json | 29 ++++++++++++ .../GHSA-p8qq-75v8-px25.json | 44 +++++++++++++++++++ .../GHSA-q43v-p4wq-wmhv.json | 29 ++++++++++++ .../GHSA-qc2q-hwc8-26rv.json | 36 +++++++++++++++ .../GHSA-qw4v-473w-8hq5.json | 29 ++++++++++++ .../GHSA-rwpx-f8qj-4h9h.json | 29 ++++++++++++ .../GHSA-v2m3-cppr-8m5q.json | 29 ++++++++++++ .../GHSA-x49p-h589-rcc4.json | 40 +++++++++++++++++ .../GHSA-xfxq-4gvm-mf69.json | 29 ++++++++++++ 38 files changed, 815 insertions(+), 63 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5xc2-vwvc-458q/GHSA-5xc2-vwvc-458q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cx33-wwv9-rm3j/GHSA-cx33-wwv9-rm3j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p8qq-75v8-px25/GHSA-p8qq-75v8-px25.json create mode 100644 advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qc2q-hwc8-26rv/GHSA-qc2q-hwc8-26rv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x49p-h589-rcc4/GHSA-x49p-h589-rcc4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json diff --git a/advisories/unreviewed/2023/03/GHSA-79mw-p7qm-h4wp/GHSA-79mw-p7qm-h4wp.json b/advisories/unreviewed/2023/03/GHSA-79mw-p7qm-h4wp/GHSA-79mw-p7qm-h4wp.json index ef3c69c91ca..e29e65f0e57 100644 --- a/advisories/unreviewed/2023/03/GHSA-79mw-p7qm-h4wp/GHSA-79mw-p7qm-h4wp.json +++ b/advisories/unreviewed/2023/03/GHSA-79mw-p7qm-h4wp/GHSA-79mw-p7qm-h4wp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79mw-p7qm-h4wp", - "modified": "2023-03-20T15:30:20Z", + "modified": "2025-02-28T00:30:50Z", "published": "2023-03-13T06:30:25Z", "aliases": [ "CVE-2022-2258" diff --git a/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json b/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json index a28835bf3c3..d645b1b2b84 100644 --- a/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json +++ b/advisories/unreviewed/2024/02/GHSA-7vf7-cqc9-qxj2/GHSA-7vf7-cqc9-qxj2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json b/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json index 18a7f8ae282..82770d390ec 100644 --- a/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json +++ b/advisories/unreviewed/2024/02/GHSA-w6r8-2m56-2cwg/GHSA-w6r8-2m56-2cwg.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-79xc-34g5-49p2/GHSA-79xc-34g5-49p2.json b/advisories/unreviewed/2024/04/GHSA-79xc-34g5-49p2/GHSA-79xc-34g5-49p2.json index 841372b827e..56d26677b11 100644 --- a/advisories/unreviewed/2024/04/GHSA-79xc-34g5-49p2/GHSA-79xc-34g5-49p2.json +++ b/advisories/unreviewed/2024/04/GHSA-79xc-34g5-49p2/GHSA-79xc-34g5-49p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79xc-34g5-49p2", - "modified": "2024-04-03T18:30:41Z", + "modified": "2025-02-28T00:30:51Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2023-52640" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fix oob in ntfs_listxattr\n\nThe length of name cannot exceed the space occupied by ea.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json b/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json index e883b6098eb..c5458e3350e 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json +++ b/advisories/unreviewed/2024/04/GHSA-gvgx-pcvr-3pc4/GHSA-gvgx-pcvr-3pc4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvgx-pcvr-3pc4", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-02-28T00:30:51Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26753" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio/akcipher - Fix stack overflow on memcpy\n\nsizeof(struct virtio_crypto_akcipher_session_para) is less than\nsizeof(struct virtio_crypto_op_ctrl_req::u), copying more bytes from\nstack variable leads stack overflow. Clang reports this issue by\ncommands:\nmake -j CC=clang-14 mrproper >/dev/null 2>&1\nmake -j O=/tmp/crypto-build CC=clang-14 allmodconfig >/dev/null 2>&1\nmake -j O=/tmp/crypto-build W=1 CC=clang-14 drivers/crypto/virtio/\n virtio_crypto_akcipher_algs.o", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json b/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json index 4b501720c18..b9280288081 100644 --- a/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json +++ b/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mccq-9gc6-hm85", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-02-28T00:30:50Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26703" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Move hrtimer_init to timerlat_fd open()\n\nCurrently, the timerlat's hrtimer is initialized at the first read of\ntimerlat_fd, and destroyed at close(). It works, but it causes an error\nif the user program open() and close() the file without reading.