From edcfba117488eca4aa4ed84169028569d421d270 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 24 Oct 2024 21:32:32 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-x9m8-f37f-rw74.json | 3 +- .../GHSA-4rf2-x7fh-vgpg.json | 3 +- .../GHSA-4wrc-8xjh-v948.json | 3 +- .../GHSA-67q8-hw3v-9fj4.json | 1 + .../GHSA-p332-vhv3-xv9m.json | 3 +- .../GHSA-j3v3-2jrv-w8cx.json | 3 +- .../GHSA-2f8j-394w-hvgc.json | 35 +++++++++++++++ .../GHSA-2gq6-q827-5p24.json | 11 +++-- .../GHSA-2m97-q37r-gwpc.json | 9 ++-- .../GHSA-358q-vf8c-9vqr.json | 39 +++++++++++++++++ .../GHSA-3p3h-j9q4-q239.json | 11 +++-- .../GHSA-42mx-rfqr-hp98.json | 35 +++++++++++++++ .../GHSA-44c5-jqqx-f38c.json | 11 +++-- .../GHSA-44h7-hpp5-qghj.json | 11 +++-- .../GHSA-495c-g5j5-wg9w.json | 11 +++-- .../GHSA-4pxm-mf9w-2x55.json | 39 +++++++++++++++++ .../GHSA-4wgw-m6jr-9h45.json | 9 ++-- .../GHSA-4wjx-5h7f-wqhw.json | 11 +++-- .../GHSA-52j3-f378-p3cw.json | 43 +++++++++++++++++++ .../GHSA-55f2-f95r-q833.json | 42 ++++++++++++++++++ .../GHSA-59m8-hg79-86pp.json | 11 +++-- .../GHSA-5cp3-hg96-hvr9.json | 11 +++-- .../GHSA-5hwh-9gc5-fwwg.json | 11 +++-- .../GHSA-5q55-gh5r-h286.json | 11 +++-- .../GHSA-5qr5-9jfv-96j2.json | 35 +++++++++++++++ .../GHSA-67rw-g94p-phv8.json | 11 +++-- .../GHSA-6892-j46w-9wqm.json | 11 +++-- .../GHSA-6ppv-9jp4-gprm.json | 11 +++-- .../GHSA-6wpg-r63h-r729.json | 9 ++-- .../GHSA-6xpp-xx5c-5qfg.json | 35 +++++++++++++++ .../GHSA-75vm-7626-f557.json | 11 +++-- .../GHSA-7jfp-wvrj-m47g.json | 11 +++-- .../GHSA-7m5m-pv6q-79fj.json | 11 +++-- .../GHSA-84x4-gjv7-hm5j.json | 11 +++-- .../GHSA-8hm3-x962-r5c7.json | 39 +++++++++++++++++ .../GHSA-8qg5-7fvg-hrc7.json | 11 +++-- .../GHSA-93cm-9ghm-5q5v.json | 35 +++++++++++++++ .../GHSA-9748-w7hv-7h34.json | 11 +++-- .../GHSA-9c44-5659-5mgq.json | 11 +++-- .../GHSA-9m3x-q77m-pwhx.json | 35 +++++++++++++++ .../GHSA-9r3v-4452-42x7.json | 39 +++++++++++++++++ .../GHSA-9r7v-6wjc-j5fj.json | 39 +++++++++++++++++ .../GHSA-c2hr-6qhm-xv9r.json | 42 ++++++++++++++++++ .../GHSA-c844-5xj7-6j82.json | 11 +++-- .../GHSA-chf9-635w-g4pv.json | 11 +++-- .../GHSA-f3gg-6f8f-39gh.json | 11 +++-- .../GHSA-f475-gxvf-mp72.json | 11 +++-- .../GHSA-f4gr-wwwj-m36c.json | 38 ++++++++++++++++ .../GHSA-f6pw-44qx-h3w9.json | 11 +++-- .../GHSA-fp5w-qv26-7xff.json | 11 +++-- .../GHSA-fx57-vmgw-6jm4.json | 11 +++-- .../GHSA-g8gm-98gj-8fwr.json | 11 +++-- .../GHSA-g8q6-23x5-v2wf.json | 35 +++++++++++++++ .../GHSA-gcv4-6hmh-xhwc.json | 11 +++-- .../GHSA-ghfq-rw9q-gx67.json | 9 ++-- .../GHSA-gx69-359j-659q.json | 11 +++-- .../GHSA-h37w-2wjf-qw6j.json | 11 +++-- .../GHSA-h52p-rfc4-3rcf.json | 11 +++-- .../GHSA-hq8j-584q-8j9q.json | 11 +++-- .../GHSA-j2cc-c4fg-77cq.json | 11 +++-- .../GHSA-j36j-5jh8-qqgc.json | 38 ++++++++++++++++ .../GHSA-j994-f74j-cwf3.json | 11 +++-- .../GHSA-jg3p-mpfh-w2hg.json | 39 +++++++++++++++++ .../GHSA-jjq3-cw48-pqmx.json | 39 +++++++++++++++++ .../GHSA-jpw5-f3qf-66fc.json | 11 +++-- .../GHSA-m2gv-rr38-g5r4.json | 11 +++-- .../GHSA-m3fc-5gx3-j98r.json | 11 +++-- .../GHSA-m6p4-vhgw-8c9c.json | 11 +++-- .../GHSA-mjhm-5r72-mjx7.json | 35 +++++++++++++++ .../GHSA-p27h-83pf-6hh9.json | 11 +++-- .../GHSA-pmp7-4p22-ggcc.json | 11 +++-- .../GHSA-pvfv-p8r5-hrcw.json | 11 +++-- .../GHSA-qfj5-q5g9-m5pm.json | 11 +++-- .../GHSA-qh7g-57ww-6fq4.json | 2 +- .../GHSA-qjvc-xmqv-cwr9.json | 11 +++-- .../GHSA-rprc-6487-2q3v.json | 11 +++-- .../GHSA-rrmj-qxgv-v296.json | 35 +++++++++++++++ .../GHSA-vcrj-5576-fc99.json | 11 +++-- .../GHSA-vpfw-56r4-6hcq.json | 35 +++++++++++++++ .../GHSA-w7vv-chh5-rjfj.json | 39 +++++++++++++++++ .../GHSA-w8r5-25wc-2c5m.json | 39 +++++++++++++++++ .../GHSA-wg4j-4q4f-6cfc.json | 11 +++-- .../GHSA-wp73-c4gh-8ccr.json | 11 +++-- .../GHSA-xwhx-3qqx-64m9.json | 11 +++-- .../GHSA-xxqv-jc35-w8cj.json | 11 +++-- 85 files changed, 1290 insertions(+), 218 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-2f8j-394w-hvgc/GHSA-2f8j-394w-hvgc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-358q-vf8c-9vqr/GHSA-358q-vf8c-9vqr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-42mx-rfqr-hp98/GHSA-42mx-rfqr-hp98.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4pxm-mf9w-2x55/GHSA-4pxm-mf9w-2x55.json create mode 100644 advisories/unreviewed/2024/10/GHSA-52j3-f378-p3cw/GHSA-52j3-f378-p3cw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-55f2-f95r-q833/GHSA-55f2-f95r-q833.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5qr5-9jfv-96j2/GHSA-5qr5-9jfv-96j2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6xpp-xx5c-5qfg/GHSA-6xpp-xx5c-5qfg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-93cm-9ghm-5q5v/GHSA-93cm-9ghm-5q5v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9m3x-q77m-pwhx/GHSA-9m3x-q77m-pwhx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9r7v-6wjc-j5fj/GHSA-9r7v-6wjc-j5fj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f4gr-wwwj-m36c/GHSA-f4gr-wwwj-m36c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g8q6-23x5-v2wf/GHSA-g8q6-23x5-v2wf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j36j-5jh8-qqgc/GHSA-j36j-5jh8-qqgc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jg3p-mpfh-w2hg/GHSA-jg3p-mpfh-w2hg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rrmj-qxgv-v296/GHSA-rrmj-qxgv-v296.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vpfw-56r4-6hcq/GHSA-vpfw-56r4-6hcq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json diff --git a/advisories/unreviewed/2024/06/GHSA-x9m8-f37f-rw74/GHSA-x9m8-f37f-rw74.json b/advisories/unreviewed/2024/06/GHSA-x9m8-f37f-rw74/GHSA-x9m8-f37f-rw74.json index bc1d93e3445..83a96183623 100644 --- a/advisories/unreviewed/2024/06/GHSA-x9m8-f37f-rw74/GHSA-x9m8-f37f-rw74.json +++ b/advisories/unreviewed/2024/06/GHSA-x9m8-f37f-rw74/GHSA-x9m8-f37f-rw74.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4rf2-x7fh-vgpg/GHSA-4rf2-x7fh-vgpg.json b/advisories/unreviewed/2024/08/GHSA-4rf2-x7fh-vgpg/GHSA-4rf2-x7fh-vgpg.json index 470993d3eb4..370c259a4df 100644 --- a/advisories/unreviewed/2024/08/GHSA-4rf2-x7fh-vgpg/GHSA-4rf2-x7fh-vgpg.json +++ b/advisories/unreviewed/2024/08/GHSA-4rf2-x7fh-vgpg/GHSA-4rf2-x7fh-vgpg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json b/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json index fc1b5d35bcb..142772f7659 100644 --- a/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json +++ b/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json b/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json index a141b3d1d27..7ff1935e527 100644 --- a/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json +++ b/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1188", "CWE-453" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json b/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json index 3b40d592757..7f60a0f626c 100644 --- a/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json +++ b/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json b/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json index 93349ca9434..204456f99f1 100644 --- a/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json +++ b/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2f8j-394w-hvgc/GHSA-2f8j-394w-hvgc.json b/advisories/unreviewed/2024/10/GHSA-2f8j-394w-hvgc/GHSA-2f8j-394w-hvgc.json new file mode 100644 index 00000000000..86266707df3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2f8j-394w-hvgc/GHSA-2f8j-394w-hvgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f8j-394w-hvgc", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-45261" + ], + "details": "An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45261" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Bypassing%20Login%20Mechanism%20with%20Passwordless%20User%20Login.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2gq6-q827-5p24/GHSA-2gq6-q827-5p24.json b/advisories/unreviewed/2024/10/GHSA-2gq6-q827-5p24/GHSA-2gq6-q827-5p24.json index c6ef9a5368e..f736f92cef6 100644 --- a/advisories/unreviewed/2024/10/GHSA-2gq6-q827-5p24/GHSA-2gq6-q827-5p24.json +++ b/advisories/unreviewed/2024/10/GHSA-2gq6-q827-5p24/GHSA-2gq6-q827-5p24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2gq6-q827-5p24", - "modified": "2024-10-24T18:30:42Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:42Z", "aliases": [ "CVE-2024-48538" ], "details": "Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T16:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2m97-q37r-gwpc/GHSA-2m97-q37r-gwpc.json b/advisories/unreviewed/2024/10/GHSA-2m97-q37r-gwpc/GHSA-2m97-q37r-gwpc.json index 73b2cff6842..db2d74a6663 100644 --- a/advisories/unreviewed/2024/10/GHSA-2m97-q37r-gwpc/GHSA-2m97-q37r-gwpc.json +++ b/advisories/unreviewed/2024/10/GHSA-2m97-q37r-gwpc/GHSA-2m97-q37r-gwpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2m97-q37r-gwpc", - "modified": "2024-10-23T15:31:08Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-23T15:31:08Z", "aliases": [ "CVE-2024-50050" ], "details": "Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-23T14:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-358q-vf8c-9vqr/GHSA-358q-vf8c-9vqr.json b/advisories/unreviewed/2024/10/GHSA-358q-vf8c-9vqr/GHSA-358q-vf8c-9vqr.json new file mode 100644 index 00000000000..a27fffc6a70 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-358q-vf8c-9vqr/GHSA-358q-vf8c-9vqr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-358q-vf8c-9vqr", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-45242" + ], + "details": "EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentials of admin/admin. An unauthorized attacker in proximity to the Wi-Fi network can exploit this window of time to execute arbitrary OS commands with root-level permissions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45242" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-45242" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-45242_Extended_Report.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3p3h-j9q4-q239/GHSA-3p3h-j9q4-q239.json b/advisories/unreviewed/2024/10/GHSA-3p3h-j9q4-q239/GHSA-3p3h-j9q4-q239.json index 0b6237aa7c6..8cf97227ad2 100644 --- a/advisories/unreviewed/2024/10/GHSA-3p3h-j9q4-q239/GHSA-3p3h-j9q4-q239.json +++ b/advisories/unreviewed/2024/10/GHSA-3p3h-j9q4-q239/GHSA-3p3h-j9q4-q239.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p3h-j9q4-q239", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-48545" ], "details": "Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-42mx-rfqr-hp98/GHSA-42mx-rfqr-hp98.json b/advisories/unreviewed/2024/10/GHSA-42mx-rfqr-hp98/GHSA-42mx-rfqr-hp98.json new file mode 100644 index 00000000000..80ff52808b9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-42mx-rfqr-hp98/GHSA-42mx-rfqr-hp98.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42mx-rfqr-hp98", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:04Z", + "aliases": [ + "CVE-2024-48426" + ], + "details": "A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48426" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/5789" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-44c5-jqqx-f38c/GHSA-44c5-jqqx-f38c.json b/advisories/unreviewed/2024/10/GHSA-44c5-jqqx-f38c/GHSA-44c5-jqqx-f38c.json index d72a596c1e4..ae43d732e54 100644 --- a/advisories/unreviewed/2024/10/GHSA-44c5-jqqx-f38c/GHSA-44c5-jqqx-f38c.json +++ b/advisories/unreviewed/2024/10/GHSA-44c5-jqqx-f38c/GHSA-44c5-jqqx-f38c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44c5-jqqx-f38c", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49010" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (coretemp) Check for null before removing sysfs attrs\n\nIf coretemp_add_core() gets an error then pdata->core_data[indx]\nis already NULL and has been kfreed. Don't pass that to\nsysfs_remove_group() as that will crash in sysfs_remove_group().\n\n[Shortened for readability]\n[91854.020159] sysfs: cannot create duplicate filename '/devices/platform/coretemp.0/hwmon/hwmon2/temp20_label'\n\n[91855.126115] BUG: kernel NULL pointer dereference, address: 0000000000000188\n[91855.165103] #PF: supervisor read access in kernel mode\n[91855.194506] #PF: error_code(0x0000) - not-present page\n[91855.224445] PGD 0 P4D 0\n[91855.238508] Oops: 0000 [#1] PREEMPT SMP PTI\n...\n[91855.342716] RIP: 0010:sysfs_remove_group+0xc/0x80\n...\n[91855.796571] Call Trace:\n[91855.810524] coretemp_cpu_offline+0x12b/0x1dd [coretemp]\n[91855.841738] ? coretemp_cpu_online+0x180/0x180 [coretemp]\n[91855.871107] cpuhp_invoke_callback+0x105/0x4b0\n[91855.893432] cpuhp_thread_fun+0x8e/0x150\n...\n\nFix this by checking for NULL first.