diff --git a/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json b/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json
index a12232692da..c5aa8e537ae 100644
--- a/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json
+++ b/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3248-f5xr-jwg7",
- "modified": "2023-11-15T15:30:21Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T03:30:32Z",
"aliases": [
"CVE-2023-46770"
diff --git a/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json b/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json
index 4a79e01a080..efdb39c2b16 100644
--- a/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json
+++ b/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cfv-7x3j-7m2c",
- "modified": "2023-11-14T21:30:54Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46760"
diff --git a/advisories/unreviewed/2023/11/GHSA-472f-g7p4-frc8/GHSA-472f-g7p4-frc8.json b/advisories/unreviewed/2023/11/GHSA-472f-g7p4-frc8/GHSA-472f-g7p4-frc8.json
index f83092627b9..cb723e94258 100644
--- a/advisories/unreviewed/2023/11/GHSA-472f-g7p4-frc8/GHSA-472f-g7p4-frc8.json
+++ b/advisories/unreviewed/2023/11/GHSA-472f-g7p4-frc8/GHSA-472f-g7p4-frc8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-472f-g7p4-frc8",
- "modified": "2023-11-15T00:31:06Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46767"
diff --git a/advisories/unreviewed/2023/11/GHSA-7389-xcrh-qpj4/GHSA-7389-xcrh-qpj4.json b/advisories/unreviewed/2023/11/GHSA-7389-xcrh-qpj4/GHSA-7389-xcrh-qpj4.json
index 2a596a43a67..14a1accb34d 100644
--- a/advisories/unreviewed/2023/11/GHSA-7389-xcrh-qpj4/GHSA-7389-xcrh-qpj4.json
+++ b/advisories/unreviewed/2023/11/GHSA-7389-xcrh-qpj4/GHSA-7389-xcrh-qpj4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7389-xcrh-qpj4",
- "modified": "2023-11-16T15:30:20Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46772"
diff --git a/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json b/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json
index c68956f7675..737cf6d8681 100644
--- a/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json
+++ b/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-782h-r93g-8gcc",
- "modified": "2023-11-16T18:30:25Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T21:30:37Z",
"aliases": [
"CVE-2023-29974"
diff --git a/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json b/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json
index 61884743e13..ce33285b694 100644
--- a/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json
+++ b/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json b/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json
index fa90a38ba40..6dd12aac81a 100644
--- a/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json
+++ b/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5hr-qxxj-7g93",
- "modified": "2023-11-14T21:30:55Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46762"
diff --git a/advisories/unreviewed/2023/11/GHSA-p52f-xxj5-g37q/GHSA-p52f-xxj5-g37q.json b/advisories/unreviewed/2023/11/GHSA-p52f-xxj5-g37q/GHSA-p52f-xxj5-g37q.json
index 04f9edfd0dd..80acfd4e732 100644
--- a/advisories/unreviewed/2023/11/GHSA-p52f-xxj5-g37q/GHSA-p52f-xxj5-g37q.json
+++ b/advisories/unreviewed/2023/11/GHSA-p52f-xxj5-g37q/GHSA-p52f-xxj5-g37q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p52f-xxj5-g37q",
- "modified": "2023-11-15T00:31:06Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46766"
diff --git a/advisories/unreviewed/2023/11/GHSA-q58c-9r4v-fff6/GHSA-q58c-9r4v-fff6.json b/advisories/unreviewed/2023/11/GHSA-q58c-9r4v-fff6/GHSA-q58c-9r4v-fff6.json
index bbe28c65c6d..0af68501f93 100644
--- a/advisories/unreviewed/2023/11/GHSA-q58c-9r4v-fff6/GHSA-q58c-9r4v-fff6.json
+++ b/advisories/unreviewed/2023/11/GHSA-q58c-9r4v-fff6/GHSA-q58c-9r4v-fff6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q58c-9r4v-fff6",
- "modified": "2023-11-15T18:30:21Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46765"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-248"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json b/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json
index 328d87d2551..7662b0c543c 100644
--- a/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json
+++ b/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvf5-fhrh-vc2m",
- "modified": "2023-11-15T21:35:03Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-09T00:33:55Z",
"aliases": [
"CVE-2023-36667"
diff --git a/advisories/unreviewed/2023/11/GHSA-wh7h-39r6-778j/GHSA-wh7h-39r6-778j.json b/advisories/unreviewed/2023/11/GHSA-wh7h-39r6-778j/GHSA-wh7h-39r6-778j.json
index ef2e188728a..7af037cd3c7 100644
--- a/advisories/unreviewed/2023/11/GHSA-wh7h-39r6-778j/GHSA-wh7h-39r6-778j.json
+++ b/advisories/unreviewed/2023/11/GHSA-wh7h-39r6-778j/GHSA-wh7h-39r6-778j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wh7h-39r6-778j",
- "modified": "2023-11-15T18:30:21Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T06:30:28Z",
"aliases": [
"CVE-2023-44115"
diff --git a/advisories/unreviewed/2023/11/GHSA-wpf5-6rrx-p345/GHSA-wpf5-6rrx-p345.json b/advisories/unreviewed/2023/11/GHSA-wpf5-6rrx-p345/GHSA-wpf5-6rrx-p345.json
index 6a55d6e83ff..8601823cfe8 100644
--- a/advisories/unreviewed/2023/11/GHSA-wpf5-6rrx-p345/GHSA-wpf5-6rrx-p345.json
+++ b/advisories/unreviewed/2023/11/GHSA-wpf5-6rrx-p345/GHSA-wpf5-6rrx-p345.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpf5-6rrx-p345",
- "modified": "2023-11-15T00:31:06Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46774"
diff --git a/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json b/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json
index 930f3a78d2e..35146cf26a1 100644
--- a/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json
+++ b/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpw2-hvhc-r9qq",
- "modified": "2023-11-14T21:30:54Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T09:30:26Z",
"aliases": [
"CVE-2023-46771"
diff --git a/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json b/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json
index 3ae9d278f30..d4d1fde8399 100644
--- a/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json
+++ b/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x5jv-p8vx-9cmf",
- "modified": "2023-11-14T21:30:54Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2023-11-08T09:30:26Z",
"aliases": [
"CVE-2023-44098"
diff --git a/advisories/unreviewed/2023/11/GHSA-x9cp-rmp2-c7h2/GHSA-x9cp-rmp2-c7h2.json b/advisories/unreviewed/2023/11/GHSA-x9cp-rmp2-c7h2/GHSA-x9cp-rmp2-c7h2.json
index 8cb0abf8908..33e1abde778 100644
--- a/advisories/unreviewed/2023/11/GHSA-x9cp-rmp2-c7h2/GHSA-x9cp-rmp2-c7h2.json
+++ b/advisories/unreviewed/2023/11/GHSA-x9cp-rmp2-c7h2/GHSA-x9cp-rmp2-c7h2.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json b/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json
index 7b7204f72a0..5013423b322 100644
--- a/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json
+++ b/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pv4-q67j-8w9h",
- "modified": "2024-01-18T21:30:31Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2024-01-12T15:30:32Z",
"aliases": [
"CVE-2023-49261"
diff --git a/advisories/unreviewed/2024/01/GHSA-8fxq-p79f-2rxp/GHSA-8fxq-p79f-2rxp.json b/advisories/unreviewed/2024/01/GHSA-8fxq-p79f-2rxp/GHSA-8fxq-p79f-2rxp.json
index 1bae94bc012..d6b1cc134c6 100644
--- a/advisories/unreviewed/2024/01/GHSA-8fxq-p79f-2rxp/GHSA-8fxq-p79f-2rxp.json
+++ b/advisories/unreviewed/2024/01/GHSA-8fxq-p79f-2rxp/GHSA-8fxq-p79f-2rxp.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/01/GHSA-8j5h-7rqc-9ghf/GHSA-8j5h-7rqc-9ghf.json b/advisories/unreviewed/2024/01/GHSA-8j5h-7rqc-9ghf/GHSA-8j5h-7rqc-9ghf.json
index ca3c0be3add..4993386ab3d 100644
--- a/advisories/unreviewed/2024/01/GHSA-8j5h-7rqc-9ghf/GHSA-8j5h-7rqc-9ghf.json
+++ b/advisories/unreviewed/2024/01/GHSA-8j5h-7rqc-9ghf/GHSA-8j5h-7rqc-9ghf.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json b/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json
index 4d675979d21..b9fce94579f 100644
--- a/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json
+++ b/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h25w-qh4w-j2hf",
- "modified": "2024-01-11T18:31:24Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2024-01-08T15:30:27Z",
"aliases": [
"CVE-2023-7224"
diff --git a/advisories/unreviewed/2024/01/GHSA-hgrc-r3ff-wxfq/GHSA-hgrc-r3ff-wxfq.json b/advisories/unreviewed/2024/01/GHSA-hgrc-r3ff-wxfq/GHSA-hgrc-r3ff-wxfq.json
index d25077743f9..3e4a5584e6e 100644
--- a/advisories/unreviewed/2024/01/GHSA-hgrc-r3ff-wxfq/GHSA-hgrc-r3ff-wxfq.json
+++ b/advisories/unreviewed/2024/01/GHSA-hgrc-r3ff-wxfq/GHSA-hgrc-r3ff-wxfq.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/02/GHSA-79qr-9mf7-fr3g/GHSA-79qr-9mf7-fr3g.json b/advisories/unreviewed/2024/02/GHSA-79qr-9mf7-fr3g/GHSA-79qr-9mf7-fr3g.json
index ccf2b4873db..ed1dbefd3ac 100644
--- a/advisories/unreviewed/2024/02/GHSA-79qr-9mf7-fr3g/GHSA-79qr-9mf7-fr3g.json
+++ b/advisories/unreviewed/2024/02/GHSA-79qr-9mf7-fr3g/GHSA-79qr-9mf7-fr3g.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79qr-9mf7-fr3g",
- "modified": "2024-02-29T03:33:18Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-02-29T03:33:18Z",
"aliases": [
"CVE-2024-25262"
],
"details": "texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-122"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:44:15Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-86g4-g26w-p44c/GHSA-86g4-g26w-p44c.json b/advisories/unreviewed/2024/02/GHSA-86g4-g26w-p44c/GHSA-86g4-g26w-p44c.json
index 34c6c97579c..58d4fcf5c7b 100644
--- a/advisories/unreviewed/2024/02/GHSA-86g4-g26w-p44c/GHSA-86g4-g26w-p44c.json
+++ b/advisories/unreviewed/2024/02/GHSA-86g4-g26w-p44c/GHSA-86g4-g26w-p44c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86g4-g26w-p44c",
- "modified": "2024-02-21T21:30:24Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-02-21T21:30:24Z",
"aliases": [
"CVE-2023-50975"
],
"details": "The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-276"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T19:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-px53-89vh-3q6f/GHSA-px53-89vh-3q6f.json b/advisories/unreviewed/2024/03/GHSA-px53-89vh-3q6f/GHSA-px53-89vh-3q6f.json
index 8878bfc2cb0..d327c3d83f8 100644
--- a/advisories/unreviewed/2024/03/GHSA-px53-89vh-3q6f/GHSA-px53-89vh-3q6f.json
+++ b/advisories/unreviewed/2024/03/GHSA-px53-89vh-3q6f/GHSA-px53-89vh-3q6f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-px53-89vh-3q6f",
- "modified": "2024-03-21T06:33:05Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-03-21T06:33:05Z",
"aliases": [
"CVE-2024-29864"
],
"details": "Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-21T04:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gmv6-m227-94c4/GHSA-gmv6-m227-94c4.json b/advisories/unreviewed/2024/05/GHSA-gmv6-m227-94c4/GHSA-gmv6-m227-94c4.json
index 2ba0fdfe229..893710974b7 100644
--- a/advisories/unreviewed/2024/05/GHSA-gmv6-m227-94c4/GHSA-gmv6-m227-94c4.json
+++ b/advisories/unreviewed/2024/05/GHSA-gmv6-m227-94c4/GHSA-gmv6-m227-94c4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmv6-m227-94c4",
- "modified": "2024-05-14T18:31:01Z",
+ "modified": "2024-09-04T21:30:30Z",
"published": "2024-05-14T18:31:01Z",
"aliases": [
"CVE-2024-33865"
],
"details": "An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T16:17:22Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-35cf-498m-vj28/GHSA-35cf-498m-vj28.json b/advisories/unreviewed/2024/08/GHSA-35cf-498m-vj28/GHSA-35cf-498m-vj28.json
index 6bf43d41585..929b06b9b2f 100644
--- a/advisories/unreviewed/2024/08/GHSA-35cf-498m-vj28/GHSA-35cf-498m-vj28.json
+++ b/advisories/unreviewed/2024/08/GHSA-35cf-498m-vj28/GHSA-35cf-498m-vj28.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35cf-498m-vj28",
- "modified": "2024-08-21T09:31:31Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-08-21T09:31:31Z",
"aliases": [
"CVE-2022-48868"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Let probe fail when workqueue cannot be enabled\n\nThe workqueue is enabled when the appropriate driver is loaded and\ndisabled when the driver is removed. When the driver is removed it\nassumes that the workqueue was enabled successfully and proceeds to\nfree allocations made during workqueue enabling.\n\nFailure during workqueue enabling does not prevent the driver from\nbeing loaded. This is because the error path within drv_enable_wq()\nreturns success unless a second failure is encountered\nduring the error path. By returning success it is possible to load\nthe driver even if the workqueue cannot be enabled and\nallocations that do not exist are attempted to be freed during\ndriver remove.\n\nSome examples of problematic flows:\n(a)\n\n idxd_dmaengine_drv_probe() -> drv_enable_wq() -> idxd_wq_request_irq():\n In above flow, if idxd_wq_request_irq() fails then\n idxd_wq_unmap_portal() is called on error exit path, but\n drv_enable_wq() returns 0 because idxd_wq_disable() succeeds. The\n driver is thus loaded successfully.\n\n idxd_dmaengine_drv_remove()->drv_disable_wq()->idxd_wq_unmap_portal()\n Above flow on driver unload triggers the WARN in devm_iounmap() because\n the device resource has already been removed during error path of\n drv_enable_wq().\n\n(b)\n\n idxd_dmaengine_drv_probe() -> drv_enable_wq() -> idxd_wq_request_irq():\n In above flow, if idxd_wq_request_irq() fails then\n idxd_wq_init_percpu_ref() is never called to initialize the percpu\n counter, yet the driver loads successfully because drv_enable_wq()\n returns 0.\n\n idxd_dmaengine_drv_remove()->__idxd_wq_quiesce()->percpu_ref_kill():\n Above flow on driver unload triggers a BUG when attempting to drop the\n initial ref of the uninitialized percpu ref:\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n\nFix the drv_enable_wq() error path by returning the original error that\nindicates failure of workqueue enabling. This ensures that the probe\nfails when an error is encountered and the driver remove paths are only\nattempted when the workqueue was enabled successfully.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json b/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json
index bb7184e6ed3..c6553b941a3 100644
--- a/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json
+++ b/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pwv-g7hj-39pr",
- "modified": "2024-09-03T15:30:38Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-08-19T21:35:10Z",
"aliases": [
"CVE-2024-7592"
@@ -33,6 +33,22 @@
"type": "WEB",
"url": "https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774"
+ },
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1"
diff --git a/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json b/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json
index 1e809f45e20..b71a678893a 100644
--- a/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json
+++ b/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87qc-q3w7-7m8w",
- "modified": "2024-08-07T15:30:39Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-08-01T15:32:20Z",
"aliases": [
"CVE-2024-6923"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/pull/122233"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147"
+ },
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7"
@@ -37,6 +41,18 @@
"type": "WEB",
"url": "https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533"
+ },
{
"type": "WEB",
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QH3BUOE2DYQBWP7NAQ7UNHPPOELKISRW"
diff --git a/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json b/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json
index 1c0ba69996f..c94af198e88 100644
--- a/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json
+++ b/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcrv-q4xw-6crp",
- "modified": "2024-08-30T18:30:40Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-08-30T18:30:40Z",
"aliases": [
"CVE-2024-38868"
diff --git a/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json b/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json
index d14e1bd204b..dea285587a4 100644
--- a/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json
+++ b/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q98g-hxg3-268c",
- "modified": "2024-09-03T18:31:32Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-08-22T21:31:29Z",
"aliases": [
"CVE-2024-8088"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/commit/795f2597a4be988e2bb19b69ff9958e981cb894e"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/7bc367e464ce50b956dd232c1dfa1cad4e7fb814"
+ },
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/7e8883a3f04d308302361aeffc73e0e9837f19d4"
@@ -57,6 +61,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/commit/95b073bddefa6243effa08e131e297c0383e7f6a"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/962055268ed4f2ca1d717bfc8b6385de50a23ab7"
+ },
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/dcc5182f27c1500006a1ef78e10613bb45788dea"
@@ -65,6 +73,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/commit/e0264a61119d551658d9445af38323ba94fc16db"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/fc0b8259e693caa8400fa8b6ac1e494e47ea7798"
+ },
{
"type": "WEB",
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/GNFCKVI4TCATKQLALJ5SN4L4CSPSMILU"
diff --git a/advisories/unreviewed/2024/08/GHSA-xxgp-66vq-x6cm/GHSA-xxgp-66vq-x6cm.json b/advisories/unreviewed/2024/08/GHSA-xxgp-66vq-x6cm/GHSA-xxgp-66vq-x6cm.json
index 2095449bc86..3653b4a54bb 100644
--- a/advisories/unreviewed/2024/08/GHSA-xxgp-66vq-x6cm/GHSA-xxgp-66vq-x6cm.json
+++ b/advisories/unreviewed/2024/08/GHSA-xxgp-66vq-x6cm/GHSA-xxgp-66vq-x6cm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxgp-66vq-x6cm",
- "modified": "2024-08-21T09:31:31Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-08-21T09:31:31Z",
"aliases": [
