Skip to content

Commit 27fa94c

Browse files
Advisory Database Sync
1 parent 6e1af5d commit 27fa94c

160 files changed

Lines changed: 6790 additions & 2 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎advisories/unreviewed/2023/11/GHSA-cjm4-2f5j-r6xx/GHSA-cjm4-2f5j-r6xx.json‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@
2626
],
2727
"database_specific": {
2828
"cwe_ids": [
29-
"CWE-284"
29+
"CWE-284",
30+
"CWE-863"
3031
],
3132
"severity": "MODERATE",
3233
"github_reviewed": false,

‎advisories/unreviewed/2023/11/GHSA-gp56-58fv-r42c/GHSA-gp56-58fv-r42c.json‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@
2626
],
2727
"database_specific": {
2828
"cwe_ids": [
29-
"CWE-276"
29+
"CWE-276",
30+
"CWE-640"
3031
],
3132
"severity": "CRITICAL",
3233
"github_reviewed": false,
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-22gp-wwxc-hrmc",
4+
"modified": "2026-08-28T09:31:48Z",
5+
"published": "2026-08-28T09:31:48Z",
6+
"aliases": [
7+
"CVE-2026-80667"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: LAG, MPESW, Fix missing complete() on devcom error\n\nmlx5_mpesw_work() returned without calling complete() when\nmlx5_lag_get_devcom_comp() returned NULL. A caller that queued the\nwork and waited on mpesww->comp would block indefinitely.\n\nFunnel the early-return path through a new \"complete\" label so the\nwaiter is always woken.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80667"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/4d720c6c60e1852253b68aeee3044ebed5243adb"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/68cdbe498da8475cfd49591954e3db8fc6582eda"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/6a802de97a8bf8d5f1e4a048c67de9a8c2d2f9eb"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://git.kernel.org/stable/c/d4b85f9a668b9c44216bb78daf4ec1a915cc92d1"
32+
}
33+
],
34+
"database_specific": {
35+
"cwe_ids": [],
36+
"severity": null,
37+
"github_reviewed": false,
38+
"github_reviewed_at": null,
39+
"nvd_published_at": "2026-08-28T08:16:51Z"
40+
}
41+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-257h-4q39-v2v3",
4+
"modified": "2026-08-28T09:31:47Z",
5+
"published": "2026-08-28T09:31:47Z",
6+
"aliases": [
7+
"CVE-2026-80621"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability\n\ndwc_pcie_rasdes_debugfs_init() returns success when the controller has no\nRAS DES capability, leaving pci->debugfs->rasdes_info unset. The common\ndebugfs teardown path still calls dwc_pcie_rasdes_debugfs_deinit(), which\ndereferences rasdes_info unconditionally.\n\nReturn early when no RAS DES state was allocated. In that case no RAS DES\nmutex was initialized, so there is nothing to destroy.\n\n[mani: reworded subject]",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80621"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/26b67fa10ef84ea667942491b50e6261a45f098d"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/514b84b1bf30f75f32c2fa66734dc1a177abb73e"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/855870e8c59b97fd424e8fa3543c9e289bb48fac"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-08-28T08:16:46Z"
36+
}
37+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-28qm-9qmh-h457",
4+
"modified": "2026-08-28T09:31:50Z",
5+
"published": "2026-08-28T09:31:50Z",
6+
"aliases": [
7+
"CVE-2026-80721"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: ensure no dangling hcon references in iso_conn\n\nAfter iso_conn_del(), ISO sockets should not dereference the hcon any\nmore. Currently, clearing iso_conn::hcon relies on iso_conn_del()\nreleasing the last reference to the iso_conn.\n\nSimplify this by explicitly clearing conn->hcon in iso_conn_del(), to\navoid more complex reasoning on races about who holds the last\nreference.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80721"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/aa9f7cb2bd3a2be998ceb739fc9a2f986eba43eb"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/cdce8af9291d8a1f8916c271de029bf558d9e8ec"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/e941799c31f68e67ce0976efb38a79101f921b64"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-08-28T08:16:57Z"
36+
}
37+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2cxw-5886-mfv5",
4+
"modified": "2026-08-28T09:31:45Z",
5+
"published": "2026-08-28T09:31:45Z",
6+
"aliases": [
7+
"CVE-2026-76581"
8+
],
9+
"details": "The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76581"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://wpmudev.com/project/wpmu-dev-dashboard"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b?source=cve"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-347"
34+
],