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-44h7-hpp5-qghj/GHSA-44h7-hpp5-qghj.json b/advisories/unreviewed/2024/10/GHSA-44h7-hpp5-qghj/GHSA-44h7-hpp5-qghj.json index da02cfc3174..357ccf9256e 100644 --- a/advisories/unreviewed/2024/10/GHSA-44h7-hpp5-qghj/GHSA-44h7-hpp5-qghj.json +++ b/advisories/unreviewed/2024/10/GHSA-44h7-hpp5-qghj/GHSA-44h7-hpp5-qghj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44h7-hpp5-qghj", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49021" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: fix null-ptr-deref while probe() failed\n\nI got a null-ptr-deref report as following when doing fault injection test:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000058\nOops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G B N 6.1.0-rc3+\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nRIP: 0010:klist_put+0x2d/0xd0\nCall Trace:\n \n klist_remove+0xf1/0x1c0\n device_release_driver_internal+0x23e/0x2d0\n bus_remove_device+0x1bd/0x240\n device_del+0x357/0x770\n phy_device_remove+0x11/0x30\n mdiobus_unregister+0xa5/0x140\n release_nodes+0x6a/0xa0\n devres_release_all+0xf8/0x150\n device_unbind_cleanup+0x19/0xd0\n\n//probe path:\nphy_device_register()\n device_add()\n\nphy_connect\n phy_attach_direct() //set device driver\n probe() //it's failed, driver is not bound\n device_bind_driver() // probe failed, it's not called\n\n//remove path:\nphy_device_remove()\n device_del()\n device_release_driver_internal()\n __device_release_driver() //dev->drv is not NULL\n klist_remove() <- knode_driver is not added yet, cause null-ptr-deref\n\nIn phy_attach_direct(), after setting the 'dev->driver', probe() fails,\ndevice_bind_driver() is not called, so the knode_driver->n_klist is not\nset, then it causes null-ptr-deref in __device_release_driver() while\ndeleting device. Fix this by setting dev->driver to NULL in the error\npath in phy_attach_direct().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-495c-g5j5-wg9w/GHSA-495c-g5j5-wg9w.json b/advisories/unreviewed/2024/10/GHSA-495c-g5j5-wg9w/GHSA-495c-g5j5-wg9w.json index 4680f4bc2cc..b3959fed647 100644 --- a/advisories/unreviewed/2024/10/GHSA-495c-g5j5-wg9w/GHSA-495c-g5j5-wg9w.json +++ b/advisories/unreviewed/2024/10/GHSA-495c-g5j5-wg9w/GHSA-495c-g5j5-wg9w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-495c-g5j5-wg9w", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49020" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/9p: Fix a potential socket leak in p9_socket_open\n\nBoth p9_fd_create_tcp() and p9_fd_create_unix() will call\np9_socket_open(). If the creation of p9_trans_fd fails,\np9_fd_create_tcp() and p9_fd_create_unix() will return an\nerror directly instead of releasing the cscoket, which will\nresult in a socket leak.\n\nThis patch adds sock_release() to fix the leak issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4pxm-mf9w-2x55/GHSA-4pxm-mf9w-2x55.json b/advisories/unreviewed/2024/10/GHSA-4pxm-mf9w-2x55/GHSA-4pxm-mf9w-2x55.json new file mode 100644 index 00000000000..4c5ecca4111 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4pxm-mf9w-2x55/GHSA-4pxm-mf9w-2x55.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pxm-mf9w-2x55", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48427" + ], + "details": "A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48427" + }, + { + "type": "WEB", + "url": "https://github.com/vighneshnair7/CVE-2024-48427/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/15360/packers-and-movers-management-system-phpoop-free-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4wgw-m6jr-9h45/GHSA-4wgw-m6jr-9h45.json b/advisories/unreviewed/2024/10/GHSA-4wgw-m6jr-9h45/GHSA-4wgw-m6jr-9h45.json index 9127a4cb710..3bddf0192af 100644 --- a/advisories/unreviewed/2024/10/GHSA-4wgw-m6jr-9h45/GHSA-4wgw-m6jr-9h45.json +++ b/advisories/unreviewed/2024/10/GHSA-4wgw-m6jr-9h45/GHSA-4wgw-m6jr-9h45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wgw-m6jr-9h45", - "modified": "2024-10-24T00:33:36Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T00:33:36Z", "aliases": [ "CVE-2024-40431" ], "details": "A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-23T22:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json b/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json index 734f7c86664..7db600bbd84 100644 --- a/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json +++ b/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wjx-5h7f-wqhw", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49879" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: omapdrm: Add missing check for alloc_ordered_workqueue\n\nAs it may return NULL pointer and cause NULL pointer dereference. Add check\nfor the return value of alloc_ordered_workqueue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-52j3-f378-p3cw/GHSA-52j3-f378-p3cw.json b/advisories/unreviewed/2024/10/GHSA-52j3-f378-p3cw/GHSA-52j3-f378-p3cw.json new file mode 100644 index 00000000000..511feadc229 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-52j3-f378-p3cw/GHSA-52j3-f378-p3cw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52j3-f378-p3cw", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48454" + ], + "details": "An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48454" + }, + { + "type": "WEB", + "url": "https://github.com/N0zoM1z0/CVEs/blob/main/CVE-2024-48454.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/14935/purchase-order-management-system-using-php-free-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-55f2-f95r-q833/GHSA-55f2-f95r-q833.json b/advisories/unreviewed/2024/10/GHSA-55f2-f95r-q833/GHSA-55f2-f95r-q833.json new file mode 100644 index 00000000000..9432ee7ee1b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-55f2-f95r-q833/GHSA-55f2-f95r-q833.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55f2-f95r-q833", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-10327" + ], + "details": "A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the notification banner and selects an option, both options allow the authentication to succeed. \nThe ContextExtension feature is one of several push mechanisms available when using Okta Verify Push on iOS devices. The vulnerable flows include: \n* When a user is presented with a notification on a locked screen, the user presses on the notification directly and selects their reply without unlocking the device; \n* When a user is presented with a notification on the home screen and drags the notification down and selects their reply; \n* When an Apple Watch is used to reply directly to a notification. \n\n A pre-condition for this vulnerability is that the user must have enrolled in Okta Verify while the Okta customer was using Okta Classic. This applies irrespective of whether the organization has since upgraded to Okta Identity Engine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10327" + }, + { + "type": "WEB", + "url": "https://help.okta.com/en-us/content/topics/releasenotes/okta-verify-release-notes.htm#panel2" + }, + { + "type": "WEB", + "url": "https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-59m8-hg79-86pp/GHSA-59m8-hg79-86pp.json b/advisories/unreviewed/2024/10/GHSA-59m8-hg79-86pp/GHSA-59m8-hg79-86pp.json index cb6fbfef3c5..93fa09dcc3e 100644 --- a/advisories/unreviewed/2024/10/GHSA-59m8-hg79-86pp/GHSA-59m8-hg79-86pp.json +++ b/advisories/unreviewed/2024/10/GHSA-59m8-hg79-86pp/GHSA-59m8-hg79-86pp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59m8-hg79-86pp", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48962" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hisilicon: Fix potential use-after-free in hisi_femac_rx()\n\nThe skb is delivered to napi_gro_receive() which may free it, after\ncalling this, dereferencing skb may trigger use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5cp3-hg96-hvr9/GHSA-5cp3-hg96-hvr9.json b/advisories/unreviewed/2024/10/GHSA-5cp3-hg96-hvr9/GHSA-5cp3-hg96-hvr9.json index cbad847c7b3..66212e8542b 100644 --- a/advisories/unreviewed/2024/10/GHSA-5cp3-hg96-hvr9/GHSA-5cp3-hg96-hvr9.json +++ b/advisories/unreviewed/2024/10/GHSA-5cp3-hg96-hvr9/GHSA-5cp3-hg96-hvr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5cp3-hg96-hvr9", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49016" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mdiobus: fix unbalanced node reference count\n\nI got the following report while doing device(mscc-miim) load test\nwith CONFIG_OF_UNITTEST and CONFIG_OF_DYNAMIC enabled:\n\n OF: ERROR: memory leak, expected refcount 1 instead of 2,\n of_node_get()/of_node_put() unbalanced - destroy cset entry:\n attach overlay node /spi/soc@0/mdio@7107009c/ethernet-phy@0\n\nIf the 'fwnode' is not an acpi node, the refcount is get in\nfwnode_mdiobus_phy_device_register(), but it has never been\nput when the device is freed in the normal path. So call\nfwnode_handle_put() in phy_device_release() to avoid leak.\n\nIf it's an acpi node, it has never been get, but it's put\nin the error path, so call fwnode_handle_get() before\nphy_device_register() to keep get/put operation balanced.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5hwh-9gc5-fwwg/GHSA-5hwh-9gc5-fwwg.json b/advisories/unreviewed/2024/10/GHSA-5hwh-9gc5-fwwg/GHSA-5hwh-9gc5-fwwg.json index 72b7caaeba3..48ecf981253 100644 --- a/advisories/unreviewed/2024/10/GHSA-5hwh-9gc5-fwwg/GHSA-5hwh-9gc5-fwwg.json +++ b/advisories/unreviewed/2024/10/GHSA-5hwh-9gc5-fwwg/GHSA-5hwh-9gc5-fwwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hwh-9gc5-fwwg", - "modified": "2024-10-21T21:30:54Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50045" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: fix panic with metadata_dst skb\n\nFix a kernel panic in the br_netfilter module when sending untagged\ntraffic via a VxLAN device.\nThis happens during the check for fragmentation in br_nf_dev_queue_xmit.\n\nIt is dependent on:\n1) the br_netfilter module being loaded;\n2) net.bridge.bridge-nf-call-iptables set to 1;\n3) a bridge with a VxLAN (single-vxlan-device) netdevice as a bridge port;\n4) untagged frames with size higher than the VxLAN MTU forwarded/flooded\n\nWhen forwarding the untagged packet to the VxLAN bridge port, before\nthe netfilter hooks are called, br_handle_egress_vlan_tunnel is called and\nchanges the skb_dst to the tunnel dst. The tunnel_dst is a metadata type\nof dst, i.e., skb_valid_dst(skb) is false, and metadata->dst.dev is NULL.\n\nThen in the br_netfilter hooks, in br_nf_dev_queue_xmit, there's a check\nfor frames that needs to be fragmented: frames with higher MTU than the\nVxLAN device end up calling br_nf_ip_fragment, which in turns call\nip_skb_dst_mtu.\n\nThe ip_dst_mtu tries to use the skb_dst(skb) as if it was a valid dst\nwith valid dst->dev, thus the crash.\n\nThis case was never supported in the first place, so drop the packet\ninstead.\n\nPING 10.0.0.2 (10.0.0.2) from 0.0.0.0 h1-eth0: 2000(2028) bytes of data.\n[ 176.291791] Unable to handle kernel NULL pointer dereference at\nvirtual address 0000000000000110\n[ 176.292101] Mem abort info:\n[ 176.292184] ESR = 0x0000000096000004\n[ 176.292322] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 176.292530] SET = 0, FnV = 0\n[ 176.292709] EA = 0, S1PTW = 0\n[ 176.292862] FSC = 0x04: level 0 translation fault\n[ 176.293013] Data abort info:\n[ 176.293104] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 176.293488] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 176.293787] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 176.293995] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000043ef5000\n[ 176.294166] [0000000000000110] pgd=0000000000000000,\np4d=0000000000000000\n[ 176.294827] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 176.295252] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel veth\nbr_netfilter bridge stp llc ipv6 crct10dif_ce\n[ 176.295923] CPU: 0 PID: 188 Comm: ping Not tainted\n6.8.0-rc3-g5b3fbd61b9d1 #2\n[ 176.296314] Hardware name: linux,dummy-virt (DT)\n[ 176.296535] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS\nBTYPE=--)\n[ 176.296808] pc : br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter]\n[ 176.297382] lr : br_nf_dev_queue_xmit+0x2ac/0x4ec [br_netfilter]\n[ 176.297636] sp : ffff800080003630\n[ 176.297743] x29: ffff800080003630 x28: 0000000000000008 x27:\nffff6828c49ad9f8\n[ 176.298093] x26: ffff6828c49ad000 x25: 0000000000000000 x24:\n00000000000003e8\n[ 176.298430] x23: 0000000000000000 x22: ffff6828c4960b40 x21:\nffff6828c3b16d28\n[ 176.298652] x20: ffff6828c3167048 x19: ffff6828c3b16d00 x18:\n0000000000000014\n[ 176.298926] x17: ffffb0476322f000 x16: ffffb7e164023730 x15:\n0000000095744632\n[ 176.299296] x14: ffff6828c3f1c880 x13: 0000000000000002 x12:\nffffb7e137926a70\n[ 176.299574] x11: 0000000000000001 x10: ffff6828c3f1c898 x9 :\n0000000000000000\n[ 176.300049] x8 : ffff6828c49bf070 x7 : 0008460f18d5f20e x6 :\nf20e0100bebafeca\n[ 176.300302] x5 : ffff6828c7f918fe x4 : ffff6828c49bf070 x3 :\n0000000000000000\n[ 176.300586] x2 : 0000000000000000 x1 : ffff6828c3c7ad00 x0 :\nffff6828c7f918f0\n[ 176.300889] Call trace:\n[ 176.301123] br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter]\n[ 176.301411] br_nf_post_routing+0x2a8/0x3e4 [br_netfilter]\n[ 176.301703] nf_hook_slow+0x48/0x124\n[ 176.302060] br_forward_finish+0xc8/0xe8 [bridge]\n[ 176.302371] br_nf_hook_thresh+0x124/0x134 [br_netfilter]\n[ 176.302605] br_nf_forward_finish+0x118/0x22c [br_netfilter]\n[ 176.302824] br_nf_forward_ip.part.0+0x264/0x290 [br_netfilter]\n[ 176.303136] br_nf_forward+0x2b8/0x4e0 [br_netfilter]\n[ 176.303359] nf_hook_slow+0x48/0x124\n[ 176.303\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5q55-gh5r-h286/GHSA-5q55-gh5r-h286.json b/advisories/unreviewed/2024/10/GHSA-5q55-gh5r-h286/GHSA-5q55-gh5r-h286.json index e287eab0794..9bb0f354f9f 100644 --- a/advisories/unreviewed/2024/10/GHSA-5q55-gh5r-h286/GHSA-5q55-gh5r-h286.json +++ b/advisories/unreviewed/2024/10/GHSA-5q55-gh5r-h286/GHSA-5q55-gh5r-h286.