diff --git a/components/producers/cloudpi/README.md b/components/producers/cloudpi/README.md
new file mode 100644
index 000000000..7a3c0166f
--- /dev/null
+++ b/components/producers/cloudpi/README.md
@@ -0,0 +1,4 @@
+# What's not automated
+
+- image build
+- task creation
\ No newline at end of file
diff --git a/components/producers/cloudpi/logs.txt b/components/producers/cloudpi/logs.txt
new file mode 100644
index 000000000..774866f15
--- /dev/null
+++ b/components/producers/cloudpi/logs.txt
@@ -0,0 +1,3 @@
+{'SchemaVersion': 2, 'ArtifactName': 'snap-079031379a8fe0057', 'ArtifactType': 'vm', 'Metadata': {'OS': {'Family': 'ubuntu', 'Name': '22.04'}, 'ImageConfig': {'architecture': '', 'created': '0001-01-01T00:00:00Z', 'os': '', 'rootfs': {'type': '', 'diff_ids': None}, 'config': {}}}, 'Results': [{'Target': 'snap-079031379a8fe0057 (ubuntu 22.04)', 'Class': 'os-pkgs', 'Type': 'ubuntu', 'Vulnerabilities': [{'VulnerabilityID': 'CVE-2021-26318', 'PkgID': 'amd64-microcode@3.20191218.1ubuntu2.2', 'PkgName': 'amd64-microcode', 'InstalledVersion': '3.20191218.1ubuntu2.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-26318', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-203', 'CWE-208'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:M/Au:N/C:P/I:N/A:N', 'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V2Score': 1.9, 'V3Score': 4.7}}, 'References': ['https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1017', 'https://www.cve.org/CVERecord?id=CVE-2021-26318'], 'PublishedDate': '2021-10-13T19:15:07.36Z', 'LastModifiedDate': '2021-10-20T18:29:12.263Z'}, {'VulnerabilityID': 'CVE-2023-31315', 'PkgID': 'amd64-microcode@3.20191218.1ubuntu2.2', 'PkgName': 'amd64-microcode', 'InstalledVersion': '3.20191218.1ubuntu2.2', 'FixedVersion': '3.20191218.1ubuntu2.3', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-31315', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'hw: amd: SMM Lock Bypass', 'Description': 'Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-94'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-31315', 'https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit?id=091bd5adf19c7ab01214c64689952acb4833b21d', 'https://ioactive.com/event/def-con-talk-amd-sinkclose-universal-ring-2-privilege-escalation/', 'https://linux.oracle.com/cve/CVE-2023-31315.html', 'https://linux.oracle.com/errata/ELSA-2024-12580.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-31315', 'https://ubuntu.com/security/notices/USN-7077-1', 'https://www.amd.com/en/resources/product-security.html', 'https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html', 'https://www.cve.org/CVERecord?id=CVE-2023-31315'], 'PublishedDate': '2024-08-12T13:38:10.353Z', 'LastModifiedDate': '2024-08-27T15:35:00.983Z'}, {'VulnerabilityID': 'CVE-2017-13716', 'PkgID': 'binutils@2.38-4ubuntu2.6', 'PkgName': 'binutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Memory leak with the C++ symbol demangler routine in libiberty', 'Description': 'The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 7.1, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2017-13716', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13716', 'https://sourceware.org/bugzilla/show_bug.cgi?id=22009', 'https://www.cve.org/CVERecord?id=CVE-2017-13716'], 'PublishedDate': '2017-08-28T21:29:00.293Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2018-20657', 'PkgID': 'binutils@2.38-4ubuntu2.6', 'PkgName': 'binutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-20657', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libiberty: Memory leak in demangle_template function resulting in a denial of service', 'Description': 'The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.', 'Severity': 'LOW', 'CweIDs': ['CWE-772'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/106444', 'https://access.redhat.com/errata/RHSA-2019:3352', 'https://access.redhat.com/security/cve/CVE-2018-20657', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539', 'https://linux.oracle.com/cve/CVE-2018-20657.html', 'https://linux.oracle.com/errata/ELSA-2019-3352.html', 'https://nvd.nist.gov/vuln/detail/CVE-2018-20657', 'https://support.f5.com/csp/article/K62602089', 'https://www.cve.org/CVERecord?id=CVE-2018-20657'], 'PublishedDate': '2019-01-02T14:29:00.313Z', 'LastModifiedDate': '2019-11-06T01:15:17.87Z'}, {'VulnerabilityID': 'CVE-2019-1010204', 'PkgID': 'binutils@2.38-4ubuntu2.6', 'PkgName': 'binutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-1010204', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service', 'Description': 'GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.', 'Severity': 'LOW', 'CweIDs': ['CWE-125', 'CWE-681'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-1010204', 'https://linux.oracle.com/cve/CVE-2019-1010204.html', 'https://linux.oracle.com/errata/ELSA-2020-1797.html', 'https://nvd.nist.gov/vuln/detail/CVE-2019-1010204', 'https://security.netapp.com/advisory/ntap-20190822-0001/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=23765', 'https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medium=RSS', 'https://ubuntu.com/security/notices/USN-5349-1', 'https://www.cve.org/CVERecord?id=CVE-2019-1010204'], 'PublishedDate': '2019-07-23T14:15:13.373Z', 'LastModifiedDate': '2023-11-07T03:02:17.51Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'binutils@2.38-4ubuntu2.6', 'PkgName': 'binutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2022-48064', 'PkgID': 'binutils@2.38-4ubuntu2.6', 'PkgName': 'binutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48064', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c', 'Description': 'GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48064', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XKYUAIORNQ32IZUOZFURECZKEXOHX7Z/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KGSKF4GH7425S6XFDQMWTJGD5U47BAZN/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSUNHSOWWLLNGHRM5TUBNCJHEYHPDX2M/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48064', 'https://security.netapp.com/advisory/ntap-20231006-0008/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=29922', 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8f2c64de86bc3d7556121fe296dd679000283931', 'https://www.cve.org/CVERecord?id=CVE-2022-48064'], 'PublishedDate': '2023-08-22T19:16:30.937Z', 'LastModifiedDate': '2023-11-07T03:56:28.11Z'}, {'VulnerabilityID': 'CVE-2017-13716', 'PkgID': 'binutils-common@2.38-4ubuntu2.6', 'PkgName': 'binutils-common', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Memory leak with the C++ symbol demangler routine in libiberty', 'Description': 'The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 7.1, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2017-13716', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13716', 'https://sourceware.org/bugzilla/show_bug.cgi?id=22009', 'https://www.cve.org/CVERecord?id=CVE-2017-13716'], 'PublishedDate': '2017-08-28T21:29:00.293Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2018-20657', 'PkgID': 'binutils-common@2.38-4ubuntu2.6', 'PkgName': 'binutils-common', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-20657', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libiberty: Memory leak in demangle_template function resulting in a denial of service', 'Description': 'The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.', 'Severity': 'LOW', 'CweIDs': ['CWE-772'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/106444', 'https://access.redhat.com/errata/RHSA-2019:3352', 'https://access.redhat.com/security/cve/CVE-2018-20657', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539', 'https://linux.oracle.com/cve/CVE-2018-20657.html', 'https://linux.oracle.com/errata/ELSA-2019-3352.html', 'https://nvd.nist.gov/vuln/detail/CVE-2018-20657', 'https://support.f5.com/csp/article/K62602089', 'https://www.cve.org/CVERecord?id=CVE-2018-20657'], 'PublishedDate': '2019-01-02T14:29:00.313Z', 'LastModifiedDate': '2019-11-06T01:15:17.87Z'}, {'VulnerabilityID': 'CVE-2019-1010204', 'PkgID': 'binutils-common@2.38-4ubuntu2.6', 'PkgName': 'binutils-common', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-1010204', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service', 'Description': 'GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.', 'Severity': 'LOW', 'CweIDs': ['CWE-125', 'CWE-681'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-1010204', 'https://linux.oracle.com/cve/CVE-2019-1010204.html', 'https://linux.oracle.com/errata/ELSA-2020-1797.html', 'https://nvd.nist.gov/vuln/detail/CVE-2019-1010204', 'https://security.netapp.com/advisory/ntap-20190822-0001/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=23765', 'https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medium=RSS', 'https://ubuntu.com/security/notices/USN-5349-1', 'https://www.cve.org/CVERecord?id=CVE-2019-1010204'], 'PublishedDate': '2019-07-23T14:15:13.373Z', 'LastModifiedDate': '2023-11-07T03:02:17.51Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'binutils-common@2.38-4ubuntu2.6', 'PkgName': 'binutils-common', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2022-48064', 'PkgID': 'binutils-common@2.38-4ubuntu2.6', 'PkgName': 'binutils-common', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48064', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c', 'Description': 'GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48064', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XKYUAIORNQ32IZUOZFURECZKEXOHX7Z/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KGSKF4GH7425S6XFDQMWTJGD5U47BAZN/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSUNHSOWWLLNGHRM5TUBNCJHEYHPDX2M/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48064', 'https://security.netapp.com/advisory/ntap-20231006-0008/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=29922', 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8f2c64de86bc3d7556121fe296dd679000283931', 'https://www.cve.org/CVERecord?id=CVE-2022-48064'], 'PublishedDate': '2023-08-22T19:16:30.937Z', 'LastModifiedDate': '2023-11-07T03:56:28.11Z'}, {'VulnerabilityID': 'CVE-2017-13716', 'PkgID': 'binutils-x86-64-linux-gnu@2.38-4ubuntu2.6', 'PkgName': 'binutils-x86-64-linux-gnu', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Memory leak with the C++ symbol demangler routine in libiberty', 'Description': 'The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 7.1, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2017-13716', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13716', 'https://sourceware.org/bugzilla/show_bug.cgi?id=22009', 'https://www.cve.org/CVERecord?id=CVE-2017-13716'], 'PublishedDate': '2017-08-28T21:29:00.293Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2018-20657', 'PkgID': 'binutils-x86-64-linux-gnu@2.38-4ubuntu2.6', 'PkgName': 'binutils-x86-64-linux-gnu', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-20657', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libiberty: Memory leak in demangle_template function resulting in a denial of service', 'Description': 'The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.', 'Severity': 'LOW', 'CweIDs': ['CWE-772'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/106444', 'https://access.redhat.com/errata/RHSA-2019:3352', 'https://access.redhat.com/security/cve/CVE-2018-20657', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539', 'https://linux.oracle.com/cve/CVE-2018-20657.html', 'https://linux.oracle.com/errata/ELSA-2019-3352.html', 'https://nvd.nist.gov/vuln/detail/CVE-2018-20657', 'https://support.f5.com/csp/article/K62602089', 'https://www.cve.org/CVERecord?id=CVE-2018-20657'], 'PublishedDate': '2019-01-02T14:29:00.313Z', 'LastModifiedDate': '2019-11-06T01:15:17.87Z'}, {'VulnerabilityID': 'CVE-2019-1010204', 'PkgID': 'binutils-x86-64-linux-gnu@2.38-4ubuntu2.6', 'PkgName': 'binutils-x86-64-linux-gnu', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-1010204', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service', 'Description': 'GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.', 'Severity': 'LOW', 'CweIDs': ['CWE-125', 'CWE-681'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-1010204', 'https://linux.oracle.com/cve/CVE-2019-1010204.html', 'https://linux.oracle.com/errata/ELSA-2020-1797.html', 'https://nvd.nist.gov/vuln/detail/CVE-2019-1010204', 'https://security.netapp.com/advisory/ntap-20190822-0001/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=23765', 'https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medium=RSS', 'https://ubuntu.com/security/notices/USN-5349-1', 'https://www.cve.org/CVERecord?id=CVE-2019-1010204'], 'PublishedDate': '2019-07-23T14:15:13.373Z', 'LastModifiedDate': '2023-11-07T03:02:17.51Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'binutils-x86-64-linux-gnu@2.38-4ubuntu2.6', 'PkgName': 'binutils-x86-64-linux-gnu', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2022-48064', 'PkgID': 'binutils-x86-64-linux-gnu@2.38-4ubuntu2.6', 'PkgName': 'binutils-x86-64-linux-gnu', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48064', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c', 'Description': 'GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48064', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XKYUAIORNQ32IZUOZFURECZKEXOHX7Z/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KGSKF4GH7425S6XFDQMWTJGD5U47BAZN/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSUNHSOWWLLNGHRM5TUBNCJHEYHPDX2M/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48064', 'https://security.netapp.com/advisory/ntap-20231006-0008/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=29922', 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8f2c64de86bc3d7556121fe296dd679000283931', 'https://www.cve.org/CVERecord?id=CVE-2022-48064'], 'PublishedDate': '2023-08-22T19:16:30.937Z', 'LastModifiedDate': '2023-11-07T03:56:28.11Z'}, {'VulnerabilityID': 'CVE-2023-39810', 'PkgID': 'busybox-initramfs@1:1.30.1-7ubuntu3.1', 'PkgName': 'busybox-initramfs', 'InstalledVersion': '1:1.30.1-7ubuntu3.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-39810', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'busybox: CPIO command of Busybox allows attackers to execute a directory traversal', 'Description': 'An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-22'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['http://busybox.com', 'http://lists.busybox.net/pipermail/busybox/2024-August/090865.html', 'https://access.redhat.com/security/cve/CVE-2023-39810', 'https://nvd.nist.gov/vuln/detail/CVE-2023-39810', 'https://www.cve.org/CVERecord?id=CVE-2023-39810', 'https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/'], 'PublishedDate': '2023-08-28T19:15:07.893Z', 'LastModifiedDate': '2023-09-07T13:48:46.393Z'}, {'VulnerabilityID': 'CVE-2023-42366', 'PkgID': 'busybox-initramfs@1:1.30.1-7ubuntu3.1', 'PkgName': 'busybox-initramfs', 'InstalledVersion': '1:1.30.1-7ubuntu3.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-42366', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'busybox: A heap-buffer-overflow', 'Description': 'A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-42366', 'https://bugs.busybox.net/show_bug.cgi?id=15874', 'https://nvd.nist.gov/vuln/detail/CVE-2023-42366', 'https://www.cve.org/CVERecord?id=CVE-2023-42366'], 'PublishedDate': '2023-11-27T23:15:07.42Z', 'LastModifiedDate': '2023-11-30T05:08:23.197Z'}, {'VulnerabilityID': 'CVE-2022-28391', 'PkgID': 'busybox-initramfs@1:1.30.1-7ubuntu3.1', 'PkgName': 'busybox-initramfs', 'InstalledVersion': '1:1.30.1-7ubuntu3.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-28391', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'busybox: remote attackers may execute arbitrary code if netstat is used', 'Description': "BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.", 'Severity': 'LOW', 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 6.8, 'V3Score': 8.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-28391', 'https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch', 'https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch', 'https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661', 'https://nvd.nist.gov/vuln/detail/CVE-2022-28391', 'https://www.cve.org/CVERecord?id=CVE-2022-28391'], 'PublishedDate': '2022-04-03T21:15:08.207Z', 'LastModifiedDate': '2022-08-11T18:44:50.37Z'}, {'VulnerabilityID': 'CVE-2023-39810', 'PkgID': 'busybox-static@1:1.30.1-7ubuntu3.1', 'PkgName': 'busybox-static', 'InstalledVersion': '1:1.30.1-7ubuntu3.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-39810', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'busybox: CPIO command of Busybox allows attackers to execute a directory traversal', 'Description': 'An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-22'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['http://busybox.com', 'http://lists.busybox.net/pipermail/busybox/2024-August/090865.html', 'https://access.redhat.com/security/cve/CVE-2023-39810', 'https://nvd.nist.gov/vuln/detail/CVE-2023-39810', 'https://www.cve.org/CVERecord?id=CVE-2023-39810', 'https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/'], 'PublishedDate': '2023-08-28T19:15:07.893Z', 'LastModifiedDate': '2023-09-07T13:48:46.393Z'}, {'VulnerabilityID': 'CVE-2023-42366', 'PkgID': 'busybox-static@1:1.30.1-7ubuntu3.1', 'PkgName': 'busybox-static', 'InstalledVersion': '1:1.30.1-7ubuntu3.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-42366', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'busybox: A heap-buffer-overflow', 'Description': 'A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-42366', 'https://bugs.busybox.net/show_bug.cgi?id=15874', 'https://nvd.nist.gov/vuln/detail/CVE-2023-42366', 'https://www.cve.org/CVERecord?id=CVE-2023-42366'], 'PublishedDate': '2023-11-27T23:15:07.42Z', 'LastModifiedDate': '2023-11-30T05:08:23.197Z'}, {'VulnerabilityID': 'CVE-2022-28391', 'PkgID': 'busybox-static@1:1.30.1-7ubuntu3.1', 'PkgName': 'busybox-static', 'InstalledVersion': '1:1.30.1-7ubuntu3.