35+
"severity": "CRITICAL",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-08-28T08:16:41Z"
39+
}
40+
}
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2fq5-fj4m-pqwr",
4+
"modified": "2026-08-28T09:31:48Z",
5+
"published": "2026-08-28T09:31:48Z",
6+
"aliases": [
7+
"CVE-2026-80644"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: don't BUG_ON an invalid journal dinode\n\n[BUG]\nA fuzzed OCFS2 image can corrupt the current slot journal dinode while\nmount is still in progress. The mount path first reports the invalid\njournal block and then crashes in shutdown:\n\nkernel BUG at fs/ocfs2/journal.c:1034!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:ocfs2_journal_toggle_dirty+0x2d6/0x340 fs/ocfs2/journal.c:1034\nCall Trace:\n ocfs2_journal_shutdown+0x414/0xc30 fs/ocfs2/journal.c:1116\n ocfs2_mount_volume fs/ocfs2/super.c:1785 [inline]\n ocfs2_fill_super+0x30a9/0x3cd0 fs/ocfs2/super.c:1083\n get_tree_bdev_flags+0x38b/0x640 fs/super.c:1698\n get_tree_bdev+0x24/0x40 fs/super.c:1721\n ocfs2_get_tree+0x21/0x30 fs/ocfs2/super.c:1184\n vfs_get_tree+0x9a/0x370 fs/super.c:1758\n fc_mount fs/namespace.c:1199 [inline]\n do_new_mount_fc fs/namespace.c:3642 [inline]\n do_new_mount fs/namespace.c:3718 [inline]\n path_mount+0x5b8/0x1ea0 fs/namespace.c:4028\n do_mount fs/namespace.c:4041 [inline]\n __do_sys_mount fs/namespace.c:4229 [inline]\n __se_sys_mount fs/namespace.c:4206 [inline]\n __x64_sys_mount+0x282/0x320 fs/namespace.c:4206\n ...\n\n[CAUSE]\nocfs2_journal_toggle_dirty() used to return -EIO when journal->j_bh no\nlonger contained a valid dinode, because the startup and shutdown paths\nalready handled that failure. Commit 10995aa2451a\n(\"ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() checks.\") changed\nthe check to a BUG_ON() under the assumption that the journal dinode had\nalready been validated. That turns an unexpected invalid journal dinode\nduring mount teardown into a kernel crash instead of a normal mount\nfailure.\n\n[FIX]\nReplace the BUG_ON() with WARN_ON() and return -EIO. This keeps the\ninvariant warning for debugging, but restores the original behavior of\nfailing startup or shutdown cleanly instead of panicking the kernel.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80644"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/12c32a7350b670aaaaf2e01583d8648ec0c9755c"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/3852478d34c7baa490ba9c7374ee901a56eea577"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/5b33f99f3e48465bd93219495381a5aef4fa967f"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://git.kernel.org/stable/c/86509c5296fe46ad6bcdd83931a53c2c6b7913a8"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://git.kernel.org/stable/c/a06eec15596e5801bad59ad16cd2bf4f0fa839a1"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://git.kernel.org/stable/c/b460f8d01a12061853d02c8fb693fb42450acd7d"
40+
},
41+
{
42+
"type": "WEB",
43+
"url": "https://git.kernel.org/stable/c/bf1d59cf2ac8a1730607ebaa0bc0dc6d00f197d0"
44+
},
45+
{
46+
"type": "WEB",
47+
"url": "https://git.kernel.org/stable/c/c0438198c28b1d22c272751af5e717c11d9fa8dd"
48+
}
49+
],
50+
"database_specific": {
51+
"cwe_ids": [],
52+
"severity": null,
53+
"github_reviewed": false,
54+
"github_reviewed_at": null,
55+
"nvd_published_at": "2026-08-28T08:16:49Z"
56+
}
57+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2h39-9r89-9rx3",
4+
"modified": "2026-08-28T09:31:48Z",
5+
"published": "2026-08-28T09:31:48Z",
6+
"aliases": [
7+
"CVE-2026-80674"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate resident attribute lists and harden the validator\n\nA base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list()\nonly on the non-resident path; ntfs_read_locked_inode() copies a *resident*\nattribute list into ni->attr_list with a plain memcpy() and no validation\nat all. Every subsequent walk of ni->attr_list --\nntfs_external_attr_find(), ntfs_inode_attach_all_extents() and\nntfs_attrlist_need() -- then trusts the entries are well-formed and reads\nattr_list_entry fixed-header fields\n(lowest_vcn at offset 8, mft_reference at offset 16, and the name) with\nbounds that assume validation already happened. A crafted resident\nattribute list therefore reaches those walks unvalidated and can drive\nout-of-bounds reads of the attribute-list buffer.\n\nload_attribute_list() itself reads ale->name_offset (offset 7),\nale->mft_reference (offset 16) and the name length under only an\n\"al < al_start + size\" bound, so its own validation loop can over-read the\nfixed header of a truncated trailing entry by a few bytes.