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q55-gh5r-h286", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50043" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix possible badness in FREE_STATEID\n\nWhen multiple FREE_STATEIDs are sent for the same delegation stateid,\nit can lead to a possible either use-after-free or counter refcount\nunderflow errors.\n\nIn nfsd4_free_stateid() under the client lock we find a delegation\nstateid, however the code drops the lock before calling nfs4_put_stid(),\nthat allows another FREE_STATE to find the stateid again. The first one\nwill proceed to then free the stateid which leads to either\nuse-after-free or decrementing already zeroed counter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5qr5-9jfv-96j2/GHSA-5qr5-9jfv-96j2.json b/advisories/unreviewed/2024/10/GHSA-5qr5-9jfv-96j2/GHSA-5qr5-9jfv-96j2.json new file mode 100644 index 00000000000..bf5fe226795 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5qr5-9jfv-96j2/GHSA-5qr5-9jfv-96j2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qr5-9jfv-96j2", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:04Z", + "aliases": [ + "CVE-2024-48425" + ], + "details": "A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48425" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/5791" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-67rw-g94p-phv8/GHSA-67rw-g94p-phv8.json b/advisories/unreviewed/2024/10/GHSA-67rw-g94p-phv8/GHSA-67rw-g94p-phv8.json index b03f8845fd9..5815fad9b21 100644 --- a/advisories/unreviewed/2024/10/GHSA-67rw-g94p-phv8/GHSA-67rw-g94p-phv8.json +++ b/advisories/unreviewed/2024/10/GHSA-67rw-g94p-phv8/GHSA-67rw-g94p-phv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67rw-g94p-phv8", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49018" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix sleep in atomic at close time\n\nMatt reported a splat at msk close time:\n\n BUG: sleeping function called from invalid context at net/mptcp/protocol.c:2877\n in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 155, name: packetdrill\n preempt_count: 201, expected: 0\n RCU nest depth: 0, expected: 0\n 4 locks held by packetdrill/155:\n #0: ffff888001536990 (&sb->s_type->i_mutex_key#6){+.+.}-{3:3}, at: __sock_release (net/socket.c:650)\n #1: ffff88800b498130 (sk_lock-AF_INET){+.+.}-{0:0}, at: mptcp_close (net/mptcp/protocol.c:2973)\n #2: ffff88800b49a130 (sk_lock-AF_INET/1){+.+.}-{0:0}, at: __mptcp_close_ssk (net/mptcp/protocol.c:2363)\n #3: ffff88800b49a0b0 (slock-AF_INET){+...}-{2:2}, at: __lock_sock_fast (include/net/sock.h:1820)\n Preemption disabled at:\n 0x0\n CPU: 1 PID: 155 Comm: packetdrill Not tainted 6.1.0-rc5 #365\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Call Trace:\n \n dump_stack_lvl (lib/dump_stack.c:107 (discriminator 4))\n __might_resched.cold (kernel/sched/core.c:9891)\n __mptcp_destroy_sock (include/linux/kernel.h:110)\n __mptcp_close (net/mptcp/protocol.c:2959)\n mptcp_subflow_queue_clean (include/net/sock.h:1777)\n __mptcp_close_ssk (net/mptcp/protocol.c:2363)\n mptcp_destroy_common (net/mptcp/protocol.c:3170)\n mptcp_destroy (include/net/sock.h:1495)\n __mptcp_destroy_sock (net/mptcp/protocol.c:2886)\n __mptcp_close (net/mptcp/protocol.c:2959)\n mptcp_close (net/mptcp/protocol.c:2974)\n inet_release (net/ipv4/af_inet.c:432)\n __sock_release (net/socket.c:651)\n sock_close (net/socket.c:1367)\n __fput (fs/file_table.c:320)\n task_work_run (kernel/task_work.c:181 (discriminator 1))\n exit_to_user_mode_prepare (include/linux/resume_user_mode.h:49)\n syscall_exit_to_user_mode (kernel/entry/common.c:130)\n do_syscall_64 (arch/x86/entry/common.c:87)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:120)\n\nWe can't call mptcp_close under the 'fast' socket lock variant, replace\nit with a sock_lock_nested() as the relevant code is already under the\nlistening msk socket lock protection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6892-j46w-9wqm/GHSA-6892-j46w-9wqm.json b/advisories/unreviewed/2024/10/GHSA-6892-j46w-9wqm/GHSA-6892-j46w-9wqm.json index 210ac8eed33..6e3acdc12bf 100644 --- a/advisories/unreviewed/2024/10/GHSA-6892-j46w-9wqm/GHSA-6892-j46w-9wqm.json +++ b/advisories/unreviewed/2024/10/GHSA-6892-j46w-9wqm/GHSA-6892-j46w-9wqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6892-j46w-9wqm", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48958" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethernet: aeroflex: fix potential skb leak in greth_init_rings()\n\nThe greth_init_rings() function won't free the newly allocated skb when\ndma_mapping_error() returns error, so add dev_kfree_skb() to fix it.\n\nCompile tested only.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json b/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json index 32bb09396ab..d64300a32ad 100644 --- a/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json +++ b/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6ppv-9jp4-gprm", - "modified": "2024-10-21T18:30:57Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49923" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags\n\n[WHAT & HOW]\n\"dcn20_validate_apply_pipe_split_flags\" dereferences merge, and thus it\ncannot be a null pointer. Let's pass a valid pointer to avoid null\ndereference.\n\nThis fixes 2 FORWARD_NULL issues reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6wpg-r63h-r729/GHSA-6wpg-r63h-r729.json b/advisories/unreviewed/2024/10/GHSA-6wpg-r63h-r729/GHSA-6wpg-r63h-r729.json index 22fbc6e9da0..7f961762498 100644 --- a/advisories/unreviewed/2024/10/GHSA-6wpg-r63h-r729/GHSA-6wpg-r63h-r729.json +++ b/advisories/unreviewed/2024/10/GHSA-6wpg-r63h-r729/GHSA-6wpg-r63h-r729.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6wpg-r63h-r729", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48961" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mdio: fix unbalanced fwnode reference count in mdio_device_release()\n\nThere is warning report about of_node refcount leak\nwhile probing mdio device:\n\nOF: ERROR: memory leak, expected refcount 1 instead of 2,\nof_node_get()/of_node_put() unbalanced - destroy cset entry:\nattach overlay node /spi/soc@0/mdio@710700c0/ethernet@4\n\nIn of_mdiobus_register_device(), we increase fwnode refcount\nby fwnode_handle_get() before associating the of_node with\nmdio device, but it has never been decreased in normal path.\nSince that, in mdio_device_release(), it needs to call\nfwnode_handle_put() in addition instead of calling kfree()\ndirectly.\n\nAfter above, just calling mdio_device_free() in the error handle\npath of of_mdiobus_register_device() is enough to keep the\nrefcount balanced.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6xpp-xx5c-5qfg/GHSA-6xpp-xx5c-5qfg.json b/advisories/unreviewed/2024/10/GHSA-6xpp-xx5c-5qfg/GHSA-6xpp-xx5c-5qfg.json new file mode 100644 index 00000000000..1151c00e148 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6xpp-xx5c-5qfg/GHSA-6xpp-xx5c-5qfg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xpp-xx5c-5qfg", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-45262" + ], + "details": "An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45262" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Improper%20Pathname%20Restriction%20Leading%20to%20Path%20Traversal%20in%20Restricted%20Directories.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-75vm-7626-f557/GHSA-75vm-7626-f557.json b/advisories/unreviewed/2024/10/GHSA-75vm-7626-f557/GHSA-75vm-7626-f557.json index ee30c8500d0..4bcb0176d82 100644 --- a/advisories/unreviewed/2024/10/GHSA-75vm-7626-f557/GHSA-75vm-7626-f557.json +++ b/advisories/unreviewed/2024/10/GHSA-75vm-7626-f557/GHSA-75vm-7626-f557.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75vm-7626-f557", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49030" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibbpf: Handle size overflow for ringbuf mmap\n\nThe maximum size of ringbuf is 2GB on x86-64 host, so 2 * max_entries\nwill overflow u32 when mapping producer page and data pages. Only\ncasting max_entries to size_t is not enough, because for 32-bits\napplication on 64-bits kernel the size of read-only mmap region\nalso could overflow size_t.\n\nSo fixing it by casting the size of read-only mmap region into a __u64\nand checking whether or not there will be overflow during mmap.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json b/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json index a402f263f95..10c706e017d 100644 --- a/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json +++ b/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jfp-wvrj-m47g", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49877" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate\n\nWhen doing cleanup, if flags without OCFS2_BH_READAHEAD, it may trigger\nNULL pointer dereference in the following ocfs2_set_buffer_uptodate() if\nbh is NULL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7m5m-pv6q-79fj/GHSA-7m5m-pv6q-79fj.json b/advisories/unreviewed/2024/10/GHSA-7m5m-pv6q-79fj/GHSA-7m5m-pv6q-79fj.json index 3e20b6d1340..e85d3c37885 100644 --- a/advisories/unreviewed/2024/10/GHSA-7m5m-pv6q-79fj/GHSA-7m5m-pv6q-79fj.json +++ b/advisories/unreviewed/2024/10/GHSA-7m5m-pv6q-79fj/GHSA-7m5m-pv6q-79fj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m5m-pv6q-79fj", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49015" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: Fix potential use-after-free\n\nThe skb is delivered to netif_rx() which may free it, after calling this,\ndereferencing skb may trigger use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-84x4-gjv7-hm5j/GHSA-84x4-gjv7-hm5j.json b/advisories/unreviewed/2024/10/GHSA-84x4-gjv7-hm5j/GHSA-84x4-gjv7-hm5j.json index 1abf51a84e1..f2ce8f53cb5 100644 --- a/advisories/unreviewed/2024/10/GHSA-84x4-gjv7-hm5j/GHSA-84x4-gjv7-hm5j.json +++ b/advisories/unreviewed/2024/10/GHSA-84x4-gjv7-hm5j/GHSA-84x4-gjv7-hm5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84x4-gjv7-hm5j", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49011" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new()\n\nAs comment of pci_get_domain_bus_and_slot() says, it returns\na pci device with refcount increment, when finish using it,\nthe caller must decrement the reference count by calling\npci_dev_put(). So call it after using to avoid refcount leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json b/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json new file mode 100644 index 00000000000..49d14161cce --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hm3-x962-r5c7", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48143" + ], + "details": "A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48143" + }, + { + "type": "WEB", + "url": "https://digitory.com/multi-channel-integrated-pos" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48143" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8qg5-7fvg-hrc7/GHSA-8qg5-7fvg-hrc7.json b/advisories/unreviewed/2024/10/GHSA-8qg5-7fvg-hrc7/GHSA-8qg5-7fvg-hrc7.json index 058f85b5cbe..ab8fd21e759 100644 --- a/advisories/unreviewed/2024/10/GHSA-8qg5-7fvg-hrc7/GHSA-8qg5-7fvg-hrc7.json +++ b/advisories/unreviewed/2024/10/GHSA-8qg5-7fvg-hrc7/GHSA-8qg5-7fvg-hrc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qg5-7fvg-hrc7", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-48542" ], "details": "Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-93cm-9ghm-5q5v/GHSA-93cm-9ghm-5q5v.json b/advisories/unreviewed/2024/10/GHSA-93cm-9ghm-5q5v/GHSA-93cm-9ghm-5q5v.json new file mode 100644 index 00000000000..14b1041c990 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-93cm-9ghm-5q5v/GHSA-93cm-9ghm-5q5v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93cm-9ghm-5q5v", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:04Z", + "aliases": [ + "CVE-2024-48424" + ], + "details": "A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48424" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/5787" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9748-w7hv-7h34/GHSA-9748-w7hv-7h34.json b/advisories/unreviewed/2024/10/GHSA-9748-w7hv-7h34/GHSA-9748-w7hv-7h34.json index 8af2ff3790d..946c0b70d57 100644 --- a/advisories/unreviewed/2024/10/GHSA-9748-w7hv-7h34/GHSA-9748-w7hv-7h34.json +++ b/advisories/unreviewed/2024/10/GHSA-9748-w7hv-7h34/GHSA-9748-w7hv-7h34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9748-w7hv-7h34", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50041" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix macvlan leak by synchronizing access to mac_filter_hash\n\nThis patch addresses a macvlan leak issue in the i40e driver caused by\nconcurrent access to vsi->mac_filter_hash. The leak occurs when multiple\nthreads attempt to modify the mac_filter_hash simultaneously, leading to\ninconsistent state and potential memory leaks.