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-28391', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'busybox: remote attackers may execute arbitrary code if netstat is used', 'Description': "BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.", 'Severity': 'LOW', 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 6.8, 'V3Score': 8.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-28391', 'https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch', 'https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch', 'https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661', 'https://nvd.nist.gov/vuln/detail/CVE-2022-28391', 'https://www.cve.org/CVERecord?id=CVE-2022-28391'], 'PublishedDate': '2022-04-03T21:15:08.207Z', 'LastModifiedDate': '2022-08-11T18:44:50.37Z'}, {'VulnerabilityID': 'CVE-2016-2781', 'PkgID': 'coreutils@8.32-4.1ubuntu1.2', 'PkgName': 'coreutils', 'InstalledVersion': '8.32-4.1ubuntu1.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-2781', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'coreutils: Non-privileged session can escape to the parent session in chroot', 'Description': "chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.", 'Severity': 'LOW', 'CweIDs': ['CWE-20'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:P/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N', 'V2Score': 2.1, 'V3Score': 6.5}, 'redhat': {'V2Vector': 'AV:L/AC:H/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H', 'V2Score': 6.2, 'V3Score': 8.6}}, 'References': ['http://seclists.org/oss-sec/2016/q1/452', 'http://www.openwall.com/lists/oss-security/2016/02/28/2', 'http://www.openwall.com/lists/oss-security/2016/02/28/3', 'https://access.redhat.com/security/cve/CVE-2016-2781', 'https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E', 'https://lore.kernel.org/patchwork/patch/793178/', 'https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.28/v2.28-ReleaseNotes', 'https://nvd.nist.gov/vuln/detail/CVE-2016-2781', 'https://www.cve.org/CVERecord?id=CVE-2016-2781'], 'PublishedDate': '2017-02-07T15:59:00.333Z', 'LastModifiedDate': '2023-11-07T02:32:03.347Z'}, {'VulnerabilityID': 'CVE-2023-7216', 'PkgID': 'cpio@2.13+dfsg-7ubuntu0.1', 'PkgName': 'cpio', 'InstalledVersion': '2.13+dfsg-7ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-7216', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'CPIO: extraction allows symlinks which enables Remote Command Execution', 'Description': 'A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-22', 'CWE-59'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L', 'V3Score': 5.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-7216', 'https://bugzilla.redhat.com/show_bug.cgi?id=2249901', 'https://nvd.nist.gov/vuln/detail/CVE-2023-7216', 'https://www.cve.org/CVERecord?id=CVE-2023-7216'], 'PublishedDate': '2024-02-05T15:15:08.903Z', 'LastModifiedDate': '2024-09-19T06:15:02.437Z'}, {'VulnerabilityID': 'CVE-2023-34969', 'PkgID': 'dbus@1.12.20-2ubuntu4.1', 'PkgName': 'dbus', 'InstalledVersion': '1.12.20-2ubuntu4.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-34969', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered', 'Description': 'D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:4569', 'https://access.redhat.com/security/cve/CVE-2023-34969', 'https://bugzilla.redhat.com/2213166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2213166', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34969', 'https://errata.almalinux.org/9/ALSA-2023-4569.html', 'https://errata.rockylinux.org/RLSA-2023:4569', 'https://gitlab.freedesktop.org/dbus/dbus/-/issues/457', 'https://linux.oracle.com/cve/CVE-2023-34969.html', 'https://linux.oracle.com/errata/ELSA-2023-4569.html', 'https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-34969', 'https://security.netapp.com/advisory/ntap-20231208-0007/', 'https://ubuntu.com/security/notices/USN-6372-1', 'https://www.cve.org/CVERecord?id=CVE-2023-34969'], 'PublishedDate': '2023-06-08T03:15:08.97Z', 'LastModifiedDate': '2023-12-27T16:36:58.353Z'}, {'VulnerabilityID': 'CVE-2023-34969', 'PkgID': 'dbus-user-session@1.12.20-2ubuntu4.1', 'PkgName': 'dbus-user-session', 'InstalledVersion': '1.12.20-2ubuntu4.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-34969', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered', 'Description': 'D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:4569', 'https://access.redhat.com/security/cve/CVE-2023-34969', 'https://bugzilla.redhat.com/2213166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2213166', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34969', 'https://errata.almalinux.org/9/ALSA-2023-4569.html', 'https://errata.rockylinux.org/RLSA-2023:4569', 'https://gitlab.freedesktop.org/dbus/dbus/-/issues/457', 'https://linux.oracle.com/cve/CVE-2023-34969.html', 'https://linux.oracle.com/errata/ELSA-2023-4569.html', 'https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-34969', 'https://security.netapp.com/advisory/ntap-20231208-0007/', 'https://ubuntu.com/security/notices/USN-6372-1', 'https://www.cve.org/CVERecord?id=CVE-2023-34969'], 'PublishedDate': '2023-06-08T03:15:08.97Z', 'LastModifiedDate': '2023-12-27T16:36:58.353Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'dirmngr@2.2.27-3ubuntu2.1', 'PkgName': 'dirmngr', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2023-30630', 'PkgID': 'dmidecode@3.3-3ubuntu0.1', 'PkgName': 'dmidecode', 'InstalledVersion': '3.3-3ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-30630', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'dmidecode: dump-bin to overwrite a local file', 'Description': 'Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:5061', 'https://access.redhat.com/security/cve/CVE-2023-30630', 'https://bugzilla.redhat.com/2186669', 'https://bugzilla.redhat.com/show_bug.cgi?id=2186669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-30630', 'https://errata.almalinux.org/9/ALSA-2023-5061.html', 'https://errata.rockylinux.org/RLSA-2023:5061', 'https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=6ca381c1247c81f74e1ca4e7706f70bdda72e6f2', 'https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=d8cfbc808f387e87091c25e7d5b8c2bb348bb206', 'https://github.com/adamreiser/dmiwrite', 'https://github.com/advisories/GHSA-9r2p-xmm5-5ppg', 'https://linux.oracle.com/cve/CVE-2023-30630.html', 'https://linux.oracle.com/errata/ELSA-2023-5252.html', 'https://lists.nongnu.org/archive/html/dmidecode-devel/2023-03/msg00003.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-30630', 'https://www.cve.org/CVERecord?id=CVE-2023-30630'], 'PublishedDate': '2023-04-13T16:15:07.93Z', 'LastModifiedDate': '2023-09-28T17:54:17.707Z'}, {'VulnerabilityID': 'CVE-2023-4039', 'PkgID': 'gcc-12-base@12.3.0-1ubuntu1~22.04', 'PkgName': 'gcc-12-base', 'InstalledVersion': '12.3.0-1ubuntu1~22.04', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-4039', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64', 'Description': '\n\n**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains \nthat target AArch64 allows an attacker to exploit an existing buffer \noverflow in dynamically-sized local variables in your application \nwithout this being detected. This stack-protector failure only applies \nto C99-style dynamically-sized local variables or those created using \nalloca(). The stack-protector operates as intended for statically-sized \nlocal variables.\n\nThe default behavior when the stack-protector \ndetects an overflow is to terminate your application, resulting in \ncontrolled loss of availability. An attacker who can exploit a buffer \noverflow without triggering the stack-protector might be able to change \nprogram flow control to cause an uncontrolled loss of availability or to\n go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.\n\n\n\n\n\n', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-693'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-4039', 'https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64', 'https://gcc.gnu.org/git/?p=gcc.git;a=blob_plain;f=SECURITY.txt', 'https://gcc.gnu.org/pipermail/gcc-patches/2023-October/634066.html', 'https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-x7ch-h5rf-w2mf', 'https://inbox.sourceware.org/gcc-patches/46cfa37b-56eb-344d-0745-e0d35393392d@gotplt.org', 'https://linux.oracle.com/cve/CVE-2023-4039.html', 'https://linux.oracle.com/errata/ELSA-2023-28766.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-4039', 'https://rtx.meta.security/mitigation/2023/09/12/CVE-2023-4039.html', 'https://www.cve.org/CVERecord?id=CVE-2023-4039'], 'PublishedDate': '2023-09-13T09:15:15.69Z', 'LastModifiedDate': '2024-08-02T08:15:14.993Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'gcc-12-base@12.3.0-1ubuntu1~22.04', 'PkgName': 'gcc-12-base', 'InstalledVersion': '12.3.0-1ubuntu1~22.04', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2018-1000021', 'PkgID': 'git@1:2.34.1-1ubuntu1.11', 'PkgName': 'git', 'InstalledVersion': '1:2.34.1-1ubuntu1.11', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-1000021', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'git: client prints server-sent ANSI escape codes to the terminal, allowing for unverified messages to potentially execute arbitrary commands', 'Description': 'GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).', 'Severity': 'LOW', 'CweIDs': ['CWE-20'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 6.8, 'V3Score': 8.8}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L', 'V3Score': 5}}, 'References': ['http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html', 'https://access.redhat.com/security/cve/CVE-2018-1000021', 'https://nvd.nist.gov/vuln/detail/CVE-2018-1000021', 'https://public-inbox.org/git/20180205204312.GB104086@aiede.svl.corp.google.com/', 'https://www.cve.org/CVERecord?id=CVE-2018-1000021'], 'PublishedDate': '2018-02-09T23:29:00.557Z', 'LastModifiedDate': '2018-03-06T19:34:06.18Z'}, {'VulnerabilityID': 'CVE-2018-1000021', 'PkgID': 'git-man@1:2.34.1-1ubuntu1.11', 'PkgName': 'git-man', 'InstalledVersion': '1:2.34.1-1ubuntu1.11', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-1000021', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'git: client prints server-sent ANSI escape codes to the terminal, allowing for unverified messages to potentially execute arbitrary commands', 'Description': 'GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).', 'Severity': 'LOW', 'CweIDs': ['CWE-20'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 6.8, 'V3Score': 8.8}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L', 'V3Score': 5}}, 'References': ['http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html', 'https://access.redhat.com/security/cve/CVE-2018-1000021', 'https://nvd.nist.gov/vuln/detail/CVE-2018-1000021', 'https://public-inbox.org/git/20180205204312.GB104086@aiede.svl.corp.google.com/', 'https://www.cve.org/CVERecord?id=CVE-2018-1000021'], 'PublishedDate': '2018-02-09T23:29:00.557Z', 'LastModifiedDate': '2018-03-06T19:34:06.18Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gnupg@2.2.27-3ubuntu2.1', 'PkgName': 'gnupg', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gnupg-l10n@2.2.27-3ubuntu2.1', 'PkgName': 'gnupg-l10n', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gnupg-utils@2.2.27-3ubuntu2.1', 'PkgName': 'gnupg-utils', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpg@2.2.27-3ubuntu2.1', 'PkgName': 'gpg', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpg-agent@2.2.27-3ubuntu2.1', 'PkgName': 'gpg-agent', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpg-wks-client@2.2.27-3ubuntu2.1', 'PkgName': 'gpg-wks-client', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpg-wks-server@2.2.27-3ubuntu2.1', 'PkgName': 'gpg-wks-server', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpgconf@2.2.27-3ubuntu2.1', 'PkgName': 'gpgconf', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpgsm@2.2.27-3ubuntu2.1', 'PkgName': 'gpgsm', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2022-3219', 'PkgID': 'gpgv@2.2.27-3ubuntu2.1', 'PkgName': 'gpgv', 'InstalledVersion': '2.2.27-3ubuntu2.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3219', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gnupg: denial of service issue (resource consumption) using compressed packets', 'Description': 'GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3219', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127010', 'https://dev.gnupg.org/D556', 'https://dev.gnupg.org/T5993', 'https://marc.info/?l=oss-security&m=165696590211434&w=4', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3219', 'https://security.netapp.com/advisory/ntap-20230324-0001/', 'https://www.cve.org/CVERecord?id=CVE-2022-3219'], 'PublishedDate': '2023-02-23T20:15:12.393Z', 'LastModifiedDate': '2023-05-26T16:31:34.07Z'}, {'VulnerabilityID': 'CVE-2024-48957', 'PkgID': 'libarchive13@3.6.0-1ubuntu1.1', 'PkgName': 'libarchive13', 'InstalledVersion': '3.6.0-1ubuntu1.1', 'FixedVersion': '3.6.0-1ubuntu1.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-48957', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "libarchive: Out-of-bounds access in libarchive's archive file handling", 'Description': 'execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-48957', 'https://github.com/libarchive/libarchive/commit/3006bc5d02ad3ae3c4f9274f60c1f9d2d834734b (v3.7.5)', 'https://github.com/libarchive/libarchive/compare/v3.7.4...v3.7.5', 'https://github.com/libarchive/libarchive/pull/2149', 'https://nvd.nist.gov/vuln/detail/CVE-2024-48957', 'https://ubuntu.com/security/notices/USN-7070-1', 'https://www.cve.org/CVERecord?id=CVE-2024-48957'], 'PublishedDate': '2024-10-10T02:15:02.99Z', 'LastModifiedDate': '2024-10-11T21:36:47.93Z'}, {'VulnerabilityID': 'CVE-2024-48958', 'PkgID': 'libarchive13@3.6.0-1ubuntu1.1', 'PkgName': 'libarchive13', 'InstalledVersion': '3.6.0-1ubuntu1.1', 'FixedVersion': '3.6.0-1ubuntu1.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-48958', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "libarchive: Out-of-bounds access in libarchive's RAR file handling", 'Description': 'execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-48958', 'https://github.com/libarchive/libarchive/commit/a1cb648d52f5b6d3f31184d9b6a7cbca628459b7 (v3.7.5)', 'https://github.com/libarchive/libarchive/compare/v3.7.4...v3.7.5', 'https://github.com/libarchive/libarchive/pull/2148', 'https://nvd.nist.gov/vuln/detail/CVE-2024-48958', 'https://ubuntu.com/security/notices/USN-7070-1', 'https://www.cve.org/CVERecord?id=CVE-2024-48958'], 'PublishedDate': '2024-10-10T02:15:03.057Z', 'LastModifiedDate': '2024-10-11T21:36:48.687Z'}, {'VulnerabilityID': 'CVE-2022-36227', 'PkgID': 'libarchive13@3.6.0-1ubuntu1.1', 'PkgName': 'libarchive13', 'InstalledVersion': '3.6.0-1ubuntu1.1', 'FixedVersion': '3.6.0-1ubuntu1.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-36227', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libarchive: NULL pointer dereference in archive_write.c', 'Description': 'In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."', 'Severity': 'LOW', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 9.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:2532', 'https://access.redhat.com/security/cve/CVE-2022-36227', 'https://bugs.gentoo.org/882521', 'https://bugzilla.redhat.com/2144972', 'https://errata.almalinux.org/9/ALSA-2023-2532.html', 'https://github.com/libarchive/libarchive/blob/v3.0.0a/libarchive/archive_write.c#L215', 'https://github.com/libarchive/libarchive/issues/1754', 'https://github.com/libarchive/libarchive/pull/1759', 'https://linux.oracle.com/cve/CVE-2022-36227.html', 'https://linux.oracle.com/errata/ELSA-2023-3018.html', 'https://lists.debian.org/debian-lts-announce/2023/01/msg00034.