"CVE-2022-48875"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: sdata can be NULL during AMPDU start\n\nieee80211_tx_ba_session_handle_start() may get NULL for sdata when a\ndeauthentication is ongoing.\n\nHere a trace triggering the race with the hostapd test\nmulti_ap_fronthaul_on_ap:\n\n(gdb) list *drv_ampdu_action+0x46\n0x8b16 is in drv_ampdu_action (net/mac80211/driver-ops.c:396).\n391 int ret = -EOPNOTSUPP;\n392\n393 might_sleep();\n394\n395 sdata = get_bss_sdata(sdata);\n396 if (!check_sdata_in_driver(sdata))\n397 return -EIO;\n398\n399 trace_drv_ampdu_action(local, sdata, params);\n400\n\nwlan0: moving STA 02:00:00:00:03:00 to state 3\nwlan0: associated\nwlan0: deauthenticating from 02:00:00:00:03:00 by local choice (Reason: 3=DEAUTH_LEAVING)\nwlan3.sta1: Open BA session requested for 02:00:00:00:00:00 tid 0\nwlan3.sta1: dropped frame to 02:00:00:00:00:00 (unauthorized port)\nwlan0: moving STA 02:00:00:00:03:00 to state 2\nwlan0: moving STA 02:00:00:00:03:00 to state 1\nwlan0: Removed STA 02:00:00:00:03:00\nwlan0: Destroyed STA 02:00:00:00:03:00\nBUG: unable to handle page fault for address: fffffffffffffb48\nPGD 11814067 P4D 11814067 PUD 11816067 PMD 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 2 PID: 133397 Comm: kworker/u16:1 Tainted: G W 6.1.0-rc8-wt+ #59\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-20220807_005459-localhost 04/01/2014\nWorkqueue: phy3 ieee80211_ba_session_work [mac80211]\nRIP: 0010:drv_ampdu_action+0x46/0x280 [mac80211]\nCode: 53 48 89 f3 be 89 01 00 00 e8 d6 43 bf ef e8 21 46 81 f0 83 bb a0 1b 00 00 04 75 0e 48 8b 9b 28 0d 00 00 48 81 eb 10 0e 00 00 <8b> 93 58 09 00 00 f6 c2 20 0f 84 3b 01 00 00 8b 05 dd 1c 0f 00 85\nRSP: 0018:ffffc900025ebd20 EFLAGS: 00010287\nRAX: 0000000000000000 RBX: fffffffffffff1f0 RCX: ffff888102228240\nRDX: 0000000080000000 RSI: ffffffff918c5de0 RDI: ffff888102228b40\nRBP: ffffc900025ebd40 R08: 0000000000000001 R09: 0000000000000001\nR10: 0000000000000001 R11: 0000000000000000 R12: ffff888118c18ec0\nR13: 0000000000000000 R14: ffffc900025ebd60 R15: ffff888018b7efb8\nFS: 0000000000000000(0000) GS:ffff88817a600000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: fffffffffffffb48 CR3: 0000000105228006 CR4: 0000000000170ee0\nCall Trace:\n \n ieee80211_tx_ba_session_handle_start+0xd0/0x190 [mac80211]\n ieee80211_ba_session_work+0xff/0x2e0 [mac80211]\n process_one_work+0x29f/0x620\n worker_thread+0x4d/0x3d0\n ? process_one_work+0x620/0x620\n kthread+0xfb/0x120\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x22/0x30\n ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:04Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json b/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json
new file mode 100644
index 00000000000..7f214e9e717
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-285g-gc96-4xjh",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44968"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntick/broadcast: Move per CPU pointer access into the atomic section\n\nThe recent fix for making the take over of the broadcast timer more\nreliable retrieves a per CPU pointer in preemptible context.\n\nThis went unnoticed as compilers hoist the access into the non-preemptible\nregion where the pointer is actually used. But of course it's valid that\nthe compiler keeps it at the place where the code puts it which rightfully\ntriggers:\n\n BUG: using smp_processor_id() in preemptible [00000000] code:\n caller is hotplug_cpu__broadcast_tick_pull+0x1c/0xc0\n\nMove it to the actual usage site which is in a non-preemptible region.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44968"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/541a900d245536d4809cb1aa322c3fcc2cdb58a6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/668c6c4a7e9e9f081c06b70f30104fb7013437ed"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6881e75237a84093d0986f56223db3724619f26e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7b3ec186ba93e333e9efe7254e7e31c1828e5d2d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7dd12f85f150010ef7518201c63fa7e395f5c3e9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b9d604933d5fd72dd37f24e1dc35f778297d745a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f54abf332a2bc0413cfa8bd6a8511f7aa99faea0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f91fb47ecacc178a83a77eeebd25cbaec18c01d6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-2gjh-m4gq-rxrh/GHSA-2gjh-m4gq-rxrh.json b/advisories/unreviewed/2024/09/GHSA-2gjh-m4gq-rxrh/GHSA-2gjh-m4gq-rxrh.json
new file mode 100644
index 00000000000..ebe8a66b089
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-2gjh-m4gq-rxrh/GHSA-2gjh-m4gq-rxrh.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2gjh-m4gq-rxrh",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44996"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: fix recursive ->recvmsg calls\n\nAfter a vsock socket has been added to a BPF sockmap, its prot->recvmsg\nhas been replaced with vsock_bpf_recvmsg(). Thus the following\nrecursiion could happen:\n\nvsock_bpf_recvmsg()\n -> __vsock_recvmsg()\n -> vsock_connectible_recvmsg()\n -> prot->recvmsg()\n -> vsock_bpf_recvmsg() again\n\nWe need to fix it by calling the original ->recvmsg() without any BPF\nsockmap logic in __vsock_recvmsg().",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44996"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/69139d2919dd4aa9a553c8245e7c63e82613e3fc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/921f1acf0c3cf6b1260ab57a8a6e8b3d5f3023d5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b4ee8cf1acc5018ed1369150d7bb3e0d0f79e135"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json b/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json
new file mode 100644
index 00000000000..41904ef84d0
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2hcr-rj2w-r9vj",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44967"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mgag200: Bind I2C lifetime to DRM device\n\nManaged cleanup with devm_add_action_or_reset() will release the I2C\nadapter when the underlying Linux device goes away. But the connector\nstill refers to it, so this cleanup leaves behind a stale pointer\nin struct drm_connector.ddc.\n\nBind the lifetime of the I2C adapter to the connector's lifetime by\nusing DRM's managed release. When the DRM device goes away (after\nthe Linux device) DRM will first clean up the connector and then\nclean up the I2C adapter.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44967"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/55a6916db77102765b22855d3a0add4751988b7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/81d34df843620e902dd04aa9205c875833d61c17"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9d96b91e03cba9dfcb4ac370c93af4dbc47d5191"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eb1ae34e48a09b7a1179c579aed042b032e408f4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-2j9f-hmx4-cvgr/GHSA-2j9f-hmx4-cvgr.json b/advisories/unreviewed/2024/09/GHSA-2j9f-hmx4-cvgr/GHSA-2j9f-hmx4-cvgr.json
new file mode 100644
index 00000000000..e8c8b634822
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-2j9f-hmx4-cvgr/GHSA-2j9f-hmx4-cvgr.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2j9f-hmx4-cvgr",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44964"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix memory leaks and crashes while performing a soft reset\n\nThe second tagged commit introduced a UAF, as it removed restoring\nq_vector->vport pointers after reinitializating the structures.\nThis is due to that all queue allocation functions are performed here\nwith the new temporary vport structure and those functions rewrite\nthe backpointers to the vport. Then, this new struct is freed and\nthe pointers start leading to nowhere.\n\nBut generally speaking, the current logic is very fragile. It claims\nto be more reliable when the system is low on memory, but in fact, it\nconsumes two times more memory as at the moment of running this\nfunction, there are two vports allocated with their queues and vectors.\nMoreover, it claims to prevent the driver from running into \"bad state\",\nbut in fact, any error during the rebuild leaves the old vport in the\npartially allocated state.\nFinally, if the interface is down when the function is called, it always\nallocates a new queue set, but when the user decides to enable the\ninterface later on, vport_open() allocates them once again, IOW there's\na clear memory leak here.\n\nJust don't allocate a new queue set when performing a reset, that solves\ncrashes and memory leaks. Readd the old queue number and reopen the\ninterface on rollback - that solves limbo states when the device is left\ndisabled and/or without HW queues enabled.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44964"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6b289f8d91537ec1e4f9c7b38b31b90d93b1419b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f01032a2ca099ec8d619aaa916c3762aa62495df"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-2jrr-ff5x-5jqg/GHSA-2jrr-ff5x-5jqg.json b/advisories/unreviewed/2024/09/GHSA-2jrr-ff5x-5jqg/GHSA-2jrr-ff5x-5jqg.json
new file mode 100644
index 00000000000..c359fd43af0
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-2jrr-ff5x-5jqg/GHSA-2jrr-ff5x-5jqg.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2jrr-ff5x-5jqg",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44997"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb()\n\nWhen there are multiple ap interfaces on one band and with WED on,\nturning the interface down will cause a kernel panic on MT798X.\n\nPreviously, cb_priv was freed in mtk_wed_setup_tc_block() without\nmarking NULL,and mtk_wed_setup_tc_block_cb() didn't check the value, too.\n\nAssign NULL after free cb_priv in mtk_wed_setup_tc_block() and check NULL\nin mtk_wed_setup_tc_block_cb().\n\n----------\nUnable to handle kernel paging request at virtual address 0072460bca32b4f5\nCall trace:\n mtk_wed_setup_tc_block_cb+0x4/0x38\n 0xffffffc0794084bc\n tcf_block_playback_offloads+0x70/0x1e8\n tcf_block_unbind+0x6c/0xc8\n...\n---------",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44997"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/326a89321f9d5fe399fe6f9ff7c0fc766582a6a0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b453a4bbda03aa8741279c360ac82d1c3ac33548"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/db1b4bedb9b97c6d34b03d03815147c04fffe8b4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-3xwf-r3fv-8c54/GHSA-3xwf-r3fv-8c54.json b/advisories/unreviewed/2024/09/GHSA-3xwf-r3fv-8c54/GHSA-3xwf-r3fv-8c54.json
new file mode 100644
index 00000000000..024d608751c
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-3xwf-r3fv-8c54/GHSA-3xwf-r3fv-8c54.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3xwf-r3fv-8c54",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44990"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix null pointer deref in bond_ipsec_offload_ok\n\nWe must check if there is an active slave before dereferencing the pointer.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44990"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0707260a18312bbcd2a5668584e3692d0a29e3f6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2f5bdd68c1ce64bda6bef4d361a3de23b04ccd59"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/32a0173600c63aadaf2103bf02f074982e8602ab"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/81216b9352be43f8958092d379f6dec85443c309"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95c90e4ad89d493a7a14fa200082e466e2548f9d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b70b0ddfed31fc92c8dc722d0afafc8e14cb550c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json b/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json
new file mode 100644
index 00000000000..80393ba13f6
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-435p-f446-gxf4",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44995"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix a deadlock problem when config TC during resetting\n\nWhen config TC during the reset process, may cause a deadlock, the flow is\nas below:\n pf reset start\n │\n ▼\n ......\nsetup tc │\n │ ▼\n ▼ DOWN: napi_disable()\nnapi_disable()(skip) │\n │ │\n ▼ ▼\n ...... ......\n │ │\n ▼ │\nnapi_enable() │\n ▼\n UINIT: netif_napi_del()\n │\n ▼\n ......\n │\n ▼\n INIT: netif_napi_add()\n │\n ▼\n ...... global reset start\n │ │\n ▼ ▼\n UP: napi_enable()(skip) ......\n │ │\n ▼ ▼\n ...... napi_disable()\n\nIn reset process, the driver will DOWN the port and then UINIT, in this\ncase, the setup tc process will UP the port before UINIT, so cause the\nproblem. Adds a DOWN process in UINIT to fix it.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44995"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/195918217448a6bb7f929d6a2ffffce9f1ece1cc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/67492d4d105c0a6321b00c393eec96b9a7a97a16"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6ae2b7d63cd056f363045eb65409143e16f23ae8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/be5e816d00a506719e9dbb1a9c861c5ced30a109"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de37408d5c26fc4a296a28a0c96dcb814219bfa1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fa1d4de7265c370e673583ac8d1bd17d21826cd9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fc250eca15bde34c4c8f806b9d88f55bd56a992c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json b/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json
new file mode 100644
index 00000000000..a635312cdc4
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4gh9-53jc-3mcr",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44983"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: validate vlan header\n\nEnsure there is sufficient room to access the protocol field of the\nVLAN header, validate it once before the flowtable lookup.\n\n=====================================================\nBUG: KMSAN: uninit-value in nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_ingress include/linux/netfilter_netdev.h:34 [inline]\n nf_ingress net/core/dev.c:5440 [inline]",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44983"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0279c35d242d037abeb73d60d06a6d1bb7f672d9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/043a18bb6cf16adaa2f8642acfde6e8956a9caaa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6ea14ccb60c8ab829349979b22b58a941ec4a3ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c05155cc455785916164aa5e1b4605a2ae946537"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d9384ae7aec46036d248d1c2c2757e471ab486c3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json b/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json
new file mode 100644
index 00000000000..68c51433d55
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4qww-pqq9-xrw5",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44970"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink\n\nWhen all the strides in a WQE have been consumed, the WQE is unlinked\nfrom the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible\nto receive CQEs with 0 consumed strides for the same WQE even after the\nWQE is fully consumed and unlinked. This triggers an additional unlink\nfor the same wqe which corrupts the linked list.\n\nFix this scenario by accepting 0 sized consumed strides without\nunlinking the WQE again.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44970"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/50d8009a0ac02c3311b23a0066511f8337bd88d9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/650e24748e1e0a7ff91d5c72b72a2f2a452b5b76"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7b379353e9144e1f7460ff15f39862012c9d0d78"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fba8334721e266f92079632598e46e5f89082f30"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json b/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json
new file mode 100644
index 00000000000..6e514feeea2
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4w3q-gj3x-9575",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44969"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/sclp: Prevent release of buffer in I/O\n\nWhen a task waiting for completion of a Store Data operation is\ninterrupted, an attempt is made to halt this operation. If this attempt\nfails due to a hardware or firmware problem, there is a chance that the\nSCLP facility might store data into buffers referenced by the original\noperation at a later time.\n\nHandle this situation by not releasing the referenced data buffers if\nthe halt attempt fails. For current use cases, this might result in a\nleak of few pages of memory in case of a rare hardware/firmware\nmalfunction.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44969"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1e8b7fb427af6b2ddd54eff66a6b428a81c96633"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1ec5ea9e25f582fd6999393e2f2c3bf56f234e05"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2429ea3b4330e3653b72b210a0d5f2a717359506"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/46f67233b011385d53cf14d272431755de3a7c79"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7a7e60ed23d471a07dbbe72565d2992ee8244bbe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a3e52a4c22c846858a6875e1c280030a3849e148"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a88a49473c94ccfd8dce1e766aacf3c627278463"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bf365071ea92b9579d5a272679b74052a5643e35"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-53cv-6gxv-7335/GHSA-53cv-6gxv-7335.json b/advisories/unreviewed/2024/09/GHSA-53cv-6gxv-7335/GHSA-53cv-6gxv-7335.json
new file mode 100644
index 00000000000..f43acbd1ddc
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-53cv-6gxv-7335/GHSA-53cv-6gxv-7335.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-53cv-6gxv-7335",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44992"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: avoid possible NULL dereference in cifs_free_subrequest()\n\nClang static checker (scan-build) warning:\n\tcifsglob.h:line 890, column 3\n\tAccess to field 'ops' results in a dereference of a null pointer.\n\nCommit 519be989717c (\"cifs: Add a tracepoint to track credits involved in\nR/W requests\") adds a check for 'rdata->server', and let clang throw this\nwarning about NULL dereference.\n\nWhen 'rdata->credits.value != 0 && rdata->server == NULL' happens,\nadd_credits_and_wake_if() will call rdata->server->ops->add_credits().\nThis will cause NULL dereference problem. Add a check for 'rdata->server'\nto avoid NULL dereference.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44992"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/74c2ab6d653b4c2354df65a7f7f2df1925a40a51"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fead60a6d5f84b472b928502a42c419253afe6c1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-53vj-vrwf-hv43/GHSA-53vj-vrwf-hv43.json b/advisories/unreviewed/2024/09/GHSA-53vj-vrwf-hv43/GHSA-53vj-vrwf-hv43.json