\n\nTo fix this, we now wrap the calls to i40e_del_mac_filter() and zeroing\nvf->default_lan_addr.addr with spin_lock/unlock_bh(&vsi->mac_filter_hash_lock),\nensuring atomic operations and preventing concurrent access.\n\nAdditionally, we add lockdep_assert_held(&vsi->mac_filter_hash_lock) in\ni40e_add_mac_filter() to help catch similar issues in the future.\n\nReproduction steps:\n1. Spawn VFs and configure port vlan on them.\n2. Trigger concurrent macvlan operations (e.g., adding and deleting\n\tportvlan and/or mac filters).\n3. Observe the potential memory leak and inconsistent state in the\n\tmac_filter_hash.\n\nThis synchronization ensures the integrity of the mac_filter_hash and prevents\nthe described leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9c44-5659-5mgq/GHSA-9c44-5659-5mgq.json b/advisories/unreviewed/2024/10/GHSA-9c44-5659-5mgq/GHSA-9c44-5659-5mgq.json index f382002d997..6192a951996 100644 --- a/advisories/unreviewed/2024/10/GHSA-9c44-5659-5mgq/GHSA-9c44-5659-5mgq.json +++ b/advisories/unreviewed/2024/10/GHSA-9c44-5659-5mgq/GHSA-9c44-5659-5mgq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9c44-5659-5mgq", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48964" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nravb: Fix potential use-after-free in ravb_rx_gbeth()\n\nThe skb is delivered to napi_gro_receive() which may free it, after calling this,\ndereferencing skb may trigger use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9m3x-q77m-pwhx/GHSA-9m3x-q77m-pwhx.json b/advisories/unreviewed/2024/10/GHSA-9m3x-q77m-pwhx/GHSA-9m3x-q77m-pwhx.json new file mode 100644 index 00000000000..ae1f7d975d2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9m3x-q77m-pwhx/GHSA-9m3x-q77m-pwhx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m3x-q77m-pwhx", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-45260" + ], + "details": "An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45260" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Unauthorized%20Access%20to%20File%20Download%20and%20Upload%20Interfaces.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json b/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json new file mode 100644 index 00000000000..aa1d3f80991 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3v-4452-42x7", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48141" + ], + "details": "A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48141" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48141" + }, + { + "type": "WEB", + "url": "https://marketplace.visualstudio.com/items?itemName=aminer.codegeex" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9r7v-6wjc-j5fj/GHSA-9r7v-6wjc-j5fj.json b/advisories/unreviewed/2024/10/GHSA-9r7v-6wjc-j5fj/GHSA-9r7v-6wjc-j5fj.json new file mode 100644 index 00000000000..9fae0e21e6c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9r7v-6wjc-j5fj/GHSA-9r7v-6wjc-j5fj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r7v-6wjc-j5fj", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48145" + ], + "details": "A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48145" + }, + { + "type": "WEB", + "url": "https://apps.microsoft.com/detail/9n3zxd05895t?hl=en-us&gl=US" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48145" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json b/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json new file mode 100644 index 00000000000..61ae82853b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2hr-6qhm-xv9r", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:04Z", + "aliases": [ + "CVE-2024-7763" + ], + "details": "In WhatsUp Gold versions released before 2024.0.0, \n\nan Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7763" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c844-5xj7-6j82/GHSA-c844-5xj7-6j82.json b/advisories/unreviewed/2024/10/GHSA-c844-5xj7-6j82/GHSA-c844-5xj7-6j82.json index 171c4db5b00..a28bec334fc 100644 --- a/advisories/unreviewed/2024/10/GHSA-c844-5xj7-6j82/GHSA-c844-5xj7-6j82.json +++ b/advisories/unreviewed/2024/10/GHSA-c844-5xj7-6j82/GHSA-c844-5xj7-6j82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c844-5xj7-6j82", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-48539" ], "details": "Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-chf9-635w-g4pv/GHSA-chf9-635w-g4pv.json b/advisories/unreviewed/2024/10/GHSA-chf9-635w-g4pv/GHSA-chf9-635w-g4pv.json index e64ffdfa526..9a3fc6f6772 100644 --- a/advisories/unreviewed/2024/10/GHSA-chf9-635w-g4pv/GHSA-chf9-635w-g4pv.json +++ b/advisories/unreviewed/2024/10/GHSA-chf9-635w-g4pv/GHSA-chf9-635w-g4pv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-chf9-635w-g4pv", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49009" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (asus-ec-sensors) Add checks for devm_kcalloc\n\nAs the devm_kcalloc may return NULL, the return value needs to be checked\nto avoid NULL poineter dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json b/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json index 078ca18e406..722e29097ab 100644 --- a/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json +++ b/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3gg-6f8f-39gh", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:01Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49863" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/scsi: null-ptr-dereference in vhost_scsi_get_req()\n\nSince commit 3f8ca2e115e5 (\"vhost/scsi: Extract common handling code\nfrom control queue handler\") a null pointer dereference bug can be\ntriggered when guest sends an SCSI AN request.\n\nIn vhost_scsi_ctl_handle_vq(), `vc.target` is assigned with\n`&v_req.tmf.lun[1]` within a switch-case block and is then passed to\nvhost_scsi_get_req() which extracts `vc->req` and `tpg`. However, for\na `VIRTIO_SCSI_T_AN_*` request, tpg is not required, so `vc.target` is\nset to NULL in this branch. Later, in vhost_scsi_get_req(),\n`vc->target` is dereferenced without being checked, leading to a null\npointer dereference bug. This bug can be triggered from guest.\n\nWhen this bug occurs, the vhost_worker process is killed while holding\n`vq->mutex` and the corresponding tpg will remain occupied\nindefinitely.\n\nBelow is the KASAN report:\nOops: general protection fault, probably for non-canonical address\n0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 1 PID: 840 Comm: poc Not tainted 6.10.0+ #1\nHardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS\n1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:vhost_scsi_get_req+0x165/0x3a0\nCode: 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 02 00 00\n48 b8 00 00 00 00 00 fc ff df 4d 8b 65 30 4c 89 e2 48 c1 ea 03 <0f> b6\n04 02 4c 89 e2 83 e2 07 38 d0 7f 08 84 c0 0f 85 be 01 00 00\nRSP: 0018:ffff888017affb50 EFLAGS: 00010246\nRAX: dffffc0000000000 RBX: ffff88801b000000 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff888017affcb8\nRBP: ffff888017affb80 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000\nR13: ffff888017affc88 R14: ffff888017affd1c R15: ffff888017993000\nFS: 000055556e076500(0000) GS:ffff88806b100000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000200027c0 CR3: 0000000010ed0004 CR4: 0000000000370ef0\nCall Trace:\n \n ? show_regs+0x86/0xa0\n ? die_addr+0x4b/0xd0\n ? exc_general_protection+0x163/0x260\n ? asm_exc_general_protection+0x27/0x30\n ? vhost_scsi_get_req+0x165/0x3a0\n vhost_scsi_ctl_handle_vq+0x2a4/0xca0\n ? __pfx_vhost_scsi_ctl_handle_vq+0x10/0x10\n ? __switch_to+0x721/0xeb0\n ? __schedule+0xda5/0x5710\n ? __kasan_check_write+0x14/0x30\n ? _raw_spin_lock+0x82/0xf0\n vhost_scsi_ctl_handle_kick+0x52/0x90\n vhost_run_work_list+0x134/0x1b0\n vhost_task_fn+0x121/0x350\n...\n \n---[ end trace 0000000000000000 ]---\n\nLet's add a check in vhost_scsi_get_req.\n\n[whitespace fixes]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f475-gxvf-mp72/GHSA-f475-gxvf-mp72.json b/advisories/unreviewed/2024/10/GHSA-f475-gxvf-mp72/GHSA-f475-gxvf-mp72.json index 1e1d3471c33..fb9ce956dd2 100644 --- a/advisories/unreviewed/2024/10/GHSA-f475-gxvf-mp72/GHSA-f475-gxvf-mp72.json +++ b/advisories/unreviewed/2024/10/GHSA-f475-gxvf-mp72/GHSA-f475-gxvf-mp72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f475-gxvf-mp72", - "modified": "2024-10-24T18:30:44Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:44Z", "aliases": [ "CVE-2024-48546" ], "details": "Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f4gr-wwwj-m36c/GHSA-f4gr-wwwj-m36c.json b/advisories/unreviewed/2024/10/GHSA-f4gr-wwwj-m36c/GHSA-f4gr-wwwj-m36c.json new file mode 100644 index 00000000000..096fd2e49f2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f4gr-wwwj-m36c/GHSA-f4gr-wwwj-m36c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4gr-wwwj-m36c", + "modified": "2024-10-24T21:31:01Z", + "published": "2024-10-24T21:31:00Z", + "aliases": [ + "CVE-2023-39941" + ], + "details": "Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39941" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00998.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f6pw-44qx-h3w9/GHSA-f6pw-44qx-h3w9.json b/advisories/unreviewed/2024/10/GHSA-f6pw-44qx-h3w9/GHSA-f6pw-44qx-h3w9.json index df9451dcae1..e7c82db7c0c 100644 --- a/advisories/unreviewed/2024/10/GHSA-f6pw-44qx-h3w9/GHSA-f6pw-44qx-h3w9.json +++ b/advisories/unreviewed/2024/10/GHSA-f6pw-44qx-h3w9/GHSA-f6pw-44qx-h3w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6pw-44qx-h3w9", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48955" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: fix memory leak in tbnet_open()\n\nWhen tb_ring_alloc_rx() failed in tbnet_open(), ida that allocated in\ntb_xdomain_alloc_out_hopid() is not released. Add\ntb_xdomain_release_out_hopid() to the error path to release ida.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fp5w-qv26-7xff/GHSA-fp5w-qv26-7xff.json b/advisories/unreviewed/2024/10/GHSA-fp5w-qv26-7xff/GHSA-fp5w-qv26-7xff.json index db5eb4d9dd8..ff7e117972c 100644 --- a/advisories/unreviewed/2024/10/GHSA-fp5w-qv26-7xff/GHSA-fp5w-qv26-7xff.json +++ b/advisories/unreviewed/2024/10/GHSA-fp5w-qv26-7xff/GHSA-fp5w-qv26-7xff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fp5w-qv26-7xff", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49012" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix server->active leak in afs_put_server\n\nThe atomic_read was accidentally replaced with atomic_inc_return,\nwhich prevents the server from getting cleaned up and causes rmmod\nto hang with a warning:\n\n Can't purge s=00000001", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-459" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fx57-vmgw-6jm4/GHSA-fx57-vmgw-6jm4.json b/advisories/unreviewed/2024/10/GHSA-fx57-vmgw-6jm4/GHSA-fx57-vmgw-6jm4.json index 4950343f999..9899e27c6dd 100644 --- a/advisories/unreviewed/2024/10/GHSA-fx57-vmgw-6jm4/GHSA-fx57-vmgw-6jm4.json +++ b/advisories/unreviewed/2024/10/GHSA-fx57-vmgw-6jm4/GHSA-fx57-vmgw-6jm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fx57-vmgw-6jm4", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50046" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Prevent NULL-pointer dereference in nfs42_complete_copies()\n\nOn the node of an NFS client, some files saved in the mountpoint of the\nNFS server were copied to another location of the same NFS server.