\n\nHere's an example:\n\n # echo NO_OSNOISE_WORKLOAD > /sys/kernel/debug/tracing/osnoise/options\n # echo timerlat > /sys/kernel/debug/tracing/current_tracer\n\n # cat < ./timerlat_load.py\n # !/usr/bin/env python3\n\n timerlat_fd = open(\"/sys/kernel/tracing/osnoise/per_cpu/cpu0/timerlat_fd\", 'r')\n timerlat_fd.close();\n EOF\n\n # ./taskset -c 0 ./timerlat_load.py\n\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 1 PID: 2673 Comm: python3 Not tainted 6.6.13-200.fc39.x86_64 #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:hrtimer_active+0xd/0x50\n Code: 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 48 8b 57 30 <8b> 42 10 a8 01 74 09 f3 90 8b 42 10 a8 01 75 f7 80 7f 38 00 75 1d\n RSP: 0018:ffffb031009b7e10 EFLAGS: 00010286\n RAX: 000000000002db00 RBX: ffff9118f786db08 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffff9117a0e64400 RDI: ffff9118f786db08\n RBP: ffff9118f786db80 R08: ffff9117a0ddd420 R09: ffff9117804d4f70\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff9118f786db08\n R13: ffff91178fdd5e20 R14: ffff9117840978c0 R15: 0000000000000000\n FS: 00007f2ffbab1740(0000) GS:ffff9118f7840000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000010 CR3: 00000001b402e000 CR4: 0000000000750ee0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? srso_alias_return_thunk+0x5/0x7f\n ? avc_has_extended_perms+0x237/0x520\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? hrtimer_active+0xd/0x50\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x48/0xe0\n __fput+0xf5/0x290\n __x64_sys_close+0x3d/0x80\n do_syscall_64+0x60/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? __x64_sys_ioctl+0x72/0xd0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? exit_to_user_mode_prepare+0x142/0x1f0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n RIP: 0033:0x7f2ffb321594\n Code: 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d d5 cd 0d 00 00 74 13 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 3c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 7d\n RSP: 002b:00007ffe8d8eef18 EFLAGS: 00000202 ORIG_RAX: 0000000000000003\n RAX: ffffffffffffffda RBX: 00007f2ffba4e668 RCX: 00007f2ffb321594\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007ffe8d8eef40 R08: 0000000000000000 R09: 0000000000000000\n R10: 55c926e3167eae79 R11: 0000000000000202 R12: 0000000000000003\n R13: 00007ffe8d8ef030 R14: 0000000000000000 R15: 00007f2ffba4e668\n \n CR2: 0000000000000010\n ---[ end trace 0000000000000000 ]---\n\nMove hrtimer_init to timerlat_fd open() to avoid this problem.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json b/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json index 78c3fbdd2c6..692d2dc1a60 100644 --- a/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json +++ b/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qv7c-pjpr-grqx", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-02-28T00:30:51Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26790" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read\n\nThere is chip (ls1028a) errata:\n\nThe SoC may hang on 16 byte unaligned read transactions by QDMA.\n\nUnaligned read transactions initiated by QDMA may stall in the NOC\n(Network On-Chip), causing a deadlock condition. Stalled transactions will\ntrigger completion timeouts in PCIe controller.\n\nWorkaround:\nEnable prefetch by setting the source descriptor prefetchable bit\n( SD[PF] = 1 ).\n\nImplement this workaround.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json b/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json index 6e00cb205fc..603056bb1c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json +++ b/advisories/unreviewed/2024/04/GHSA-wm8x-c4gv-vvw5/GHSA-wm8x-c4gv-vvw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wm8x-c4gv-vvw5", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-02-28T00:30:51Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26766" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix sdma.h tx->num_descs off-by-one error\n\nUnfortunately the commit `fd8958efe877` introduced another error\ncausing the `descs` array to overflow. This reults in further crashes\neasily reproducible by `sendmsg` system call.