new file mode 100644
index 00000000000..2b3c81d9920
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-53vj-vrwf-hv43/GHSA-53vj-vrwf-hv43.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-53vj-vrwf-hv43",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44976"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: pata_macio: Fix DMA table overflow\n\nKolbjørn and Jonáš reported that their 32-bit PowerMacs were crashing\nin pata-macio since commit 09fe2bfa6b83 (\"ata: pata_macio: Fix\nmax_segment_size with PAGE_SIZE == 64K\").\n\nFor example:\n\n kernel BUG at drivers/ata/pata_macio.c:544!\n Oops: Exception in kernel mode, sig: 5 [#1]\n BE PAGE_SIZE=4K MMU=Hash SMP NR_CPUS=2 DEBUG_PAGEALLOC PowerMac\n ...\n NIP pata_macio_qc_prep+0xf4/0x190\n LR pata_macio_qc_prep+0xfc/0x190\n Call Trace:\n 0xc1421660 (unreliable)\n ata_qc_issue+0x14c/0x2d4\n __ata_scsi_queuecmd+0x200/0x53c\n ata_scsi_queuecmd+0x50/0xe0\n scsi_queue_rq+0x788/0xb1c\n __blk_mq_issue_directly+0x58/0xf4\n blk_mq_plug_issue_direct+0x8c/0x1b4\n blk_mq_flush_plug_list.part.0+0x584/0x5e0\n __blk_flush_plug+0xf8/0x194\n __submit_bio+0x1b8/0x2e0\n submit_bio_noacct_nocheck+0x230/0x304\n btrfs_work_helper+0x200/0x338\n process_one_work+0x1a8/0x338\n worker_thread+0x364/0x4c0\n kthread+0x100/0x104\n start_kernel_thread+0x10/0x14\n\nThat commit increased max_segment_size to 64KB, with the justification\nthat the SCSI core was already using that size when PAGE_SIZE == 64KB,\nand that there was existing logic to split over-sized requests.\n\nHowever with a sufficiently large request, the splitting logic causes\neach sg to be split into two commands in the DMA table, leading to\noverflow of the DMA table, triggering the BUG_ON().\n\nWith default settings the bug doesn't trigger, because the request size\nis limited by max_sectors_kb == 1280, however max_sectors_kb can be\nincreased, and apparently some distros do that by default using udev\nrules.\n\nFix the bug for 4KB kernels by reverting to the old max_segment_size.\n\nFor 64KB kernels the sg_tablesize needs to be halved, to allow for the\npossibility that each sg will be split into two.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44976"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/709e4c8f78e156ab332297bdd87527ec3da4e2d4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/822c8020aebcf5804a143b891e34f29873fee5e2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-5822-38r8-r5p2/GHSA-5822-38r8-r5p2.json b/advisories/unreviewed/2024/09/GHSA-5822-38r8-r5p2/GHSA-5822-38r8-r5p2.json
new file mode 100644
index 00000000000..49f35a7b854
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-5822-38r8-r5p2/GHSA-5822-38r8-r5p2.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5822-38r8-r5p2",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44952"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: Fix uevent_show() vs driver detach race\n\nuevent_show() wants to de-reference dev->driver->name. There is no clean\nway for a device attribute to de-reference dev->driver unless that\nattribute is defined via (struct device_driver).dev_groups. Instead, the\nanti-pattern of taking the device_lock() in the attribute handler risks\ndeadlocks with code paths that remove device attributes while holding\nthe lock.\n\nThis deadlock is typically invisible to lockdep given the device_lock()\nis marked lockdep_set_novalidate_class(), but some subsystems allocate a\nlocal lockdep key for @dev->mutex to reveal reports of the form:\n\n ======================================================\n WARNING: possible circular locking dependency detected\n 6.10.0-rc7+ #275 Tainted: G OE N\n ------------------------------------------------------\n modprobe/2374 is trying to acquire lock:\n ffff8c2270070de0 (kn->active#6){++++}-{0:0}, at: __kernfs_remove+0xde/0x220\n\n but task is already holding lock:\n ffff8c22016e88f8 (&cxl_root_key){+.+.}-{3:3}, at: device_release_driver_internal+0x39/0x210\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #1 (&cxl_root_key){+.+.}-{3:3}:\n __mutex_lock+0x99/0xc30\n uevent_show+0xac/0x130\n dev_attr_show+0x18/0x40\n sysfs_kf_seq_show+0xac/0xf0\n seq_read_iter+0x110/0x450\n vfs_read+0x25b/0x340\n ksys_read+0x67/0xf0\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n -> #0 (kn->active#6){++++}-{0:0}:\n __lock_acquire+0x121a/0x1fa0\n lock_acquire+0xd6/0x2e0\n kernfs_drain+0x1e9/0x200\n __kernfs_remove+0xde/0x220\n kernfs_remove_by_name_ns+0x5e/0xa0\n device_del+0x168/0x410\n device_unregister+0x13/0x60\n devres_release_all+0xb8/0x110\n device_unbind_cleanup+0xe/0x70\n device_release_driver_internal+0x1c7/0x210\n driver_detach+0x47/0x90\n bus_remove_driver+0x6c/0xf0\n cxl_acpi_exit+0xc/0x11 [cxl_acpi]\n __do_sys_delete_module.isra.0+0x181/0x260\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe observation though is that driver objects are typically much longer\nlived than device objects. It is reasonable to perform lockless\nde-reference of a @driver pointer even if it is racing detach from a\ndevice. Given the infrequency of driver unregistration, use\nsynchronize_rcu() in module_remove_driver() to close any potential\nraces. It is potentially overkill to suffer synchronize_rcu() just to\nhandle the rare module removal racing uevent_show() event.\n\nThanks to Tetsuo Handa for the debug analysis of the syzbot report [1].",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44952"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/15fffc6a5624b13b428bb1c6e9088e32a55eb82c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/49ea4e0d862632d51667da5e7a9c88a560e9c5a1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4a7c2a8387524942171037e70b80e969c3b5c05b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4d035c743c3e391728a6f81cbf0f7f9ca700cf62"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9c23fc327d6ec67629b4ad323bd64d3834c0417d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cd490a247ddf325325fd0de8898659400c9237ef"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dd98c9630b7ee273da87e9a244f94ddf947161e2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f098e8fc7227166206256c18d56ab622039108b1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-59fp-j85q-63j4/GHSA-59fp-j85q-63j4.json b/advisories/unreviewed/2024/09/GHSA-59fp-j85q-63j4/GHSA-59fp-j85q-63j4.json
new file mode 100644
index 00000000000..f77953da9d1
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-59fp-j85q-63j4/GHSA-59fp-j85q-63j4.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-59fp-j85q-63j4",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44982"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: cleanup FB if dpu_format_populate_layout fails\n\nIf the dpu_format_populate_layout() fails, then FB is prepared, but not\ncleaned up. This ends up leaking the pin_count on the GEM object and\ncauses a splat during DRM file closure:\n\nmsm_obj->pin_count\nWARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc\n[...]\nCall trace:\n update_lru_locked+0xc4/0xcc\n put_pages+0xac/0x100\n msm_gem_free_object+0x138/0x180\n drm_gem_object_free+0x1c/0x30\n drm_gem_object_handle_put_unlocked+0x108/0x10c\n drm_gem_object_release_handle+0x58/0x70\n idr_for_each+0x68/0xec\n drm_gem_release+0x28/0x40\n drm_file_free+0x174/0x234\n drm_release+0xb0/0x160\n __fput+0xc0/0x2c8\n __fput_sync+0x50/0x5c\n __arm64_sys_close+0x38/0x7c\n invoke_syscall+0x48/0x118\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x4c/0x120\n el0t_64_sync_handler+0x100/0x12c\n el0t_64_sync+0x190/0x194\nirq event stamp: 129818\nhardirqs last enabled at (129817): [] console_unlock+0x118/0x124\nhardirqs last disabled at (129818): [] el1_dbg+0x24/0x8c\nsoftirqs last enabled at (129808): [] handle_softirqs+0x4c8/0x4e8\nsoftirqs last disabled at (129785): [] __do_softirq+0x14/0x20\n\nPatchwork: https://patchwork.freedesktop.org/patch/600714/",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44982"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/02193c70723118889281f75b88722b26b58bf4ae"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7ecf85542169012765e4c2817cd3be6c2e009962"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9b8b65211a880af8fe8330a101e1e239a2d4008f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a3c5815b07f4ee19d0b7e2ddf91ff9f03ecbf27d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bfa1a6283be390947d3649c482e5167186a37016"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json b/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json
new file mode 100644
index 00000000000..c1daa34a61e
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-5fw5-93q4-68pf/GHSA-5fw5-93q4-68pf.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5fw5-93q4-68pf",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44981"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nworkqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask()\n\nUBSAN reports the following 'subtraction overflow' error when booting\nin a virtual machine on Android:\n\n | Internal error: UBSAN: integer subtraction overflow: 00000000f2005515 [#1] PREEMPT SMP\n | Modules linked in:\n | CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.10.0-00006-g3cbe9e5abd46-dirty #4\n | Hardware name: linux,dummy-virt (DT)\n | pstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n | pc : cancel_delayed_work+0x34/0x44\n | lr : cancel_delayed_work+0x2c/0x44\n | sp : ffff80008002ba60\n | x29: ffff80008002ba60 x28: 0000000000000000 x27: 0000000000000000\n | x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n | x23: 0000000000000000 x22: 0000000000000000 x21: ffff1f65014cd3c0\n | x20: ffffc0e84c9d0da0 x19: ffffc0e84cab3558 x18: ffff800080009058\n | x17: 00000000247ee1f8 x16: 00000000247ee1f8 x15: 00000000bdcb279d\n | x14: 0000000000000001 x13: 0000000000000075 x12: 00000a0000000000\n | x11: ffff1f6501499018 x10: 00984901651fffff x9 : ffff5e7cc35af000\n | x8 : 0000000000000001 x7 : 3d4d455453595342 x6 : 000000004e514553\n | x5 : ffff1f6501499265 x4 : ffff1f650ff60b10 x3 : 0000000000000620\n | x2 : ffff80008002ba78 x1 : 0000000000000000 x0 : 0000000000000000\n | Call trace:\n | cancel_delayed_work+0x34/0x44\n | deferred_probe_extend_timeout+0x20/0x70\n | driver_register+0xa8/0x110\n | __platform_driver_register+0x28/0x3c\n | syscon_init+0x24/0x38\n | do_one_initcall+0xe4/0x338\n | do_initcall_level+0xac/0x178\n | do_initcalls+0x5c/0xa0\n | do_basic_setup+0x20/0x30\n | kernel_init_freeable+0x8c/0xf8\n | kernel_init+0x28/0x1b4\n | ret_from_fork+0x10/0x20\n | Code: f9000fbf 97fffa2f 39400268 37100048 (d42aa2a0)\n | ---[ end trace 0000000000000000 ]---\n | Kernel panic - not syncing: UBSAN: integer subtraction overflow: Fatal exception\n\nThis is due to shift_and_mask() using a signed immediate to construct\nthe mask and being called with a shift of 31 (WORK_OFFQ_POOL_SHIFT) so\nthat it ends up decrementing from INT_MIN.\n\nUse an unsigned constant '1U' to generate the mask in shift_and_mask().",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44981"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/38f7e14519d39cf524ddc02d4caee9b337dad703"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/90a6a844b2d9927d192758438a4ada33d8cd9de5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-727x-p98c-5cg7/GHSA-727x-p98c-5cg7.json b/advisories/unreviewed/2024/09/GHSA-727x-p98c-5cg7/GHSA-727x-p98c-5cg7.json
new file mode 100644
index 00000000000..290efca5dad
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-727x-p98c-5cg7/GHSA-727x-p98c-5cg7.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-727x-p98c-5cg7",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44998"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\natm: idt77252: prevent use after free in dequeue_rx()\n\nWe can't dereference \"skb\" after calling vcc->push() because the skb\nis released.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44998"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/09e086a5f72ea27c758b3f3b419a69000c32adc1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1cece837e387c039225f19028df255df87a97c0d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/24cf390a5426aac9255205e9533cdd7b4235d518"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/379a6a326514a3e2f71b674091dfb0e0e7522b55"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/628ea82190a678a56d2ec38cda3addf3b3a6248d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/91b4850e7165a4b7180ef1e227733bcb41ccdf10"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a9a18e8f770c9b0703dab93580d0b02e199a4c79"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef23c18ab88e33ce000d06a5c6aad0620f219bfd"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json b/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json
new file mode 100644
index 00000000000..ea3958f2a74
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7h55-66vh-33gg",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45007"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Don't destroy workqueue from work item running on it\n\nTriggered by a kref decrement, destroy_workqueue() may be called from\nwithin a work item for destroying its own workqueue. This illegal\nsituation is averted by adding a module-global workqueue for exclusive\nuse of the offending work item. Other work items continue to be queued\non per-device workqueues to ensure performance.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45007"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/409b495f8e3300d5fba08bc817fa8825dae48cc9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5d3567caff2a1d678aa40cc74a54e1318941fad3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7ad105b12256ec7fb6d6d1a0e2e60f00b7da157"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aa1a19724fa2c31e97a9be48baedd4692b265157"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ccbde4b128ef9c73d14d0d7817d68ef795f6d131"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7hqv-cx6x-h3c9/GHSA-7hqv-cx6x-h3c9.json b/advisories/unreviewed/2024/09/GHSA-7hqv-cx6x-h3c9/GHSA-7hqv-cx6x-h3c9.json
new file mode 100644
index 00000000000..4c00b7cce90
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7hqv-cx6x-h3c9/GHSA-7hqv-cx6x-h3c9.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7hqv-cx6x-h3c9",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44994"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu: Restore lost return in iommu_report_device_fault()\n\nWhen iommu_report_device_fault gets called with a partial fault it is\nsupposed to collect the fault into the group and then return.\n\nInstead the return was accidently deleted which results in trying to\nprocess the fault and an eventual crash.\n\nDeleting the return was a typo, put it back.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44994"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cc6bc2ab1663ec9353636416af22452b078510e9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fca5b78511e98bdff2cdd55c172b23200a7b3404"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7m5m-jw3r-vxv2/GHSA-7m5m-jw3r-vxv2.json b/advisories/unreviewed/2024/09/GHSA-7m5m-jw3r-vxv2/GHSA-7m5m-jw3r-vxv2.json
new file mode 100644
index 00000000000..1e948e6bf72
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7m5m-jw3r-vxv2/GHSA-7m5m-jw3r-vxv2.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7m5m-jw3r-vxv2",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44958"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/smt: Fix unbalance sched_smt_present dec/inc\n\nI got the following warn report while doing stress test:\n\njump label: negative count!\nWARNING: CPU: 3 PID: 38 at kernel/jump_label.c:263 static_key_slow_try_dec+0x9d/0xb0\nCall Trace:\n \n __static_key_slow_dec_cpuslocked+0x16/0x70\n sched_cpu_deactivate+0x26e/0x2a0\n cpuhp_invoke_callback+0x3ad/0x10d0\n cpuhp_thread_fun+0x3f5/0x680\n smpboot_thread_fn+0x56d/0x8d0\n kthread+0x309/0x400\n ret_from_fork+0x41/0x70\n ret_from_fork_asm+0x1b/0x30\n \n\nBecause when cpuset_cpu_inactive() fails in sched_cpu_deactivate(),\nthe cpu offline failed, but sched_smt_present is decremented before\ncalling sched_cpu_deactivate(), it leads to unbalanced dec/inc, so\nfix it by incrementing sched_smt_present in the error path.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44958"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a3548c7ef2e135aee40e7e5e44e7d11b893e7c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2cf7665efe451e48d27953e6b5bc627d518c902b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/65727331b60197b742089855ac09464c22b96f66"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d0c87a3c6be10a57aa3463c32c3fc6b2a47c3dab"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7p6j-4w59-cjvv/GHSA-7p6j-4w59-cjvv.json b/advisories/unreviewed/2024/09/GHSA-7p6j-4w59-cjvv/GHSA-7p6j-4w59-cjvv.json
new file mode 100644
index 00000000000..58d5fb49637
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7p6j-4w59-cjvv/GHSA-7p6j-4w59-cjvv.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7p6j-4w59-cjvv",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44948"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mtrr: Check if fixed MTRRs exist before saving them\n\nMTRRs have an obsolete fixed variant for fine grained caching control\nof the 640K-1MB region that uses separate MSRs. This fixed variant has\na separate capability bit in the MTRR capability MSR.\n\nSo far all x86 CPUs which support MTRR have this separate bit set, so it\nwent unnoticed that mtrr_save_state() does not check the capability bit\nbefore accessing the fixed MTRR MSRs.\n\nThough on a CPU that does not support the fixed MTRR capability this\nresults in a #GP. The #GP itself is harmless because the RDMSR fault is\nhandled gracefully, but results in a WARN_ON().\n\nAdd the missing capability check to prevent this.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44948"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/06c1de44d378ec5439db17bf476507d68589bfe9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/388f1c954019f253a8383f7eb733f38d541e10b6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/450b6b22acdaac67a18eaf5ed498421ffcf10051"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8a90d3fc7c24608548d3a750671f9dac21d1a462"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8aa79dfb216b865e96ff890bc4ea71650f9bc8d7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/919f18f961c03d6694aa726c514184f2311a4614"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ca7d00c5656d1791e28369919e3e10febe9c3b16"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-7q5q-96vf-8rg6/GHSA-7q5q-96vf-8rg6.json b/advisories/unreviewed/2024/09/GHSA-7q5q-96vf-8rg6/GHSA-7q5q-96vf-8rg6.json