\nAccidentally, the nfs42_complete_copies() got a NULL-pointer dereference\ncrash with the following syslog:\n\n[232064.838881] NFSv4: state recovery failed for open file nfs/pvc-12b5200d-cd0f-46a3-b9f0-af8f4fe0ef64.qcow2, error = -116\n[232064.839360] NFSv4: state recovery failed for open file nfs/pvc-12b5200d-cd0f-46a3-b9f0-af8f4fe0ef64.qcow2, error = -116\n[232066.588183] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000058\n[232066.588586] Mem abort info:\n[232066.588701] ESR = 0x0000000096000007\n[232066.588862] EC = 0x25: DABT (current EL), IL = 32 bits\n[232066.589084] SET = 0, FnV = 0\n[232066.589216] EA = 0, S1PTW = 0\n[232066.589340] FSC = 0x07: level 3 translation fault\n[232066.589559] Data abort info:\n[232066.589683] ISV = 0, ISS = 0x00000007\n[232066.589842] CM = 0, WnR = 0\n[232066.589967] user pgtable: 64k pages, 48-bit VAs, pgdp=00002000956ff400\n[232066.590231] [0000000000000058] pgd=08001100ae100003, p4d=08001100ae100003, pud=08001100ae100003, pmd=08001100b3c00003, pte=0000000000000000\n[232066.590757] Internal error: Oops: 96000007 [#1] SMP\n[232066.590958] Modules linked in: rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs ocfs2_dlmfs ocfs2_stack_o2cb ocfs2_dlm vhost_net vhost vhost_iotlb tap tun ipt_rpfilter xt_multiport ip_set_hash_ip ip_set_hash_net xfrm_interface xfrm6_tunnel tunnel4 tunnel6 esp4 ah4 wireguard libcurve25519_generic veth xt_addrtype xt_set nf_conntrack_netlink ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_bitmap_port ip_set_hash_ipport dummy ip_set ip_vs_sh ip_vs_wrr ip_vs_rr ip_vs iptable_filter sch_ingress nfnetlink_cttimeout vport_gre ip_gre ip_tunnel gre vport_geneve geneve vport_vxlan vxlan ip6_udp_tunnel udp_tunnel openvswitch nf_conncount dm_round_robin dm_service_time dm_multipath xt_nat xt_MASQUERADE nft_chain_nat nf_nat xt_mark xt_conntrack xt_comment nft_compat nft_counter nf_tables nfnetlink ocfs2 ocfs2_nodemanager ocfs2_stackglue iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi ipmi_ssif nbd overlay 8021q garp mrp bonding tls rfkill sunrpc ext4 mbcache jbd2\n[232066.591052] vfat fat cas_cache cas_disk ses enclosure scsi_transport_sas sg acpi_ipmi ipmi_si ipmi_devintf ipmi_msghandler ip_tables vfio_pci vfio_pci_core vfio_virqfd vfio_iommu_type1 vfio dm_mirror dm_region_hash dm_log dm_mod nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 br_netfilter bridge stp llc fuse xfs libcrc32c ast drm_vram_helper qla2xxx drm_kms_helper syscopyarea crct10dif_ce sysfillrect ghash_ce sysimgblt sha2_ce fb_sys_fops cec sha256_arm64 sha1_ce drm_ttm_helper ttm nvme_fc igb sbsa_gwdt nvme_fabrics drm nvme_core i2c_algo_bit i40e scsi_transport_fc megaraid_sas aes_neon_bs\n[232066.596953] CPU: 6 PID: 4124696 Comm: 10.253.166.125- Kdump: loaded Not tainted 5.15.131-9.cl9_ocfs2.aarch64 #1\n[232066.597356] Hardware name: Great Wall .\\x93\\x8e...RF6260 V5/GWMSSE2GL1T, BIOS T656FBE_V3.0.18 2024-01-06\n[232066.597721] pstate: 20400009 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[232066.598034] pc : nfs4_reclaim_open_state+0x220/0x800 [nfsv4]\n[232066.598327] lr : nfs4_reclaim_open_state+0x12c/0x800 [nfsv4]\n[232066.598595] sp : ffff8000f568fc70\n[232066.598731] x29: ffff8000f568fc70 x28: 0000000000001000 x27: ffff21003db33000\n[232066.599030] x26: ffff800005521ae0 x25: ffff0100f98fa3f0 x24: 0000000000000001\n[232066.599319] x23: ffff800009920008 x22: ffff21003db33040 x21: ffff21003db33050\n[232066.599628] x20: ffff410172fe9e40 x19: ffff410172fe9e00 x18: 0000000000000000\n[232066.599914] x17: 0000000000000000 x16: 0000000000000004 x15: 0000000000000000\n[232066.600195] x14: 0000000000000000 x13: ffff800008e685a8 x12: 00000000eac0c6e6\n[232066.600498] x11: 00000000000000\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g8gm-98gj-8fwr/GHSA-g8gm-98gj-8fwr.json b/advisories/unreviewed/2024/10/GHSA-g8gm-98gj-8fwr/GHSA-g8gm-98gj-8fwr.json index 4411fe50026..1229e5782c7 100644 --- a/advisories/unreviewed/2024/10/GHSA-g8gm-98gj-8fwr/GHSA-g8gm-98gj-8fwr.json +++ b/advisories/unreviewed/2024/10/GHSA-g8gm-98gj-8fwr/GHSA-g8gm-98gj-8fwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8gm-98gj-8fwr", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48959" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: sja1105: fix memory leak in sja1105_setup_devlink_regions()\n\nWhen dsa_devlink_region_create failed in sja1105_setup_devlink_regions(),\npriv->regions is not released.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g8q6-23x5-v2wf/GHSA-g8q6-23x5-v2wf.json b/advisories/unreviewed/2024/10/GHSA-g8q6-23x5-v2wf/GHSA-g8q6-23x5-v2wf.json new file mode 100644 index 00000000000..f6789335ccb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g8q6-23x5-v2wf/GHSA-g8q6-23x5-v2wf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8q6-23x5-v2wf", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-45259" + ], + "details": "An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45259" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Delete%20Any%20File%20via%20Download%20Interface.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json b/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json index f8e8b0578f0..f61e6b1929f 100644 --- a/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json +++ b/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gcv4-6hmh-xhwc", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:01Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49869" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: send: fix buffer overflow detection when copying path to cache entry\n\nStarting with commit c0247d289e73 (\"btrfs: send: annotate struct\nname_cache_entry with __counted_by()\") we annotated the variable length\narray \"name\" from the name_cache_entry structure with __counted_by() to\nimprove overflow detection. However that alone was not correct, because\nthe length of that array does not match the \"name_len\" field - it matches\nthat plus 1 to include the NUL string terminator, so that makes a\nfortified kernel think there's an overflow and report a splat like this:\n\n strcpy: detected buffer overflow: 20 byte write of buffer size 19\n WARNING: CPU: 3 PID: 3310 at __fortify_report+0x45/0x50\n CPU: 3 UID: 0 PID: 3310 Comm: btrfs Not tainted 6.11.0-prnet #1\n Hardware name: CompuLab Ltd. sbc-ihsw/Intense-PC2 (IPC2), BIOS IPC2_3.330.7 X64 03/15/2018\n RIP: 0010:__fortify_report+0x45/0x50\n Code: 48 8b 34 (...)\n RSP: 0018:ffff97ebc0d6f650 EFLAGS: 00010246\n RAX: 7749924ef60fa600 RBX: ffff8bf5446a521a RCX: 0000000000000027\n RDX: 00000000ffffdfff RSI: ffff97ebc0d6f548 RDI: ffff8bf84e7a1cc8\n RBP: ffff8bf548574080 R08: ffffffffa8c40e10 R09: 0000000000005ffd\n R10: 0000000000000004 R11: ffffffffa8c70e10 R12: ffff8bf551eef400\n R13: 0000000000000000 R14: 0000000000000013 R15: 00000000000003a8\n FS: 00007fae144de8c0(0000) GS:ffff8bf84e780000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fae14691690 CR3: 00000001027a2003 CR4: 00000000001706f0\n Call Trace:\n \n ? __warn+0x12a/0x1d0\n ? __fortify_report+0x45/0x50\n ? report_bug+0x154/0x1c0\n ? handle_bug+0x42/0x70\n ? exc_invalid_op+0x1a/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? __fortify_report+0x45/0x50\n __fortify_panic+0x9/0x10\n __get_cur_name_and_parent+0x3bc/0x3c0\n get_cur_path+0x207/0x3b0\n send_extent_data+0x709/0x10d0\n ? find_parent_nodes+0x22df/0x25d0\n ? mas_nomem+0x13/0x90\n ? mtree_insert_range+0xa5/0x110\n ? btrfs_lru_cache_store+0x5f/0x1e0\n ? iterate_extent_inodes+0x52d/0x5a0\n process_extent+0xa96/0x11a0\n ? __pfx_lookup_backref_cache+0x10/0x10\n ? __pfx_store_backref_cache+0x10/0x10\n ? __pfx_iterate_backrefs+0x10/0x10\n ? __pfx_check_extent_item+0x10/0x10\n changed_cb+0x6fa/0x930\n ? tree_advance+0x362/0x390\n ? memcmp_extent_buffer+0xd7/0x160\n send_subvol+0xf0a/0x1520\n btrfs_ioctl_send+0x106b/0x11d0\n ? __pfx___clone_root_cmp_sort+0x10/0x10\n _btrfs_ioctl_send+0x1ac/0x240\n btrfs_ioctl+0x75b/0x850\n __se_sys_ioctl+0xca/0x150\n do_syscall_64+0x85/0x160\n ? __count_memcg_events+0x69/0x100\n ? handle_mm_fault+0x1327/0x15c0\n ? __se_sys_rt_sigprocmask+0xf1/0x180\n ? syscall_exit_to_user_mode+0x75/0xa0\n ? do_syscall_64+0x91/0x160\n ? do_user_addr_fault+0x21d/0x630\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7fae145eeb4f\n Code: 00 48 89 (...)\n RSP: 002b:00007ffdf1cb09b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fae145eeb4f\n RDX: 00007ffdf1cb0ad0 RSI: 0000000040489426 RDI: 0000000000000004\n RBP: 00000000000078fe R08: 00007fae144006c0 R09: 00007ffdf1cb0927\n R10: 0000000000000008 R11: 0000000000000246 R12: 00007ffdf1cb1ce8\n R13: 0000000000000003 R14: 000055c499fab2e0 R15: 0000000000000004\n \n\nFix this by not storing the NUL string terminator since we don't actually\nneed it for name cache entries, this way \"name_len\" corresponds to the\nactual size of the \"name\" array. This requires marking the \"name\" array\nfield with __nonstring and using memcpy() instead of strcpy() as\nrecommended by the guidelines at:\n\n https://github.com/KSPP/linux/issues/90", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-ghfq-rw9q-gx67/GHSA-ghfq-rw9q-gx67.json b/advisories/unreviewed/2024/10/GHSA-ghfq-rw9q-gx67/GHSA-ghfq-rw9q-gx67.json index 042de0f08fc..ee9835a13fd 100644 --- a/advisories/unreviewed/2024/10/GHSA-ghfq-rw9q-gx67/GHSA-ghfq-rw9q-gx67.json +++ b/advisories/unreviewed/2024/10/GHSA-ghfq-rw9q-gx67/GHSA-ghfq-rw9q-gx67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghfq-rw9q-gx67", - "modified": "2024-10-24T18:30:42Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:42Z", "aliases": [ "CVE-2024-44141" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to an unlocked Mac may be able to gain root code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gx69-359j-659q/GHSA-gx69-359j-659q.json b/advisories/unreviewed/2024/10/GHSA-gx69-359j-659q/GHSA-gx69-359j-659q.json index 0f2d1448065..5579c51b1fa 100644 --- a/advisories/unreviewed/2024/10/GHSA-gx69-359j-659q/GHSA-gx69-359j-659q.json +++ b/advisories/unreviewed/2024/10/GHSA-gx69-359j-659q/GHSA-gx69-359j-659q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gx69-359j-659q", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48960" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hisilicon: Fix potential use-after-free in hix5hd2_rx()\n\nThe skb is delivered to napi_gro_receive() which may free it, after\ncalling this, dereferencing skb may trigger use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h37w-2wjf-qw6j/GHSA-h37w-2wjf-qw6j.json b/advisories/unreviewed/2024/10/GHSA-h37w-2wjf-qw6j/GHSA-h37w-2wjf-qw6j.json index 853d5479d25..f3662ed1004 100644 --- a/advisories/unreviewed/2024/10/GHSA-h37w-2wjf-qw6j/GHSA-h37w-2wjf-qw6j.json +++ b/advisories/unreviewed/2024/10/GHSA-h37w-2wjf-qw6j/GHSA-h37w-2wjf-qw6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h37w-2wjf-qw6j", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48963" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix memory leak in ipc_mux_init()\n\nWhen failed to alloc ipc_mux->ul_adb.pp_qlt in ipc_mux_init(), ipc_mux\nis not released.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h52p-rfc4-3rcf/GHSA-h52p-rfc4-3rcf.json b/advisories/unreviewed/2024/10/GHSA-h52p-rfc4-3rcf/GHSA-h52p-rfc4-3rcf.json index 31f9c4569ff..ee380d5aeee 100644 --- a/advisories/unreviewed/2024/10/GHSA-h52p-rfc4-3rcf/GHSA-h52p-rfc4-3rcf.json +++ b/advisories/unreviewed/2024/10/GHSA-h52p-rfc4-3rcf/GHSA-h52p-rfc4-3rcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h52p-rfc4-3rcf", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48956" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: avoid use-after-free in ip6_fragment()\n\nBlamed commit claimed rcu_read_lock() was held by ip6_fragment() callers.\n\nIt seems to not be always true, at least for UDP stack.\n\nsyzbot reported:\n\nBUG: KASAN: use-after-free in ip6_dst_idev include/net/ip6_fib.h:245 [inline]\nBUG: KASAN: use-after-free in ip6_fragment+0x2724/0x2770 net/ipv6/ip6_output.c:951\nRead of size 8 at addr ffff88801d403e80 by task syz-executor.3/7618\n\nCPU: 1 PID: 7618 Comm: syz-executor.3 Not tainted 6.1.0-rc6-syzkaller-00012-g4312098baf37 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd1/0x138 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:284 [inline]\n print_report+0x15e/0x45d mm/kasan/report.c:395\n kasan_report+0xbf/0x1f0 mm/kasan/report.c:495\n ip6_dst_idev include/net/ip6_fib.h:245 [inline]\n ip6_fragment+0x2724/0x2770 net/ipv6/ip6_output.c:951\n __ip6_finish_output net/ipv6/ip6_output.c:193 [inline]\n ip6_finish_output+0x9a3/0x1170 net/ipv6/ip6_output.c:206\n NF_HOOK_COND include/linux/netfilter.h:291 [inline]\n ip6_output+0x1f1/0x540 net/ipv6/ip6_output.c:227\n dst_output include/net/dst.h:445 [inline]\n ip6_local_out+0xb3/0x1a0 net/ipv6/output_core.c:161\n ip6_send_skb+0xbb/0x340 net/ipv6/ip6_output.c:1966\n udp_v6_send_skb+0x82a/0x18a0 net/ipv6/udp.c:1286\n udp_v6_push_pending_frames+0x140/0x200 net/ipv6/udp.c:1313\n udpv6_sendmsg+0x18da/0x2c80 net/ipv6/udp.c:1606\n inet6_sendmsg+0x9d/0xe0 net/ipv6/af_inet6.c:665\n sock_sendmsg_nosec net/socket.c:714 [inline]\n sock_sendmsg+0xd3/0x120 net/socket.c:734\n sock_write_iter+0x295/0x3d0 net/socket.c:1108\n call_write_iter include/linux/fs.h:2191 [inline]\n new_sync_write fs/read_write.c:491 [inline]\n vfs_write+0x9ed/0xdd0 fs/read_write.c:584\n ksys_write+0x1ec/0x250 fs/read_write.c:637\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7fde3588c0d9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fde365b6168 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00007fde359ac050 RCX: 00007fde3588c0d9\nRDX: 000000000000ffdc RSI: 00000000200000c0 RDI: 000000000000000a\nRBP: 00007fde358e7ae9 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fde35acfb1f R14: 00007fde365b6300 R15: 0000000000022000\n \n\nAllocated by task 7618:\n kasan_save_stack+0x22/0x40 mm/kasan/common.c:45\n kasan_set_track+0x25/0x30 mm/kasan/common.c:52\n __kasan_slab_alloc+0x82/0x90 mm/kasan/common.c:325\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slab.h:737 [inline]\n slab_alloc_node mm/slub.c:3398 [inline]\n slab_alloc mm/slub.c:3406 [inline]\n __kmem_cache_alloc_lru mm/slub.c:3413 [inline]\n kmem_cache_alloc+0x2b4/0x3d0 mm/slub.c:3422\n dst_alloc+0x14a/0x1f0 net/core/dst.c:92\n ip6_dst_alloc+0x32/0xa0 net/ipv6/route.c:344\n ip6_rt_pcpu_alloc net/ipv6/route.c:1369 [inline]\n rt6_make_pcpu_route net/ipv6/route.c:1417 [inline]\n ip6_pol_route+0x901/0x1190 net/ipv6/route.c:2254\n pol_lookup_func include/net/ip6_fib.h:582 [inline]\n fib6_rule_lookup+0x52e/0x6f0 net/ipv6/fib6_rules.c:121\n ip6_route_output_flags_noref+0x2e6/0x380 net/ipv6/route.c:2625\n ip6_route_output_flags+0x76/0x320 net/ipv6/route.c:2638\n ip6_route_output include/net/ip6_route.h:98 [inline]\n ip6_dst_lookup_tail+0x5ab/0x1620 net/ipv6/ip6_output.c:1092\n ip6_dst_lookup_flow+0x90/0x1d0 net/ipv6/ip6_output.c:1222\n ip6_sk_dst_lookup_flow+0x553/0x980 net/ipv6/ip6_output.c:1260\n udpv6_sendmsg+0x151d/0x2c80 net/ipv6/udp.c:1554\n inet6_sendmsg+0x9d/0xe0 net/ipv6/af_inet6.c:665\n sock_sendmsg_nosec n\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hq8j-584q-8j9q/GHSA-hq8j-584q-8j9q.json b/advisories/unreviewed/2024/10/GHSA-hq8j-584q-8j9q/GHSA-hq8j-584q-8j9q.json index fb817ac5b38..2bcb7a94c5d 100644 --- a/advisories/unreviewed/2024/10/GHSA-hq8j-584q-8j9q/GHSA-hq8j-584q-8j9q.json +++ b/advisories/unreviewed/2024/10/GHSA-hq8j-584q-8j9q/GHSA-hq8j-584q-8j9q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq8j-584q-8j9q", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50035" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: fix ppp_async_encode() illegal access\n\nsyzbot reported an issue in ppp_async_encode() [1]\n\nIn this case, pppoe_sendmsg() is called with a zero size.