\n\n[ 1080.836473] general protection fault, probably for non-canonical address 0x400300015528b00a: 0000 [#1] PREEMPT SMP PTI\n[ 1080.869326] RIP: 0010:hfi1_ipoib_build_ib_tx_headers.constprop.0+0xe1/0x2b0 [hfi1]\n--\n[ 1080.974535] Call Trace:\n[ 1080.976990] \n[ 1081.021929] hfi1_ipoib_send_dma_common+0x7a/0x2e0 [hfi1]\n[ 1081.027364] hfi1_ipoib_send_dma_list+0x62/0x270 [hfi1]\n[ 1081.032633] hfi1_ipoib_send+0x112/0x300 [hfi1]\n[ 1081.042001] ipoib_start_xmit+0x2a9/0x2d0 [ib_ipoib]\n[ 1081.046978] dev_hard_start_xmit+0xc4/0x210\n--\n[ 1081.148347] __sys_sendmsg+0x59/0xa0\n\ncrash> ipoib_txreq 0xffff9cfeba229f00\nstruct ipoib_txreq {\n txreq = {\n list = {\n next = 0xffff9cfeba229f00,\n prev = 0xffff9cfeba229f00\n },\n descp = 0xffff9cfeba229f40,\n coalesce_buf = 0x0,\n wait = 0xffff9cfea4e69a48,\n complete = 0xffffffffc0fe0760 ,\n packet_len = 0x46d,\n tlen = 0x0,\n num_desc = 0x0,\n desc_limit = 0x6,\n next_descq_idx = 0x45c,\n coalesce_idx = 0x0,\n flags = 0x0,\n descs = {{\n qw = {0x8024000120dffb00, 0x4} # SDMA_DESC0_FIRST_DESC_FLAG (bit 63)\n }, {\n qw = { 0x3800014231b108, 0x4}\n }, {\n qw = { 0x310000e4ee0fcf0, 0x8}\n }, {\n qw = { 0x3000012e9f8000, 0x8}\n }, {\n qw = { 0x59000dfb9d0000, 0x8}\n }, {\n qw = { 0x78000e02e40000, 0x8}\n }}\n },\n sdma_hdr = 0x400300015528b000, <<< invalid pointer in the tx request structure\n sdma_status = 0x0, SDMA_DESC0_LAST_DESC_FLAG (bit 62)\n complete = 0x0,\n priv = 0x0,\n txq = 0xffff9cfea4e69880,\n skb = 0xffff9d099809f400\n}\n\nIf an SDMA send consists of exactly 6 descriptors and requires dword\npadding (in the 7th descriptor), the sdma_txreq descriptor array is not\nproperly expanded and the packet will overflow into the container\nstructure. This results in a panic when the send completion runs. The\nexact panic varies depending on what elements of the container structure\nget corrupted. The fix is to use the correct expression in\n_pad_sdma_tx_descs() to test the need to expand the descriptor array.\n\nWith this patch the crashes are no longer reproducible and the machine is\nstable.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-193" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json b/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json index 274efca2925..5031fa22355 100644 --- a/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json +++ b/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xf3h-rpgf-fmvp", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-02-28T00:30:51Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26711" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad4130: zero-initialize clock init data\n\nThe clk_init_data struct does not have all its members\ninitialized, causing issues when trying to expose the internal\nclock on the CLK pin.\n\nFix this by zero-initializing the clk_init_data struct.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2025/01/GHSA-24v3-p69g-7cx6/GHSA-24v3-p69g-7cx6.json b/advisories/unreviewed/2025/01/GHSA-24v3-p69g-7cx6/GHSA-24v3-p69g-7cx6.json index 9e7cf0ac884..7b10b28a190 100644 --- a/advisories/unreviewed/2025/01/GHSA-24v3-p69g-7cx6/GHSA-24v3-p69g-7cx6.json +++ b/advisories/unreviewed/2025/01/GHSA-24v3-p69g-7cx6/GHSA-24v3-p69g-7cx6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24v3-p69g-7cx6", - "modified": "2025-01-23T18:31:17Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21636" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n syzbot [1] using acct(2).\n\nThe 'net' structure can be obtained from the table->data using\ncontainer_of().\n\nNote that table->data could also be used directly, as this is the only\nmember needed from the 'net' structure, but that would increase the size\nof this fix, to use '*data' everywhere 'net->sctp.probe_interval' is\nused.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2gpq-mc93-wwwp/GHSA-2gpq-mc93-wwwp.json b/advisories/unreviewed/2025/01/GHSA-2gpq-mc93-wwwp/GHSA-2gpq-mc93-wwwp.json index f013fba26bf..3218a3cad48 100644 --- a/advisories/unreviewed/2025/01/GHSA-2gpq-mc93-wwwp/GHSA-2gpq-mc93-wwwp.json +++ b/advisories/unreviewed/2025/01/GHSA-2gpq-mc93-wwwp/GHSA-2gpq-mc93-wwwp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gpq-mc93-wwwp", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21640" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n syzbot [1] using acct(2).