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-36227', 'https://security.gentoo.org/glsa/202309-14', 'https://ubuntu.com/security/notices/USN-7070-1', 'https://www.cve.org/CVERecord?id=CVE-2022-36227'], 'PublishedDate': '2022-11-22T02:15:11.003Z', 'LastModifiedDate': '2024-03-27T16:04:27.21Z'}, {'VulnerabilityID': 'CVE-2017-13716', 'PkgID': 'libbinutils@2.38-4ubuntu2.6', 'PkgName': 'libbinutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Memory leak with the C++ symbol demangler routine in libiberty', 'Description': 'The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 7.1, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2017-13716', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13716', 'https://sourceware.org/bugzilla/show_bug.cgi?id=22009', 'https://www.cve.org/CVERecord?id=CVE-2017-13716'], 'PublishedDate': '2017-08-28T21:29:00.293Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2018-20657', 'PkgID': 'libbinutils@2.38-4ubuntu2.6', 'PkgName': 'libbinutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-20657', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libiberty: Memory leak in demangle_template function resulting in a denial of service', 'Description': 'The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.', 'Severity': 'LOW', 'CweIDs': ['CWE-772'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/106444', 'https://access.redhat.com/errata/RHSA-2019:3352', 'https://access.redhat.com/security/cve/CVE-2018-20657', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539', 'https://linux.oracle.com/cve/CVE-2018-20657.html', 'https://linux.oracle.com/errata/ELSA-2019-3352.html', 'https://nvd.nist.gov/vuln/detail/CVE-2018-20657', 'https://support.f5.com/csp/article/K62602089', 'https://www.cve.org/CVERecord?id=CVE-2018-20657'], 'PublishedDate': '2019-01-02T14:29:00.313Z', 'LastModifiedDate': '2019-11-06T01:15:17.87Z'}, {'VulnerabilityID': 'CVE-2019-1010204', 'PkgID': 'libbinutils@2.38-4ubuntu2.6', 'PkgName': 'libbinutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-1010204', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service', 'Description': 'GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.', 'Severity': 'LOW', 'CweIDs': ['CWE-125', 'CWE-681'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-1010204', 'https://linux.oracle.com/cve/CVE-2019-1010204.html', 'https://linux.oracle.com/errata/ELSA-2020-1797.html', 'https://nvd.nist.gov/vuln/detail/CVE-2019-1010204', 'https://security.netapp.com/advisory/ntap-20190822-0001/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=23765', 'https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medium=RSS', 'https://ubuntu.com/security/notices/USN-5349-1', 'https://www.cve.org/CVERecord?id=CVE-2019-1010204'], 'PublishedDate': '2019-07-23T14:15:13.373Z', 'LastModifiedDate': '2023-11-07T03:02:17.51Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'libbinutils@2.38-4ubuntu2.6', 'PkgName': 'libbinutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2022-48064', 'PkgID': 'libbinutils@2.38-4ubuntu2.6', 'PkgName': 'libbinutils', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48064', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c', 'Description': 'GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48064', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XKYUAIORNQ32IZUOZFURECZKEXOHX7Z/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KGSKF4GH7425S6XFDQMWTJGD5U47BAZN/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSUNHSOWWLLNGHRM5TUBNCJHEYHPDX2M/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48064', 'https://security.netapp.com/advisory/ntap-20231006-0008/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=29922', 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8f2c64de86bc3d7556121fe296dd679000283931', 'https://www.cve.org/CVERecord?id=CVE-2022-48064'], 'PublishedDate': '2023-08-22T19:16:30.937Z', 'LastModifiedDate': '2023-11-07T03:56:28.11Z'}, {'VulnerabilityID': 'CVE-2016-20013', 'PkgID': 'libc-bin@2.35-0ubuntu3.8', 'PkgName': 'libc-bin', 'InstalledVersion': '2.35-0ubuntu3.8', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-20013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': "sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.", 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}}, 'References': ['https://akkadia.org/drepper/SHA-crypt.txt', 'https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/', 'https://twitter.com/solardiz/status/795601240151457793', 'https://www.cve.org/CVERecord?id=CVE-2016-20013'], 'PublishedDate': '2022-02-19T05:15:09.413Z', 'LastModifiedDate': '2022-03-03T16:43:19.667Z'}, {'VulnerabilityID': 'CVE-2016-20013', 'PkgID': 'libc6@2.35-0ubuntu3.8', 'PkgName': 'libc6', 'InstalledVersion': '2.35-0ubuntu3.8', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-20013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': "sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.", 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}}, 'References': ['https://akkadia.org/drepper/SHA-crypt.txt', 'https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/', 'https://twitter.com/solardiz/status/795601240151457793', 'https://www.cve.org/CVERecord?id=CVE-2016-20013'], 'PublishedDate': '2022-02-19T05:15:09.413Z', 'LastModifiedDate': '2022-03-03T16:43:19.667Z'}, {'VulnerabilityID': 'CVE-2017-13716', 'PkgID': 'libctf-nobfd0@2.38-4ubuntu2.6', 'PkgName': 'libctf-nobfd0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Memory leak with the C++ symbol demangler routine in libiberty', 'Description': 'The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 7.1, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2017-13716', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13716', 'https://sourceware.org/bugzilla/show_bug.cgi?id=22009', 'https://www.cve.org/CVERecord?id=CVE-2017-13716'], 'PublishedDate': '2017-08-28T21:29:00.293Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2018-20657', 'PkgID': 'libctf-nobfd0@2.38-4ubuntu2.6', 'PkgName': 'libctf-nobfd0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-20657', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libiberty: Memory leak in demangle_template function resulting in a denial of service', 'Description': 'The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.', 'Severity': 'LOW', 'CweIDs': ['CWE-772'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/106444', 'https://access.redhat.com/errata/RHSA-2019:3352', 'https://access.redhat.com/security/cve/CVE-2018-20657', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539', 'https://linux.oracle.com/cve/CVE-2018-20657.html', 'https://linux.oracle.com/errata/ELSA-2019-3352.html', 'https://nvd.nist.gov/vuln/detail/CVE-2018-20657', 'https://support.f5.com/csp/article/K62602089', 'https://www.cve.org/CVERecord?id=CVE-2018-20657'], 'PublishedDate': '2019-01-02T14:29:00.313Z', 'LastModifiedDate': '2019-11-06T01:15:17.87Z'}, {'VulnerabilityID': 'CVE-2019-1010204', 'PkgID': 'libctf-nobfd0@2.38-4ubuntu2.6', 'PkgName': 'libctf-nobfd0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-1010204', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service', 'Description': 'GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.', 'Severity': 'LOW', 'CweIDs': ['CWE-125', 'CWE-681'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-1010204', 'https://linux.oracle.com/cve/CVE-2019-1010204.html', 'https://linux.oracle.com/errata/ELSA-2020-1797.html', 'https://nvd.nist.gov/vuln/detail/CVE-2019-1010204', 'https://security.netapp.com/advisory/ntap-20190822-0001/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=23765', 'https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medium=RSS', 'https://ubuntu.com/security/notices/USN-5349-1', 'https://www.cve.org/CVERecord?id=CVE-2019-1010204'], 'PublishedDate': '2019-07-23T14:15:13.373Z', 'LastModifiedDate': '2023-11-07T03:02:17.51Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'libctf-nobfd0@2.38-4ubuntu2.6', 'PkgName': 'libctf-nobfd0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2022-48064', 'PkgID': 'libctf-nobfd0@2.38-4ubuntu2.6', 'PkgName': 'libctf-nobfd0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48064', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c', 'Description': 'GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48064', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XKYUAIORNQ32IZUOZFURECZKEXOHX7Z/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KGSKF4GH7425S6XFDQMWTJGD5U47BAZN/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSUNHSOWWLLNGHRM5TUBNCJHEYHPDX2M/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48064', 'https://security.netapp.com/advisory/ntap-20231006-0008/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=29922', 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8f2c64de86bc3d7556121fe296dd679000283931', 'https://www.cve.org/CVERecord?id=CVE-2022-48064'], 'PublishedDate': '2023-08-22T19:16:30.937Z', 'LastModifiedDate': '2023-11-07T03:56:28.11Z'}, {'VulnerabilityID': 'CVE-2017-13716', 'PkgID': 'libctf0@2.38-4ubuntu2.6', 'PkgName': 'libctf0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Memory leak with the C++ symbol demangler routine in libiberty', 'Description': 'The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 7.1, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2017-13716', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13716', 'https://sourceware.org/bugzilla/show_bug.cgi?id=22009', 'https://www.cve.org/CVERecord?id=CVE-2017-13716'], 'PublishedDate': '2017-08-28T21:29:00.293Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2018-20657', 'PkgID': 'libctf0@2.38-4ubuntu2.6', 'PkgName': 'libctf0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-20657', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libiberty: Memory leak in demangle_template function resulting in a denial of service', 'Description': 'The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.', 'Severity': 'LOW', 'CweIDs': ['CWE-772'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 5, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/106444', 'https://access.redhat.com/errata/RHSA-2019:3352', 'https://access.redhat.com/security/cve/CVE-2018-20657', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539', 'https://linux.oracle.com/cve/CVE-2018-20657.html', 'https://linux.oracle.com/errata/ELSA-2019-3352.html', 'https://nvd.nist.gov/vuln/detail/CVE-2018-20657', 'https://support.f5.com/csp/article/K62602089', 'https://www.cve.org/CVERecord?id=CVE-2018-20657'], 'PublishedDate': '2019-01-02T14:29:00.313Z', 'LastModifiedDate': '2019-11-06T01:15:17.87Z'}, {'VulnerabilityID': 'CVE-2019-1010204', 'PkgID': 'libctf0@2.38-4ubuntu2.6', 'PkgName': 'libctf0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-1010204', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service', 'Description': 'GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.', 'Severity': 'LOW', 'CweIDs': ['CWE-125', 'CWE-681'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-1010204', 'https://linux.oracle.com/cve/CVE-2019-1010204.html', 'https://linux.oracle.com/errata/ELSA-2020-1797.html', 'https://nvd.nist.gov/vuln/detail/CVE-2019-1010204', 'https://security.netapp.com/advisory/ntap-20190822-0001/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=23765', 'https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medium=RSS', 'https://ubuntu.com/security/notices/USN-5349-1', 'https://www.cve.org/CVERecord?id=CVE-2019-1010204'], 'PublishedDate': '2019-07-23T14:15:13.373Z', 'LastModifiedDate': '2023-11-07T03:02:17.51Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'libctf0@2.38-4ubuntu2.6', 'PkgName': 'libctf0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2022-48064', 'PkgID': 'libctf0@2.38-4ubuntu2.6', 'PkgName': 'libctf0', 'InstalledVersion': '2.38-4ubuntu2.6', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48064', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c', 'Description': 'GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48064', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XKYUAIORNQ32IZUOZFURECZKEXOHX7Z/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KGSKF4GH7425S6XFDQMWTJGD5U47BAZN/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSUNHSOWWLLNGHRM5TUBNCJHEYHPDX2M/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48064', 'https://security.netapp.com/advisory/ntap-20231006-0008/', 'https://sourceware.org/bugzilla/show_bug.cgi?id=29922', 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8f2c64de86bc3d7556121fe296dd679000283931', 'https://www.cve.org/CVERecord?id=CVE-2022-48064'], 'PublishedDate': '2023-08-22T19:16:30.937Z', 'LastModifiedDate': '2023-11-07T03:56:28.11Z'}, {'VulnerabilityID': 'CVE-2023-34969', 'PkgID': 'libdbus-1-3@1.12.20-2ubuntu4.1', 'PkgName': 'libdbus-1-3', 'InstalledVersion': '1.12.20-2ubuntu4.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-34969', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered', 'Description': 'D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.2}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:4569', 'https://access.redhat.com/security/cve/CVE-2023-34969', 'https://bugzilla.redhat.com/2213166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2213166', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34969', 'https://errata.almalinux.org/9/ALSA-2023-4569.html', 'https://errata.rockylinux.org/RLSA-2023:4569', 'https://gitlab.freedesktop.org/dbus/dbus/-/issues/457', 'https://linux.oracle.com/cve/CVE-2023-34969.html', 'https://linux.oracle.com/errata/ELSA-2023-4569.html', 'https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-34969', 'https://security.netapp.com/advisory/ntap-20231208-0007/', 'https://ubuntu.com/security/notices/USN-6372-1', 'https://www.cve.org/CVERecord?id=CVE-2023-34969'], 'PublishedDate': '2023-06-08T03:15:08.97Z', 'LastModifiedDate': '2023-12-27T16:36:58.353Z'}, {'VulnerabilityID': 'CVE-2022-3287', 'PkgID': 'libfwupd2@1.7.9-1~22.04.3', 'PkgName': 'libfwupd2', 'InstalledVersion': '1.7.9-1~22.04.3', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3287', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'fwupd: world readable password in /etc/fwupd/redfish.conf', 'Description': 'When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.', 'Severity': 'LOW', 'CweIDs': ['CWE-552', 'CWE-256'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:2487', 'https://access.redhat.com/security/cve/CVE-2022-3287', 'https://bugzilla.redhat.com/2120687', 'https://bugzilla.redhat.com/2120699', 'https://bugzilla.redhat.com/2120701', 'https://bugzilla.redhat.com/2129904', 'https://bugzilla.redhat.com/show_bug.cgi?id=2129904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3287', 'https://errata.almalinux.org/9/ALSA-2023-2487.html', 'https://errata.rockylinux.org/RLSA-2023:7189', 'https://github.com/fwupd/fwupd/commit/ea676855f2119e36d433fbd2ed604039f53b2091', 'https://linux.oracle.com/cve/CVE-2022-3287.html', 'https://linux.oracle.com/errata/ELSA-2023-7189.html', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3287', 'https://www.cve.org/CVERecord?id=CVE-2022-3287'], 'PublishedDate': '2022-09-28T20:15:18.433Z', 'LastModifiedDate': '2023-11-07T03:51:04.06Z'}, {'VulnerabilityID': 'CVE-2022-3287', 'PkgID': 'libfwupdplugin5@1.7.9-1~22.04.3', 'PkgName': 'libfwupdplugin5', 'InstalledVersion': '1.7.9-1~22.04.3', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3287', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'fwupd: world readable password in /etc/fwupd/redfish.conf', 'Description': 'When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.', 'Severity': 'LOW', 'CweIDs': ['CWE-552', 'CWE-256'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:2487', 'https://access.redhat.com/security/cve/CVE-2022-3287', 'https://bugzilla.redhat.com/2120687', 'https://bugzilla.redhat.com/2120699', 'https://bugzilla.redhat.com/2120701', 'https://bugzilla.redhat.com/2129904', 'https://bugzilla.redhat.com/show_bug.cgi?id=2129904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3287', 'https://errata.almalinux.org/9/ALSA-2023-2487.html', 'https://errata.rockylinux.org/RLSA-2023:7189', 'https://github.com/fwupd/fwupd/commit/ea676855f2119e36d433fbd2ed604039f53b2091', 'https://linux.oracle.com/cve/CVE-2022-3287.html', 'https://linux.oracle.com/errata/ELSA-2023-7189.html', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3287', 'https://www.cve.org/CVERecord?id=CVE-2022-3287'], 'PublishedDate': '2022-09-28T20:15:18.433Z', 'LastModifiedDate': '2023-11-07T03:51:04.06Z'}, {'VulnerabilityID': 'CVE-2023-4039', 'PkgID': 'libgcc-s1@12.3.0-1ubuntu1~22.04', 'PkgName': 'libgcc-s1', 'InstalledVersion': '12.3.0-1ubuntu1~22.04', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-4039', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64', 'Description': '\n\n**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains \nthat target AArch64 allows an attacker to exploit an existing buffer \noverflow in dynamically-sized local variables in your application \nwithout this being detected. This stack-protector failure only applies \nto C99-style dynamically-sized local variables or those created using \nalloca(). The stack-protector operates as intended for statically-sized \nlocal variables.\n\nThe default behavior when the stack-protector \ndetects an overflow is to terminate your application, resulting in \ncontrolled loss of availability. An attacker who can exploit a buffer \noverflow without triggering the stack-protector might be able to change \nprogram flow control to cause an uncontrolled loss of availability or to\n go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.\n\n\n\n\n\n', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-693'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-4039', 'https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64', 'https://gcc.gnu.org/git/?p=gcc.git;a=blob_plain;f=SECURITY.txt', 'https://gcc.gnu.org/pipermail/gcc-patches/2023-October/634066.html', 'https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-x7ch-h5rf-w2mf', 'https://inbox.sourceware.org/gcc-patches/46cfa37b-56eb-344d-0745-e0d35393392d@gotplt.org', 'https://linux.oracle.com/cve/CVE-2023-4039.html', 'https://linux.oracle.com/errata/ELSA-2023-28766.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-4039', 'https://rtx.meta.security/mitigation/2023/09/12/CVE-2023-4039.html', 'https://www.cve.org/CVERecord?id=CVE-2023-4039'], 'PublishedDate': '2023-09-13T09:15:15.69Z', 'LastModifiedDate': '2024-08-02T08:15:14.993Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'libgcc-s1@12.3.0-1ubuntu1~22.04', 'PkgName': 'libgcc-s1', 'InstalledVersion': '12.3.0-1ubuntu1~22.04', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2024-2236', 'PkgID': 'libgcrypt20@1.9.4-3ubuntu3', 'PkgName': 'libgcrypt20', 'InstalledVersion': '1.9.4-3ubuntu3', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-2236', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libgcrypt: vulnerable to Marvin Attack', 'Description': "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-208'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-2236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2245218', 'https://dev.gnupg.org/T7136', 'https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt', 'https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17', 'https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-2236', 'https://www.cve.org/CVERecord?id=CVE-2024-2236'], 'PublishedDate': '2024-03-06T22:15:57.977Z', 'LastModifiedDate': '2024-09-14T04:15:02.903Z'}, {'VulnerabilityID': 'CVE-2024-26462', 'PkgID': 'libgssapi-krb5-2@1.19.2-2ubuntu0.4', 'PkgName': 'libgssapi-krb5-2', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26462', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/kdc/ndr.