\nThen ppp_async_encode() is called with an empty skb.\n\nBUG: KMSAN: uninit-value in ppp_async_encode drivers/net/ppp/ppp_async.c:545 [inline]\n BUG: KMSAN: uninit-value in ppp_async_push+0xb4f/0x2660 drivers/net/ppp/ppp_async.c:675\n ppp_async_encode drivers/net/ppp/ppp_async.c:545 [inline]\n ppp_async_push+0xb4f/0x2660 drivers/net/ppp/ppp_async.c:675\n ppp_async_send+0x130/0x1b0 drivers/net/ppp/ppp_async.c:634\n ppp_channel_bridge_input drivers/net/ppp/ppp_generic.c:2280 [inline]\n ppp_input+0x1f1/0xe60 drivers/net/ppp/ppp_generic.c:2304\n pppoe_rcv_core+0x1d3/0x720 drivers/net/ppp/pppoe.c:379\n sk_backlog_rcv+0x13b/0x420 include/net/sock.h:1113\n __release_sock+0x1da/0x330 net/core/sock.c:3072\n release_sock+0x6b/0x250 net/core/sock.c:3626\n pppoe_sendmsg+0x2b8/0xb90 drivers/net/ppp/pppoe.c:903\n sock_sendmsg_nosec net/socket.c:729 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:744\n ____sys_sendmsg+0x903/0xb60 net/socket.c:2602\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2656\n __sys_sendmmsg+0x3c1/0x960 net/socket.c:2742\n __do_sys_sendmmsg net/socket.c:2771 [inline]\n __se_sys_sendmmsg net/socket.c:2768 [inline]\n __x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2768\n x64_sys_call+0xb6e/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:308\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:4092 [inline]\n slab_alloc_node mm/slub.c:4135 [inline]\n kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4187\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:587\n __alloc_skb+0x363/0x7b0 net/core/skbuff.c:678\n alloc_skb include/linux/skbuff.h:1322 [inline]\n sock_wmalloc+0xfe/0x1a0 net/core/sock.c:2732\n pppoe_sendmsg+0x3a7/0xb90 drivers/net/ppp/pppoe.c:867\n sock_sendmsg_nosec net/socket.c:729 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:744\n ____sys_sendmsg+0x903/0xb60 net/socket.c:2602\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2656\n __sys_sendmmsg+0x3c1/0x960 net/socket.c:2742\n __do_sys_sendmmsg net/socket.c:2771 [inline]\n __se_sys_sendmmsg net/socket.c:2768 [inline]\n __x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2768\n x64_sys_call+0xb6e/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:308\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCPU: 1 UID: 0 PID: 5411 Comm: syz.1.14 Not tainted 6.12.0-rc1-syzkaller-00165-g360c1f1f24c6 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json b/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json index 76c867f963f..ddfeae5a703 100644 --- a/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json +++ b/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2cc-c4fg-77cq", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:01Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49873" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: fix filemap_get_folios_contig THP panic\n\nPatch series \"memfd-pin huge page fixes\".\n\nFix multiple bugs that occur when using memfd_pin_folios with hugetlb\npages and THP. The hugetlb bugs only bite when the page is not yet\nfaulted in when memfd_pin_folios is called. The THP bug bites when the\nstarting offset passed to memfd_pin_folios is not huge page aligned. See\nthe commit messages for details.\n\n\nThis patch (of 5):\n\nmemfd_pin_folios on memory backed by THP panics if the requested start\noffset is not huge page aligned:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000036\nRIP: 0010:filemap_get_folios_contig+0xdf/0x290\nRSP: 0018:ffffc9002092fbe8 EFLAGS: 00010202\nRAX: 0000000000000002 RBX: 0000000000000002 RCX: 0000000000000002\n\nThe fault occurs here, because xas_load returns a folio with value 2:\n\n filemap_get_folios_contig()\n for (folio = xas_load(&xas); folio && xas.xa_index <= end;\n folio = xas_next(&xas)) {\n ...\n if (!folio_try_get(folio)) <-- BOOM\n\n\"2\" is an xarray sibling entry. We get it because memfd_pin_folios does\nnot round the indices passed to filemap_get_folios_contig to huge page\nboundaries for THP, so we load from the middle of a huge page range see a\nsibling. (It does round for hugetlbfs, at the is_file_hugepages test).\n\nTo fix, if the folio is a sibling, then return the next index as the\nstarting point for the next call to filemap_get_folios_contig.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j36j-5jh8-qqgc/GHSA-j36j-5jh8-qqgc.json b/advisories/unreviewed/2024/10/GHSA-j36j-5jh8-qqgc/GHSA-j36j-5jh8-qqgc.json new file mode 100644 index 00000000000..38309aac583 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j36j-5jh8-qqgc/GHSA-j36j-5jh8-qqgc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j36j-5jh8-qqgc", + "modified": "2024-10-24T21:31:00Z", + "published": "2024-10-24T21:31:00Z", + "aliases": [ + "CVE-2023-39432" + ], + "details": "Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39432" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00993.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json b/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json index 311edfb0570..e5039797c28 100644 --- a/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json +++ b/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j994-f74j-cwf3", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49876" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: fix UAF around queue destruction\n\nWe currently do stuff like queuing the final destruction step on a\nrandom system wq, which will outlive the driver instance. With bad\ntiming we can teardown the driver with one or more work workqueue still\nbeing alive leading to various UAF splats. Add a fini step to ensure\nuser queues are properly torn down. At this point GuC should already be\nnuked so queue itself should no longer be referenced from hw pov.\n\nv2 (Matt B)\n - Looks much safer to use a waitqueue and then just wait for the\n xa_array to become empty before triggering the drain.\n\n(cherry picked from commit 861108666cc0e999cffeab6aff17b662e68774e3)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jg3p-mpfh-w2hg/GHSA-jg3p-mpfh-w2hg.json b/advisories/unreviewed/2024/10/GHSA-jg3p-mpfh-w2hg/GHSA-jg3p-mpfh-w2hg.json new file mode 100644 index 00000000000..c4720a6b145 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jg3p-mpfh-w2hg/GHSA-jg3p-mpfh-w2hg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg3p-mpfh-w2hg", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48144" + ], + "details": "A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48144" + }, + { + "type": "WEB", + "url": "https://apps.microsoft.com/detail/9n3ff8j3d7zr?hl=en-US&gl=US" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48144" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json b/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json new file mode 100644 index 00000000000..89e35a497ee --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjq3-cw48-pqmx", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48139" + ], + "details": "A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48139" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48139" + }, + { + "type": "WEB", + "url": "https://marketplace.visualstudio.com/items?itemName=Blackboxapp.blackbox" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jpw5-f3qf-66fc/GHSA-jpw5-f3qf-66fc.json b/advisories/unreviewed/2024/10/GHSA-jpw5-f3qf-66fc/GHSA-jpw5-f3qf-66fc.json index 8accfab9e2d..8320fa23cb2 100644 --- a/advisories/unreviewed/2024/10/GHSA-jpw5-f3qf-66fc/GHSA-jpw5-f3qf-66fc.json +++ b/advisories/unreviewed/2024/10/GHSA-jpw5-f3qf-66fc/GHSA-jpw5-f3qf-66fc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jpw5-f3qf-66fc", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50033" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nslip: make slhc_remember() more robust against malicious packets\n\nsyzbot found that slhc_remember() was missing checks against\nmalicious packets [1].\n\nslhc_remember() only checked the size of the packet was at least 20,\nwhich is not good enough.\n\nWe need to make sure the packet includes the IPv4 and TCP header\nthat are supposed to be carried.\n\nAdd iph and th pointers to make the code more readable.\n\n[1]\n\nBUG: KMSAN: uninit-value in slhc_remember+0x2e8/0x7b0 drivers/net/slip/slhc.c:666\n slhc_remember+0x2e8/0x7b0 drivers/net/slip/slhc.c:666\n ppp_receive_nonmp_frame+0xe45/0x35e0 drivers/net/ppp/ppp_generic.c:2455\n ppp_receive_frame drivers/net/ppp/ppp_generic.c:2372 [inline]\n ppp_do_recv+0x65f/0x40d0 drivers/net/ppp/ppp_generic.c:2212\n ppp_input+0x7dc/0xe60 drivers/net/ppp/ppp_generic.c:2327\n pppoe_rcv_core+0x1d3/0x720 drivers/net/ppp/pppoe.c:379\n sk_backlog_rcv+0x13b/0x420 include/net/sock.h:1113\n __release_sock+0x1da/0x330 net/core/sock.c:3072\n release_sock+0x6b/0x250 net/core/sock.c:3626\n pppoe_sendmsg+0x2b8/0xb90 drivers/net/ppp/pppoe.c:903\n sock_sendmsg_nosec net/socket.c:729 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:744\n ____sys_sendmsg+0x903/0xb60 net/socket.c:2602\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2656\n __sys_sendmmsg+0x3c1/0x960 net/socket.c:2742\n __do_sys_sendmmsg net/socket.c:2771 [inline]\n __se_sys_sendmmsg net/socket.c:2768 [inline]\n __x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2768\n x64_sys_call+0xb6e/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:308\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:4091 [inline]\n slab_alloc_node mm/slub.c:4134 [inline]\n kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4186\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:587\n __alloc_skb+0x363/0x7b0 net/core/skbuff.c:678\n alloc_skb include/linux/skbuff.h:1322 [inline]\n sock_wmalloc+0xfe/0x1a0 net/core/sock.c:2732\n pppoe_sendmsg+0x3a7/0xb90 drivers/net/ppp/pppoe.c:867\n sock_sendmsg_nosec net/socket.c:729 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:744\n ____sys_sendmsg+0x903/0xb60 net/socket.c:2602\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2656\n __sys_sendmmsg+0x3c1/0x960 net/socket.c:2742\n __do_sys_sendmmsg net/socket.c:2771 [inline]\n __se_sys_sendmmsg net/socket.c:2768 [inline]\n __x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2768\n x64_sys_call+0xb6e/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:308\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCPU: 0 UID: 0 PID: 5460 Comm: syz.2.33 Not tainted 6.12.0-rc2-syzkaller-00006-g87d6aab2389e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m2gv-rr38-g5r4/GHSA-m2gv-rr38-g5r4.json b/advisories/unreviewed/2024/10/GHSA-m2gv-rr38-g5r4/GHSA-m2gv-rr38-g5r4.json index b1257a91411..1bb80d4d396 100644 --- a/advisories/unreviewed/2024/10/GHSA-m2gv-rr38-g5r4/GHSA-m2gv-rr38-g5r4.json +++ b/advisories/unreviewed/2024/10/GHSA-m2gv-rr38-g5r4/GHSA-m2gv-rr38-g5r4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2gv-rr38-g5r4", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49017" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: re-fetch skb cb after tipc_msg_validate\n\nAs the call trace shows, the original skb was freed in tipc_msg_validate(),\nand dereferencing the old skb cb would cause an use-after-free crash.\n\n BUG: KASAN: use-after-free in tipc_crypto_rcv_complete+0x1835/0x2240 [tipc]\n Call Trace:\n \n tipc_crypto_rcv_complete+0x1835/0x2240 [tipc]\n tipc_crypto_rcv+0xd32/0x1ec0 [tipc]\n tipc_rcv+0x744/0x1150 [tipc]\n ...\n Allocated by task 47078:\n kmem_cache_alloc_node+0x158/0x4d0\n __alloc_skb+0x1c1/0x270\n tipc_buf_acquire+0x1e/0xe0 [tipc]\n tipc_msg_create+0x33/0x1c0 [tipc]\n tipc_link_build_proto_msg+0x38a/0x2100 [tipc]\n tipc_link_timeout+0x8b8/0xef0 [tipc]\n tipc_node_timeout+0x2a1/0x960 [tipc]\n call_timer_fn+0x2d/0x1c0\n ...