\n\nThe 'net' structure can be obtained from the table->data using\ncontainer_of().\n\nNote that table->data could also be used directly, as this is the only\nmember needed from the 'net' structure, but that would increase the size\nof this fix, to use '*data' everywhere 'net->sctp.sctp_hmac_alg' is\nused.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5m3g-gpvq-34jp/GHSA-5m3g-gpvq-34jp.json b/advisories/unreviewed/2025/01/GHSA-5m3g-gpvq-34jp/GHSA-5m3g-gpvq-34jp.json index c08235d8a12..2f8ccc910c8 100644 --- a/advisories/unreviewed/2025/01/GHSA-5m3g-gpvq-34jp/GHSA-5m3g-gpvq-34jp.json +++ b/advisories/unreviewed/2025/01/GHSA-5m3g-gpvq-34jp/GHSA-5m3g-gpvq-34jp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5m3g-gpvq-34jp", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57913" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Remove WARN_ON in functionfs_bind\n\nThis commit addresses an issue related to below kernel panic where\npanic_on_warn is enabled. It is caused by the unnecessary use of WARN_ON\nin functionsfs_bind, which easily leads to the following scenarios.\n\n1.adb_write in adbd 2. UDC write via configfs\n =================\t =====================\n\n->usb_ffs_open_thread() ->UDC write\n ->open_functionfs() ->configfs_write_iter()\n ->adb_open() ->gadget_dev_desc_UDC_store()\n ->adb_write() ->usb_gadget_register_driver_owner\n ->driver_register()\n->StartMonitor() ->bus_add_driver()\n ->adb_read() ->gadget_bind_driver()\n ->configfs_composite_bind()\n ->usb_add_function()\n->open_functionfs() ->ffs_func_bind()\n ->adb_open() ->functionfs_bind()\n state !=FFS_ACTIVE>\n\nThe adb_open, adb_read, and adb_write operations are invoked from the\ndaemon, but trying to bind the function is a process that is invoked by\nUDC write through configfs, which opens up the possibility of a race\ncondition between the two paths. In this race scenario, the kernel panic\noccurs due to the WARN_ON from functionfs_bind when panic_on_warn is\nenabled. This commit fixes the kernel panic by removing the unnecessary\nWARN_ON.\n\nKernel panic - not syncing: kernel: panic_on_warn set ...\n[ 14.542395] Call trace:\n[ 14.542464] ffs_func_bind+0x1c8/0x14a8\n[ 14.542468] usb_add_function+0xcc/0x1f0\n[ 14.542473] configfs_composite_bind+0x468/0x588\n[ 14.542478] gadget_bind_driver+0x108/0x27c\n[ 14.542483] really_probe+0x190/0x374\n[ 14.542488] __driver_probe_device+0xa0/0x12c\n[ 14.542492] driver_probe_device+0x3c/0x220\n[ 14.542498] __driver_attach+0x11c/0x1fc\n[ 14.542502] bus_for_each_dev+0x104/0x160\n[ 14.542506] driver_attach+0x24/0x34\n[ 14.542510] bus_add_driver+0x154/0x270\n[ 14.542514] driver_register+0x68/0x104\n[ 14.542518] usb_gadget_register_driver_owner+0x48/0xf4\n[ 14.542523] gadget_dev_desc_UDC_store+0xf8/0x144\n[ 14.542526] configfs_write_iter+0xf0/0x138", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6w8c-3g24-p9jh/GHSA-6w8c-3g24-p9jh.json b/advisories/unreviewed/2025/01/GHSA-6w8c-3g24-p9jh/GHSA-6w8c-3g24-p9jh.json index 4c4f75f6153..dad19bf0052 100644 --- a/advisories/unreviewed/2025/01/GHSA-6w8c-3g24-p9jh/GHSA-6w8c-3g24-p9jh.json +++ b/advisories/unreviewed/2025/01/GHSA-6w8c-3g24-p9jh/GHSA-6w8c-3g24-p9jh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6w8c-3g24-p9jh", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21639" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: rto_min/max: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n syzbot [1] using acct(2).\n\nThe 'net' structure can be obtained from the table->data using\ncontainer_of().\n\nNote that table->data could also be used directly, as this is the only\nmember needed from the 'net' structure, but that would increase the size\nof this fix, to use '*data' everywhere 'net->sctp.rto_min/max' is used.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7qcm-45jm-fj5g/GHSA-7qcm-45jm-fj5g.json b/advisories/unreviewed/2025/01/GHSA-7qcm-45jm-fj5g/GHSA-7qcm-45jm-fj5g.json index dbfd28352c6..ad18c6d390e 100644 --- a/advisories/unreviewed/2025/01/GHSA-7qcm-45jm-fj5g/GHSA-7qcm-45jm-fj5g.json +++ b/advisories/unreviewed/2025/01/GHSA-7qcm-45jm-fj5g/GHSA-7qcm-45jm-fj5g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7qcm-45jm-fj5g", - "modified": "2025-01-23T18:31:17Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21637" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: udp_port: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n syzbot [1] using acct(2).