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26462', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_3.md', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26462', 'https://security.netapp.com/advisory/ntap-20240415-0012/', 'https://www.cve.org/CVERecord?id=CVE-2024-26462'], 'PublishedDate': '2024-02-29T01:44:18.857Z', 'LastModifiedDate': '2024-05-14T15:09:01.053Z'}, {'VulnerabilityID': 'CVE-2024-26458', 'PkgID': 'libgssapi-krb5-2@1.19.2-2ubuntu0.4', 'PkgName': 'libgssapi-krb5-2', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26458', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26458', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md', 'https://linux.oracle.com/cve/CVE-2024-26458.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26458', 'https://security.netapp.com/advisory/ntap-20240415-0010/', 'https://www.cve.org/CVERecord?id=CVE-2024-26458'], 'PublishedDate': '2024-02-29T01:44:18.78Z', 'LastModifiedDate': '2024-05-14T15:09:00.47Z'}, {'VulnerabilityID': 'CVE-2024-26461', 'PkgID': 'libgssapi-krb5-2@1.19.2-2ubuntu0.4', 'PkgName': 'libgssapi-krb5-2', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26461', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26461', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md', 'https://linux.oracle.com/cve/CVE-2024-26461.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26461', 'https://security.netapp.com/advisory/ntap-20240415-0011/', 'https://www.cve.org/CVERecord?id=CVE-2024-26461'], 'PublishedDate': '2024-02-29T01:44:18.82Z', 'LastModifiedDate': '2024-08-14T16:35:10.207Z'}, {'VulnerabilityID': 'CVE-2024-26462', 'PkgID': 'libk5crypto3@1.19.2-2ubuntu0.4', 'PkgName': 'libk5crypto3', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26462', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/kdc/ndr.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26462', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_3.md', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26462', 'https://security.netapp.com/advisory/ntap-20240415-0012/', 'https://www.cve.org/CVERecord?id=CVE-2024-26462'], 'PublishedDate': '2024-02-29T01:44:18.857Z', 'LastModifiedDate': '2024-05-14T15:09:01.053Z'}, {'VulnerabilityID': 'CVE-2024-26458', 'PkgID': 'libk5crypto3@1.19.2-2ubuntu0.4', 'PkgName': 'libk5crypto3', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26458', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26458', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md', 'https://linux.oracle.com/cve/CVE-2024-26458.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26458', 'https://security.netapp.com/advisory/ntap-20240415-0010/', 'https://www.cve.org/CVERecord?id=CVE-2024-26458'], 'PublishedDate': '2024-02-29T01:44:18.78Z', 'LastModifiedDate': '2024-05-14T15:09:00.47Z'}, {'VulnerabilityID': 'CVE-2024-26461', 'PkgID': 'libk5crypto3@1.19.2-2ubuntu0.4', 'PkgName': 'libk5crypto3', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26461', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26461', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md', 'https://linux.oracle.com/cve/CVE-2024-26461.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26461', 'https://security.netapp.com/advisory/ntap-20240415-0011/', 'https://www.cve.org/CVERecord?id=CVE-2024-26461'], 'PublishedDate': '2024-02-29T01:44:18.82Z', 'LastModifiedDate': '2024-08-14T16:35:10.207Z'}, {'VulnerabilityID': 'CVE-2024-26462', 'PkgID': 'libkrb5-3@1.19.2-2ubuntu0.4', 'PkgName': 'libkrb5-3', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26462', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/kdc/ndr.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26462', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_3.md', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26462', 'https://security.netapp.com/advisory/ntap-20240415-0012/', 'https://www.cve.org/CVERecord?id=CVE-2024-26462'], 'PublishedDate': '2024-02-29T01:44:18.857Z', 'LastModifiedDate': '2024-05-14T15:09:01.053Z'}, {'VulnerabilityID': 'CVE-2024-26458', 'PkgID': 'libkrb5-3@1.19.2-2ubuntu0.4', 'PkgName': 'libkrb5-3', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26458', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26458', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md', 'https://linux.oracle.com/cve/CVE-2024-26458.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26458', 'https://security.netapp.com/advisory/ntap-20240415-0010/', 'https://www.cve.org/CVERecord?id=CVE-2024-26458'], 'PublishedDate': '2024-02-29T01:44:18.78Z', 'LastModifiedDate': '2024-05-14T15:09:00.47Z'}, {'VulnerabilityID': 'CVE-2024-26461', 'PkgID': 'libkrb5-3@1.19.2-2ubuntu0.4', 'PkgName': 'libkrb5-3', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26461', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26461', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md', 'https://linux.oracle.com/cve/CVE-2024-26461.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26461', 'https://security.netapp.com/advisory/ntap-20240415-0011/', 'https://www.cve.org/CVERecord?id=CVE-2024-26461'], 'PublishedDate': '2024-02-29T01:44:18.82Z', 'LastModifiedDate': '2024-08-14T16:35:10.207Z'}, {'VulnerabilityID': 'CVE-2024-26462', 'PkgID': 'libkrb5support0@1.19.2-2ubuntu0.4', 'PkgName': 'libkrb5support0', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26462', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/kdc/ndr.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26462', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_3.md', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26462', 'https://security.netapp.com/advisory/ntap-20240415-0012/', 'https://www.cve.org/CVERecord?id=CVE-2024-26462'], 'PublishedDate': '2024-02-29T01:44:18.857Z', 'LastModifiedDate': '2024-05-14T15:09:01.053Z'}, {'VulnerabilityID': 'CVE-2024-26458', 'PkgID': 'libkrb5support0@1.19.2-2ubuntu0.4', 'PkgName': 'libkrb5support0', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26458', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26458', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md', 'https://linux.oracle.com/cve/CVE-2024-26458.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26458', 'https://security.netapp.com/advisory/ntap-20240415-0010/', 'https://www.cve.org/CVERecord?id=CVE-2024-26458'], 'PublishedDate': '2024-02-29T01:44:18.78Z', 'LastModifiedDate': '2024-05-14T15:09:00.47Z'}, {'VulnerabilityID': 'CVE-2024-26461', 'PkgID': 'libkrb5support0@1.19.2-2ubuntu0.4', 'PkgName': 'libkrb5support0', 'InstalledVersion': '1.19.2-2ubuntu0.4', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26461', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c', 'Description': 'Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.', 'Severity': 'LOW', 'CweIDs': ['CWE-770'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:3268', 'https://access.redhat.com/security/cve/CVE-2024-26461', 'https://bugzilla.redhat.com/2266731', 'https://bugzilla.redhat.com/2266740', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266731', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26458', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26461', 'https://errata.almalinux.org/8/ALSA-2024-3268.html', 'https://errata.rockylinux.org/RLSA-2024:3268', 'https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md', 'https://linux.oracle.com/cve/CVE-2024-26461.html', 'https://linux.oracle.com/errata/ELSA-2024-3268.html', 'https://mailman.mit.edu/pipermail/kerberos/2024-March/023095.html', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26461', 'https://security.netapp.com/advisory/ntap-20240415-0011/', 'https://www.cve.org/CVERecord?id=CVE-2024-26461'], 'PublishedDate': '2024-02-29T01:44:18.82Z', 'LastModifiedDate': '2024-08-14T16:35:10.207Z'}, {'VulnerabilityID': 'CVE-2023-45918', 'PkgID': 'libncurses6@6.3-2ubuntu0.1', 'PkgName': 'libncurses6', 'InstalledVersion': '6.3-2ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-45918', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c', 'Description': 'ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-45918', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-45918', 'https://security.netapp.com/advisory/ntap-20240315-0006/', 'https://www.cve.org/CVERecord?id=CVE-2023-45918'], 'PublishedDate': '2024-02-16T22:15:07.88Z', 'LastModifiedDate': '2024-03-15T11:15:08.51Z'}, {'VulnerabilityID': 'CVE-2023-50495', 'PkgID': 'libncurses6@6.3-2ubuntu0.1', 'PkgName': 'libncurses6', 'InstalledVersion': '6.3-2ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-50495', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'ncurses: segmentation fault via _nc_wrap_entry()', 'Description': 'NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-50495', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-50495', 'https://security.netapp.com/advisory/ntap-20240119-0008/', 'https://ubuntu.com/security/notices/USN-6684-1', 'https://www.cve.org/CVERecord?id=CVE-2023-50495'], 'PublishedDate': '2023-12-12T15:15:07.867Z', 'LastModifiedDate': '2024-01-31T03:15:08.49Z'}, {'VulnerabilityID': 'CVE-2023-45918', 'PkgID': 'libncursesw6@6.3-2ubuntu0.1', 'PkgName': 'libncursesw6', 'InstalledVersion': '6.3-2ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-45918', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c', 'Description': 'ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-45918', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-45918', 'https://security.netapp.com/advisory/ntap-20240315-0006/', 'https://www.cve.org/CVERecord?id=CVE-2023-45918'], 'PublishedDate': '2024-02-16T22:15:07.88Z', 'LastModifiedDate': '2024-03-15T11:15:08.51Z'}, {'VulnerabilityID': 'CVE-2023-50495', 'PkgID': 'libncursesw6@6.3-2ubuntu0.1', 'PkgName': 'libncursesw6', 'InstalledVersion': '6.3-2ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-50495', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'ncurses: segmentation fault via _nc_wrap_entry()', 'Description': 'NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-50495', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-50495', 'https://security.netapp.com/advisory/ntap-20240119-0008/', 'https://ubuntu.com/security/notices/USN-6684-1', 'https://www.cve.org/CVERecord?id=CVE-2023-50495'], 'PublishedDate': '2023-12-12T15:15:07.867Z', 'LastModifiedDate': '2024-01-31T03:15:08.49Z'}, {'VulnerabilityID': 'CVE-2023-7008', 'PkgID': 'libnss-systemd@249.11-0ubuntu3.12', 'PkgName': 'libnss-systemd', 'InstalledVersion': '249.11-0ubuntu3.12', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-7008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes', 'Description': 'A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.', 'Severity': 'LOW', 'CweIDs': ['CWE-300'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:2463', 'https://access.redhat.com/errata/RHSA-2024:3203', 'https://access.redhat.com/security/cve/CVE-2023-7008', 'https://bugzilla.redhat.com/2222672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222261', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222672', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7008', 'https://errata.almalinux.org/9/ALSA-2024-2463.html', 'https://errata.rockylinux.org/RLSA-2024:2463', 'https://github.com/systemd/systemd/issues/25676', 'https://linux.oracle.com/cve/CVE-2023-7008.html', 'https://linux.oracle.com/errata/ELSA-2024-3203.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-7008', 'https://www.cve.org/CVERecord?id=CVE-2023-7008'], 'PublishedDate': '2023-12-23T13:15:07.573Z', 'LastModifiedDate': '2024-09-16T17:16:02.17Z'}, {'VulnerabilityID': 'CVE-2023-52890', 'PkgID': 'libntfs-3g89@1:2021.8.22-3ubuntu1.2', 'PkgName': 'libntfs-3g89', 'InstalledVersion': '1:2021.8.22-3ubuntu1.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52890', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in l ...', 'Description': 'NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.', 'Severity': 'LOW', 'References': ['https://github.com/tuxera/ntfs-3g/issues/84', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52890', 'https://www.cve.org/CVERecord?id=CVE-2023-52890'], 'PublishedDate': '2024-06-13T04:15:15.92Z', 'LastModifiedDate': '2024-06-13T18:36:09.01Z'}, {'VulnerabilityID': 'CVE-2023-7008', 'PkgID': 'libpam-systemd@249.11-0ubuntu3.12', 'PkgName': 'libpam-systemd', 'InstalledVersion': '249.11-0ubuntu3.12', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-7008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes', 'Description': 'A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.', 'Severity': 'LOW', 'CweIDs': ['CWE-300'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:2463', 'https://access.redhat.com/errata/RHSA-2024:3203', 'https://access.redhat.com/security/cve/CVE-2023-7008', 'https://bugzilla.redhat.com/2222672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222261', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222672', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7008', 'https://errata.almalinux.org/9/ALSA-2024-2463.html', 'https://errata.rockylinux.org/RLSA-2024:2463', 'https://github.com/systemd/systemd/issues/25676', 'https://linux.oracle.com/cve/CVE-2023-7008.html', 'https://linux.oracle.com/errata/ELSA-2024-3203.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-7008', 'https://www.cve.org/CVERecord?id=CVE-2023-7008'], 'PublishedDate': '2023-12-23T13:15:07.573Z', 'LastModifiedDate': '2024-09-16T17:16:02.17Z'}, {'VulnerabilityID': 'CVE-2022-41409', 'PkgID': 'libpcre2-8-0@10.39-3ubuntu0.1', 'PkgName': 'libpcre2-8-0', 'InstalledVersion': '10.39-3ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-41409', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop', 'Description': 'Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.', 'Severity': 'LOW', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-41409', 'https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35', 'https://github.com/PCRE2Project/pcre2/issues/141', 'https://github.com/advisories/GHSA-4qfx-v7wh-3q4j', 'https://nvd.nist.gov/vuln/detail/CVE-2022-41409', 'https://www.cve.org/CVERecord?id=CVE-2022-41409'], 'PublishedDate': '2023-07-18T14:15:12.197Z', 'LastModifiedDate': '2023-07-27T03:46:09.807Z'}, {'VulnerabilityID': 'CVE-2017-11164', 'PkgID': 'libpcre3@2:8.39-13ubuntu0.22.04.1', 'PkgName': 'libpcre3', 'InstalledVersion': '2:8.39-13ubuntu0.22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-11164', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'pcre: OP_KETRMAX feature in the match function in pcre_exec.c', 'Description': 'In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 7.8, 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['http://openwall.com/lists/oss-security/2017/07/11/3', 'http://www.openwall.com/lists/oss-security/2023/04/11/1', 'http://www.openwall.com/lists/oss-security/2023/04/12/1', 'http://www.securityfocus.com/bid/99575', 'https://access.redhat.com/security/cve/CVE-2017-11164', 'https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E', 'https://nvd.nist.gov/vuln/detail/CVE-2017-11164', 'https://www.cve.org/CVERecord?id=CVE-2017-11164'], 'PublishedDate': '2017-07-11T03:29:00.277Z', 'LastModifiedDate': '2023-11-07T02:38:10.98Z'}, {'VulnerabilityID': 'CVE-2022-3857', 'PkgID': 'libpng16-16@1.6.37-3build5', 'PkgName': 'libpng16-16', 'InstalledVersion': '1.6.37-3build5', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3857', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'libpng: Null pointer dereference leads to segmentation fault', 'Description': 'Rejected reason: Maintainer contacted. This is a false-positive. The flaw does not actually exist and was erroneously tested.