\n Freed by task 47078:\n tipc_msg_validate+0x7b/0x440 [tipc]\n tipc_crypto_rcv_complete+0x4b5/0x2240 [tipc]\n tipc_crypto_rcv+0xd32/0x1ec0 [tipc]\n tipc_rcv+0x744/0x1150 [tipc]\n\nThis patch fixes it by re-fetching the skb cb from the new allocated skb\nafter calling tipc_msg_validate().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json b/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json index 238c556c631..e5de4a108c5 100644 --- a/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json +++ b/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3fc-5gx3-j98r", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:01Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49871" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: adp5589-keys - fix NULL pointer dereference\n\nWe register a devm action to call adp5589_clear_config() and then pass\nthe i2c client as argument so that we can call i2c_get_clientdata() in\norder to get our device object. However, i2c_set_clientdata() is only\nbeing set at the end of the probe function which means that we'll get a\nNULL pointer dereference in case the probe function fails early.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json b/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json index 1891e769663..dec44e3d936 100644 --- a/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json +++ b/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6p4-vhgw-8c9c", - "modified": "2024-10-23T18:33:09Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-23T18:33:09Z", "aliases": [ "CVE-2024-50383" ], "details": "Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be affected.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-23T17:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json b/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json new file mode 100644 index 00000000000..c2b77767513 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjhm-5r72-mjx7", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:04Z", + "aliases": [ + "CVE-2024-48423" + ], + "details": "An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48423" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/5788" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json b/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json index 78f2376226d..097ae0ca655 100644 --- a/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json +++ b/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p27h-83pf-6hh9", - "modified": "2024-10-23T18:33:09Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-23T18:33:08Z", "aliases": [ "CVE-2024-50382" ], "details": "Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-23T17:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pmp7-4p22-ggcc/GHSA-pmp7-4p22-ggcc.json b/advisories/unreviewed/2024/10/GHSA-pmp7-4p22-ggcc/GHSA-pmp7-4p22-ggcc.json index 66eefafe41e..3042db01d57 100644 --- a/advisories/unreviewed/2024/10/GHSA-pmp7-4p22-ggcc/GHSA-pmp7-4p22-ggcc.json +++ b/advisories/unreviewed/2024/10/GHSA-pmp7-4p22-ggcc/GHSA-pmp7-4p22-ggcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmp7-4p22-ggcc", - "modified": "2024-10-24T18:30:44Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-48547" ], "details": "Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pvfv-p8r5-hrcw/GHSA-pvfv-p8r5-hrcw.json b/advisories/unreviewed/2024/10/GHSA-pvfv-p8r5-hrcw/GHSA-pvfv-p8r5-hrcw.json index 74ec3575664..e090bbd707b 100644 --- a/advisories/unreviewed/2024/10/GHSA-pvfv-p8r5-hrcw/GHSA-pvfv-p8r5-hrcw.json +++ b/advisories/unreviewed/2024/10/GHSA-pvfv-p8r5-hrcw/GHSA-pvfv-p8r5-hrcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvfv-p8r5-hrcw", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48954" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: fix use-after-free in hsci\n\nKASAN found that addr was dereferenced after br2dev_event_work was freed.\n\n==================================================================\nBUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0\nRead of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540\nCPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G E 6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1\nHardware name: IBM 8561 T01 703 (LPAR)\nWorkqueue: 0.0.8000_event qeth_l2_br2dev_worker\nCall Trace:\n [<000000016944d4ce>] dump_stack_lvl+0xc6/0xf8\n [<000000016942cd9c>] print_address_description.constprop.0+0x34/0x2a0\n [<000000016942d118>] print_report+0x110/0x1f8\n [<0000000167a7bd04>] kasan_report+0xfc/0x128\n [<000000016938d79a>] qeth_l2_br2dev_worker+0x5ba/0x6b0\n [<00000001673edd1e>] process_one_work+0x76e/0x1128\n [<00000001673ee85c>] worker_thread+0x184/0x1098\n [<000000016740718a>] kthread+0x26a/0x310\n [<00000001672c606a>] __ret_from_fork+0x8a/0xe8\n [<00000001694711da>] ret_from_fork+0xa/0x40\nAllocated by task 108338:\n kasan_save_stack+0x40/0x68\n kasan_set_track+0x36/0x48\n __kasan_kmalloc+0xa0/0xc0\n qeth_l2_switchdev_event+0x25a/0x738\n atomic_notifier_call_chain+0x9c/0xf8\n br_switchdev_fdb_notify+0xf4/0x110\n fdb_notify+0x122/0x180\n fdb_add_entry.constprop.0.isra.0+0x312/0x558\n br_fdb_add+0x59e/0x858\n rtnl_fdb_add+0x58a/0x928\n rtnetlink_rcv_msg+0x5f8/0x8d8\n netlink_rcv_skb+0x1f2/0x408\n netlink_unicast+0x570/0x790\n netlink_sendmsg+0x752/0xbe0\n sock_sendmsg+0xca/0x110\n ____sys_sendmsg+0x510/0x6a8\n ___sys_sendmsg+0x12a/0x180\n __sys_sendmsg+0xe6/0x168\n __do_sys_socketcall+0x3c8/0x468\n do_syscall+0x22c/0x328\n __do_syscall+0x94/0xf0\n system_call+0x82/0xb0\nFreed by task 540:\n kasan_save_stack+0x40/0x68\n kasan_set_track+0x36/0x48\n kasan_save_free_info+0x4c/0x68\n ____kasan_slab_free+0x14e/0x1a8\n __kasan_slab_free+0x24/0x30\n __kmem_cache_free+0x168/0x338\n qeth_l2_br2dev_worker+0x154/0x6b0\n process_one_work+0x76e/0x1128\n worker_thread+0x184/0x1098\n kthread+0x26a/0x310\n __ret_from_fork+0x8a/0xe8\n ret_from_fork+0xa/0x40\nLast potentially related work creation:\n kasan_save_stack+0x40/0x68\n __kasan_record_aux_stack+0xbe/0xd0\n insert_work+0x56/0x2e8\n __queue_work+0x4ce/0xd10\n queue_work_on+0xf4/0x100\n qeth_l2_switchdev_event+0x520/0x738\n atomic_notifier_call_chain+0x9c/0xf8\n br_switchdev_fdb_notify+0xf4/0x110\n fdb_notify+0x122/0x180\n fdb_add_entry.constprop.0.isra.0+0x312/0x558\n br_fdb_add+0x59e/0x858\n rtnl_fdb_add+0x58a/0x928\n rtnetlink_rcv_msg+0x5f8/0x8d8\n netlink_rcv_skb+0x1f2/0x408\n netlink_unicast+0x570/0x790\n netlink_sendmsg+0x752/0xbe0\n sock_sendmsg+0xca/0x110\n ____sys_sendmsg+0x510/0x6a8\n ___sys_sendmsg+0x12a/0x180\n __sys_sendmsg+0xe6/0x168\n __do_sys_socketcall+0x3c8/0x468\n do_syscall+0x22c/0x328\n __do_syscall+0x94/0xf0\n system_call+0x82/0xb0\nSecond to last potentially related work creation:\n kasan_save_stack+0x40/0x68\n __kasan_record_aux_stack+0xbe/0xd0\n kvfree_call_rcu+0xb2/0x760\n kernfs_unlink_open_file+0x348/0x430\n kernfs_fop_release+0xc2/0x320\n __fput+0x1ae/0x768\n task_work_run+0x1bc/0x298\n exit_to_user_mode_prepare+0x1a0/0x1a8\n __do_syscall+0x94/0xf0\n system_call+0x82/0xb0\nThe buggy address belongs to the object at 00000000fdcea400\n which belongs to the cache kmalloc-96 of size 96\nThe buggy address is located 64 bytes inside of\n 96-byte region [00000000fdcea400, 00000000fdcea460)\nThe buggy address belongs to the physical page:\npage:000000005a9c26e8 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xfdcea\nflags: 0x3ffff00000000200(slab|node=0|zone=1|lastcpupid=0x1ffff)\nraw: 3ffff00000000200 0000000000000000 0000000100000122 000000008008cc00\nraw: 0000000000000000 0020004100000000 ffffffff00000001 0000000000000000\npage dumped because: kasan: bad access detected\nMemory state around the buggy address:\n 00000000fdcea300: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n 00000000fdcea380: fb fb fb fb fb fb f\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qfj5-q5g9-m5pm/GHSA-qfj5-q5g9-m5pm.json b/advisories/unreviewed/2024/10/GHSA-qfj5-q5g9-m5pm/GHSA-qfj5-q5g9-m5pm.json index f27cedecef0..87b0b9bb967 100644 --- a/advisories/unreviewed/2024/10/GHSA-qfj5-q5g9-m5pm/GHSA-qfj5-q5g9-m5pm.json +++ b/advisories/unreviewed/2024/10/GHSA-qfj5-q5g9-m5pm/GHSA-qfj5-q5g9-m5pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfj5-q5g9-m5pm", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49013" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix memory leak in sctp_stream_outq_migrate()\n\nWhen sctp_stream_outq_migrate() is called to release stream out resources,\nthe memory pointed to by prio_head in stream out is not released.\n\nThe memory leak information is as follows:\n unreferenced object 0xffff88801fe79f80 (size 64):\n comm \"sctp_repo\", pid 7957, jiffies 4294951704 (age 36.480s)\n hex dump (first 32 bytes):\n 80 9f e7 1f 80 88 ff ff 80 9f e7 1f 80 88 ff ff ................\n 90 9f e7 1f 80 88 ff ff 90 9f e7 1f 80 88 ff ff ................\n backtrace:\n [] kmalloc_trace+0x26/0x60\n [] sctp_sched_prio_set+0x4cc/0x770\n [] sctp_stream_init_ext+0xd2/0x1b0\n [] sctp_sendmsg_to_asoc+0x1614/0x1a30\n [] sctp_sendmsg+0xda1/0x1ef0\n [] inet_sendmsg+0x9d/0xe0\n [] sock_sendmsg+0xd3/0x120\n [] __sys_sendto+0x23a/0x340\n [] __x64_sys_sendto+0xe1/0x1b0\n [] do_syscall_64+0x39/0xb0\n [] entry_SYSCALL_64_after_hwframe+0x63/0xcd", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qh7g-57ww-6fq4/GHSA-qh7g-57ww-6fq4.json b/advisories/unreviewed/2024/10/GHSA-qh7g-57ww-6fq4/GHSA-qh7g-57ww-6fq4.json index 7b0ecd56571..180259a5692 100644 --- a/advisories/unreviewed/2024/10/GHSA-qh7g-57ww-6fq4/GHSA-qh7g-57ww-6fq4.json +++ b/advisories/unreviewed/2024/10/GHSA-qh7g-57ww-6fq4/GHSA-qh7g-57ww-6fq4.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-qjvc-xmqv-cwr9/GHSA-qjvc-xmqv-cwr9.json b/advisories/unreviewed/2024/10/GHSA-qjvc-xmqv-cwr9/GHSA-qjvc-xmqv-cwr9.json index fd9c8c177ab..89280dae003 100644 --- a/advisories/unreviewed/2024/10/GHSA-qjvc-xmqv-cwr9/GHSA-qjvc-xmqv-cwr9.json +++ b/advisories/unreviewed/2024/10/GHSA-qjvc-xmqv-cwr9/GHSA-qjvc-xmqv-cwr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qjvc-xmqv-cwr9", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50044" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change\n\nrfcomm_sk_state_change attempts to use sock_lock so it must never be\ncalled with it locked but rfcomm_sock_ioctl always attempt to lock it\ncausing the following trace:\n\n======================================================\nWARNING: possible circular locking dependency detected\n6.8.0-syzkaller-08951-gfe46a7dd189e #0 Not tainted\n------------------------------------------------------\nsyz-executor386/5093 is trying to acquire lock:\nffff88807c396258 (sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1671 [inline]\nffff88807c396258 (sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM){+.+.}-{0:0}, at: rfcomm_sk_state_change+0x5b/0x310 net/bluetooth/rfcomm/sock.c:73\n\nbut task is already holding lock:\nffff88807badfd28 (&d->lock){+.+.}-{3:3}, at: __rfcomm_dlc_close+0x226/0x6a0 net/bluetooth/rfcomm/core.c:491", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rprc-6487-2q3v/GHSA-rprc-6487-2q3v.json b/advisories/unreviewed/2024/10/GHSA-rprc-6487-2q3v/GHSA-rprc-6487-2q3v.json index f83e9c33ff6..23a1b1a81f2 100644 --- a/advisories/unreviewed/2024/10/GHSA-rprc-6487-2q3v/GHSA-rprc-6487-2q3v.json +++ b/advisories/unreviewed/2024/10/GHSA-rprc-6487-2q3v/GHSA-rprc-6487-2q3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rprc-6487-2q3v", - "modified": "2024-10-21T21:30:53Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-21T21:30:53Z", "aliases": [ "CVE-2024-50034" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix lacks of icsk_syn_mss with IPPROTO_SMC\n\nEric report a panic on IPPROTO_SMC, and give the facts\nthat when INET_PROTOSW_ICSK was set, icsk->icsk_sync_mss must be set too.