\n\nThe 'net' structure can be obtained from the table->data using\ncontainer_of().\n\nNote that table->data could also be used directly, but that would\nincrease the size of this fix, while 'sctp.ctl_sock' still needs to be\nretrieved from 'net' structure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-94vx-hxvv-26m7/GHSA-94vx-hxvv-26m7.json b/advisories/unreviewed/2025/01/GHSA-94vx-hxvv-26m7/GHSA-94vx-hxvv-26m7.json index 3370c9d503c..a5a6a4db9be 100644 --- a/advisories/unreviewed/2025/01/GHSA-94vx-hxvv-26m7/GHSA-94vx-hxvv-26m7.json +++ b/advisories/unreviewed/2025/01/GHSA-94vx-hxvv-26m7/GHSA-94vx-hxvv-26m7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-94vx-hxvv-26m7", - "modified": "2025-02-02T12:30:25Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57922" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add check for granularity in dml ceil/floor helpers\n\n[Why]\nWrapper functions for dcn_bw_ceil2() and dcn_bw_floor2()\nshould check for granularity is non zero to avoid assert and\ndivide-by-zero error in dcn_bw_ functions.\n\n[How]\nAdd check for granularity 0.\n\n(cherry picked from commit f6e09701c3eb2ccb8cb0518e0b67f1c69742a4ec)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v3qj-q3px-pcxw/GHSA-v3qj-q3px-pcxw.json b/advisories/unreviewed/2025/01/GHSA-v3qj-q3px-pcxw/GHSA-v3qj-q3px-pcxw.json index d75925a8695..ee41b0fbee1 100644 --- a/advisories/unreviewed/2025/01/GHSA-v3qj-q3px-pcxw/GHSA-v3qj-q3px-pcxw.json +++ b/advisories/unreviewed/2025/01/GHSA-v3qj-q3px-pcxw/GHSA-v3qj-q3px-pcxw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v3qj-q3px-pcxw", - "modified": "2025-01-23T18:31:18Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:27Z", "aliases": [ "CVE-2024-57925" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix a missing return value check bug\n\nIn the smb2_send_interim_resp(), if ksmbd_alloc_work_struct()\nfails to allocate a node, it returns a NULL pointer to the\nin_work pointer. This can lead to an illegal memory write of\nin_work->response_buf when allocate_interim_rsp_buf() attempts\nto perform a kzalloc() on it.\n\nTo address this issue, incorporating a check for the return\nvalue of ksmbd_alloc_work_struct() ensures that the function\nreturns immediately upon allocation failure, thereby preventing\nthe aforementioned illegal memory access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vrx4-x92w-9vhv/GHSA-vrx4-x92w-9vhv.json b/advisories/unreviewed/2025/01/GHSA-vrx4-x92w-9vhv/GHSA-vrx4-x92w-9vhv.json index 1158db58fed..20f14c970cd 100644 --- a/advisories/unreviewed/2025/01/GHSA-vrx4-x92w-9vhv/GHSA-vrx4-x92w-9vhv.json +++ b/advisories/unreviewed/2025/01/GHSA-vrx4-x92w-9vhv/GHSA-vrx4-x92w-9vhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrx4-x92w-9vhv", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21638" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: auth_enable: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n syzbot [1] using acct(2).\n\nThe 'net' structure can be obtained from the table->data using\ncontainer_of().\n\nNote that table->data could also be used directly, but that would\nincrease the size of this fix, while 'sctp.ctl_sock' still needs to be\nretrieved from 'net' structure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wgq7-x72m-hm6h/GHSA-wgq7-x72m-hm6h.json b/advisories/unreviewed/2025/01/GHSA-wgq7-x72m-hm6h/GHSA-wgq7-x72m-hm6h.json index 0b42b0d03b8..93f11437f80 100644 --- a/advisories/unreviewed/2025/01/GHSA-wgq7-x72m-hm6h/GHSA-wgq7-x72m-hm6h.json +++ b/advisories/unreviewed/2025/01/GHSA-wgq7-x72m-hm6h/GHSA-wgq7-x72m-hm6h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgq7-x72m-hm6h", - "modified": "2025-01-19T12:31:25Z", + "modified": "2025-02-28T00:30:51Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21650" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue\n\nThe TQP BAR space is divided into two segments. TQPs 0-1023 and TQPs\n1024-1279 are in different BAR space addresses. However,\nhclge_fetch_pf_reg does not distinguish the tqp space information when\nreading the tqp space information. When the number of TQPs is greater\nthan 1024, access bar space overwriting occurs.