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3857', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3857', 'https://sourceforge.net/p/libpng/bugs/300/', 'https://www.cve.org/CVERecord?id=CVE-2022-3857'], 'PublishedDate': '2023-03-06T23:15:11.087Z', 'LastModifiedDate': '2024-10-09T04:15:06.567Z'}, {'VulnerabilityID': 'CVE-2016-2568', 'PkgID': 'libpolkit-agent-1-0@0.105-33', 'PkgName': 'libpolkit-agent-1-0', 'InstalledVersion': '0.105-33', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-2568', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'polkit: Program run via pkexec as unprivileged user can escape to parent session via TIOCSTI ioctl', 'Description': "pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.", 'Severity': 'LOW', 'CweIDs': ['CWE-116'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'V2Score': 4.4, 'V3Score': 7.8}, 'redhat': {'V2Vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L', 'V2Score': 5.1, 'V3Score': 6.1}}, 'References': ['http://seclists.org/oss-sec/2016/q1/443', 'http://www.openwall.com/lists/oss-security/2016/02/26/3', 'https://access.redhat.com/security/cve/CVE-2016-2568', 'https://access.redhat.com/security/cve/cve-2016-2568', 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816062', 'https://bugzilla.redhat.com/show_bug.cgi?id=1300746', 'https://lore.kernel.org/patchwork/patch/793178/', 'https://nvd.nist.gov/vuln/detail/CVE-2016-2568', 'https://ubuntu.com/security/CVE-2016-2568', 'https://www.cve.org/CVERecord?id=CVE-2016-2568'], 'PublishedDate': '2017-02-13T18:59:00.393Z', 'LastModifiedDate': '2022-04-18T17:59:06.053Z'}, {'VulnerabilityID': 'CVE-2016-2568', 'PkgID': 'libpolkit-gobject-1-0@0.105-33', 'PkgName': 'libpolkit-gobject-1-0', 'InstalledVersion': '0.105-33', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-2568', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'polkit: Program run via pkexec as unprivileged user can escape to parent session via TIOCSTI ioctl', 'Description': "pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.", 'Severity': 'LOW', 'CweIDs': ['CWE-116'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'V2Score': 4.4, 'V3Score': 7.8}, 'redhat': {'V2Vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L', 'V2Score': 5.1, 'V3Score': 6.1}}, 'References': ['http://seclists.org/oss-sec/2016/q1/443', 'http://www.openwall.com/lists/oss-security/2016/02/26/3', 'https://access.redhat.com/security/cve/CVE-2016-2568', 'https://access.redhat.com/security/cve/cve-2016-2568', 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816062', 'https://bugzilla.redhat.com/show_bug.cgi?id=1300746', 'https://lore.kernel.org/patchwork/patch/793178/', 'https://nvd.nist.gov/vuln/detail/CVE-2016-2568', 'https://ubuntu.com/security/CVE-2016-2568', 'https://www.cve.org/CVERecord?id=CVE-2016-2568'], 'PublishedDate': '2017-02-13T18:59:00.393Z', 'LastModifiedDate': '2022-04-18T17:59:06.053Z'}, {'VulnerabilityID': 'CVE-2024-41996', 'PkgID': 'libssl3@3.0.2-0ubuntu1.18', 'PkgName': 'libssl3', 'InstalledVersion': '3.0.2-0ubuntu1.18', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41996', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations', 'Description': 'Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.', 'Severity': 'LOW', 'CweIDs': ['CWE-295'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41996', 'https://dheatattack.gitlab.io/details/', 'https://dheatattack.gitlab.io/faq/', 'https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1', 'https://github.com/openssl/openssl/issues/17374', 'https://github.com/openssl/openssl/pull/25088', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41996', 'https://openssl-library.org/post/2022-10-21-tls-groups-configuration/', 'https://www.cve.org/CVERecord?id=CVE-2024-41996'], 'PublishedDate': '2024-08-26T06:15:04.603Z', 'LastModifiedDate': '2024-08-26T16:35:11.247Z'}, {'VulnerabilityID': 'CVE-2023-4039', 'PkgID': 'libstdc++6@12.3.0-1ubuntu1~22.04', 'PkgName': 'libstdc++6', 'InstalledVersion': '12.3.0-1ubuntu1~22.04', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-4039', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64', 'Description': '\n\n**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains \nthat target AArch64 allows an attacker to exploit an existing buffer \noverflow in dynamically-sized local variables in your application \nwithout this being detected. This stack-protector failure only applies \nto C99-style dynamically-sized local variables or those created using \nalloca(). The stack-protector operates as intended for statically-sized \nlocal variables.\n\nThe default behavior when the stack-protector \ndetects an overflow is to terminate your application, resulting in \ncontrolled loss of availability. An attacker who can exploit a buffer \noverflow without triggering the stack-protector might be able to change \nprogram flow control to cause an uncontrolled loss of availability or to\n go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.\n\n\n\n\n\n', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-693'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-4039', 'https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64', 'https://gcc.gnu.org/git/?p=gcc.git;a=blob_plain;f=SECURITY.txt', 'https://gcc.gnu.org/pipermail/gcc-patches/2023-October/634066.html', 'https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-x7ch-h5rf-w2mf', 'https://inbox.sourceware.org/gcc-patches/46cfa37b-56eb-344d-0745-e0d35393392d@gotplt.org', 'https://linux.oracle.com/cve/CVE-2023-4039.html', 'https://linux.oracle.com/errata/ELSA-2023-28766.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-4039', 'https://rtx.meta.security/mitigation/2023/09/12/CVE-2023-4039.html', 'https://www.cve.org/CVERecord?id=CVE-2023-4039'], 'PublishedDate': '2023-09-13T09:15:15.69Z', 'LastModifiedDate': '2024-08-02T08:15:14.993Z'}, {'VulnerabilityID': 'CVE-2022-27943', 'PkgID': 'libstdc++6@12.3.0-1ubuntu1~22.04', 'PkgName': 'libstdc++6', 'InstalledVersion': '12.3.0-1ubuntu1~22.04', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-27943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const', 'Description': 'libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.', 'Severity': 'LOW', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V2Score': 4.3, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-27943', 'https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79', 'https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead', 'https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-27943', 'https://sourceware.org/bugzilla/show_bug.cgi?id=28995', 'https://www.cve.org/CVERecord?id=CVE-2022-27943'], 'PublishedDate': '2022-03-26T13:15:07.9Z', 'LastModifiedDate': '2023-11-07T03:45:32.64Z'}, {'VulnerabilityID': 'CVE-2023-7008', 'PkgID': 'libsystemd0@249.11-0ubuntu3.12', 'PkgName': 'libsystemd0', 'InstalledVersion': '249.11-0ubuntu3.12', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-7008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes', 'Description': 'A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.', 'Severity': 'LOW', 'CweIDs': ['CWE-300'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:2463', 'https://access.redhat.com/errata/RHSA-2024:3203', 'https://access.redhat.com/security/cve/CVE-2023-7008', 'https://bugzilla.redhat.com/2222672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222261', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222672', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7008', 'https://errata.almalinux.org/9/ALSA-2024-2463.html', 'https://errata.rockylinux.org/RLSA-2024:2463', 'https://github.com/systemd/systemd/issues/25676', 'https://linux.oracle.com/cve/CVE-2023-7008.html', 'https://linux.oracle.com/errata/ELSA-2024-3203.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-7008', 'https://www.cve.org/CVERecord?id=CVE-2023-7008'], 'PublishedDate': '2023-12-23T13:15:07.573Z', 'LastModifiedDate': '2024-09-16T17:16:02.17Z'}, {'VulnerabilityID': 'CVE-2023-45918', 'PkgID': 'libtinfo6@6.3-2ubuntu0.1', 'PkgName': 'libtinfo6', 'InstalledVersion': '6.3-2ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-45918', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c', 'Description': 'ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c.', 'Severity': 'LOW', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-45918', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-45918', 'https://security.netapp.com/advisory/ntap-20240315-0006/', 'https://www.cve.org/CVERecord?id=CVE-2023-45918'], 'PublishedDate': '2024-02-16T22:15:07.88Z', 'LastModifiedDate': '2024-03-15T11:15:08.51Z'}, {'VulnerabilityID': 'CVE-2023-50495', 'PkgID': 'libtinfo6@6.3-2ubuntu0.1', 'PkgName': 'libtinfo6', 'InstalledVersion': '6.3-2ubuntu0.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-50495', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'ncurses: segmentation fault via _nc_wrap_entry()', 'Description': 'NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().', 'Severity': 'LOW', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-50495', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html', 'https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-50495', 'https://security.netapp.com/advisory/ntap-20240119-0008/', 'https://ubuntu.com/security/notices/USN-6684-1', 'https://www.cve.org/CVERecord?id=CVE-2023-50495'], 'PublishedDate': '2023-12-12T15:15:07.867Z', 'LastModifiedDate': '2024-01-31T03:15:08.49Z'}, {'VulnerabilityID': 'CVE-2023-7008', 'PkgID': 'libudev1@249.11-0ubuntu3.12', 'PkgName': 'libudev1', 'InstalledVersion': '249.11-0ubuntu3.12', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-7008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes', 'Description': 'A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.', 'Severity': 'LOW', 'CweIDs': ['CWE-300'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:2463', 'https://access.redhat.com/errata/RHSA-2024:3203', 'https://access.redhat.com/security/cve/CVE-2023-7008', 'https://bugzilla.redhat.com/2222672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222261', 'https://bugzilla.redhat.com/show_bug.cgi?id=2222672', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7008', 'https://errata.almalinux.org/9/ALSA-2024-2463.html', 'https://errata.rockylinux.org/RLSA-2024:2463', 'https://github.com/systemd/systemd/issues/25676', 'https://linux.oracle.com/cve/CVE-2023-7008.html', 'https://linux.oracle.com/errata/ELSA-2024-3203.html', 'https://nvd.nist.gov/vuln/detail/CVE-2023-7008', 'https://www.cve.org/CVERecord?id=CVE-2023-7008'], 'PublishedDate': '2023-12-23T13:15:07.573Z', 'LastModifiedDate': '2024-09-16T17:16:02.17Z'}, {'VulnerabilityID': 'CVE-2022-4899', 'PkgID': 'libzstd1@1.4.8+dfsg-3build1', 'PkgName': 'libzstd1', 'InstalledVersion': '1.4.8+dfsg-3build1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-4899', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'zstd: mysql: buffer overrun in util.c', 'Description': 'A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.', 'Severity': 'LOW', 'CweIDs': ['CWE-400'], 'CVSS': {'ghsa': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}, 'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:1141', 'https://access.redhat.com/security/cve/CVE-2022-4899', 'https://bugzilla.redhat.com/2179864', 'https://bugzilla.redhat.com/2188109', 'https://bugzilla.redhat.com/2188113', 'https://bugzilla.redhat.com/2188115', 'https://bugzilla.redhat.com/2188116', 'https://bugzilla.redhat.com/2188117', 'https://bugzilla.redhat.com/2188118', 'https://bugzilla.redhat.com/2188119', 'https://bugzilla.redhat.com/2188120', 'https://bugzilla.redhat.com/2188121', 'https://bugzilla.redhat.com/2188122', 'https://bugzilla.redhat.com/2188123', 'https://bugzilla.redhat.com/2188124', 'https://bugzilla.redhat.com/2188125', 'https://bugzilla.redhat.com/2188127', 'https://bugzilla.redhat.com/2188128', 'https://bugzilla.redhat.com/2188129', 'https://bugzilla.redhat.com/2188130', 'https://bugzilla.redhat.com/2188131', 'https://bugzilla.redhat.com/2188132', 'https://bugzilla.redhat.com/2224211', 'https://bugzilla.redhat.com/2224212', 'https://bugzilla.redhat.com/2224213', 'https://bugzilla.redhat.com/2224214', 'https://bugzilla.redhat.com/2224215', 'https://bugzilla.redhat.com/2224216', 'https://bugzilla.redhat.com/2224217', 'https://bugzilla.redhat.com/2224218', 'https://bugzilla.redhat.com/2224219', 'https://bugzilla.redhat.com/2224220', 'https://bugzilla.redhat.com/2224221', 'https://bugzilla.redhat.com/2224222', 'https://bugzilla.redhat.com/2245014', 'https://bugzilla.redhat.com/2245015', 'https://bugzilla.redhat.com/2245016', 'https://bugzilla.redhat.com/2245017', 'https://bugzilla.redhat.com/2245018', 'https://bugzilla.redhat.com/2245019', 'https://bugzilla.redhat.com/2245020', 'https://bugzilla.redhat.com/2245021', 'https://bugzilla.redhat.com/2245022', 'https://bugzilla.redhat.com/2245023', 'https://bugzilla.redhat.com/2245024', 'https://bugzilla.redhat.com/2245026', 'https://bugzilla.redhat.com/2245027', 'https://bugzilla.redhat.com/2245028', 'https://bugzilla.redhat.com/2245029', 'https://bugzilla.redhat.com/2245030', 'https://bugzilla.redhat.com/2245031', 'https://bugzilla.redhat.com/2245032', 'https://bugzilla.redhat.com/2245033', 'https://bugzilla.redhat.com/2245034', 'https://bugzilla.redhat.com/2258771', 'https://bugzilla.redhat.com/2258772', 'https://bugzilla.redhat.com/2258773', 'https://bugzilla.redhat.com/2258774', 'https://bugzilla.redhat.com/2258775', 'https://bugzilla.redhat.com/2258776', 'https://bugzilla.redhat.com/2258777', 'https://bugzilla.redhat.com/2258778', 'https://bugzilla.redhat.com/2258779', 'https://bugzilla.redhat.com/2258780', 'https://bugzilla.redhat.com/2258781', 'https://bugzilla.redhat.com/2258782', 'https://bugzilla.redhat.com/2258783', 'https://bugzilla.redhat.com/2258784', 'https://bugzilla.redhat.com/2258785', 'https://bugzilla.redhat.com/2258787', 'https://bugzilla.redhat.com/2258788', 'https://bugzilla.redhat.com/2258789', 'https://bugzilla.redhat.com/2258790', 'https://bugzilla.redhat.com/2258791', 'https://bugzilla.redhat.com/2258792', 'https://bugzilla.redhat.com/2258793', 'https://bugzilla.redhat.com/2258794', 'https://errata.almalinux.org/9/ALSA-2024-1141.html', 'https://github.com/facebook/zstd', 'https://github.com/facebook/zstd/issues/3200', 'https://github.com/facebook/zstd/pull/3220', 'https://github.com/pypa/advisory-database/tree/main/vulns/zstd/PYSEC-2023-121.yaml', 'https://github.com/sergey-dryabzhinsky/python-zstd/commit/c8a619aebdbd6b838fbfef6e19325a70f631a4c6', 'https://linux.oracle.com/cve/CVE-2022-4899.html', 'https://linux.oracle.com/errata/ELSA-2024-1141.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/', 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2', 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA', 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN', 'https://nvd.nist.gov/vuln/detail/CVE-2022-4899', 'https://security.netapp.com/advisory/ntap-20230725-0005', 'https://security.netapp.com/advisory/ntap-20230725-0005/', 'https://www.cve.org/CVERecord?id=CVE-2022-4899'], 'PublishedDate': '2023-03-31T20:15:07.213Z', 'LastModifiedDate': '2023-11-07T03:59:16.09Z'}, {'VulnerabilityID': 'CVE-2024-43882', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43882', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: exec: Fix ToCToU between perm check and set-uid/gid usage', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Fix ToCToU between perm check and set-uid/gid usage\n\nWhen opening a file for exec via do_filp_open(), permission checking is\ndone against the file\'s metadata at that moment, and on success, a file\npointer is passed back. Much later in the execve() code path, the file\nmetadata (specifically mode, uid, and gid) is used to determine if/how\nto set the uid and gid. However, those values may have changed since the\npermissions check, meaning the execution may gain unintended privileges.\n\nFor example, if a file could change permissions from executable and not\nset-id:\n\n---------x 1 root root 16048 Aug 7 13:16 target\n\nto set-id and non-executable:\n\n---S------ 1 root root 16048 Aug 7 13:16 target\n\nit is possible to gain root privileges when execution should have been\ndisallowed.\n\nWhile this race condition is rare in real-world scenarios, it has been\nobserved (and proven exploitable) when package managers are updating\nthe setuid bits of installed programs. Such files start with being\nworld-executable but then are adjusted to be group-exec with a set-uid\nbit. For example, "chmod o-x,u+s target" makes "target" executable only\nby uid "root" and gid "cdrom", while also becoming setuid-root:\n\n-rwxr-xr-x 1 root cdrom 16048 Aug 7 13:16 target\n\nbecomes:\n\n-rwsr-xr-- 1 root cdrom 16048 Aug 7 13:16 target\n\nBut racing the chmod means users without group "cdrom" membership can\nget the permission to execute "target" just before the chmod, and when\nthe chmod finishes, the exec reaches brpm_fill_uid(), and performs the\nsetuid to root, violating the expressed authorization of "only cdrom\ngroup members can setuid to root".\n\nRe-check that we still have execute permissions in case the metadata\nhas changed. It would be better to keep a copy from the perm-check time,\nbut until we can do that refactoring, the least-bad option is to do a\nfull inode_permission() call (under inode lock). It is understood that\nthis is safe against dead-locks, but hardly optimal.', 'Severity': 'HIGH', 'CweIDs': ['CWE-367'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43882', 'https://git.kernel.org/linus/f50733b45d865f91db90919f8311e2127ce5a0cb (6.11-rc4)', 'https://git.kernel.org/stable/c/15469d46ba34559bfe7e3de6659115778c624759', 'https://git.kernel.org/stable/c/368f6985d46657b8b466a421dddcacd4051f7ada', 'https://git.kernel.org/stable/c/90dfbba89ad4f0d9c9744ecbb1adac4aa2ff4f3e', 'https://git.kernel.org/stable/c/9b424c5d4130d56312e2a3be17efb0928fec4d64', 'https://git.kernel.org/stable/c/d2a2a4714d80d09b0f8eb6438ab4224690b7121e', 'https://git.kernel.org/stable/c/d5c3c7e26275a2d83b894d30f7582a42853a958f', 'https://git.kernel.org/stable/c/f50733b45d865f91db90919f8311e2127ce5a0cb', 'https://git.kernel.org/stable/c/f6cfc6bcfd5e1cf76115b6450516ea4c99897ae1', 'https://linux.oracle.com/cve/CVE-2024-43882.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082152-CVE-2024-43882-4fa4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43882', 'https://www.cve.org/CVERecord?id=CVE-2024-43882'], 'PublishedDate': '2024-08-21T01:15:12.34Z', 'LastModifiedDate': '2024-09-03T13:25:39.747Z'}, {'VulnerabilityID': 'CVE-2013-7445', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2013-7445', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memory exhaustion via crafted Graphics Execution Manager (GEM) objects', 'Description': 'The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-399'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:C', 'V2Score': 7.8}, 'redhat': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V2Score': 4.