\n\nBug: Unable to handle kernel NULL pointer dereference at virtual address\n0000000000000000\nMem abort info:\nESR = 0x0000000086000005\nEC = 0x21: IABT (current EL), IL = 32 bits\nSET = 0, FnV = 0\nEA = 0, S1PTW = 0\nFSC = 0x05: level 1 translation fault\nuser pgtable: 4k pages, 48-bit VAs, pgdp=00000001195d1000\n[0000000000000000] pgd=0800000109c46003, p4d=0800000109c46003,\npud=0000000000000000\nInternal error: Oops: 0000000086000005 [#1] PREEMPT SMP\nModules linked in:\nCPU: 1 UID: 0 PID: 8037 Comm: syz.3.265 Not tainted\n6.11.0-rc7-syzkaller-g5f5673607153 #0\nHardware name: Google Google Compute Engine/Google Compute Engine,\nBIOS Google 08/06/2024\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : 0x0\nlr : cipso_v4_sock_setattr+0x2a8/0x3c0 net/ipv4/cipso_ipv4.c:1910\nsp : ffff80009b887a90\nx29: ffff80009b887aa0 x28: ffff80008db94050 x27: 0000000000000000\nx26: 1fffe0001aa6f5b3 x25: dfff800000000000 x24: ffff0000db75da00\nx23: 0000000000000000 x22: ffff0000d8b78518 x21: 0000000000000000\nx20: ffff0000d537ad80 x19: ffff0000d8b78000 x18: 1fffe000366d79ee\nx17: ffff8000800614a8 x16: ffff800080569b84 x15: 0000000000000001\nx14: 000000008b336894 x13: 00000000cd96feaa x12: 0000000000000003\nx11: 0000000000040000 x10: 00000000000020a3 x9 : 1fffe0001b16f0f1\nx8 : 0000000000000000 x7 : 0000000000000000 x6 : 000000000000003f\nx5 : 0000000000000040 x4 : 0000000000000001 x3 : 0000000000000000\nx2 : 0000000000000002 x1 : 0000000000000000 x0 : ffff0000d8b78000\nCall trace:\n0x0\nnetlbl_sock_setattr+0x2e4/0x338 net/netlabel/netlabel_kapi.c:1000\nsmack_netlbl_add+0xa4/0x154 security/smack/smack_lsm.c:2593\nsmack_socket_post_create+0xa8/0x14c security/smack/smack_lsm.c:2973\nsecurity_socket_post_create+0x94/0xd4 security/security.c:4425\n__sock_create+0x4c8/0x884 net/socket.c:1587\nsock_create net/socket.c:1622 [inline]\n__sys_socket_create net/socket.c:1659 [inline]\n__sys_socket+0x134/0x340 net/socket.c:1706\n__do_sys_socket net/socket.c:1720 [inline]\n__se_sys_socket net/socket.c:1718 [inline]\n__arm64_sys_socket+0x7c/0x94 net/socket.c:1718\n__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\ninvoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\nel0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\ndo_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\nel0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:712\nel0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\nel0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\nCode: ???????? ???????? ???????? ???????? (????????)\n---[ end trace 0000000000000000 ]---\n\nThis patch add a toy implementation that performs a simple return to\nprevent such panic. This is because MSS can be set in sock_create_kern\nor smc_setsockopt, similar to how it's done in AF_SMC. However, for\nAF_SMC, there is currently no way to synchronize MSS within\n__sys_connect_file. This toy implementation lays the groundwork for us\nto support such feature for IPPROTO_SMC in the future.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rrmj-qxgv-v296/GHSA-rrmj-qxgv-v296.json b/advisories/unreviewed/2024/10/GHSA-rrmj-qxgv-v296/GHSA-rrmj-qxgv-v296.json new file mode 100644 index 00000000000..7785d3958a3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rrmj-qxgv-v296/GHSA-rrmj-qxgv-v296.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrmj-qxgv-v296", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:04Z", + "aliases": [ + "CVE-2024-48208" + ], + "details": "pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48208" + }, + { + "type": "WEB", + "url": "https://github.com/jedisct1/pure-ftpd/pull/176" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json b/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json index 44b66975472..a94b2c20eff 100644 --- a/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json +++ b/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcrj-5576-fc99", - "modified": "2024-10-21T18:30:57Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49875" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: map the EBADMSG to nfserr_io to avoid warning\n\nExt4 will throw -EBADMSG through ext4_readdir when a checksum error\noccurs, resulting in the following WARNING.\n\nFix it by mapping EBADMSG to nfserr_io.\n\nnfsd_buffered_readdir\n iterate_dir // -EBADMSG -74\n ext4_readdir // .iterate_shared\n ext4_dx_readdir\n ext4_htree_fill_tree\n htree_dirblock_to_tree\n ext4_read_dirblock\n __ext4_read_dirblock\n ext4_dirblock_csum_verify\n warn_no_space_for_csum\n __warn_no_space_for_csum\n return ERR_PTR(-EFSBADCRC) // -EBADMSG -74\n nfserrno // WARNING\n\n[ 161.115610] ------------[ cut here ]------------\n[ 161.116465] nfsd: non-standard errno: -74\n[ 161.117315] WARNING: CPU: 1 PID: 780 at fs/nfsd/nfsproc.c:878 nfserrno+0x9d/0xd0\n[ 161.118596] Modules linked in:\n[ 161.119243] CPU: 1 PID: 780 Comm: nfsd Not tainted 5.10.0-00014-g79679361fd5d #138\n[ 161.120684] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qe\nmu.org 04/01/2014\n[ 161.123601] RIP: 0010:nfserrno+0x9d/0xd0\n[ 161.124676] Code: 0f 87 da 30 dd 00 83 e3 01 b8 00 00 00 05 75 d7 44 89 ee 48 c7 c7 c0 57 24 98 89 44 24 04 c6\n 05 ce 2b 61 03 01 e8 99 20 d8 00 <0f> 0b 8b 44 24 04 eb b5 4c 89 e6 48 c7 c7 a0 6d a4 99 e8 cc 15 33\n[ 161.127797] RSP: 0018:ffffc90000e2f9c0 EFLAGS: 00010286\n[ 161.128794] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\n[ 161.130089] RDX: 1ffff1103ee16f6d RSI: 0000000000000008 RDI: fffff520001c5f2a\n[ 161.131379] RBP: 0000000000000022 R08: 0000000000000001 R09: ffff8881f70c1827\n[ 161.132664] R10: ffffed103ee18304 R11: 0000000000000001 R12: 0000000000000021\n[ 161.133949] R13: 00000000ffffffb6 R14: ffff8881317c0000 R15: ffffc90000e2fbd8\n[ 161.135244] FS: 0000000000000000(0000) GS:ffff8881f7080000(0000) knlGS:0000000000000000\n[ 161.136695] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 161.137761] CR2: 00007fcaad70b348 CR3: 0000000144256006 CR4: 0000000000770ee0\n[ 161.139041] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 161.140291] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 161.141519] PKRU: 55555554\n[ 161.142076] Call Trace:\n[ 161.142575] ? __warn+0x9b/0x140\n[ 161.143229] ? nfserrno+0x9d/0xd0\n[ 161.143872] ? report_bug+0x125/0x150\n[ 161.144595] ? handle_bug+0x41/0x90\n[ 161.145284] ? exc_invalid_op+0x14/0x70\n[ 161.146009] ? asm_exc_invalid_op+0x12/0x20\n[ 161.146816] ? nfserrno+0x9d/0xd0\n[ 161.147487] nfsd_buffered_readdir+0x28b/0x2b0\n[ 161.148333] ? nfsd4_encode_dirent_fattr+0x380/0x380\n[ 161.149258] ? nfsd_buffered_filldir+0xf0/0xf0\n[ 161.150093] ? wait_for_concurrent_writes+0x170/0x170\n[ 161.151004] ? generic_file_llseek_size+0x48/0x160\n[ 161.151895] nfsd_readdir+0x132/0x190\n[ 161.152606] ? nfsd4_encode_dirent_fattr+0x380/0x380\n[ 161.153516] ? nfsd_unlink+0x380/0x380\n[ 161.154256] ? override_creds+0x45/0x60\n[ 161.155006] nfsd4_encode_readdir+0x21a/0x3d0\n[ 161.155850] ? nfsd4_encode_readlink+0x210/0x210\n[ 161.156731] ? write_bytes_to_xdr_buf+0x97/0xe0\n[ 161.157598] ? __write_bytes_to_xdr_buf+0xd0/0xd0\n[ 161.158494] ? lock_downgrade+0x90/0x90\n[ 161.159232] ? nfs4svc_decode_voidarg+0x10/0x10\n[ 161.160092] nfsd4_encode_operation+0x15a/0x440\n[ 161.160959] nfsd4_proc_compound+0x718/0xe90\n[ 161.161818] nfsd_dispatch+0x18e/0x2c0\n[ 161.162586] svc_process_common+0x786/0xc50\n[ 161.163403] ? nfsd_svc+0x380/0x380\n[ 161.164137] ? svc_printk+0x160/0x160\n[ 161.164846] ? svc_xprt_do_enqueue.part.0+0x365/0x380\n[ 161.165808] ? nfsd_svc+0x380/0x380\n[ 161.166523] ? rcu_is_watching+0x23/0x40\n[ 161.167309] svc_process+0x1a5/0x200\n[ 161.168019] nfsd+0x1f5/0x380\n[ 161.168663] ? nfsd_shutdown_threads+0x260/0x260\n[ 161.169554] kthread+0x1c4/0x210\n[ 161.170224] ? kthread_insert_work_sanity_check+0x80/0x80\n[ 161.171246] ret_from_fork+0x1f/0x30", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-354" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vpfw-56r4-6hcq/GHSA-vpfw-56r4-6hcq.json b/advisories/unreviewed/2024/10/GHSA-vpfw-56r4-6hcq/GHSA-vpfw-56r4-6hcq.json new file mode 100644 index 00000000000..6ba84234a2b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vpfw-56r4-6hcq/GHSA-vpfw-56r4-6hcq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpfw-56r4-6hcq", + "modified": "2024-10-24T21:31:04Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-45263" + ], + "details": "An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45263" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Arbitrary%20File%20Upload%20to%20ovpn_upload%20via%20Upload%20Interface.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json b/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json new file mode 100644 index 00000000000..d899a32744d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7vv-chh5-rjfj", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48142" + ], + "details": "A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48142" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48142" + }, + { + "type": "WEB", + "url": "https://monica.im/desktop" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json b/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json new file mode 100644 index 00000000000..c46febe6ba2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8r5-25wc-2c5m", + "modified": "2024-10-24T21:31:03Z", + "published": "2024-10-24T21:31:03Z", + "aliases": [ + "CVE-2024-48140" + ], + "details": "A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48140" + }, + { + "type": "WEB", + "url": "https://chromewebstore.google.com/detail/monica-your-ai-copilot-po/ofpnmcalabcbjgholdjcjblkibolbppb?hl=en" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48140" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-24T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json b/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json index 328bc7a2499..a671f9e8366 100644 --- a/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json +++ b/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg4j-4q4f-6cfc", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49874" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: svc: Fix use after free vulnerability in svc_i3c_master Driver Due to Race Condition\n\nIn the svc_i3c_master_probe function, &master->hj_work is bound with\nsvc_i3c_master_hj_work, &master->ibi_work is bound with\nsvc_i3c_master_ibi_work. And svc_i3c_master_ibi_work can start the\nhj_work, svc_i3c_master_irq_handler can start the ibi_work.\n\nIf we remove the module which will call svc_i3c_master_remove to\nmake cleanup, it will free master->base through i3c_master_unregister\nwhile the work mentioned above will be used. The sequence of operations\nthat may lead to a UAF bug is as follows:\n\nCPU0 CPU1\n\n | svc_i3c_master_hj_work\nsvc_i3c_master_remove |\ni3c_master_unregister(&master->base)|\ndevice_unregister(&master->dev) |\ndevice_release |\n//free master->base |\n | i3c_master_do_daa(&master->base)\n | //use master->base\n\nFix it by ensuring that the work is canceled before proceeding with the\ncleanup in svc_i3c_master_remove.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wp73-c4gh-8ccr/GHSA-wp73-c4gh-8ccr.json b/advisories/unreviewed/2024/10/GHSA-wp73-c4gh-8ccr/GHSA-wp73-c4gh-8ccr.json index 2c8a4f7feaa..61cccf0e772 100644 --- a/advisories/unreviewed/2024/10/GHSA-wp73-c4gh-8ccr/GHSA-wp73-c4gh-8ccr.json +++ b/advisories/unreviewed/2024/10/GHSA-wp73-c4gh-8ccr/GHSA-wp73-c4gh-8ccr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp73-c4gh-8ccr", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-24T21:31:03Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-48541" ], "details": "Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xwhx-3qqx-64m9/GHSA-xwhx-3qqx-64m9.json b/advisories/unreviewed/2024/10/GHSA-xwhx-3qqx-64m9/GHSA-xwhx-3qqx-64m9.json index 7dd83003aca..627e4326d0e 100644 --- a/advisories/unreviewed/2024/10/GHSA-xwhx-3qqx-64m9/GHSA-xwhx-3qqx-64m9.json +++ b/advisories/unreviewed/2024/10/GHSA-xwhx-3qqx-64m9/GHSA-xwhx-3qqx-64m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwhx-3qqx-64m9", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49022" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac8021: fix possible oob access in ieee80211_get_rate_duration\n\nFix possible out-of-bound access in ieee80211_get_rate_duration routine\nas reported by the following UBSAN report:\n\nUBSAN: array-index-out-of-bounds in net/mac80211/airtime.c:455:47\nindex 15 is out of range for type 'u16 [12]'\nCPU: 2 PID: 217 Comm: kworker/u32:10 Not tainted 6.1.0-060100rc3-generic\nHardware name: Acer Aspire TC-281/Aspire TC-281, BIOS R01-A2 07/18/2017\nWorkqueue: mt76 mt76u_tx_status_data [mt76_usb]\nCall Trace:\n \n show_stack+0x4e/0x61\n dump_stack_lvl+0x4a/0x6f\n dump_stack+0x10/0x18\n ubsan_epilogue+0x9/0x43\n __ubsan_handle_out_of_bounds.cold+0x42/0x47\nieee80211_get_rate_duration.constprop.0+0x22f/0x2a0 [mac80211]\n ? ieee80211_tx_status_ext+0x32e/0x640 [mac80211]\n ieee80211_calc_rx_airtime+0xda/0x120 [mac80211]\n ieee80211_calc_tx_airtime+0xb4/0x100 [mac80211]\n mt76x02_send_tx_status+0x266/0x480 [mt76x02_lib]\n mt76x02_tx_status_data+0x52/0x80 [mt76x02_lib]\n mt76u_tx_status_data+0x67/0xd0 [mt76_usb]\n process_one_work+0x225/0x400\n worker_thread+0x50/0x3e0\n ? process_one_work+0x400/0x400\n kthread+0xe9/0x110\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x22/0x30", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xxqv-jc35-w8cj/GHSA-xxqv-jc35-w8cj.json b/advisories/unreviewed/2024/10/GHSA-xxqv-jc35-w8cj/GHSA-xxqv-jc35-w8cj.json index 05461bcbaa7..4ba46cbba32 100644 --- a/advisories/unreviewed/2024/10/GHSA-xxqv-jc35-w8cj/GHSA-xxqv-jc35-w8cj.json +++ b/advisories/unreviewed/2024/10/GHSA-xxqv-jc35-w8cj/GHSA-xxqv-jc35-w8cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxqv-jc35-w8cj", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-24T21:31:02Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49019" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: nixge: fix NULL dereference\n\nIn function nixge_hw_dma_bd_release() dereference of NULL pointer\npriv->rx_bd_v is possible for the case of its allocation failure in\nnixge_hw_dma_bd_init().\n\nMove for() loop with priv->rx_bd_v dereference under the check for\nits validity.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:13Z"