new file mode 100644
index 00000000000..436090ca3a9
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-7q5q-96vf-8rg6/GHSA-7q5q-96vf-8rg6.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7q5q-96vf-8rg6",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45002"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtla/osnoise: Prevent NULL dereference in error handling\n\nIf the \"tool->data\" allocation fails then there is no need to call\nosnoise_free_top() and, in fact, doing so will lead to a NULL dereference.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45002"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/753f1745146e03abd17eec8eee95faffc96d743d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/90574d2a675947858b47008df8d07f75ea50d0d0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/abdb9ddaaab476e62805e36cce7b4ef8413ffd01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fc575212c6b75d538e1a0a74f4c7e2ac73bc46ac"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json b/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json
new file mode 100644
index 00000000000..6830675d8d2
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-82q8-gr92-pr6w",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45008"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: MT - limit max slots\n\nsyzbot is reporting too large allocation at input_mt_init_slots(), for\nnum_slots is supplied from userspace using ioctl(UI_DEV_CREATE).\n\nSince nobody knows possible max slots, this patch chose 1024.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45008"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/05dd9aabd04f9b5eb04dab9bb83d8c3e982d7549"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2829c80614890624456337e47320289112785f3e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/87f610a1a7fbdb1f2e3d90b54c955bd3b8a0c322"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8f04edd554d191834e9e1349ef030318ea6b11ba"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/94736334b8a25e4fae8daa6934e54a31f099be43"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95f73d01f547dfc67fda3022c51e377a0454b505"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cd19f1799c32ba7b874474b1b968815ce5364f73"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-8px8-w879-9rmh/GHSA-8px8-w879-9rmh.json b/advisories/unreviewed/2024/09/GHSA-8px8-w879-9rmh/GHSA-8px8-w879-9rmh.json
new file mode 100644
index 00000000000..155c6987e0e
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-8px8-w879-9rmh/GHSA-8px8-w879-9rmh.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8px8-w879-9rmh",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44965"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Fix pti_clone_pgtable() alignment assumption\n\nGuenter reported dodgy crashes on an i386-nosmp build using GCC-11\nthat had the form of endless traps until entry stack exhaust and then\n#DF from the stack guard.\n\nIt turned out that pti_clone_pgtable() had alignment assumptions on\nthe start address, notably it hard assumes start is PMD aligned. This\nis true on x86_64, but very much not true on i386.\n\nThese assumptions can cause the end condition to malfunction, leading\nto a 'short' clone. Guess what happens when the user mapping has a\nshort copy of the entry text?\n\nUse the correct increment form for addr to avoid alignment\nassumptions.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44965"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/18da1b27ce16a14a9b636af9232acb4fb24f4c9e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/25a727233a40a9b33370eec9f0cad67d8fd312f8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/41e71dbb0e0a0fe214545fe64af031303a08524c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4d143ae782009b43b4f366402e5c37f59d4e4346"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5c580c1050bcbc15c3e78090859d798dcf8c9763"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ca07aab70dd3b5e7fddb62d7a6ecd7a7d6d0b2ed"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d00c9b4bbc442d99e1dafbdfdab848bc1ead73f6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/df3eecb5496f87263d171b254ca6e2758ab3c35c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json b/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json
new file mode 100644
index 00000000000..7e5901c1ed5
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9388-m6c7-2394",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44963"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not BUG_ON() when freeing tree block after error\n\nWhen freeing a tree block, at btrfs_free_tree_block(), if we fail to\ncreate a delayed reference we don't deal with the error and just do a\nBUG_ON(). The error most likely to happen is -ENOMEM, and we have a\ncomment mentioning that only -ENOMEM can happen, but that is not true,\nbecause in case qgroups are enabled any error returned from\nbtrfs_qgroup_trace_extent_post() (can be -EUCLEAN or anything returned\nfrom btrfs_search_slot() for example) can be propagated back to\nbtrfs_free_tree_block().\n\nSo stop doing a BUG_ON() and return the error to the callers and make\nthem abort the transaction to prevent leaking space. Syzbot was\ntriggering this, likely due to memory allocation failure injection.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44963"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/98251cd60b4d702a8a81de442ab621e83a3fb24f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bb3868033a4cccff7be57e9145f2117cbdc91c11"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-9p8f-qh7p-793j/GHSA-9p8f-qh7p-793j.json b/advisories/unreviewed/2024/09/GHSA-9p8f-qh7p-793j/GHSA-9p8f-qh7p-793j.json
new file mode 100644
index 00000000000..fc32117d1ba
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-9p8f-qh7p-793j/GHSA-9p8f-qh7p-793j.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9p8f-qh7p-793j",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-45001"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix RX buf alloc_size alignment and atomic op panic\n\nThe MANA driver's RX buffer alloc_size is passed into napi_build_skb() to\ncreate SKB. skb_shinfo(skb) is located at the end of skb, and its alignment\nis affected by the alloc_size passed into napi_build_skb(). The size needs\nto be aligned properly for better performance and atomic operations.\nOtherwise, on ARM64 CPU, for certain MTU settings like 4000, atomic\noperations may panic on the skb_shinfo(skb)->dataref due to alignment fault.\n\nTo fix this bug, add proper alignment to the alloc_size calculation.\n\nSample panic info:\n[ 253.298819] Unable to handle kernel paging request at virtual address ffff000129ba5cce\n[ 253.300900] Mem abort info:\n[ 253.301760] ESR = 0x0000000096000021\n[ 253.302825] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 253.304268] SET = 0, FnV = 0\n[ 253.305172] EA = 0, S1PTW = 0\n[ 253.306103] FSC = 0x21: alignment fault\nCall trace:\n __skb_clone+0xfc/0x198\n skb_clone+0x78/0xe0\n raw6_local_deliver+0xfc/0x228\n ip6_protocol_deliver_rcu+0x80/0x500\n ip6_input_finish+0x48/0x80\n ip6_input+0x48/0xc0\n ip6_sublist_rcv_finish+0x50/0x78\n ip6_sublist_rcv+0x1cc/0x2b8\n ipv6_list_rcv+0x100/0x150\n __netif_receive_skb_list_core+0x180/0x220\n netif_receive_skb_list_internal+0x198/0x2a8\n __napi_poll+0x138/0x250\n net_rx_action+0x148/0x330\n handle_softirqs+0x12c/0x3a0",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45001"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/32316f676b4ee87c0404d333d248ccf777f739bc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/65f20b174ec0172f2d6bcfd8533ab9c9e7e347fa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e6bea6a45f8a401f3d5a430bc81814f0cc8848cf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-cj8h-mjwg-43cc/GHSA-cj8h-mjwg-43cc.json b/advisories/unreviewed/2024/09/GHSA-cj8h-mjwg-43cc/GHSA-cj8h-mjwg-43cc.json
new file mode 100644
index 00000000000..f3f9d88ab95
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-cj8h-mjwg-43cc/GHSA-cj8h-mjwg-43cc.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cj8h-mjwg-43cc",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45005"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: fix validity interception issue when gisa is switched off\n\nWe might run into a SIE validity if gisa has been disabled either via using\nkernel parameter \"kvm.use_gisa=0\" or by setting the related sysfs\nattribute to N (echo N >/sys/module/kvm/parameters/use_gisa).\n\nThe validity is caused by an invalid value in the SIE control block's\ngisa designation. That happens because we pass the uninitialized gisa\norigin to virt_to_phys() before writing it to the gisa designation.\n\nTo fix this we return 0 in kvm_s390_get_gisa_desc() if the origin is 0.\nkvm_s390_get_gisa_desc() is used to determine which gisa designation to\nset in the SIE control block. A value of 0 in the gisa designation disables\ngisa usage.\n\nThe issue surfaces in the host kernel with the following kernel message as\nsoon a new kvm guest start is attemted.\n\nkvm: unhandled validity intercept 0x1011\nWARNING: CPU: 0 PID: 781237 at arch/s390/kvm/intercept.c:101 kvm_handle_sie_intercept+0x42e/0x4d0 [kvm]\nModules linked in: vhost_net tap tun xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT xt_tcpudp nft_compat x_tables nf_nat_tftp nf_conntrack_tftp vfio_pci_core irqbypass vhost_vsock vmw_vsock_virtio_transport_common vsock vhost vhost_iotlb kvm nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables sunrpc mlx5_ib ib_uverbs ib_core mlx5_core uvdevice s390_trng eadm_sch vfio_ccw zcrypt_cex4 mdev vfio_iommu_type1 vfio sch_fq_codel drm i2c_core loop drm_panel_orientation_quirks configfs nfnetlink lcs ctcm fsm dm_service_time ghash_s390 prng chacha_s390 libchacha aes_s390 des_s390 libdes sha3_512_s390 sha3_256_s390 sha512_s390 sha256_s390 sha1_s390 sha_common dm_mirror dm_region_hash dm_log zfcp scsi_transport_fc scsi_dh_rdac scsi_dh_emc scsi_dh_alua pkey zcrypt dm_multipath rng_core autofs4 [last unloaded: vfio_pci]\nCPU: 0 PID: 781237 Comm: CPU 0/KVM Not tainted 6.10.0-08682-gcad9f11498ea #6\nHardware name: IBM 3931 A01 701 (LPAR)\nKrnl PSW : 0704c00180000000 000003d93deb0122 (kvm_handle_sie_intercept+0x432/0x4d0 [kvm])\n R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:0 PM:0 RI:0 EA:3\nKrnl GPRS: 000003d900000027 000003d900000023 0000000000000028 000002cd00000000\n 000002d063a00900 00000359c6daf708 00000000000bebb5 0000000000001eff\n 000002cfd82e9000 000002cfd80bc000 0000000000001011 000003d93deda412\n 000003ff8962df98 000003d93de77ce0 000003d93deb011e 00000359c6daf960\nKrnl Code: 000003d93deb0112: c020fffe7259\tlarl\t%r2,000003d93de7e5c4\n 000003d93deb0118: c0e53fa8beac\tbrasl\t%r14,000003d9bd3c7e70\n #000003d93deb011e: af000000\t\tmc\t0,0\n >000003d93deb0122: a728ffea\t\tlhi\t%r2,-22\n 000003d93deb0126: a7f4fe24\t\tbrc\t15,000003d93deafd6e\n 000003d93deb012a: 9101f0b0\t\ttm\t176(%r15),1\n 000003d93deb012e: a774fe48\t\tbrc\t7,000003d93deafdbe\n 000003d93deb0132: 40a0f0ae\t\tsth\t%r10,174(%r15)\nCall Trace:\n [<000003d93deb0122>] kvm_handle_sie_intercept+0x432/0x4d0 [kvm]\n([<000003d93deb011e>] kvm_handle_sie_intercept+0x42e/0x4d0 [kvm])\n [<000003d93deacc10>] vcpu_post_run+0x1d0/0x3b0 [kvm]\n [<000003d93deaceda>] __vcpu_run+0xea/0x2d0 [kvm]\n [<000003d93dead9da>] kvm_arch_vcpu_ioctl_run+0x16a/0x430 [kvm]\n [<000003d93de93ee0>] kvm_vcpu_ioctl+0x190/0x7c0 [kvm]\n [<000003d9bd728b4e>] vfs_ioctl+0x2e/0x70\n [<000003d9bd72a092>] __s390x_sys_ioctl+0xc2/0xd0\n [<000003d9be0e9222>] __do_syscall+0x1f2/0x2e0\n [<000003d9be0f9a90>] system_call+0x70/0x98\nLast Breaking-Event-Address:\n [<000003d9bd3c7f58>] __warn_printk+0xe8/0xf0",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45005"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/027ac3c5092561bccce09b314a73a1c167117ef6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/051c0a558154174cfcea301a386e4c91ade83ce1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a44bb061d04b0306f2aa8add761d86d152b9377"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-cm9j-4q8h-89pr/GHSA-cm9j-4q8h-89pr.json b/advisories/unreviewed/2024/09/GHSA-cm9j-4q8h-89pr/GHSA-cm9j-4q8h-89pr.json
new file mode 100644
index 00000000000..e4b959a8373
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-cm9j-4q8h-89pr/GHSA-cm9j-4q8h-89pr.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cm9j-4q8h-89pr",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44980"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix opregion leak\n\nBeing part o the display, ideally the setup and cleanup would be done by\ndisplay itself. However this is a bigger refactor that needs to be done\non both i915 and xe. For now, just fix the leak:\n\nunreferenced object 0xffff8881a0300008 (size 192):\n comm \"modprobe\", pid 4354, jiffies 4295647021\n hex dump (first 32 bytes):\n 00 00 87 27 81 88 ff ff 18 80 9b 00 00 c9 ff ff ...'............\n 18 81 9b 00 00 c9 ff ff 00 00 00 00 00 00 00 00 ................\n backtrace (crc 99260e31):\n [] kmemleak_alloc+0x4b/0x80\n [] kmalloc_trace_noprof+0x312/0x3d0\n [] intel_opregion_setup+0x89/0x700 [xe]\n [] xe_display_init_noirq+0x2f/0x90 [xe]\n [] xe_device_probe+0x7a3/0xbf0 [xe]\n [] xe_pci_probe+0x333/0x5b0 [xe]\n [] local_pci_probe+0x48/0xb0\n [] pci_device_probe+0xc8/0x280\n [] really_probe+0xf8/0x390\n [] __driver_probe_device+0x8a/0x170\n [] driver_probe_device+0x23/0xb0\n [] __driver_attach+0xc7/0x190\n [] bus_for_each_dev+0x7d/0xd0\n [] driver_attach+0x1e/0x30\n [] bus_add_driver+0x117/0x250\n\n(cherry picked from commit 6f4e43a2f771b737d991142ec4f6d4b7ff31fbb4)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44980"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f7ecdd9853dd9f34e7cdfdadfb70b8f40644ebb4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json b/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json
new file mode 100644
index 00000000000..0463775b386
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f3vh-8mjp-cx6c",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44972"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not clear page dirty inside extent_write_locked_range()\n\n[BUG]\nFor subpage + zoned case, the following workload can lead to rsv data\nleak at unmount time:\n\n # mkfs.btrfs -f -s 4k $dev\n # mount $dev $mnt\n # fsstress -w -n 8 -d $mnt -s 1709539240\n 0/0: fiemap - no filename\n 0/1: copyrange read - no filename\n 0/2: write - no filename\n 0/3: rename - no source filename\n 0/4: creat f0 x:0 0 0\n 0/4: creat add id=0,parent=-1\n 0/5: writev f0[259 1 0 0 0 0] [778052,113,965] 0\n 0/6: ioctl(FIEMAP) f0[259 1 0 0 224 887097] [1294220,2291618343991484791,0x10000] -1\n 0/7: dwrite - xfsctl(XFS_IOC_DIOINFO) f0[259 1 0 0 224 887097] return 25, fallback to stat()\n 0/7: dwrite f0[259 1 0 0 224 887097] [696320,102400] 0\n # umount $mnt\n\nThe dmesg includes the following rsv leak detection warning (all call\ntrace skipped):\n\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8653 btrfs_destroy_inode+0x1e0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8654 btrfs_destroy_inode+0x1a8/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8660 btrfs_destroy_inode+0x1a0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): last unmount of filesystem 1b4abba9-de34-4f07-9e7f-157cf12a18d6\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info DATA has 268218368 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=204800, pinned=0, reserved=0, may_use=12288, readonly=0 zone_unusable=0\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info METADATA has 267796480 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=131072, pinned=0, reserved=0, may_use=262144, readonly=0 zone_unusable=245760\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n\nAbove $dev is a tcmu-runner emulated zoned HDD, which has a max zone\nappend size of 64K, and the system has 64K page size.\n\n[CAUSE]\nI have added several trace_printk() to show the events (header skipped):\n\n > btrfs_dirty_pages: r/i=5/259 dirty start=774144 len=114688\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=720896 off_in_page=53248 len_in_page=12288\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=786432 off_in_page=0 len_in_page=65536\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=851968 off_in_page=0 len_in_page=36864\n\nThe above lines show our buffered write has dirtied 3 pages of inode\n259 of root 5:\n\n 704K 768K 832K 896K\n I |////I/////////////////I///////////| I\n 756K 868K\n\n |///| is the dirtied range using subpage bitmaps. and 'I' is the page\n boundary.\n\n Meanwhile all three pages (704K, 768K, 832K) have their PageDirty\n flag set.\n\n > btrfs_direct_write: r/i=5/259 start dio filepos=696320 len=102400\n\nThen direct IO writ\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44972"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/97713b1a2ced1e4a2a6c40045903797ebd44d7e0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ba4dedb71356638d8284e34724daca944be70368"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3b403209f767e5857c1b9fda66726e6e6ffc99f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json b/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json
new file mode 100644
index 00000000000..060a36c470b
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-fv74-m98x-m3w2/GHSA-fv74-m98x-m3w2.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fv74-m98x-m3w2",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44985"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible UAF in ip6_xmit()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand the associated dst/idev could also have been freed.\n\nWe must use rcu_read_lock() to prevent a possible UAF.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44985"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/124b428fe28064c809e4237b0b38e97200a8a4a8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2d5ff7e339d04622d8282661df36151906d0e1c7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/38a21c026ed2cc7232414cb166efc1923f34af17"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/975f764e96f71616b530e300c1bb2ac0ce0c2596"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fc88d6c1f2895a5775795d82ec581afdff7661d1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json b/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json