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2013-7445', 'https://bugzilla.kernel.org/show_bug.cgi?id=60533', 'https://lists.freedesktop.org/archives/dri-devel/2015-September/089778.html (potential start towards fixing)', 'https://nvd.nist.gov/vuln/detail/CVE-2013-7445', 'https://www.cve.org/CVERecord?id=CVE-2013-7445'], 'PublishedDate': '2015-10-16T01:59:00.12Z', 'LastModifiedDate': '2015-10-16T16:22:25.587Z'}, {'VulnerabilityID': 'CVE-2015-8553', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2015-8553', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'xen: non-maskable interrupts triggerable by guests (xsa120)', 'Description': 'Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N', 'V2Score': 2.1, 'V3Score': 6.5}, 'redhat': {'V2Vector': 'AV:A/AC:M/Au:S/C:N/I:N/A:C', 'V2Score': 5.2}}, 'References': ['http://thread.gmane.org/gmane.linux.kernel/1924087/focus=1930758 (regression mention)', 'http://xenbits.xen.org/xsa/advisory-120.html', 'https://access.redhat.com/security/cve/CVE-2015-8553', 'https://nvd.nist.gov/vuln/detail/CVE-2015-8553', 'https://seclists.org/bugtraq/2019/Aug/18', 'https://www.cve.org/CVERecord?id=CVE-2015-8553', 'https://www.debian.org/security/2019/dsa-4497'], 'PublishedDate': '2016-04-13T15:59:07.307Z', 'LastModifiedDate': '2019-08-13T23:15:11.203Z'}, {'VulnerabilityID': 'CVE-2016-8660', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-8660', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: local DoS due to a page lock order bug in the XFS seek hole/data implementation', 'Description': 'The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implementation."', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-19'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V2Vector': 'AV:L/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.7, 'V3Score': 5.5}}, 'References': ['http://www.openwall.com/lists/oss-security/2016/10/13/8', 'http://www.securityfocus.com/bid/93558', 'https://access.redhat.com/security/cve/CVE-2016-8660', 'https://bugzilla.redhat.com/show_bug.cgi?id=1384851', 'https://lore.kernel.org/linux-xfs/895314622.769515.1476375930648.JavaMail.zimbra@redhat.com/', 'https://marc.info/?l=linux-fsdevel&m=147639177409294&w=2', 'https://marc.info/?l=linux-xfs&m=149498118228320&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2016-8660', 'https://www.cve.org/CVERecord?id=CVE-2016-8660'], 'PublishedDate': '2016-10-16T21:59:14.333Z', 'LastModifiedDate': '2016-11-28T20:41:02.59Z'}, {'VulnerabilityID': 'CVE-2018-17977', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-17977', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service', 'Description': 'The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-400'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.9}}, 'References': ['http://www.securityfocus.com/bid/105539', 'https://access.redhat.com/security/cve/CVE-2018-17977', 'https://bugzilla.suse.com/show_bug.cgi?id=1111609', 'https://nvd.nist.gov/vuln/detail/CVE-2018-17977', 'https://www.cve.org/CVERecord?id=CVE-2018-17977', 'https://www.openwall.com/lists/oss-security/2018/10/05/5'], 'PublishedDate': '2018-10-08T17:29:00.653Z', 'LastModifiedDate': '2018-11-26T15:51:30.427Z'}, {'VulnerabilityID': 'CVE-2021-3714', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-3714', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Remote Page Deduplication Attacks', 'Description': 'A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-3714', 'https://arxiv.org/abs/2111.08553', 'https://arxiv.org/pdf/2111.08553.pdf', 'https://bugzilla.redhat.com/show_bug.cgi?id=1931327', 'https://nvd.nist.gov/vuln/detail/CVE-2021-3714', 'https://www.cve.org/CVERecord?id=CVE-2021-3714'], 'PublishedDate': '2022-08-23T16:15:09.6Z', 'LastModifiedDate': '2024-02-01T18:51:23.66Z'}, {'VulnerabilityID': 'CVE-2021-47599', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-47599', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: use latest_dev in btrfs_show_devname', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: use latest_dev in btrfs_show_devname\n\nThe test case btrfs/238 reports the warning below:\n\n WARNING: CPU: 3 PID: 481 at fs/btrfs/super.c:2509 btrfs_show_devname+0x104/0x1e8 [btrfs]\n CPU: 2 PID: 1 Comm: systemd Tainted: G W O 5.14.0-rc1-custom #72\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n Call trace:\n btrfs_show_devname+0x108/0x1b4 [btrfs]\n show_mountinfo+0x234/0x2c4\n m_show+0x28/0x34\n seq_read_iter+0x12c/0x3c4\n vfs_read+0x29c/0x2c8\n ksys_read+0x80/0xec\n __arm64_sys_read+0x28/0x34\n invoke_syscall+0x50/0xf8\n do_el0_svc+0x88/0x138\n el0_svc+0x2c/0x8c\n el0t_64_sync_handler+0x84/0xe4\n el0t_64_sync+0x198/0x19c\n\nReason:\nWhile btrfs_prepare_sprout() moves the fs_devices::devices into\nfs_devices::seed_list, the btrfs_show_devname() searches for the devices\nand found none, leading to the warning as in above.\n\nFix:\nlatest_dev is updated according to the changes to the device list.\nThat means we could use the latest_dev->name to show the device name in\n/proc/self/mounts, the pointer will be always valid as it's assigned\nbefore the device is deleted from the list in remove or replace.\nThe RCU protection is sufficient as the device structure is freed after\nsynchronization.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-47599', 'https://git.kernel.org/linus/6605fd2f394bba0a0059df2b6cfc87b0b6d393a2 (5.16-rc1)', 'https://git.kernel.org/stable/c/6605fd2f394bba0a0059df2b6cfc87b0b6d393a2', 'https://git.kernel.org/stable/c/e342c2558016ead462f376b6c6c2ac5efc17f3b1', 'https://lore.kernel.org/linux-cve-announce/2024061921-CVE-2021-47599-37b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2021-47599', 'https://www.cve.org/CVERecord?id=CVE-2021-47599'], 'PublishedDate': '2024-06-19T15:15:54.483Z', 'LastModifiedDate': '2024-06-20T12:43:25.663Z'}, {'VulnerabilityID': 'CVE-2021-47615', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-47615', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/mlx5: Fix releasing unallocated memory in dereg MR flow', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix releasing unallocated memory in dereg MR flow\n\nFor the case of IB_MR_TYPE_DM the mr does doesn't have a umem, even though\nit is a user MR. This causes function mlx5_free_priv_descs() to think that\nit is a kernel MR, leading to wrongly accessing mr->descs that will get\nwrong values in the union which leads to attempt to release resources that\nwere not allocated in the first place.\n\nFor example:\n DMA-API: mlx5_core 0000:08:00.1: device driver tries to free DMA memory it has not allocated [device address=0x0000000000000000] [size=0 bytes]\n WARNING: CPU: 8 PID: 1021 at kernel/dma/debug.c:961 check_unmap+0x54f/0x8b0\n RIP: 0010:check_unmap+0x54f/0x8b0\n Call Trace:\n debug_dma_unmap_page+0x57/0x60\n mlx5_free_priv_descs+0x57/0x70 [mlx5_ib]\n mlx5_ib_dereg_mr+0x1fb/0x3d0 [mlx5_ib]\n ib_dereg_mr_user+0x60/0x140 [ib_core]\n uverbs_destroy_uobject+0x59/0x210 [ib_uverbs]\n uobj_destroy+0x3f/0x80 [ib_uverbs]\n ib_uverbs_cmd_verbs+0x435/0xd10 [ib_uverbs]\n ? uverbs_finalize_object+0x50/0x50 [ib_uverbs]\n ? lock_acquire+0xc4/0x2e0\n ? lock_acquired+0x12/0x380\n ? lock_acquire+0xc4/0x2e0\n ? lock_acquire+0xc4/0x2e0\n ? ib_uverbs_ioctl+0x7c/0x140 [ib_uverbs]\n ? lock_release+0x28a/0x400\n ib_uverbs_ioctl+0xc0/0x140 [ib_uverbs]\n ? ib_uverbs_ioctl+0x7c/0x140 [ib_uverbs]\n __x64_sys_ioctl+0x7f/0xb0\n do_syscall_64+0x38/0x90\n\nFix it by reorganizing the dereg flow and mlx5_ib_mr structure:\n - Move the ib_umem field into the user MRs structure in the union as it's\n applicable only there.\n - Function mlx5_ib_dereg_mr() will now call mlx5_free_priv_descs() only\n in case there isn't udata, which indicates that this isn't a user MR.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-47615', 'https://git.kernel.org/linus/f0ae4afe3d35e67db042c58a52909e06262b740f (5.16-rc5)', 'https://git.kernel.org/stable/c/c44979ace49b4aede3cc7cb5542316e53a4005c9', 'https://git.kernel.org/stable/c/e3bc4d4b50cae7db08e50dbe43f771c906e97701', 'https://git.kernel.org/stable/c/f0ae4afe3d35e67db042c58a52909e06262b740f', 'https://lore.kernel.org/linux-cve-announce/2024061909-CVE-2021-47615-3c6a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2021-47615', 'https://www.cve.org/CVERecord?id=CVE-2021-47615'], 'PublishedDate': '2024-06-19T15:15:56.03Z', 'LastModifiedDate': '2024-06-20T12:43:25.663Z'}, {'VulnerabilityID': 'CVE-2022-0400', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-0400', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Out of bounds read in the smc protocol stack', 'Description': 'An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-0400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2040604', 'https://bugzilla.redhat.com/show_bug.cgi?id=2040604 (not public)', 'https://bugzilla.redhat.com/show_bug.cgi?id=2044575', 'https://nvd.nist.gov/vuln/detail/CVE-2022-0400', 'https://www.cve.org/CVERecord?id=CVE-2022-0400'], 'PublishedDate': '2022-08-29T15:15:09.423Z', 'LastModifiedDate': '2022-09-01T20:18:18.247Z'}, {'VulnerabilityID': 'CVE-2022-0480', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-0480', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion', 'Description': 'A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-0480', 'https://bugzilla.redhat.com/show_bug.cgi?id=2049700', 'https://git.kernel.org/linus/0f12156dff2862ac54235fc72703f18770769042 (5.15-rc1)', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0f12156dff2862ac54235fc72703f18770769042', 'https://github.com/kata-containers/kata-containers/issues/3373', 'https://linux.oracle.com/cve/CVE-2022-0480.html', 'https://linux.oracle.com/errata/ELSA-2024-2394.html', 'https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm%40linux-foundation.org/', 'https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm@linux-foundation.org/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-0480', 'https://ubuntu.com/security/CVE-2022-0480', 'https://www.cve.org/CVERecord?id=CVE-2022-0480'], 'PublishedDate': '2022-08-29T15:15:09.477Z', 'LastModifiedDate': '2023-03-03T18:49:53.213Z'}, {'VulnerabilityID': 'CVE-2022-3238', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3238', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously', 'Description': 'A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415', 'CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127927', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3238', 'https://www.cve.org/CVERecord?id=CVE-2022-3238'], 'PublishedDate': '2022-11-14T21:15:16.163Z', 'LastModifiedDate': '2022-11-17T20:24:18.537Z'}, {'VulnerabilityID': 'CVE-2022-48846', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: release rq qos structures for queue without disk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: release rq qos structures for queue without disk\n\nblkcg_init_queue() may add rq qos structures to request queue, previously\nblk_cleanup_queue() calls rq_qos_exit() to release them, but commit\n8e141f9eb803 ("block: drain file system I/O on del_gendisk")\nmoves rq_qos_exit() into del_gendisk(), so memory leak is caused\nbecause queues may not have disk, such as un-present scsi luns, nvme\nadmin queue, ...\n\nFixes the issue by adding rq_qos_exit() to blk_cleanup_queue() back.\n\nBTW, v5.18 won\'t need this patch any more since we move\nblkcg_init_queue()/blkcg_exit_queue() into disk allocation/release\nhandler, and patches have been in for-5.18/block.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48846', 'https://git.kernel.org/linus/daaca3522a8e67c46e39ef09c1d542e866f85f3b (5.17)', 'https://git.kernel.org/stable/c/60c2c8e2ef3a3ec79de8cbc80a06ca0c21df8c29', 'https://git.kernel.org/stable/c/d4ad8736ac982111bb0be8306bf19c8207f6600e', 'https://git.kernel.org/stable/c/daaca3522a8e67c46e39ef09c1d542e866f85f3b', 'https://lore.kernel.org/linux-cve-announce/2024071623-CVE-2022-48846-a1a8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48846', 'https://www.cve.org/CVERecord?id=CVE-2022-48846'], 'PublishedDate': '2024-07-16T13:15:11.883Z', 'LastModifiedDate': '2024-07-24T17:56:26.767Z'}, {'VulnerabilityID': 'CVE-2022-48929', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48929', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids.', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix crash due to out of bounds access into reg2btf_ids.\n\nWhen commit e6ac2450d6de ("bpf: Support bpf program calling kernel function") added\nkfunc support, it defined reg2btf_ids as a cheap way to translate the verifier\nreg type to the appropriate btf_vmlinux BTF ID, however\ncommit c25b2ae13603 ("bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL")\nmoved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after\nthe base register types, and defined other variants using type flag\ncomposition. However, now, the direct usage of reg->type to index into\nreg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to\nout of bounds access and kernel crash on dereference of bad pointer.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48929', 'https://git.kernel.org/linus/45ce4b4f9009102cd9f581196d480a59208690c1 (5.17-rc6)', 'https://git.kernel.org/stable/c/45ce4b4f9009102cd9f581196d480a59208690c1', 'https://git.kernel.org/stable/c/8c39925e98d498b9531343066ef82ae39e41adae', 'https://git.kernel.org/stable/c/f0ce1bc9e0235dd7412240be493d7ea65ed9eadc', 'https://lore.kernel.org/linux-cve-announce/2024082222-CVE-2022-48929-857d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48929', 'https://www.cve.org/CVERecord?id=CVE-2022-48929'], 'PublishedDate': '2024-08-22T04:15:15.773Z', 'LastModifiedDate': '2024-08-23T02:00:22.653Z'}, {'VulnerabilityID': 'CVE-2023-0030', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-0030', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Use after Free in nvkm_vmm_pfn_map', 'Description': 'A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-0030', 'https://bugzilla.redhat.com/show_bug.cgi?id=2157270', 'https://git.kernel.org/linus/729eba3355674f2d9524629b73683ba1d1cd3f10 (5.0-rc1)', 'https://github.com/torvalds/linux/commit/729eba3355674f2d9524629b73683ba1d1cd3f10', 'https://lore.kernel.org/all/20221230072758.443644-1-zyytlz.wz@163.com/', 'https://lore.kernel.org/all/63d485b2.170a0220.4af4c.d54f@mx.google.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-0030', 'https://security.netapp.com/advisory/ntap-20230413-0010/', 'https://www.cve.org/CVERecord?id=CVE-2023-0030'], 'PublishedDate': '2023-03-08T23:15:10.963Z', 'LastModifiedDate': '2023-04-13T17:15:09.433Z'}, {'VulnerabilityID': 'CVE-2023-0160', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-0160', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: possibility of deadlock in libbpf function sock_hash_delete_elem', 'Description': 'A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667', 'CWE-833'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-0160', 'https://bugzilla.redhat.com/show_bug.cgi?id=2159764', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ed17aa92dc56', 'https://lore.kernel.org/all/20230406122622.109978-1-liuxin350@huawei.com/', 'https://lore.kernel.org/all/CABcoxUayum5oOqFMMqAeWuS8+EzojquSOSyDA3J_2omY=2EeAg@mail.gmail.com/', 'https://lore.kernel.org/bpf/000000000000f1db9605f939720e@google.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-0160', 'https://www.cve.org/CVERecord?id=CVE-2023-0160'], 'PublishedDate': '2023-07-18T17:15:11.313Z', 'LastModifiedDate': '2023-11-07T03:59:46.343Z'}, {'VulnerabilityID': 'CVE-2023-1193', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-1193', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free in setup_async_work()', 'Description': 'A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-1193', 'https://bugzilla.redhat.com/show_bug.cgi?id=2154177', 'https://lkml.kernel.org/linux-cifs/20230401084951.6085-2-linkinjeon@kernel.org/T/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-1193', 'https://www.cve.org/CVERecord?id=CVE-2023-1193'], 'PublishedDate': '2023-11-01T20:15:08.663Z', 'LastModifiedDate': '2023-11-09T15:13:51.737Z'}, {'VulnerabilityID': 'CVE-2023-26242', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-26242', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the ...', 'Description': 'afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://bugzilla.suse.com/show_bug.cgi?id=1208518', 'https://lore.kernel.org/all/20230206054326.89323-1-k1rh4.lee@gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-26242', 'https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee%40gmail.com', 'https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee@gmail.com/', 'https://security.netapp.com/advisory/ntap-20230406-0002/', 'https://www.cve.org/CVERecord?id=CVE-2023-26242'], 'PublishedDate': '2023-02-21T01:15:11.423Z', 'LastModifiedDate': '2024-03-25T01:15:53.57Z'}, {'VulnerabilityID': 'CVE-2023-31082', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-31082', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sleeping function called from an invalid context in gsmld_write', 'Description': 'An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-763'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-31082', 'https://bugzilla.suse.com/show_bug.cgi?id=1210781', 'https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A%40mail.gmail.com/', 'https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A@mail.gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-31082', 'https://security.netapp.com/advisory/ntap-20230929-0003/', 'https://www.cve.org/CVERecord?id=CVE-2023-31082'], 'PublishedDate': '2023-04-24T06:15:07.783Z', 'LastModifiedDate': '2024-08-02T15:16:00.853Z'}, {'VulnerabilityID': 'CVE-2023-52879', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52879', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Have trace_event_file have ref counters', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have trace_event_file have ref counters\n\nThe following can crash the kernel:\n\n # cd /sys/kernel/tracing\n # echo \'p:sched schedule\' > kprobe_events\n # exec 5>>events/kprobes/sched/enable\n # > kprobe_events\n # exec 5>&-\n\nThe above commands:\n\n 1. Change directory to the tracefs directory\n 2. Create a kprobe event (doesn\'t matter what one)\n 3. Open bash file descriptor 5 on the enable file of the kprobe event\n 4. Delete the kprobe event (removes the files too)\n 5. Close the bash file descriptor 5\n\nThe above causes a crash!\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 6 PID: 877 Comm: bash Not tainted 6.5.0-rc4-test-00008-g2c6b6b1029d4-dirty #186\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\n RIP: 0010:tracing_release_file_tr+0xc/0x50\n\nWhat happens here is that the kprobe event creates a trace_event_file\n"file" descriptor that represents the file in tracefs to the event. It\nmaintains state of the event (is it enabled for the given instance?).