\nThe problem of different segments has been considered during the\ninitialization of tqp.io_base. Therefore, tqp.io_base is directly used\nwhen the queue is read in hclge_fetch_pf_reg.\n\nThe error message:\n\nUnable to handle kernel paging request at virtual address ffff800037200000\npc : hclge_fetch_pf_reg+0x138/0x250 [hclge]\nlr : hclge_get_regs+0x84/0x1d0 [hclge]\nCall trace:\n hclge_fetch_pf_reg+0x138/0x250 [hclge]\n hclge_get_regs+0x84/0x1d0 [hclge]\n hns3_get_regs+0x2c/0x50 [hns3]\n ethtool_get_regs+0xf4/0x270\n dev_ethtool+0x674/0x8a0\n dev_ioctl+0x270/0x36c\n sock_do_ioctl+0x110/0x2a0\n sock_ioctl+0x2ac/0x530\n __arm64_sys_ioctl+0xa8/0x100\n invoke_syscall+0x4c/0x124\n el0_svc_common.constprop.0+0x140/0x15c\n do_el0_svc+0x30/0xd0\n el0_svc+0x1c/0x2c\n el0_sync_handler+0xb0/0xb4\n el0_sync+0x168/0x180", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json b/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json new file mode 100644 index 00000000000..88560b092a6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qf8-ww35-9vjg", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2025-26325" + ], + "details": "ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26325" + }, + { + "type": "WEB", + "url": "https://github.com/gongfuxiang/shopxo/issues/86" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json b/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json new file mode 100644 index 00000000000..74829c9a131 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53j9-5hmj-8v9f", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2024-37566" + ], + "details": "Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37566" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/000010392" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T23:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5xc2-vwvc-458q/GHSA-5xc2-vwvc-458q.json b/advisories/unreviewed/2025/02/GHSA-5xc2-vwvc-458q/GHSA-5xc2-vwvc-458q.json new file mode 100644 index 00000000000..f8e751c8115 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5xc2-vwvc-458q/GHSA-5xc2-vwvc-458q.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xc2-vwvc-458q", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-1687" + ], + "details": "The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to update the user email and password via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1687" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/car-dealer-automotive-wordpress-theme-responsive/8574708" + }, + { + "type": "WEB", + "url": "https://webtemplatemasters.com/cardealer/changelog/#v165" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6305b7be-8651-4028-a8cf-ea58b4977225?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json b/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json new file mode 100644 index 00000000000..15ebb7b0241 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vc4-8cgc-2m74", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-25729" + ], + "details": "An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via the update or boot process.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25729" + }, + { + "type": "WEB", + "url": "https://gainsec.com/2025/02/27/cve-2025-25727cve-2025-25728cve-2025-25729-multiple-vulnerabilities-found-in-bosscomm-obd2-tablet" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json b/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json new file mode 100644 index 00000000000..7f930e36ecd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c2w-rfmh-q65f", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2025-26264" + ], + "details": "GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with \"System Settings\" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26264" + }, + { + "type": "WEB", + "url": "https://github.com/DRAGOWN/CVE-2025-26264" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cx33-wwv9-rm3j/GHSA-cx33-wwv9-rm3j.json b/advisories/unreviewed/2025/02/GHSA-cx33-wwv9-rm3j/GHSA-cx33-wwv9-rm3j.json new file mode 100644 index 00000000000..693f9045e4d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cx33-wwv9-rm3j/GHSA-cx33-wwv9-rm3j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx33-wwv9-rm3j", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-1681" + ], + "details": "The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change or delete arbitrary css and js files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1681" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/car-dealer-automotive-wordpress-theme-responsive/8574708" + }, + { + "type": "WEB", + "url": "https://webtemplatemasters.com/cardealer/changelog/#v165" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3e394ee2-13c1-4b04-a8a5-4642f1794d59?