new file mode 100644
index 00000000000..768a65b9a22
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fxwr-6hqv-m4wv",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-42642"
+ ],
+ "details": "Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42642"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/VL4DR/CVE-2024-42642/tree/main"
+ },
+ {
+ "type": "WEB",
+ "url": "http://microncrucial.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json b/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json
new file mode 100644
index 00000000000..ea095231e8e
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g477-g2gm-cjmf",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44953"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix deadlock during RTC update\n\nThere is a deadlock when runtime suspend waits for the flush of RTC work,\nand the RTC work calls ufshcd_rpm_get_sync() to wait for runtime resume.\n\nHere is deadlock backtrace:\n\nkworker/0:1 D 4892.876354 10 10971 4859 0x4208060 0x8 10 0 120 670730152367\nptr f0ffff80c2e40000 0 1 0x00000001 0x000000ff 0x000000ff 0x000000ff\n __switch_to+0x1a8/0x2d4\n __schedule+0x684/0xa98\n schedule+0x48/0xc8\n schedule_timeout+0x48/0x170\n do_wait_for_common+0x108/0x1b0\n wait_for_completion+0x44/0x60\n __flush_work+0x39c/0x424\n __cancel_work_sync+0xd8/0x208\n cancel_delayed_work_sync+0x14/0x28\n __ufshcd_wl_suspend+0x19c/0x480\n ufshcd_wl_runtime_suspend+0x3c/0x1d4\n scsi_runtime_suspend+0x78/0xc8\n __rpm_callback+0x94/0x3e0\n rpm_suspend+0x2d4/0x65c\n __pm_runtime_suspend+0x80/0x114\n scsi_runtime_idle+0x38/0x6c\n rpm_idle+0x264/0x338\n __pm_runtime_idle+0x80/0x110\n ufshcd_rtc_work+0x128/0x1e4\n process_one_work+0x26c/0x650\n worker_thread+0x260/0x3d8\n kthread+0x110/0x134\n ret_from_fork+0x10/0x20\n\nSkip updating RTC if RPM state is not RPM_ACTIVE.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44953"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3911af778f208e5f49d43ce739332b91e26bc48e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f13f1858a28c68b7fc0d72c2008d5c1f80d2e8d5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-g596-f5rr-4qjp/GHSA-g596-f5rr-4qjp.json b/advisories/unreviewed/2024/09/GHSA-g596-f5rr-4qjp/GHSA-g596-f5rr-4qjp.json
new file mode 100644
index 00000000000..9282c1ce0c9
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-g596-f5rr-4qjp/GHSA-g596-f5rr-4qjp.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g596-f5rr-4qjp",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45004"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: dcp: fix leak of blob encryption key\n\nTrusted keys unseal the key blob on load, but keep the sealed payload in\nthe blob field so that every subsequent read (export) will simply\nconvert this field to hex and send it to userspace.\n\nWith DCP-based trusted keys, we decrypt the blob encryption key (BEK)\nin the Kernel due hardware limitations and then decrypt the blob payload.\nBEK decryption is done in-place which means that the trusted key blob\nfield is modified and it consequently holds the BEK in plain text.\nEvery subsequent read of that key thus send the plain text BEK instead\nof the encrypted BEK to userspace.\n\nThis issue only occurs when importing a trusted DCP-based key and\nthen exporting it again. This should rarely happen as the common use cases\nare to either create a new trusted key and export it, or import a key\nblob and then just use it without exporting it again.\n\nFix this by performing BEK decryption and encryption in a dedicated\nbuffer. Further always wipe the plain text BEK buffer to prevent leaking\nthe key via uninitialized memory.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45004"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0e28bf61a5f9ab30be3f3b4eafb8d097e39446bb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9e3b266afcfe4294e84496f50f006f029d3100db"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-g9qh-hcq6-2x9p/GHSA-g9qh-hcq6-2x9p.json b/advisories/unreviewed/2024/09/GHSA-g9qh-hcq6-2x9p/GHSA-g9qh-hcq6-2x9p.json
new file mode 100644
index 00000000000..cbca49567f2
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-g9qh-hcq6-2x9p/GHSA-g9qh-hcq6-2x9p.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g9qh-hcq6-2x9p",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44966"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_flat: Fix corruption when not offsetting data start\n\nCommit 04d82a6d0881 (\"binfmt_flat: allow not offsetting data start\")\nintroduced a RISC-V specific variant of the FLAT format which does\nnot allocate any space for the (obsolete) array of shared library\npointers. However, it did not disable the code which initializes the\narray, resulting in the corruption of sizeof(long) bytes before the DATA\nsegment, generally the end of the TEXT segment.\n\nIntroduce MAX_SHARED_LIBS_UPDATE which depends on the state of\nCONFIG_BINFMT_FLAT_NO_DATA_START_OFFSET to guard the initialization of\nthe shared library pointer region so that it will only be initialized\nif space is reserved for it.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44966"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3a684499261d0f7ed5ee72793025c88c2276809c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3eb3cd5992f7a0c37edc8d05b4c38c98758d8671"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/49df34d2b7da9e57c839555a2f7877291ce45ad1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9350ba06ee61db392c486716ac68ecc20e030f7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af65d5383854cc3f172a7d0843b628758bf462c8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gcpr-pgrp-45fp/GHSA-gcpr-pgrp-45fp.json b/advisories/unreviewed/2024/09/GHSA-gcpr-pgrp-45fp/GHSA-gcpr-pgrp-45fp.json
new file mode 100644
index 00000000000..b2f92ad1bd2
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gcpr-pgrp-45fp/GHSA-gcpr-pgrp-45fp.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gcpr-pgrp-45fp",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-45000"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/netfs/fscache_cookie: add missing \"n_accesses\" check\n\nThis fixes a NULL pointer dereference bug due to a data race which\nlooks like this:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000008\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP PTI\n CPU: 33 PID: 16573 Comm: kworker/u97:799 Not tainted 6.8.7-cm4all1-hp+ #43\n Hardware name: HP ProLiant DL380 Gen9/ProLiant DL380 Gen9, BIOS P89 10/17/2018\n Workqueue: events_unbound netfs_rreq_write_to_cache_work\n RIP: 0010:cachefiles_prepare_write+0x30/0xa0\n Code: 57 41 56 45 89 ce 41 55 49 89 cd 41 54 49 89 d4 55 53 48 89 fb 48 83 ec 08 48 8b 47 08 48 83 7f 10 00 48 89 34 24 48 8b 68 20 <48> 8b 45 08 4c 8b 38 74 45 49 8b 7f 50 e8 4e a9 b0 ff 48 8b 73 10\n RSP: 0018:ffffb4e78113bde0 EFLAGS: 00010286\n RAX: ffff976126be6d10 RBX: ffff97615cdb8438 RCX: 0000000000020000\n RDX: ffff97605e6c4c68 RSI: ffff97605e6c4c60 RDI: ffff97615cdb8438\n RBP: 0000000000000000 R08: 0000000000278333 R09: 0000000000000001\n R10: ffff97605e6c4600 R11: 0000000000000001 R12: ffff97605e6c4c68\n R13: 0000000000020000 R14: 0000000000000001 R15: ffff976064fe2c00\n FS: 0000000000000000(0000) GS:ffff9776dfd40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000005942c002 CR4: 00000000001706f0\n Call Trace:\n \n ? __die+0x1f/0x70\n ? page_fault_oops+0x15d/0x440\n ? search_module_extables+0xe/0x40\n ? fixup_exception+0x22/0x2f0\n ? exc_page_fault+0x5f/0x100\n ? asm_exc_page_fault+0x22/0x30\n ? cachefiles_prepare_write+0x30/0xa0\n netfs_rreq_write_to_cache_work+0x135/0x2e0\n process_one_work+0x137/0x2c0\n worker_thread+0x2e9/0x400\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xcc/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x30/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n Modules linked in:\n CR2: 0000000000000008\n ---[ end trace 0000000000000000 ]---\n\nThis happened because fscache_cookie_state_machine() was slow and was\nstill running while another process invoked fscache_unuse_cookie();\nthis led to a fscache_cookie_lru_do_one() call, setting the\nFSCACHE_COOKIE_DO_LRU_DISCARD flag, which was picked up by\nfscache_cookie_state_machine(), withdrawing the cookie via\ncachefiles_withdraw_cookie(), clearing cookie->cache_priv.\n\nAt the same time, yet another process invoked\ncachefiles_prepare_write(), which found a NULL pointer in this code\nline:\n\n struct cachefiles_object *object = cachefiles_cres_object(cres);\n\nThe next line crashes, obviously:\n\n struct cachefiles_cache *cache = object->volume->cache;\n\nDuring cachefiles_prepare_write(), the \"n_accesses\" counter is\nnon-zero (via fscache_begin_operation()). The cookie must not be\nwithdrawn until it drops to zero.\n\nThe counter is checked by fscache_cookie_state_machine() before\nswitching to FSCACHE_COOKIE_STATE_RELINQUISHING and\nFSCACHE_COOKIE_STATE_WITHDRAWING (in \"case\nFSCACHE_COOKIE_STATE_FAILED\"), but not for\nFSCACHE_COOKIE_STATE_LRU_DISCARDING (\"case\nFSCACHE_COOKIE_STATE_ACTIVE\").\n\nThis patch adds the missing check. With a non-zero access counter,\nthe function returns and the next fscache_end_cookie_access() call\nwill queue another fscache_cookie_state_machine() call to handle the\nstill-pending FSCACHE_COOKIE_DO_LRU_DISCARD.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45000"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0a4d41fa14b2a0efd40e350cfe8ec6a4c998ac1d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b8a50877f68efdcc0be3fcc5116e00c31b90e45b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dfaa39b05a6cf34a16c525a2759ee6ab26b5fef6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f71aa06398aabc2e3eaac25acdf3d62e0094ba70"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gfrq-fc5g-52f6/GHSA-gfrq-fc5g-52f6.json b/advisories/unreviewed/2024/09/GHSA-gfrq-fc5g-52f6/GHSA-gfrq-fc5g-52f6.json
new file mode 100644
index 00000000000..79cc8132da1
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gfrq-fc5g-52f6/GHSA-gfrq-fc5g-52f6.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gfrq-fc5g-52f6",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44989"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix xfrm real_dev null pointer dereference\n\nWe shouldn't set real_dev to NULL because packets can be in transit and\nxfrm might call xdo_dev_offload_ok() in parallel. All callbacks assume\nreal_dev is set.\n\n Example trace:\n kernel: BUG: unable to handle page fault for address: 0000000000001030\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: #PF: supervisor write access in kernel mode\n kernel: #PF: error_code(0x0002) - not-present page\n kernel: PGD 0 P4D 0\n kernel: Oops: 0002 [#1] PREEMPT SMP\n kernel: CPU: 4 PID: 2237 Comm: ping Not tainted 6.7.7+ #12\n kernel: Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\n kernel: RIP: 0010:nsim_ipsec_offload_ok+0xc/0x20 [netdevsim]\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: Code: e0 0f 0b 48 83 7f 38 00 74 de 0f 0b 48 8b 47 08 48 8b 37 48 8b 78 40 e9 b2 e5 9a d7 66 90 0f 1f 44 00 00 48 8b 86 80 02 00 00 <83> 80 30 10 00 00 01 b8 01 00 00 00 c3 0f 1f 80 00 00 00 00 0f 1f\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: RSP: 0018:ffffabde81553b98 EFLAGS: 00010246\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel:\n kernel: RAX: 0000000000000000 RBX: ffff9eb404e74900 RCX: ffff9eb403d97c60\n kernel: RDX: ffffffffc090de10 RSI: ffff9eb404e74900 RDI: ffff9eb3c5de9e00\n kernel: RBP: ffff9eb3c0a42000 R08: 0000000000000010 R09: 0000000000000014\n kernel: R10: 7974203030303030 R11: 3030303030303030 R12: 0000000000000000\n kernel: R13: ffff9eb3c5de9e00 R14: ffffabde81553cc8 R15: ffff9eb404c53000\n kernel: FS: 00007f2a77a3ad00(0000) GS:ffff9eb43bd00000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 0000000000001030 CR3: 00000001122ab000 CR4: 0000000000350ef0\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: Call Trace:\n kernel: \n kernel: ? __die+0x1f/0x60\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ? page_fault_oops+0x142/0x4c0\n kernel: ? do_user_addr_fault+0x65/0x670\n kernel: ? kvm_read_and_reset_apf_flags+0x3b/0x50\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: ? exc_page_fault+0x7b/0x180\n kernel: ? asm_exc_page_fault+0x22/0x30\n kernel: ? nsim_bpf_uninit+0x50/0x50 [netdevsim]\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ? nsim_ipsec_offload_ok+0xc/0x20 [netdevsim]\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: bond_ipsec_offload_ok+0x7b/0x90 [bonding]\n kernel: xfrm_output+0x61/0x3b0\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ip_push_pending_frames+0x56/0x80",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44989"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/21816b696c172c19d53a30d45ee005cce246ed21"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2f72c6a66bcd7e0187ec085237fee5db27145294"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4582d4ff413a07d4ed8a4823c652dc5207760548"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7fa9243391ad2afe798ef4ea2e2851947b95754f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/89fc1dca79db5c3e7a2d589ecbf8a3661c65f436"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f8cde9805981c50d0c029063dc7d82821806fc44"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gh37-h7xr-7hj2/GHSA-gh37-h7xr-7hj2.json b/advisories/unreviewed/2024/09/GHSA-gh37-h7xr-7hj2/GHSA-gh37-h7xr-7hj2.json
new file mode 100644
index 00000000000..5e87e7f18a4
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gh37-h7xr-7hj2/GHSA-gh37-h7xr-7hj2.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gh37-h7xr-7hj2",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44954"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: line6: Fix racy access to midibuf\n\nThere can be concurrent accesses to line6 midibuf from both the URB\ncompletion callback and the rawmidi API access. This could be a cause\nof KMSAN warning triggered by syzkaller below (so put as reported-by\nhere).\n\nThis patch protects the midibuf call of the former code path with a\nspinlock for avoiding the possible races.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44954"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/15b7a03205b31bc5623378c190d22b7ff60026f1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/40f3d5cb0e0cbf7fa697913a27d5d361373bdcf5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/51d87f11dd199bbc6a85982b088ff27bde53b48a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/535df7f896a568a8a1564114eaea49d002cb1747"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/643293b68fbb6c03f5e907736498da17d43f0d81"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a54da4b787dcac60b598da69c9c0072812b8282d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c80f454a805443c274394b1db0d1ebf477abd94e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e7e7d2b180d8f297cea6db43ea72402fd33e1a29"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gjp8-77gc-r4rr/GHSA-gjp8-77gc-r4rr.json b/advisories/unreviewed/2024/09/GHSA-gjp8-77gc-r4rr/GHSA-gjp8-77gc-r4rr.json
new file mode 100644
index 00000000000..3be86cd1f20
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gjp8-77gc-r4rr/GHSA-gjp8-77gc-r4rr.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gjp8-77gc-r4rr",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45006"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: Fix Panther point NULL pointer deref at full-speed re-enumeration\n\nre-enumerating full-speed devices after a failed address device command\ncan trigger a NULL pointer dereference.\n\nFull-speed devices may need to reconfigure the endpoint 0 Max Packet Size\nvalue during enumeration. Usb core calls usb_ep0_reinit() in this case,\nwhich ends up calling xhci_configure_endpoint().\n\nOn Panther point xHC the xhci_configure_endpoint() function will\nadditionally check and reserve bandwidth in software. Other hosts do\nthis in hardware\n\nIf xHC address device command fails then a new xhci_virt_device structure\nis allocated as part of re-enabling the slot, but the bandwidth table\npointers are not set up properly here.\nThis triggers the NULL pointer dereference the next time usb_ep0_reinit()\nis called and xhci_configure_endpoint() tries to check and reserve\nbandwidth\n\n[46710.713538] usb 3-1: new full-speed USB device number 5 using xhci_hcd\n[46710.713699] usb 3-1: Device not responding to setup address.\n[46710.917684] usb 3-1: Device not responding to setup address.\n[46711.125536] usb 3-1: device not accepting address 5, error -71\n[46711.125594] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[46711.125600] #PF: supervisor read access in kernel mode\n[46711.125603] #PF: error_code(0x0000) - not-present page\n[46711.125606] PGD 0 P4D 0\n[46711.125610] Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n[46711.125615] CPU: 1 PID: 25760 Comm: kworker/1:2 Not tainted 6.10.3_2 #1\n[46711.125620] Hardware name: Gigabyte Technology Co., Ltd.\n[46711.125623] Workqueue: usb_hub_wq hub_event [usbcore]\n[46711.125668] RIP: 0010:xhci_reserve_bandwidth (drivers/usb/host/xhci.c\n\nFix this by making sure bandwidth table pointers are set up correctly\nafter a failed address device command, and additionally by avoiding\nchecking for bandwidth in cases like this where no actual endpoints are\nadded or removed, i.e. only context for default control endpoint 0 is\nevaluated.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45006"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0f0654318e25b2c185e245ba4a591e42fabb5e59"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/365ef7c4277fdd781a695c3553fa157d622d805d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5ad898ae82412f8a689d59829804bff2999dd0ea"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6b99de301d78e1f5249e57ef2c32e1dec3df2bb1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8fb9d412ebe2f245f13481e4624b40e651570cbd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a57b0ebabe6862dce0a2e0f13e17941ad72fc56b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af8e119f52e9c13e556be9e03f27957554a84656"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef0a0e616b2789bb804a0ce5e161db03170a85b6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-gxhp-q3mw-vmqh/GHSA-gxhp-q3mw-vmqh.json b/advisories/unreviewed/2024/09/GHSA-gxhp-q3mw-vmqh/GHSA-gxhp-q3mw-vmqh.json