\nOpening the "enable" file gets a reference to the event "file" descriptor\nvia the open file descriptor. When the kprobe event is deleted, the file is\nalso deleted from the tracefs system which also frees the event "file"\ndescriptor.\n\nBut as the tracefs file is still opened by user space, it will not be\ntotally removed until the final dput() is called on it. But this is not\ntrue with the event "file" descriptor that is already freed. If the user\ndoes a write to or simply closes the file descriptor it will reference the\nevent "file" descriptor that was just freed, causing a use-after-free bug.\n\nTo solve this, add a ref count to the event "file" descriptor as well as a\nnew flag called "FREED". The "file" will not be freed until the last\nreference is released. But the FREE flag will be set when the event is\nremoved to prevent any more modifications to that event from happening,\neven if there\'s still a reference to the event "file" descriptor.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-52879', 'https://git.kernel.org/linus/bb32500fb9b78215e4ef6ee8b4345c5f5d7eafb4 (6.7-rc1)', 'https://git.kernel.org/stable/c/2c9de867ca285c397cd71af703763fe416265706', 'https://git.kernel.org/stable/c/2fa74d29fc1899c237d51bf9a6e132ea5c488976', 'https://git.kernel.org/stable/c/9034c87d61be8cff989017740a91701ac8195a1d', 'https://git.kernel.org/stable/c/961c4511c7578d6b8f39118be919016ec3db1c1e', 'https://git.kernel.org/stable/c/a98172e36e5f1b3d29ad71fade2d611cfcc2fe6f', 'https://git.kernel.org/stable/c/bb32500fb9b78215e4ef6ee8b4345c5f5d7eafb4', 'https://git.kernel.org/stable/c/cbc7c29dff0fa18162f2a3889d82eeefd67305e0', 'https://lore.kernel.org/linux-cve-announce/2024052122-CVE-2023-52879-fa4d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52879', 'https://www.cve.org/CVERecord?id=CVE-2023-52879'], 'PublishedDate': '2024-05-21T16:15:24.53Z', 'LastModifiedDate': '2024-05-21T16:53:56.55Z'}, {'VulnerabilityID': 'CVE-2023-52889', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52889', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: apparmor: Fix null pointer deref when receiving skb during sock creation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: Fix null pointer deref when receiving skb during sock creation\n\nThe panic below is observed when receiving ICMP packets with secmark set\nwhile an ICMP raw socket is being created. SK_CTX(sk)->label is updated\nin apparmor_socket_post_create(), but the packet is delivered to the\nsocket before that, causing the null pointer dereference.\nDrop the packet if label context is not set.\n\n BUG: kernel NULL pointer dereference, address: 000000000000004c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 PID: 407 Comm: a.out Not tainted 6.4.12-arch1-1 #1 3e6fa2753a2d75925c34ecb78e22e85a65d083df\n Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 05/28/2020\n RIP: 0010:aa_label_next_confined+0xb/0x40\n Code: 00 00 48 89 ef e8 d5 25 0c 00 e9 66 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 89 f0 <8b> 77 4c 39 c6 7e 1f 48 63 d0 48 8d 14 d7 eb 0b 83 c0 01 48 83 c2\n RSP: 0018:ffffa92940003b08 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 000000000000000e\n RDX: ffffa92940003be8 RSI: 0000000000000000 RDI: 0000000000000000\n RBP: ffff8b57471e7800 R08: ffff8b574c642400 R09: 0000000000000002\n R10: ffffffffbd820eeb R11: ffffffffbeb7ff00 R12: ffff8b574c642400\n R13: 0000000000000001 R14: 0000000000000001 R15: 0000000000000000\n FS: 00007fb092ea7640(0000) GS:ffff8b577bc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000004c CR3: 00000001020f2005 CR4: 00000000007706f0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? aa_label_next_confined+0xb/0x40\n apparmor_secmark_check+0xec/0x330\n security_sock_rcv_skb+0x35/0x50\n sk_filter_trim_cap+0x47/0x250\n sock_queue_rcv_skb_reason+0x20/0x60\n raw_rcv+0x13c/0x210\n raw_local_deliver+0x1f3/0x250\n ip_protocol_deliver_rcu+0x4f/0x2f0\n ip_local_deliver_finish+0x76/0xa0\n __netif_receive_skb_one_core+0x89/0xa0\n netif_receive_skb+0x119/0x170\n ? __netdev_alloc_skb+0x3d/0x140\n vmxnet3_rq_rx_complete+0xb23/0x1010 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a]\n vmxnet3_poll_rx_only+0x36/0xb0 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a]\n __napi_poll+0x28/0x1b0\n net_rx_action+0x2a4/0x380\n __do_softirq+0xd1/0x2c8\n __irq_exit_rcu+0xbb/0xf0\n common_interrupt+0x86/0xa0\n \n \n asm_common_interrupt+0x26/0x40\n RIP: 0010:apparmor_socket_post_create+0xb/0x200\n Code: 08 48 85 ff 75 a1 eb b1 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 <55> 48 89 fd 53 45 85 c0 0f 84 b2 00 00 00 48 8b 1d 80 56 3f 02 48\n RSP: 0018:ffffa92940ce7e50 EFLAGS: 00000286\n RAX: ffffffffbc756440 RBX: 0000000000000000 RCX: 0000000000000001\n RDX: 0000000000000003 RSI: 0000000000000002 RDI: ffff8b574eaab740\n RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff8b57444cec70 R11: 0000000000000000 R12: 0000000000000003\n R13: 0000000000000002 R14: ffff8b574eaab740 R15: ffffffffbd8e4748\n ? __pfx_apparmor_socket_post_create+0x10/0x10\n security_socket_post_create+0x4b/0x80\n __sock_create+0x176/0x1f0\n __sys_socket+0x89/0x100\n __x64_sys_socket+0x17/0x20\n do_syscall_64+0x5d/0x90\n ? do_syscall_64+0x6c/0x90\n ? do_syscall_64+0x6c/0x90\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-52889', 'https://git.kernel.org/linus/fce09ea314505a52f2436397608fa0a5d0934fb1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0abe35bc48d4ec80424b1f4b3560c0e082cbd5c1', 'https://git.kernel.org/stable/c/290a6b88e8c19b6636ed1acc733d1458206f7697', 'https://git.kernel.org/stable/c/347dcb84a4874b5fb375092c08d8cc4069b94f81', 'https://git.kernel.org/stable/c/46c17ead5b7389e22e7dc9903fd0ba865d05bda2', 'https://git.kernel.org/stable/c/6c920754f62cefc63fccdc38a062c7c3452e2961', 'https://git.kernel.org/stable/c/ead2ad1d9f045f26fdce3ef1644913b3a6cd38f2', 'https://git.kernel.org/stable/c/fce09ea314505a52f2436397608fa0a5d0934fb1', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2023-52889-cdd0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52889', 'https://www.cve.org/CVERecord?id=CVE-2023-52889'], 'PublishedDate': '2024-08-17T09:15:07.073Z', 'LastModifiedDate': '2024-08-19T21:19:16.97Z'}, {'VulnerabilityID': 'CVE-2024-26713', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26713', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/pseries/iommu: Fix iommu initialisation during DLPAR add', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: Fix iommu initialisation during DLPAR add\n\nWhen a PCI device is dynamically added, the kernel oopses with a NULL\npointer dereference:\n\n BUG: Kernel NULL pointer dereference on read at 0x00000030\n Faulting instruction address: 0xc0000000006bbe5c\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: rpadlpar_io rpaphp rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs xsk_diag bonding nft_compat nf_tables nfnetlink rfkill binfmt_misc dm_multipath rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi ib_ipoib rdma_cm iw_cm ib_cm mlx5_ib ib_uverbs ib_core pseries_rng drm drm_panel_orientation_quirks xfs libcrc32c mlx5_core mlxfw sd_mod t10_pi sg tls ibmvscsi ibmveth scsi_transport_srp vmx_crypto pseries_wdt psample dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 17 PID: 2685 Comm: drmgr Not tainted 6.7.0-203405+ #66\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c0000000006bbe5c LR: c000000000a13e68 CTR: c0000000000579f8\n REGS: c00000009924f240 TRAP: 0300 Not tainted (6.7.0-203405+)\n MSR: 8000000000009033 CR: 24002220 XER: 20040006\n CFAR: c000000000a13e64 DAR: 0000000000000030 DSISR: 40000000 IRQMASK: 0\n ...\n NIP sysfs_add_link_to_group+0x34/0x94\n LR iommu_device_link+0x5c/0x118\n Call Trace:\n iommu_init_device+0x26c/0x318 (unreliable)\n iommu_device_link+0x5c/0x118\n iommu_init_device+0xa8/0x318\n iommu_probe_device+0xc0/0x134\n iommu_bus_notifier+0x44/0x104\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n bus_notify+0x50/0x7c\n device_add+0x640/0x918\n pci_device_add+0x23c/0x298\n of_create_pci_dev+0x400/0x884\n of_scan_pci_dev+0x124/0x1b0\n __of_scan_bus+0x78/0x18c\n pcibios_scan_phb+0x2a4/0x3b0\n init_phb_dynamic+0xb8/0x110\n dlpar_add_slot+0x170/0x3b8 [rpadlpar_io]\n add_slot_store.part.0+0xb4/0x130 [rpadlpar_io]\n kobj_attr_store+0x2c/0x48\n sysfs_kf_write+0x64/0x78\n kernfs_fop_write_iter+0x1b0/0x290\n vfs_write+0x350/0x4a0\n ksys_write+0x84/0x140\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nCommit a940904443e4 ("powerpc/iommu: Add iommu_ops to report capabilities\nand allow blocking domains") broke DLPAR add of PCI devices.\n\nThe above added iommu_device structure to pci_controller. During\nsystem boot, PCI devices are discovered and this newly added iommu_device\nstructure is initialized by a call to iommu_device_register().\n\nDuring DLPAR add of a PCI device, a new pci_controller structure is\nallocated but there are no calls made to iommu_device_register()\ninterface.\n\nFix is to register the iommu device during DLPAR add as well.\n\n[mpe: Trim oops and tweak some change log wording]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26713', 'https://git.kernel.org/linus/ed8b94f6e0acd652ce69bd69d678a0c769172df8 (6.8-rc5)', 'https://git.kernel.org/stable/c/9978d5b744e0227afe19e3bcb4c5f75442dde753', 'https://git.kernel.org/stable/c/d4f762d6403f7419de90d7749fa83dd92ffb0e1d', 'https://git.kernel.org/stable/c/ed8b94f6e0acd652ce69bd69d678a0c769172df8', 'https://lore.kernel.org/linux-cve-announce/2024040342-CVE-2024-26713-1b52@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26713', 'https://www.cve.org/CVERecord?id=CVE-2024-26713'], 'PublishedDate': '2024-04-03T15:15:53.647Z', 'LastModifiedDate': '2024-04-03T17:24:18.15Z'}, {'VulnerabilityID': 'CVE-2024-27025', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-27025', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nbd: null check for nla_nest_start', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: null check for nla_nest_start\n\nnla_nest_start() may fail and return NULL. Insert a check and set errno\nbased on other call sites within the same source code.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:5102', 'https://access.redhat.com/security/cve/CVE-2024-27025', 'https://bugzilla.redhat.com/2263879', 'https://bugzilla.redhat.com/2265645', 'https://bugzilla.redhat.com/2265797', 'https://bugzilla.redhat.com/2266341', 'https://bugzilla.redhat.com/2266347', 'https://bugzilla.redhat.com/2266497', 'https://bugzilla.redhat.com/2267787', 'https://bugzilla.redhat.com/2268118', 'https://bugzilla.redhat.com/2269070', 'https://bugzilla.redhat.com/2269211', 'https://bugzilla.redhat.com/2270084', 'https://bugzilla.redhat.com/2270100', 'https://bugzilla.redhat.com/2271686', 'https://bugzilla.redhat.com/2271688', 'https://bugzilla.redhat.com/2272782', 'https://bugzilla.redhat.com/2272795', 'https://bugzilla.redhat.com/2273109', 'https://bugzilla.redhat.com/2273174', 'https://bugzilla.redhat.com/2273236', 'https://bugzilla.redhat.com/2273242', 'https://bugzilla.redhat.com/2273247', 'https://bugzilla.redhat.com/2273268', 'https://bugzilla.redhat.com/2273427', 'https://bugzilla.redhat.com/2273654', 'https://bugzilla.redhat.com/2275565', 'https://bugzilla.redhat.com/2275573', 'https://bugzilla.redhat.com/2275580', 'https://bugzilla.redhat.com/2275694', 'https://bugzilla.redhat.com/2275711', 'https://bugzilla.redhat.com/2275748', 'https://bugzilla.redhat.com/2275761', 'https://bugzilla.redhat.com/2275928', 'https://bugzilla.redhat.com/2277166', 'https://bugzilla.redhat.com/2277238', 'https://bugzilla.redhat.com/2277840', 'https://bugzilla.redhat.com/2278176', 'https://bugzilla.redhat.com/2278178', 'https://bugzilla.redhat.com/2278182', 'https://bugzilla.redhat.com/2278218', 'https://bugzilla.redhat.com/2278256', 'https://bugzilla.redhat.com/2278258', 'https://bugzilla.redhat.com/2278277', 'https://bugzilla.redhat.com/2278279', 'https://bugzilla.redhat.com/2278380', 'https://bugzilla.redhat.com/2278484', 'https://bugzilla.redhat.com/2278515', 'https://bugzilla.redhat.com/2278535', 'https://bugzilla.redhat.com/2278539', 'https://bugzilla.redhat.com/2278989', 'https://bugzilla.redhat.com/2280440', 'https://bugzilla.redhat.com/2281054', 'https://bugzilla.redhat.com/2281133', 'https://bugzilla.redhat.com/2281149', 'https://bugzilla.redhat.com/2281207', 'https://bugzilla.redhat.com/2281215', 'https://bugzilla.redhat.com/2281221', 'https://bugzilla.redhat.com/2281235', 'https://bugzilla.redhat.com/2281268', 'https://bugzilla.redhat.com/2281326', 'https://bugzilla.redhat.com/2281360', 'https://bugzilla.redhat.com/2281510', 'https://bugzilla.redhat.com/2281519', 'https://bugzilla.redhat.com/2281636', 'https://bugzilla.redhat.com/2281641', 'https://bugzilla.redhat.com/2281664', 'https://bugzilla.redhat.com/2281667', 'https://bugzilla.redhat.com/2281672', 'https://bugzilla.redhat.com/2281675', 'https://bugzilla.redhat.com/2281682', 'https://bugzilla.redhat.com/2281725', 'https://bugzilla.redhat.com/2281752', 'https://bugzilla.redhat.com/2281758', 'https://bugzilla.redhat.com/2281819', 'https://bugzilla.redhat.com/2281821', 'https://bugzilla.redhat.com/2281833', 'https://bugzilla.redhat.com/2281938', 'https://bugzilla.redhat.com/2281949', 'https://bugzilla.redhat.com/2281968', 'https://bugzilla.redhat.com/2281989', 'https://bugzilla.redhat.com/2282328', 'https://bugzilla.redhat.com/2282373', 'https://bugzilla.redhat.com/2282479', 'https://bugzilla.redhat.com/2282553', 'https://bugzilla.redhat.com/2282615', 'https://bugzilla.redhat.com/2282623', 'https://bugzilla.redhat.com/2282640', 'https://bugzilla.redhat.com/2282642', 'https://bugzilla.redhat.com/2282645', 'https://bugzilla.redhat.com/2282717', 'https://bugzilla.redhat.com/2282719', 'https://bugzilla.redhat.com/2282727', 'https://bugzilla.redhat.com/2282742', 'https://bugzilla.redhat.com/2282743', 'https://bugzilla.redhat.com/2282744', 'https://bugzilla.redhat.com/2282759', 'https://bugzilla.redhat.com/2282763', 'https://bugzilla.redhat.com/2282766', 'https://bugzilla.redhat.com/2282772', 'https://bugzilla.redhat.com/2282780', 'https://bugzilla.redhat.com/2282887', 'https://bugzilla.redhat.com/2282896', 'https://bugzilla.redhat.com/2282923', 'https://bugzilla.redhat.com/2282925', 'https://bugzilla.redhat.com/2282950', 'https://bugzilla.redhat.com/2283401', 'https://bugzilla.redhat.com/2283894', 'https://bugzilla.redhat.com/2284400', 'https://bugzilla.redhat.com/2284417', 'https://bugzilla.redhat.com/2284421', 'https://bugzilla.redhat.com/2284474', 'https://bugzilla.redhat.com/2284477', 'https://bugzilla.redhat.com/2284488', 'https://bugzilla.redhat.com/2284496', 'https://bugzilla.redhat.com/2284500', 'https://bugzilla.redhat.com/2284513', 'https://bugzilla.redhat.com/2284519', 'https://bugzilla.redhat.com/2284539', 'https://bugzilla.redhat.com/2284541', 'https://bugzilla.redhat.com/2284556', 'https://bugzilla.redhat.com/2284571', 'https://bugzilla.redhat.com/2284590', 'https://bugzilla.redhat.com/2284625', 'https://bugzilla.redhat.com/2290408', 'https://bugzilla.redhat.com/2292331', 'https://bugzilla.redhat.com/2293078', 'https://bugzilla.redhat.com/2293250', 'https://bugzilla.redhat.com/2293276', 'https://bugzilla.redhat.com/2293312', 'https://bugzilla.redhat.com/2293316', 'https://bugzilla.redhat.com/2293348', 'https://bugzilla.redhat.com/2293371', 'https://bugzilla.redhat.com/2293383', 'https://bugzilla.redhat.com/2293418', 'https://bugzilla.redhat.com/2293420', 'https://bugzilla.redhat.com/2293444', 'https://bugzilla.redhat.com/2293461', 'https://bugzilla.redhat.com/2293653', 'https://bugzilla.redhat.com/2293657', 'https://bugzilla.redhat.com/2293684', 'https://bugzilla.redhat.com/2293687', 'https://bugzilla.redhat.com/2293700', 'https://bugzilla.redhat.com/2293711', 'https://bugzilla.redhat.com/2294274', 'https://bugzilla.redhat.com/2295914', 'https://bugzilla.redhat.com/2296067', 'https://bugzilla.redhat.com/2297056', 'https://bugzilla.redhat.com/2297474', 'https://bugzilla.redhat.com/2297511', 'https://bugzilla.redhat.com/2298108', 'https://bugzilla.redhat.com/show_bug.cgi?id=2263879', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265650', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265797', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266341', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266347', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266497', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266594', 'https://bugzilla.redhat.com/show_bug.cgi?id=2267787', 