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json b/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json new file mode 100644 index 00000000000..de4c30ec398 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4v7-6h28-6phm", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2024-38291" + ], + "details": "In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38291" + }, + { + "type": "WEB", + "url": "https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2024-105-xiq-se-unauthorized-access-to-user-credentials-cve/ba-p/116363" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json b/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json new file mode 100644 index 00000000000..23c089a2568 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h33c-355w-g26q", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2025-25730" + ], + "details": "An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25730" + }, + { + "type": "WEB", + "url": "https://gainsec.com/2025/02/27/cve-2025-25730-developer-options-and-usb-debugging-authorization-bypass" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json b/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json new file mode 100644 index 00000000000..8705c1247fe --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf75-x4f2-r8c9", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2024-36047" + ], + "details": "Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36047" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/000010391" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T23:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json b/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json new file mode 100644 index 00000000000..ef7f132af6e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv4p-6m84-hhpv", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-25477" + ], + "details": "A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25477" + }, + { + "type": "WEB", + "url": "https://github.com/sysentr0py/CVEs/tree/main/CVE-2025-25477" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json b/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json new file mode 100644 index 00000000000..4fc1adc8d15 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m73p-w5w2-3m5h", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2024-38292" + ], + "details": "In XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38292" + }, + { + "type": "WEB", + "url": "https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2024-104-xiq-se-path-traversal-privilege-escalation-cve-2024/ba-p/116362" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json b/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json new file mode 100644 index 00000000000..d8cf647a1e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2c8-vcc7-q39q", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2025-25570" + ], + "details": "Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25570" + }, + { + "type": "WEB", + "url": "https://github.com/Hackerhan/Vben-Admin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p8qq-75v8-px25/GHSA-p8qq-75v8-px25.json b/advisories/unreviewed/2025/02/GHSA-p8qq-75v8-px25/GHSA-p8qq-75v8-px25.json new file mode 100644 index 00000000000..7a096e521ab --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p8qq-75v8-px25/GHSA-p8qq-75v8-px25.