new file mode 100644
index 00000000000..cd394b0e8db
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-gxhp-q3mw-vmqh/GHSA-gxhp-q3mw-vmqh.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gxhp-q3mw-vmqh",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44999"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: pull network headers in gtp_dev_xmit()\n\nsyzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1]\n\nWe must make sure the IPv4 or Ipv6 header is pulled in skb->head\nbefore accessing fields in them.\n\nUse pskb_inet_may_pull() to fix this issue.\n\n[1]\nBUG: KMSAN: uninit-value in ipv6_pdp_find drivers/net/gtp.c:220 [inline]\n BUG: KMSAN: uninit-value in gtp_build_skb_ip6 drivers/net/gtp.c:1229 [inline]\n BUG: KMSAN: uninit-value in gtp_dev_xmit+0x1424/0x2540 drivers/net/gtp.c:1281\n ipv6_pdp_find drivers/net/gtp.c:220 [inline]\n gtp_build_skb_ip6 drivers/net/gtp.c:1229 [inline]\n gtp_dev_xmit+0x1424/0x2540 drivers/net/gtp.c:1281\n __netdev_start_xmit include/linux/netdevice.h:4913 [inline]\n netdev_start_xmit include/linux/netdevice.h:4922 [inline]\n xmit_one net/core/dev.c:3580 [inline]\n dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3596\n __dev_queue_xmit+0x358c/0x5610 net/core/dev.c:4423\n dev_queue_xmit include/linux/netdevice.h:3105 [inline]\n packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3145 [inline]\n packet_sendmsg+0x90e3/0xa3a0 net/packet/af_packet.c:3177\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n __sys_sendto+0x685/0x830 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2212\n x64_sys_call+0x3799/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3994 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4080\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:583\n __alloc_skb+0x363/0x7b0 net/core/skbuff.c:674\n alloc_skb include/linux/skbuff.h:1320 [inline]\n alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6526\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2815\n packet_alloc_skb net/packet/af_packet.c:2994 [inline]\n packet_snd net/packet/af_packet.c:3088 [inline]\n packet_sendmsg+0x749c/0xa3a0 net/packet/af_packet.c:3177\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n __sys_sendto+0x685/0x830 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2212\n x64_sys_call+0x3799/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCPU: 0 UID: 0 PID: 7115 Comm: syz.1.515 Not tainted 6.11.0-rc1-syzkaller-00043-g94ede2a3e913 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44999"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/137d565ab89ce3584503b443bc9e00d44f482593"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1f6b62392453d8f36685d19b761307a8c5617ac1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/34ba4f29f3d9eb52dee37512059efb2afd7e966f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3939d787139e359b77aaf9485d1e145d6713d7b9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3a3be7ff9224f424e485287b54be00d2c6bd9c40"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3d89d0c4a1c6d4d2a755e826351b0a101dbc86f3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cbb9a969fc190e85195d1b0f08038e7f6199044e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f5dda8db382c5751c4e572afc7c99df7da1f83ca"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json b/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json
index 68c28bb18f9..c814657bae9 100644
--- a/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json
+++ b/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hph4-74mx-4369",
- "modified": "2024-09-04T18:30:58Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-09-04T18:30:58Z",
"aliases": [
"CVE-2024-45174"
],
"details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web interface are vulnerable to SQL injection attacks. This kind of attack allows an authenticated user to execute arbitrary SQL commands in the context of the corresponding MySQL database.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T17:15:14Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json b/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json
new file mode 100644
index 00000000000..9c05b374d36
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hw6f-2v4x-m477",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44950"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix invalid FIFO access with special register set\n\nWhen enabling access to the special register set, Receiver time-out and\nRHR interrupts can happen. In this case, the IRQ handler will try to read\nfrom the FIFO thru the RHR register at address 0x00, but address 0x00 is\nmapped to DLL register, resulting in erroneous FIFO reading.\n\nCall graph example:\n sc16is7xx_startup(): entry\n sc16is7xx_ms_proc(): entry\n sc16is7xx_set_termios(): entry\n sc16is7xx_set_baud(): DLH/DLL = $009C --> access special register set\n sc16is7xx_port_irq() entry --> IIR is 0x0C\n sc16is7xx_handle_rx() entry\n sc16is7xx_fifo_read(): --> unable to access FIFO (RHR) because it is\n mapped to DLL (LCR=LCR_CONF_MODE_A)\n sc16is7xx_set_baud(): exit --> Restore access to general register set\n\nFix the problem by claiming the efr_lock mutex when accessing the Special\nregister set.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44950"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6a6730812220a9a5ce4003eb347da1ee5abd06b0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d3b793faaab1305994ce568b59d61927235f57b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json b/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json
new file mode 100644
index 00000000000..9a2b8353d29
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hwvg-2jxc-754g",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45172"
+ ],
+ "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site request forgery (CSRF) attacks. The C-MOR web interface offers no protection against cross-site request forgery (CSRF) attacks.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45172"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-022.txt"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json b/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json
index be36f484524..19b4ed37b29 100644
--- a/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json
+++ b/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2p5-fvjc-rrwc",
- "modified": "2024-09-04T15:30:35Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-09-04T15:30:35Z",
"aliases": [
"CVE-2024-44820"
],
"details": "A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200",
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T15:15:13Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-j3xr-2g3j-267r/GHSA-j3xr-2g3j-267r.json b/advisories/unreviewed/2024/09/GHSA-j3xr-2g3j-267r/GHSA-j3xr-2g3j-267r.json
new file mode 100644
index 00000000000..559039211f3
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-j3xr-2g3j-267r/GHSA-j3xr-2g3j-267r.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j3xr-2g3j-267r",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44988"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Fix out-of-bound access\n\nIf an ATU violation was caused by a CPU Load operation, the SPID could\nbe larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44988"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/050e7274ab2150cd212b2372595720e7b83a15bd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/18b2e833daf049223ab3c2efdf8cdee08854c484"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/528876d867a23b5198022baf2e388052ca67c952"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a10d0337115a6d223a1563d853d4455f05d0b2e3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d39f5be62f098fe367d672b4dd4bc4b2b80e08e7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f7d8c2fabd39250cf2333fbf8eef67e837f90a5d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f87ce03c652dba199aef15ac18ade3991db5477e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-jqwp-jgh2-892r/GHSA-jqwp-jgh2-892r.json b/advisories/unreviewed/2024/09/GHSA-jqwp-jgh2-892r/GHSA-jqwp-jgh2-892r.json
new file mode 100644
index 00000000000..6e651ca4151
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-jqwp-jgh2-892r/GHSA-jqwp-jgh2-892r.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jqwp-jgh2-892r",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44961"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Forward soft recovery errors to userspace\n\nAs we discussed before[1], soft recovery should be\nforwarded to userspace, or we can get into a really\nbad state where apps will keep submitting hanging\ncommand buffers cascading us to a hard reset.\n\n1: https://lore.kernel.org/all/bf23d5ed-9a6b-43e7-84ee-8cbfd0d60f18@froggi.es/\n(cherry picked from commit 434967aadbbbe3ad9103cc29e9a327de20fdba01)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44961"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0da0b06165d83a8ecbb6582d9d5a135f9d38a52a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/829798c789f567ef6ba4b084c15b7b5f3bd98d51"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c28d207edfc5679585f4e96acb67000076ce90be"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-m5q9-gx2f-vvf3/GHSA-m5q9-gx2f-vvf3.json b/advisories/unreviewed/2024/09/GHSA-m5q9-gx2f-vvf3/GHSA-m5q9-gx2f-vvf3.json
new file mode 100644
index 00000000000..59869238ee8
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-m5q9-gx2f-vvf3/GHSA-m5q9-gx2f-vvf3.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m5q9-gx2f-vvf3",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44957"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Switch from mutex to spinlock for irqfds\n\nirqfd_wakeup() gets EPOLLHUP, when it is called by\neventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which\ngets called under spin_lock_irqsave(). We can't use a mutex here as it\nwill lead to a deadlock.\n\nFix it by switching over to a spin lock.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44957"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1c682593096a487fd9aebc079a307ff7a6d054a3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/49f2a5da6785b2dbde93e291cae037662440346e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c2775ae4d9227729f8ca9ee2a068f62a00d5ea9c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json b/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json
new file mode 100644
index 00000000000..fcc7b44af66
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-mgf7-9fq3-64j5/GHSA-mgf7-9fq3-64j5.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mgf7-9fq3-64j5",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44974"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: avoid possible UaF when selecting endp\n\nselect_local_address() and select_signal_address() both select an\nendpoint entry from the list inside an RCU protected section, but return\na reference to it, to be read later on. If the entry is dereferenced\nafter the RCU unlock, reading info could cause a Use-after-Free.\n\nA simple solution is to copy the required info while inside the RCU\nprotected section to avoid any risk of UaF later. The address ID might\nneed to be modified later to handle the ID0 case later, so a copy seems\nOK to deal with.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44974"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0201d65d9806d287a00e0ba96f0321835631f63f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/48e50dcbcbaaf713d82bf2da5c16aeced94ad07d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9a9afbbc3fbfca4975eea4aa5b18556db5a0c0b8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-mhp8-p4cm-q5rh/GHSA-mhp8-p4cm-q5rh.json b/advisories/unreviewed/2024/09/GHSA-mhp8-p4cm-q5rh/GHSA-mhp8-p4cm-q5rh.json
new file mode 100644
index 00000000000..aef012b0d57
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-mhp8-p4cm-q5rh/GHSA-mhp8-p4cm-q5rh.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mhp8-p4cm-q5rh",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44979"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix missing workqueue destroy in xe_gt_pagefault\n\nOn driver reload we never free up the memory for the pagefault and\naccess counter workqueues. Add those destroy calls here.\n\n(cherry picked from commit 7586fc52b14e0b8edd0d1f8a434e0de2078b7b2b)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44979"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a6f78359ac75f24cac3c1bdd753c49c1877bcd82"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b09ef3b762a7fc641fb2f89afd3ebdb65b8ba1b9"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json b/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json
index b2531fab661..e97ed1a9e9b 100644
--- a/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json
+++ b/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmm5-wgvp-wp8r",
- "modified": "2024-09-04T15:30:33Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-09-03T15:30:44Z",
"aliases": [
"CVE-2024-6232"
@@ -37,6 +37,14 @@
"type": "WEB",
"url": "https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877"
+ },
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf"
diff --git a/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json b/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json
index a1187954898..c87f9c70dca 100644
--- a/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json
+++ b/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mq6r-xpp8-hm92",
- "modified": "2024-09-04T18:30:58Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-09-04T18:30:58Z",
"aliases": [
"CVE-2024-45170"
],
"details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of the C-MOR web interface. It was found out that different functions are only available to administrative users. However, access those functions is restricted via the web application user interface and not checked on the server side. Thus, by sending corresponding HTTP requests to the web server of the C-MOR web interface, low privileged users can also use administrative functionality, for instance downloading backup files or changing configuration settings.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-284"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T17:15:14Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-mwvh-q9h7-62fg/GHSA-mwvh-q9h7-62fg.json b/advisories/unreviewed/2024/09/GHSA-mwvh-q9h7-62fg/GHSA-mwvh-q9h7-62fg.json
new file mode 100644
index 00000000000..e5e4f4185f3
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-mwvh-q9h7-62fg/GHSA-mwvh-q9h7-62fg.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mwvh-q9h7-62fg",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44959"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracefs: Use generic inode RCU for synchronizing freeing\n\nWith structure layout randomization enabled for 'struct inode' we need to\navoid overlapping any of the RCU-used / initialized-only-once members,\ne.g. i_lru or i_sb_list to not corrupt related list traversals when making\nuse of the rcu_head.\n\nFor an unlucky structure layout of 'struct inode' we may end up with the\nfollowing splat when running the ftrace selftests:\n\n[<...>] list_del corruption, ffff888103ee2cb0->next (tracefs_inode_cache+0x0/0x4e0 [slab object]) is NULL (prev is tracefs_inode_cache+0x78/0x4e0 [slab object])\n[<...>] ------------[ cut here ]------------\n[<...>] kernel BUG at lib/list_debug.c:54!\n[<...>] invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[<...>] CPU: 3 PID: 2550 Comm: mount Tainted: G N 6.8.12-grsec+ #122 ed2f536ca62f28b087b90e3cc906a8d25b3ddc65\n[<...>] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\n[<...>] RIP: 0010:[] __list_del_entry_valid_or_report+0x138/0x3e0\n[<...>] Code: 48 b8 99 fb 65 f2 ff ff ff ff e9 03 5c d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff e9 33 5a d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff <0f> 0b 4c 89 e9 48 89 ea 48 89 ee 48 c7 c7 60 8f dd 89 31 c0 e8 2f\n[<...>] RSP: 0018:fffffe80416afaf0 EFLAGS: 00010283\n[<...>] RAX: 0000000000000098 RBX: ffff888103ee2cb0 RCX: 0000000000000000\n[<...>] RDX: ffffffff84655fe8 RSI: ffffffff89dd8b60 RDI: 0000000000000001\n[<...>] RBP: ffff888103ee2cb0 R08: 0000000000000001 R09: fffffbd0082d5f25\n[<...>] R10: fffffe80416af92f R11: 0000000000000001 R12: fdf99c16731d9b6d\n[<...>] R13: 0000000000000000 R14: ffff88819ad4b8b8 R15: 0000000000000000\n[<...>] RBX: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RDX: __list_del_entry_valid_or_report+0x108/0x3e0\n[<...>] RSI: __func__.47+0x4340/0x4400\n[<...>] RBP: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RSP: process kstack fffffe80416afaf0+0x7af0/0x8000 [mount 2550 2550]\n[<...>] R09: kasan shadow of process kstack fffffe80416af928+0x7928/0x8000 [mount 2550 2550]\n[<...>] R10: process kstack fffffe80416af92f+0x792f/0x8000 [mount 2550 2550]\n[<...>] R14: tracefs_inode_cache+0x78/0x4e0 [slab object]\n[<...>] FS: 00006dcb380c1840(0000) GS:ffff8881e0600000(0000) knlGS:0000000000000000\n[<...>] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[<...>] CR2: 000076ab72b30e84 CR3: 000000000b088004 CR4: 0000000000360ef0 shadow CR4: 0000000000360ef0\n[<...>] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[<...>] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[<...>] ASID: 0003\n[<...>] Stack:\n[<...>] ffffffff818a2315 00000000f5c856ee ffffffff896f1840 ffff888103ee2cb0\n[<...>] ffff88812b6b9750 0000000079d714b6 fffffbfff1e9280b ffffffff8f49405f\n[<...>] 0000000000000001 0000000000000000 ffff888104457280 ffffffff8248b392\n[<...>] Call Trace:\n[<...>] \n[<...>] [] ? lock_release+0x175/0x380 fffffe80416afaf0\n[<...>] [] list_lru_del+0x152/0x740 fffffe80416afb48\n[<...>] [] list_lru_del_obj+0x113/0x280 fffffe80416afb88\n[<...>] [] ? _atomic_dec_and_lock+0x119/0x200 fffffe80416afb90\n[<...>] [] iput_final+0x1c4/0x9a0 fffffe80416afbb8\n[<...>] [] dentry_unlink_inode+0x44b/0xaa0 fffffe80416afbf8\n[<...>] [] __dentry_kill+0x23c/0xf00 fffffe80416afc40\n[<...>] [] ? __this_cpu_preempt_check+0x1f/0xa0 fffffe80416afc48\n[<...>] [] ? shrink_dentry_list+0x1c5/0x760 fffffe80416afc70\n[<...>] [] ? shrink_dentry_list+0x51/0x760 fffffe80416afc78\n[<...>] [] shrink_dentry_list+0x288/0x760 fffffe80416afc80\n[<...>] [] shrink_dcache_sb+0x155/0x420 fffffe80416afcc8\n[<...>] [] ? debug_smp_processor_id+0x23/0xa0 fffffe80416afce0\n[<...>] [] ? do_one_tre\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44959"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/061da60716ce0cde99f62f31937b81e1c03acef6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0b6743bd60a56a701070b89fb80c327a44b7b3e2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/726f4c241e17be75a9cf6870d80cd7479dc89e8f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json b/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json