\n\nFactor the per-entry validation into ntfs_attr_list_entry_is_valid(),\nwhich requires each entry's fixed header (offsetof(struct\nattr_list_entry, name)) to be in range before any field is dereferenced,\nthat ale->length is a multiple of 8 covering the fixed header plus the\nname, and that the entry is in use and carries a live MFT reference.\nntfs_attr_list_is_valid() walks the buffer with it and checks the entries\ntile it exactly. Use the list validator in load_attribute_list()\n(replacing the open-coded loop, closing its own over-read) and on the\nresident path in ntfs_read_locked_inode() (which previously skipped\nvalidation entirely); patches 2/3 reuse the per-entry helper at the other\ntwo attribute-list walks.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80674"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/55e97648f7753c6097cb682d24d1abcfe878e812"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/7d19e1ffee084c4f7d321a360c14ba43404f7cc8"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-08-28T08:16:52Z"
32+
}
33+
}
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-38hv-9295-2cxw",
4+
"modified": "2026-08-28T09:31:46Z",
5+
"published": "2026-08-28T09:31:45Z",
6+
"aliases": [
7+
"CVE-2026-80593"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (asus_atk0110) Check package count before accessing element\n\natk_ec_present() walks the management group package returned by the GGRP\nACPI method and, for each sub-package, reads its first element:\n\n\tid = &obj->package.elements[0];\n\tif (id->type != ACPI_TYPE_INTEGER)\n\nwithout checking that the sub-package is non-empty. ACPICA allocates the\nelement array with exactly package.count entries, so for a sub-package\nwith a zero count this reads past the allocation.\n\nThe sibling function atk_debugfs_ggrp_open() performs the same access but\nskips empty packages with a package.count check first. Add the same\ncheck to atk_ec_present() so a malformed firmware package cannot trigger\nan out-of-bounds read.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80593"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/2a137124664aad1e36d8d74e8e2207365a04737f"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/459b0a0439ea65b2b612aa572eb62a2e26d05618"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/76392d35c8df471b288cfc6536bd092b3c8ee2cf"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://git.kernel.org/stable/c/768f20e7bb48d723b82cb142120263d0806fbeb8"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://git.kernel.org/stable/c/981a8a2e3773dc7e704943388a1fb97970b23275"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://git.kernel.org/stable/c/b770fcfcdced569bcf7c6982aeea8c3d11a21c2b"
40+
},
41+
{
42+
"type": "WEB",
43+
"url": "https://git.kernel.org/stable/c/d8d4fa0c4f818e30b6f6737bdd989b7e2b511cae"
44+
},
45+
{
46+
"type": "WEB",
47+
"url": "https://git.kernel.org/stable/c/e2735b39f044bad7bf2017aef248935525bc0b97"
48+
}
49+
],
50+
"database_specific": {
51+
"cwe_ids": [],
52+
"severity": null,
53+
"github_reviewed": false,
54+
"github_reviewed_at": null,
55+
"nvd_published_at": "2026-08-28T08:16:42Z"
56+
}
57+
}
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3h3p-2268-63w8",
4+
"modified": "2026-08-28T09:31:46Z",
5+
"published": "2026-08-28T09:31:46Z",
6+
"aliases": [
7+
"CVE-2026-80598"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: fix out-of-bounds read in decompress_lznt\n\ndecompress_lznt() does not validate array index bounds before accessing\nthe decompression table. A corrupted NTFS3 image with invalid compressed\ndata can trigger an out-of-bounds read.\n\nAdd index bounds checking to prevent the OOB access.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80598"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/1113fa5b01a47a1a4cdbb9c695197ca6215f02a8"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/61415ffa365d2eca6986914afd0d1412444aa1dd"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/7160a57192fb16d7a6fa9b7f5c7ac341d2444a89"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://git.kernel.org/stable/c/a93980141253c932aa6ae5d4422d90e0162dc774"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://git.kernel.org/stable/c/bd77afca2ae9b6d44d37902e3ad672ebb028b070"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://git.kernel.org/stable/c/c694f8ea2611e7413b3f04ee47e04a9b7b45817b"
40+
},
41+
{
42+
"type": "WEB",
43+
"url": "https://git.kernel.org/stable/c/ff05a98150ebb2b03919a9c05c576681e86abbb7"
44+
}
45+
],
46+
"database_specific": {
47+
"cwe_ids": [],
48+
"severity": null,
49+
"github_reviewed": false,
50+
"github_reviewed_at": null,
51+
"nvd_published_at": "2026-08-28T08:16:43Z"
52+
}
53+
}

0 commit comments

Comments
 (0)