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8qq-75v8-px25", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-1682" + ], + "details": "The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1682" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/car-dealer-automotive-wordpress-theme-responsive/8574708" + }, + { + "type": "WEB", + "url": "https://webtemplatemasters.com/cardealer/changelog/#v165" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4e337281-f05e-486c-9491-161365af252a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json b/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json new file mode 100644 index 00000000000..a8e3b986ff6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q43v-p4wq-wmhv", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2024-38290" + ], + "details": "In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38290" + }, + { + "type": "WEB", + "url": "https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2024-106-xiq-se-unauthorized-access-to-user-account/ba-p/116364" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qc2q-hwc8-26rv/GHSA-qc2q-hwc8-26rv.json b/advisories/unreviewed/2025/02/GHSA-qc2q-hwc8-26rv/GHSA-qc2q-hwc8-26rv.json new file mode 100644 index 00000000000..bb9c76c3749 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qc2q-hwc8-26rv/GHSA-qc2q-hwc8-26rv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc2q-hwc8-26rv", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-24832" + ], + "details": "Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24832" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7649" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T23:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json b/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json new file mode 100644 index 00000000000..f3b8a842fad --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw4v-473w-8hq5", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-25728" + ], + "details": "Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25728" + }, + { + "type": "WEB", + "url": "https://gainsec.com/2025/02/27/cve-2025-25727cve-2025-25728cve-2025-25729-multiple-vulnerabilities-found-in-bosscomm-obd2-tablet" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json b/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json new file mode 100644 index 00000000000..b6f23d6697a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwpx-f8qj-4h9h", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2025-25727" + ], + "details": "Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25727" + }, + { + "type": "WEB", + "url": "https://gainsec.com/2025/02/27/cve-2025-25727cve-2025-25728cve-2025-25729-multiple-vulnerabilities-found-in-bosscomm-obd2-tablet" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json b/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json new file mode 100644 index 00000000000..296ad98f3a9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2m3-cppr-8m5q", + "modified": "2025-02-28T00:30:51Z", + "published": "2025-02-28T00:30:51Z", + "aliases": [ + "CVE-2024-36046" + ], + "details": "Infoblox NIOS through 8.6.4 executes with more privileges than required.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36046" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/000010390" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T23:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x49p-h589-rcc4/GHSA-x49p-h589-rcc4.json b/advisories/unreviewed/2025/02/GHSA-x49p-h589-rcc4/GHSA-x49p-h589-rcc4.json new file mode 100644 index 00000000000..209f28b5be8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x49p-h589-rcc4/GHSA-x49p-h589-rcc4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x49p-h589-rcc4", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2024-12811" + ], + "details": "The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12811" + }, + { + "type": "WEB", + "url": "https://travelerwp.com/traveler-changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a09298b3-3b5c-4a92-9332-79ff83234479?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T00:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json b/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json new file mode 100644 index 00000000000..e9342baf991 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfxq-4gvm-mf69", + "modified": "2025-02-28T00:30:52Z", + "published": "2025-02-28T00:30:52Z", + "aliases": [ + "CVE-2024-37567" + ], + "details": "Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37567" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/000010393" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T23:15:37Z" + } +} \ No newline at end of file