new file mode 100644
index 00000000000..276085437fd
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p79g-j2j8-9wqw",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44973"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: do not call do_slab_free for kfence object\n\nIn 782f8906f805 the freeing of kfence objects was moved from deep\ninside do_slab_free to the wrapper functions outside. This is a nice\nchange, but unfortunately it missed one spot in __kmem_cache_free_bulk.\n\nThis results in a crash like this:\n\nBUG skbuff_head_cache (Tainted: G S B E ): Padding overwritten. 0xffff88907fea0f00-0xffff88907fea0fff @offset=3840\n\nslab_err (mm/slub.c:1129)\nfree_to_partial_list (mm/slub.c:? mm/slub.c:4036)\nslab_pad_check (mm/slub.c:864 mm/slub.c:1290)\ncheck_slab (mm/slub.c:?)\nfree_to_partial_list (mm/slub.c:3171 mm/slub.c:4036)\nkmem_cache_alloc_bulk (mm/slub.c:? mm/slub.c:4495 mm/slub.c:4586 mm/slub.c:4635)\nnapi_build_skb (net/core/skbuff.c:348 net/core/skbuff.c:527 net/core/skbuff.c:549)\n\nAll the other callers to do_slab_free appear to be ok.\n\nAdd a kfence_free check in __kmem_cache_free_bulk to avoid the crash.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44973"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a371d558e6f3aed977a8a7346350557de5d25190"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b35cd7f1e969aaa63e6716d82480f6b8a3230949"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-q2gx-5vc4-pjjw/GHSA-q2gx-5vc4-pjjw.json b/advisories/unreviewed/2024/09/GHSA-q2gx-5vc4-pjjw/GHSA-q2gx-5vc4-pjjw.json
new file mode 100644
index 00000000000..815f03fd96f
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-q2gx-5vc4-pjjw/GHSA-q2gx-5vc4-pjjw.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q2gx-5vc4-pjjw",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44956"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/preempt_fence: enlarge the fence critical section\n\nIt is really easy to introduce subtle deadlocks in\npreempt_fence_work_func() since we operate on single global ordered-wq\nfor signalling our preempt fences behind the scenes, so even though we\nsignal a particular fence, everything in the callback should be in the\nfence critical section, since blocking in the callback will prevent\nother published fences from signalling. If we enlarge the fence critical\nsection to cover the entire callback, then lockdep should be able to\nunderstand this better, and complain if we grab a sensitive lock like\nvm->lock, which is also held when waiting on preempt fences.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44956"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3cd1585e57908b6efcd967465ef7685f40b2a294"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/458bb83119dfee5d14c677f7846dd9363817006f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json b/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json
index f98219158c6..1ccf9e9ce37 100644
--- a/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json
+++ b/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q4cc-q982-86m8",
- "modified": "2024-09-04T18:30:57Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-09-04T18:30:57Z",
"aliases": [
"CVE-2024-44808"
],
"details": "An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-20"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T16:15:07Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json b/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json
new file mode 100644
index 00000000000..802f1be7994
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qcm7-vmfg-h8xw",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44955"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute\n\n[Why]\nWhen unplug one of monitors connected after mst hub, encounter null pointer dereference.\n\nIt's due to dc_sink get released immediately in early_unregister() or detect_ctx(). When\ncommit new state which directly referring to info stored in dc_sink will cause null pointer\ndereference.\n\n[how]\nRemove redundant checking condition. Relevant condition should already be covered by checking\nif dsc_aux is null or not. Also reset dsc_aux to NULL when the connector is disconnected.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44955"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/39b217193729aa45eded8de24d9245468a0c0263"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fcf6a49d79923a234844b8efe830a61f3f0584e4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json b/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json
new file mode 100644
index 00000000000..9d86de9a891
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qh7m-p5jw-2wvg",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44975"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: fix panic caused by partcmd_update\n\nWe find a bug as below:\nBUG: unable to handle page fault for address: 00000003\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 3 PID: 358 Comm: bash Tainted: G W I 6.6.0-10893-g60d6\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/4\nRIP: 0010:partition_sched_domains_locked+0x483/0x600\nCode: 01 48 85 d2 74 0d 48 83 05 29 3f f8 03 01 f3 48 0f bc c2 89 c0 48 9\nRSP: 0018:ffffc90000fdbc58 EFLAGS: 00000202\nRAX: 0000000100000003 RBX: ffff888100b3dfa0 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000002fe80\nRBP: ffff888100b3dfb0 R08: 0000000000000001 R09: 0000000000000000\nR10: ffffc90000fdbcb0 R11: 0000000000000004 R12: 0000000000000002\nR13: ffff888100a92b48 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f44a5425740(0000) GS:ffff888237d80000(0000) knlGS:0000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000100030973 CR3: 000000010722c000 CR4: 00000000000006e0\nCall Trace:\n \n ? show_regs+0x8c/0xa0\n ? __die_body+0x23/0xa0\n ? __die+0x3a/0x50\n ? page_fault_oops+0x1d2/0x5c0\n ? partition_sched_domains_locked+0x483/0x600\n ? search_module_extables+0x2a/0xb0\n ? search_exception_tables+0x67/0x90\n ? kernelmode_fixup_or_oops+0x144/0x1b0\n ? __bad_area_nosemaphore+0x211/0x360\n ? up_read+0x3b/0x50\n ? bad_area_nosemaphore+0x1a/0x30\n ? exc_page_fault+0x890/0xd90\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? asm_exc_page_fault+0x26/0x30\n ? partition_sched_domains_locked+0x483/0x600\n ? partition_sched_domains_locked+0xf0/0x600\n rebuild_sched_domains_locked+0x806/0xdc0\n update_partition_sd_lb+0x118/0x130\n cpuset_write_resmask+0xffc/0x1420\n cgroup_file_write+0xb2/0x290\n kernfs_fop_write_iter+0x194/0x290\n new_sync_write+0xeb/0x160\n vfs_write+0x16f/0x1d0\n ksys_write+0x81/0x180\n __x64_sys_write+0x21/0x30\n x64_sys_call+0x2f25/0x4630\n do_syscall_64+0x44/0xb0\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\nRIP: 0033:0x7f44a553c887\n\nIt can be reproduced with cammands:\ncd /sys/fs/cgroup/\nmkdir test\ncd test/\necho +cpuset > ../cgroup.subtree_control\necho root > cpuset.cpus.partition\ncat /sys/fs/cgroup/cpuset.cpus.effective\n0-3\necho 0-3 > cpuset.cpus // taking away all cpus from root\n\nThis issue is caused by the incorrect rebuilding of scheduling domains.\nIn this scenario, test/cpuset.cpus.partition should be an invalid root\nand should not trigger the rebuilding of scheduling domains. When calling\nupdate_parent_effective_cpumask with partcmd_update, if newmask is not\nnull, it should recheck newmask whether there are cpus is available\nfor parect/cs that has tasks.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44975"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/73d6c6cf8ef6a3c532aa159f5114077746a372d6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/959ab6350add903e352890af53e86663739fcb9a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json b/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json
new file mode 100644
index 00000000000..4f47418d464
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qmgp-8gjw-93v8",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44978"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Free job before xe_exec_queue_put\n\nFree job depends on job->vm being valid, the last xe_exec_queue_put can\ndestroy the VM. Prevent UAF by freeing job before xe_exec_queue_put.\n\n(cherry picked from commit 32a42c93b74c8ca6d0915ea3eba21bceff53042f)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44978"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/98aa0330f200b9b8fb9e1298e006eda57a13351c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9e7f30563677fbeff62d368d5d2a5ac7aaa9746a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-qqj2-pmc2-p5vr/GHSA-qqj2-pmc2-p5vr.json b/advisories/unreviewed/2024/09/GHSA-qqj2-pmc2-p5vr/GHSA-qqj2-pmc2-p5vr.json
new file mode 100644
index 00000000000..869a355eb69
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-qqj2-pmc2-p5vr/GHSA-qqj2-pmc2-p5vr.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qqj2-pmc2-p5vr",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44962"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Shutdown timer and prevent rearming when driver unloading\n\nWhen unload the btnxpuart driver, its associated timer will be deleted.\nIf the timer happens to be modified at this moment, it leads to the\nkernel call this timer even after the driver unloaded, resulting in\nkernel panic.\nUse timer_shutdown_sync() instead of del_timer_sync() to prevent rearming.\n\npanic log:\n Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n Modules linked in: algif_hash algif_skcipher af_alg moal(O) mlan(O) crct10dif_ce polyval_ce polyval_generic snd_soc_imx_card snd_soc_fsl_asoc_card snd_soc_imx_audmux mxc_jpeg_encdec v4l2_jpeg snd_soc_wm8962 snd_soc_fsl_micfil snd_soc_fsl_sai flexcan snd_soc_fsl_utils ap130x rpmsg_ctrl imx_pcm_dma can_dev rpmsg_char pwm_fan fuse [last unloaded: btnxpuart]\n CPU: 5 PID: 723 Comm: memtester Tainted: G O 6.6.23-lts-next-06207-g4aef2658ac28 #1\n Hardware name: NXP i.MX95 19X19 board (DT)\n pstate: 20400009 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : 0xffff80007a2cf464\n lr : call_timer_fn.isra.0+0x24/0x80\n...\n Call trace:\n 0xffff80007a2cf464\n __run_timers+0x234/0x280\n run_timer_softirq+0x20/0x40\n __do_softirq+0x100/0x26c\n ____do_softirq+0x10/0x1c\n call_on_irq_stack+0x24/0x4c\n do_softirq_own_stack+0x1c/0x2c\n irq_exit_rcu+0xc0/0xdc\n el0_interrupt+0x54/0xd8\n __el0_irq_handler_common+0x18/0x24\n el0t_64_irq_handler+0x10/0x1c\n el0t_64_irq+0x190/0x194\n Code: ???????? ???????? ???????? ???????? (????????)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Oops: Fatal exception in interrupt\n SMP: stopping secondary CPUs\n Kernel Offset: disabled\n CPU features: 0x0,c0000000,40028143,1000721b\n Memory Limit: none\n ---[ end Kernel panic - not syncing: Oops: Fatal exception in interrupt ]---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44962"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0d0df1e750bac0fdaa77940e711c1625cff08d33"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/28bbb5011a9723700006da67bdb57ab6a914452b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4d9adcb94d55e9be8a3e464d9f2ff7d27e2ed016"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json b/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json
new file mode 100644
index 00000000000..150a160dd58
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qv39-hg6q-9r5r",
+ "modified": "2024-09-04T21:30:33Z",
+ "published": "2024-09-04T21:30:33Z",
+ "aliases": [
+ "CVE-2024-45003"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfs: Don't evict inode under the inode lru traversing context\n\nThe inode reclaiming process(See function prune_icache_sb) collects all\nreclaimable inodes and mark them with I_FREEING flag at first, at that\ntime, other processes will be stuck if they try getting these inodes\n(See function find_inode_fast), then the reclaiming process destroy the\ninodes by function dispose_list(). Some filesystems(eg. ext4 with\nea_inode feature, ubifs with xattr) may do inode lookup in the inode\nevicting callback function, if the inode lookup is operated under the\ninode lru traversing context, deadlock problems may happen.\n\nCase 1: In function ext4_evict_inode(), the ea inode lookup could happen\n if ea_inode feature is enabled, the lookup process will be stuck\n\tunder the evicting context like this:\n\n 1. File A has inode i_reg and an ea inode i_ea\n 2. getfattr(A, xattr_buf) // i_ea is added into lru // lru->i_ea\n 3. Then, following three processes running like this:\n\n PA PB\n echo 2 > /proc/sys/vm/drop_caches\n shrink_slab\n prune_dcache_sb\n // i_reg is added into lru, lru->i_ea->i_reg\n prune_icache_sb\n list_lru_walk_one\n inode_lru_isolate\n i_ea->i_state |= I_FREEING // set inode state\n inode_lru_isolate\n __iget(i_reg)\n spin_unlock(&i_reg->i_lock)\n spin_unlock(lru_lock)\n rm file A\n i_reg->nlink = 0\n iput(i_reg) // i_reg->nlink is 0, do evict\n ext4_evict_inode\n ext4_xattr_delete_inode\n ext4_xattr_inode_dec_ref_all\n ext4_xattr_inode_iget\n ext4_iget(i_ea->i_ino)\n iget_locked\n find_inode_fast\n __wait_on_freeing_inode(i_ea) ----→ AA deadlock\n dispose_list // cannot be executed by prune_icache_sb\n wake_up_bit(&i_ea->i_state)\n\nCase 2: In deleted inode writing function ubifs_jnl_write_inode(), file\n deleting process holds BASEHD's wbuf->io_mutex while getting the\n\txattr inode, which could race with inode reclaiming process(The\n reclaiming process could try locking BASEHD's wbuf->io_mutex in\n\tinode evicting function), then an ABBA deadlock problem would\n\thappen as following:\n\n 1. File A has inode ia and a xattr(with inode ixa), regular file B has\n inode ib and a xattr.\n 2. getfattr(A, xattr_buf) // ixa is added into lru // lru->ixa\n 3. Then, following three processes running like this:\n\n PA PB PC\n echo 2 > /proc/sys/vm/drop_caches\n shrink_slab\n prune_dcache_sb\n // ib and ia are added into lru, lru->ixa->ib->ia\n prune_icache_sb\n list_lru_walk_one\n inode_lru_isolate\n ixa->i_state |= I_FREEING // set inode state\n inode_lru_isolate\n __iget(ib)\n spin_unlock(&ib->i_lock)\n spin_unlock(lru_lock)\n rm file B\n ib->nlink = 0\n rm file A\n iput(ia)\n ubifs_evict_inode(ia)\n ubifs_jnl_delete_inode(ia)\n ubifs_jnl_write_inode(ia)\n make_reservation(BASEHD) // Lock wbuf->io_mutex\n ubifs_iget(ixa->i_ino)\n iget_locked\n find_inode_fast\n __wait_on_freeing_inode(ixa)\n | iput(ib) // ib->nlink is 0, do evict\n | ubifs_evict_inode\n | ubifs_jnl_delete_inode(ib)\n ↓ ubifs_jnl_write_inode\n ABBA deadlock ←-----make_reservation(BASEHD)\n dispose_list // cannot be executed by prune_icache_sb\n wake_up_bit(&ixa->i_state)\n\nFix the possible deadlock by using new inode state flag I_LRU_ISOLATING\nto pin the inode in memory while inode_lru_isolate(\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45003"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/03880af02a78bc9a98b5a581f529cf709c88a9b8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a0629834cd82f05d424bbc193374f9a43d1f87d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3525ad25240dfdd8c78f3470911ed10aa727aa72"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/437741eba63bf4e437e2beb5583f8633556a2b98"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9063ab49c11e9518a3f2352434bb276cc8134c5f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b9bda5f6012dd00372f3a06a82ed8971a4c57c32"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cda54ec82c0f9d05393242b20b13f69b083f7e88"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-qx5p-7g35-jj49/GHSA-qx5p-7g35-jj49.json b/advisories/unreviewed/2024/09/GHSA-qx5p-7g35-jj49/GHSA-qx5p-7g35-jj49.json
new file mode 100644
index 00000000000..3d82253278e
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-qx5p-7g35-jj49/GHSA-qx5p-7g35-jj49.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qx5p-7g35-jj49",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44951"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix TX fifo corruption\n\nSometimes, when a packet is received on channel A at almost the same time\nas a packet is about to be transmitted on channel B, we observe with a\nlogic analyzer that the received packet on channel A is transmitted on\nchannel B. In other words, the Tx buffer data on channel B is corrupted\nwith data from channel A.\n\nThe problem appeared since commit 4409df5866b7 (\"serial: sc16is7xx: change\nEFR lock to operate on each channels\"), which changed the EFR locking to\noperate on each channel instead of chip-wise.\n\nThis commit has introduced a regression, because the EFR lock is used not\nonly to protect the EFR registers access, but also, in a very obscure and\nundocumented way, to protect access to the data buffer, which is shared by\nthe Tx and Rx handlers, but also by each channel of the IC.\n\nFix this regression first by switching to kfifo_out_linear_ptr() in\nsc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer.\n\nSecondly, replace the chip-wise Rx buffer with a separate Rx buffer for\neach channel.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44951"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/09cfe05e9907f3276887a20e267cc40e202f4fdd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-r228-rjcp-r9q9/GHSA-r228-rjcp-r9q9.json b/advisories/unreviewed/2024/09/GHSA-r228-rjcp-r9q9/GHSA-r228-rjcp-r9q9.json
new file mode 100644
index 00000000000..8b8f0a7cd31
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-r228-rjcp-r9q9/GHSA-r228-rjcp-r9q9.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r228-rjcp-r9q9",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44977"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Validate TA binary size\n\nAdd TA binary size validation to avoid OOB write.\n\n(cherry picked from commit c0a04e3570d72aaf090962156ad085e37c62e442)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44977"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/50553ea7cbd3344fbf40afb065f6a2d38171c1ad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5ab8793b9a6cc059f503cbe6fe596f80765e0f19"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c99769bceab4ecb6a067b9af11f9db281eea3e2a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e562415248f402203e7fb6d8c38c1b32fa99220f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-vc2g-hqvc-wcmf/GHSA-vc2g-hqvc-wcmf.json b/advisories/unreviewed/2024/09/GHSA-vc2g-hqvc-wcmf/GHSA-vc2g-hqvc-wcmf.json
new file mode 100644
index 00000000000..5eaafb462f5
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-vc2g-hqvc-wcmf/GHSA-vc2g-hqvc-wcmf.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vc2g-hqvc-wcmf",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44960"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: core: Check for unset descriptor\n\nMake sure the descriptor has been set before looking at maxpacket.\nThis fixes a null pointer panic in this case.\n\nThis may happen if the gadget doesn't properly set up the endpoint\nfor the current speed, or the gadget descriptors are malformed and\nthe descriptor for the speed/endpoint are not found.\n\nNo current gadget driver is known to have this problem, but this\nmay cause a hard-to-find bug during development of new gadgets.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44960"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1a9df57d57452b104c46c918569143cf21d7ebf1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/50c5248b0ea8aae0529fdf28dac42a41312d3b62"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/716cba46f73a92645cf13eded8d257ed48afc2a4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7cc9ebcfe58be22f18056ad8bc6272d120bdcb3e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/973a57891608a98e894db2887f278777f564de18"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a0362cd6e503278add954123957fd47990e8d9bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ba15815dd24cc5ec0d23e2170dc58c7db1e03b4a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/df8e734ae5e605348aa0ca2498aedb73e815f244"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-w62v-m336-jqj7/GHSA-w62v-m336-jqj7.json b/advisories/unreviewed/2024/09/GHSA-w62v-m336-jqj7/GHSA-w62v-m336-jqj7.json
new file mode 100644
index 00000000000..0932583d8e1
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-w62v-m336-jqj7/GHSA-w62v-m336-jqj7.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w62v-m336-jqj7",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44984"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix double DMA unmapping for XDP_REDIRECT\n\nRemove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT\ncode path. This should have been removed when we let the page pool\nhandle the DMA mapping. This bug causes the warning:\n\nWARNING: CPU: 7 PID: 59 at drivers/iommu/dma-iommu.c:1198 iommu_dma_unmap_page+0xd5/0x100\nCPU: 7 PID: 59 Comm: ksoftirqd/7 Tainted: G W 6.8.0-1010-gcp #11-Ubuntu\nHardware name: Dell Inc. PowerEdge R7525/0PYVT1, BIOS 2.15.2 04/02/2024\nRIP: 0010:iommu_dma_unmap_page+0xd5/0x100\nCode: 89 ee 48 89 df e8 cb f2 69 ff 48 83 c4 08 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 c9 31 f6 31 ff 45 31 c0 e9 ab 17 71 00 <0f> 0b 48 83 c4 08 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 c9\nRSP: 0018:ffffab1fc0597a48 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff99ff838280c8 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffab1fc0597a78 R08: 0000000000000002 R09: ffffab1fc0597c1c\nR10: ffffab1fc0597cd3 R11: ffff99ffe375acd8 R12: 00000000e65b9000\nR13: 0000000000000050 R14: 0000000000001000 R15: 0000000000000002\nFS: 0000000000000000(0000) GS:ffff9a06efb80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000565c34c37210 CR3: 00000005c7e3e000 CR4: 0000000000350ef0\n? show_regs+0x6d/0x80\n? __warn+0x89/0x150\n? iommu_dma_unmap_page+0xd5/0x100\n? report_bug+0x16a/0x190\n? handle_bug+0x51/0xa0\n? exc_invalid_op+0x18/0x80\n? iommu_dma_unmap_page+0xd5/0x100\n? iommu_dma_unmap_page+0x35/0x100\ndma_unmap_page_attrs+0x55/0x220\n? bpf_prog_4d7e87c0d30db711_xdp_dispatcher+0x64/0x9f\nbnxt_rx_xdp+0x237/0x520 [bnxt_en]\nbnxt_rx_pkt+0x640/0xdd0 [bnxt_en]\n__bnxt_poll_work+0x1a1/0x3d0 [bnxt_en]\nbnxt_poll+0xaa/0x1e0 [bnxt_en]\n__napi_poll+0x33/0x1e0\nnet_rx_action+0x18a/0x2f0",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44984"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8baeef7616d5194045c5a6b97fd1246b87c55b13"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95a305ba259b685780ed62ea2295aa2feb2d6c0c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fa4e6ae38574d0fc5596272bee64727d8ab7052b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json b/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json
new file mode 100644
index 00000000000..a0ac4b5ea37
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-wp45-jw6q-jm9q/GHSA-wp45-jw6q-jm9q.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wp45-jw6q-jm9q",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44987"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent UAF in ip6_send_skb()\n\nsyzbot reported an UAF in ip6_send_skb() [1]\n\nAfter ip6_local_out() has returned, we no longer can safely\ndereference rt, unless we hold rcu_read_lock().\n\nA similar issue has been fixed in commit\na688caa34beb (\"ipv6: take rcu lock in rawv6_send_hdrinc()\")\n\nAnother potential issue in ip6_finish_output2() is handled in a\nseparate patch.\n\n[1]\n BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\nRead of size 8 at addr ffff88806dde4858 by task syz.1.380/6530\n\nCPU: 1 UID: 0 PID: 6530 Comm: syz.1.380 Not tainted 6.11.0-rc3-syzkaller-00306-gdf6cbc62cc9b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\n rawv6_push_pending_frames+0x75c/0x9e0 net/ipv6/raw.c:588\n rawv6_sendmsg+0x19c7/0x23c0 net/ipv6/raw.c:926\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n sock_write_iter+0x2dd/0x400 net/socket.c:1160\n do_iter_readv_writev+0x60a/0x890\n vfs_writev+0x37c/0xbb0 fs/read_write.c:971\n do_writev+0x1b1/0x350 fs/read_write.c:1018\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f936bf79e79\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f936cd7f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000014\nRAX: ffffffffffffffda RBX: 00007f936c115f80 RCX: 00007f936bf79e79\nRDX: 0000000000000001 RSI: 0000000020000040 RDI: 0000000000000004\nRBP: 00007f936bfe7916 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f936c115f80 R15: 00007fff2860a7a8\n \n\nAllocated by task 6530:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:312 [inline]\n __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:338\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3988 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_noprof+0x135/0x2a0 mm/slub.c:4044\n dst_alloc+0x12b/0x190 net/core/dst.c:89\n ip6_blackhole_route+0x59/0x340 net/ipv6/route.c:2670\n make_blackhole net/xfrm/xfrm_policy.c:3120 [inline]\n xfrm_lookup_route+0xd1/0x1c0 net/xfrm/xfrm_policy.c:3313\n ip6_dst_lookup_flow+0x13e/0x180 net/ipv6/ip6_output.c:1257\n rawv6_sendmsg+0x1283/0x23c0 net/ipv6/raw.c:898\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597\n ___sys_sendmsg net/socket.c:2651 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2680\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 45:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2252 [inline]\n slab_free mm/slub.c:4473 [inline]\n kmem_cache_free+0x145/0x350 mm/slub.c:4548\n dst_destroy+0x2ac/0x460 net/core/dst.c:124\n rcu_do_batch kernel/rcu/tree.c:2569 [inline]\n rcu_core+0xafd/0x1830 kernel/rcu/tree.\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44987"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/24e93695b1239fbe4c31e224372be77f82dab69a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/571567e0277008459750f0728f246086b2659429"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9a3e55afa95ed4ac9eda112d4f918af645d72f25"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af1dde074ee2ed7dd5bdca4e7e8ba17f44e7b011"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cb5880a0de12c7f618d2bdd84e2d985f1e06ed7e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ce2f6cfab2c637d0bd9762104023a15d0ab7c0a8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e44bd76dd072756e674f45c5be00153f4ded68b2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/faa389b2fbaaec7fd27a390b4896139f9da662e3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-wq9h-7v97-wgcp/GHSA-wq9h-7v97-wgcp.json b/advisories/unreviewed/2024/09/GHSA-wq9h-7v97-wgcp/GHSA-wq9h-7v97-wgcp.json
new file mode 100644
index 00000000000..1ef5011ddc8
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-wq9h-7v97-wgcp/GHSA-wq9h-7v97-wgcp.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wq9h-7v97-wgcp",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44991"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: prevent concurrent execution of tcp_sk_exit_batch\n\nIts possible that two threads call tcp_sk_exit_batch() concurrently,\nonce from the cleanup_net workqueue, once from a task that failed to clone\na new netns. In the latter case, error unwinding calls the exit handlers\nin reverse order for the 'failed' netns.\n\ntcp_sk_exit_batch() calls tcp_twsk_purge().\nProblem is that since commit b099ce2602d8 (\"net: Batch inet_twsk_purge\"),\nthis function picks up twsk in any dying netns, not just the one passed\nin via exit_batch list.\n\nThis means that the error unwind of setup_net() can \"steal\" and destroy\ntimewait sockets belonging to the exiting netns.\n\nThis allows the netns exit worker to proceed to call\n\nWARN_ON_ONCE(!refcount_dec_and_test(&net->ipv4.tcp_death_row.tw_refcount));\n\nwithout the expected 1 -> 0 transition, which then splats.\n\nAt same time, error unwind path that is also running inet_twsk_purge()\nwill splat as well:\n\nWARNING: .. at lib/refcount.c:31 refcount_warn_saturate+0x1ed/0x210\n...\n refcount_dec include/linux/refcount.h:351 [inline]\n inet_twsk_kill+0x758/0x9c0 net/ipv4/inet_timewait_sock.c:70\n inet_twsk_deschedule_put net/ipv4/inet_timewait_sock.c:221\n inet_twsk_purge+0x725/0x890 net/ipv4/inet_timewait_sock.c:304\n tcp_sk_exit_batch+0x1c/0x170 net/ipv4/tcp_ipv4.c:3522\n ops_exit_list+0x128/0x180 net/core/net_namespace.c:178\n setup_net+0x714/0xb40 net/core/net_namespace.c:375\n copy_net_ns+0x2f0/0x670 net/core/net_namespace.c:508\n create_new_namespaces+0x3ea/0xb10 kernel/nsproxy.c:110\n\n... because refcount_dec() of tw_refcount unexpectedly dropped to 0.\n\nThis doesn't seem like an actual bug (no tw sockets got lost and I don't\nsee a use-after-free) but as erroneous trigger of debug check.\n\nAdd a mutex to force strict ordering: the task that calls tcp_twsk_purge()\nblocks other task from doing final _dec_and_test before mutex-owner has\nremoved all tw sockets of dying netns.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44991"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/565d121b69980637f040eb4d84289869cdaabedf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/99580ae890ec8bd98b21a2a9c6668f8f1555b62e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e3d9de3742f4d5c47ae35f888d3023a5b54fcd2f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f6fd2dbf584a4047ba88d1369ff91c9851261ec1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json b/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json
index fe3bf0feed7..97bd9e8e80b 100644
--- a/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json
+++ b/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvf7-c4v8-cmj9",
- "modified": "2024-09-04T18:30:58Z",
+ "modified": "2024-09-04T21:30:31Z",
"published": "2024-09-04T18:30:58Z",
"aliases": [
"CVE-2024-45177"
],
"details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent cross-site scripting (XSS) attacks. It was found out that the camera configuration is vulnerable to a persistent cross-site scripting attack due to insufficient user input validation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T18:15:05Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-wxc5-fq68-h9mh/GHSA-wxc5-fq68-h9mh.json b/advisories/unreviewed/2024/09/GHSA-wxc5-fq68-h9mh/GHSA-wxc5-fq68-h9mh.json
new file mode 100644
index 00000000000..b072847b718
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-wxc5-fq68-h9mh/GHSA-wxc5-fq68-h9mh.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wxc5-fq68-h9mh",
+ "modified": "2024-09-04T21:30:31Z",
+ "published": "2024-09-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-44949"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: fix a possible DMA corruption\n\nARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be\npossible that two unrelated 16-byte allocations share a cache line. If\none of these allocations is written using DMA and the other is written\nusing cached write, the value that was written with DMA may be\ncorrupted.\n\nThis commit changes ARCH_DMA_MINALIGN to be 128 on PA20 and 32 on PA1.1 -\nthat's the largest possible cache line size.\n\nAs different parisc microarchitectures have different cache line size, we\ndefine arch_slab_minalign(), cache_line_size() and\ndma_get_cache_alignment() so that the kernel may tune slab cache\nparameters dynamically, based on the detected cache line size.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44949"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/533de2f470baac40d3bf622fe631f15231a03c9f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/642a0b7453daff0295310774016fcb56d1f5bc7f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7ae04ba36b381bffe2471eff3a93edced843240f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json b/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json
new file mode 100644
index 00000000000..6ce2429942c
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-x53w-73fx-jmfj/GHSA-x53w-73fx-jmfj.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x53w-73fx-jmfj",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44986"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in ip6_finish_output2()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand associated dst/idev could also have been freed.\n\nWe need to hold rcu_read_lock() to make sure the dst and\nassociated idev are alive.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44986"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3574d28caf9a09756ae87ad1ea096c6f47b6101e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/56efc253196751ece1fc535a5b582be127b0578a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6ab6bf731354a6fdbaa617d1ec194960db61cf3b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/da273b377ae0d9bd255281ed3c2adb228321687b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e891b36de161fcd96f12ff83667473e5067b9037"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json b/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json
new file mode 100644
index 00000000000..274a159694c
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-xqr4-wc4c-36xj/GHSA-xqr4-wc4c-36xj.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xqr4-wc4c-36xj",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44971"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()\n\nbcm_sf2_mdio_register() calls of_phy_find_device() and then\nphy_device_remove() in a loop to remove existing PHY devices.\nof_phy_find_device() eventually calls bus_find_device(), which calls\nget_device() on the returned struct device * to increment the refcount.\nThe current implementation does not decrement the refcount, which causes\nmemory leak.\n\nThis commit adds the missing phy_device_free() call to decrement the\nrefcount via put_device() to balance the refcount.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44971"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7feef10768ea71d468d9bbc1e0d14c461876768c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7d2808d67570e6acae45c2a96e0d59986888e4c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b7b8d9f5e679af60c94251fd6728dde34be69a71"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c05516c072903f6fb9134b8e7e1ad4bffcdc4819"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e3862093ee93fcfbdadcb7957f5f8974fffa806a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f3d5efe18a11f94150fee8b3fda9d62079af640a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T19:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-xvjp-2h38-99ph/GHSA-xvjp-2h38-99ph.json b/advisories/unreviewed/2024/09/GHSA-xvjp-2h38-99ph/GHSA-xvjp-2h38-99ph.json
new file mode 100644
index 00000000000..8a1bafa8ab7
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-xvjp-2h38-99ph/GHSA-xvjp-2h38-99ph.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xvjp-2h38-99ph",
+ "modified": "2024-09-04T21:30:32Z",
+ "published": "2024-09-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-44993"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()`\n\nWhen enabling UBSAN on Raspberry Pi 5, we get the following warning:\n\n[ 387.894977] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/v3d/v3d_sched.c:320:3\n[ 387.903868] index 7 is out of range for type '__u32 [7]'\n[ 387.909692] CPU: 0 PID: 1207 Comm: kworker/u16:2 Tainted: G WC 6.10.3-v8-16k-numa #151\n[ 387.919166] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT)\n[ 387.925961] Workqueue: v3d_csd drm_sched_run_job_work [gpu_sched]\n[ 387.932525] Call trace:\n[ 387.935296] dump_backtrace+0x170/0x1b8\n[ 387.939403] show_stack+0x20/0x38\n[ 387.942907] dump_stack_lvl+0x90/0xd0\n[ 387.946785] dump_stack+0x18/0x28\n[ 387.950301] __ubsan_handle_out_of_bounds+0x98/0xd0\n[ 387.955383] v3d_csd_job_run+0x3a8/0x438 [v3d]\n[ 387.960707] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched]\n[ 387.966862] process_one_work+0x62c/0xb48\n[ 387.971296] worker_thread+0x468/0x5b0\n[ 387.975317] kthread+0x1c4/0x1e0\n[ 387.978818] ret_from_fork+0x10/0x20\n[ 387.983014] ---[ end trace ]---\n\nThis happens because the UAPI provides only seven configuration\nregisters and we are reading the eighth position of this u32 array.\n\nTherefore, fix the out-of-bounds read in `v3d_csd_job_run()` by\naccessing only seven positions on the '__u32 [7]' array. The eighth\nregister exists indeed on V3D 7.1, but it isn't currently used. That\nbeing so, let's guarantee that it remains unused and add a note that it\ncould be set in a future patch.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44993"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/497d370a644d95a9f04271aa92cb96d32e84c770"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d656b82c4b30cf12715e6cd129d3df808fde24a7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-04T20:15:08Z"
+ }
+}
\ No newline at end of file