'https://bugzilla.redhat.com/show_bug.cgi?id=2268118', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269070', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269211', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270084', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270100', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271686', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271688', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272782', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272795', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273109', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273117', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273174', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273242', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273247', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273427', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273654', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275565', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275573', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275580', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275694', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275748', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275761', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275928', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277840', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278176', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278182', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278218', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278256', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278258', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278277', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278279', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278380', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278484', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278515', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278535', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2280440', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281054', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281133', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281149', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281189', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281190', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281207', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281215', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281221', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281235', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281326', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281360', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281636', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281641', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281664', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281667', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281675', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281682', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281725', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281752', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281758', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281819', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281821', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281833', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281938', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281949', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281968', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282328', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282373', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282479', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282553', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282615', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282623', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282640', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282642', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282690', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282717', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282719', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282727', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282742', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282743', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282759', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282763', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282766', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282772', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282780', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282887', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282896', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282923', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282925', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282950', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283401', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283894', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284417', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284421', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284465', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284477', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284488', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284496', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284500', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284541', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284556', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284571', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284590', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284625', 'https://bugzilla.redhat.com/show_bug.cgi?id=2290408', 'https://bugzilla.redhat.com/show_bug.cgi?id=2292331', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293078', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293250', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293276', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293312', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293316', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293348', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293367', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293371', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293383', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293418', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293420', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293444', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293461', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293653', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293657', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293684', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293687', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2294274', 'https://bugzilla.redhat.com/show_bug.cgi?id=2295914', 'https://bugzilla.redhat.com/show_bug.cgi?id=2296067', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297056', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297558', 'https://bugzilla.redhat.com/show_bug.cgi?id=2298108', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47018', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47257', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47304', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47373', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47408', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47468', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47491', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47548', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47579', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48743', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48747', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52451', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52463', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52469', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52471', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52486', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52530', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52619', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52622', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52623', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52648', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52653', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52662', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52679', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52707', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52730', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52756', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52762', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52764', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52775', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52777', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52784', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52791', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52796', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52803', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52811', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52832', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52845', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52864', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2201', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25739', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26586', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26614', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26640', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26686', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26698', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26704', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26772', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26773', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26802', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26837', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26840', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26843', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26852', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26870', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26878', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26908', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26961', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27011', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27019', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27065', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27388', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27395', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27434', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31076', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33621', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35790', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35801', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35807', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35814', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35824', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35876', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35893', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35897', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35899', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35900', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35910', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35912', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35930', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35937', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35938', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35952', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36000', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36005', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36006', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36016', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36017', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36270', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36489', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36917', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36929', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36933', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36941', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36945', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36950', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36954', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36971', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36978', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36979', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38538', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38555', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38573', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38575', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38596', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38598', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38615', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38627', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39276', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39472', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39476', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39487', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39502', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40974', 'https://errata.almalinux.org/8/ALSA-2024-5102.html', 'https://errata.rockylinux.org/RLSA-2024:5101', 'https://git.kernel.org/linus/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d (6.9-rc1)', 'https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d', 'https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19e', 'https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dced', 'https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8', 'https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797', 'https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983', 'https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596a', 'https://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcf', 'https://linux.oracle.com/cve/CVE-2024-27025.html', 'https://linux.oracle.com/errata/ELSA-2024-5101.html', 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'https://lore.kernel.org/linux-cve-announce/2024050107-CVE-2024-27025-babd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-27025', 'https://www.cve.org/CVERecord?id=CVE-2024-27025'], 'PublishedDate': '2024-05-01T13:15:48.89Z', 'LastModifiedDate': '2024-06-25T22:15:28.24Z'}, {'VulnerabilityID': 'CVE-2024-35928', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35928', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()\n\nThis ensures that the memory mapped by ioremap for adev->rmmio, is\nproperly handled in amdgpu_device_init(). If the function exits early\ndue to an error, the memory is unmapped. If the function completes\nsuccessfully, the memory remains mapped.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/amdgpu_device.c:4337 amdgpu_device_init() warn: 'adev->rmmio' from ioremap() not released on lines: 4035,4045,4051,4058,4068,4337", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35928', 'https://git.kernel.org/linus/eb4f139888f636614dab3bcce97ff61cefc4b3a7 (6.9-rc1)', 'https://git.kernel.org/stable/c/14ac934db851642ea8cd1bd4121c788a8899ef69', 'https://git.kernel.org/stable/c/aa665c3a2aca2ffe31b9645bda278e96dfc3b55c', 'https://git.kernel.org/stable/c/c5f9fe2c1e5023fa096189a8bfba6420aa035587', 'https://git.kernel.org/stable/c/eb4f139888f636614dab3bcce97ff61cefc4b3a7', 'https://lore.kernel.org/linux-cve-announce/2024051915-CVE-2024-35928-ead3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35928', 'https://www.cve.org/CVERecord?id=CVE-2024-35928'], 'PublishedDate': '2024-05-19T11:15:48.93Z', 'LastModifiedDate': '2024-05-20T13:00:04.957Z'}, {'VulnerabilityID': 'CVE-2024-35948', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35948', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bcachefs: Check for journal entries overruning end of sb clean section', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: Check for journal entries overruning end of sb clean section\n\nFix a missing bounds check in superblock validation.\n\nNote that we don't yet have repair code for this case - repair code for\nindividual items is generally low priority, since the whole superblock\nis checksummed, validated prior to write, and we have backups.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-400'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35948', 'https://git.kernel.org/linus/fcdbc1d7a4b638e5d5668de461f320386f3002aa (6.9-rc6)', 'https://git.kernel.org/stable/c/fcdbc1d7a4b638e5d5668de461f320386f3002aa', 'https://lore.kernel.org/linux-cve-announce/2024052043-CVE-2024-35948-a92f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35948', 'https://www.cve.org/CVERecord?id=CVE-2024-35948'], 'PublishedDate': '2024-05-20T10:15:09.44Z', 'LastModifiedDate': '2024-07-03T02:02:27.897Z'}, {'VulnerabilityID': 'CVE-2024-35995', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35995', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Use access_width over bit_width for system memory accesses\n\nTo align with ACPI 6.3+, since bit_width can be any 8-bit value, it\ncannot be depended on to be always on a clean 8b boundary. This was\nuncovered on the Cobalt 100 platform.\n\nSError Interrupt on CPU26, code 0xbe000011 -- SError\n CPU: 26 PID: 1510 Comm: systemd-udevd Not tainted 5.15.2.1-13 #1\n Hardware name: MICROSOFT CORPORATION, BIOS MICROSOFT CORPORATION\n pstate: 62400009 (nZCv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)\n pc : cppc_get_perf_caps+0xec/0x410\n lr : cppc_get_perf_caps+0xe8/0x410\n sp : ffff8000155ab730\n x29: ffff8000155ab730 x28: ffff0080139d0038 x27: ffff0080139d0078\n x26: 0000000000000000 x25: ffff0080139d0058 x24: 00000000ffffffff\n x23: ffff0080139d0298 x22: ffff0080139d0278 x21: 0000000000000000\n x20: ffff00802b251910 x19: ffff0080139d0000 x18: ffffffffffffffff\n x17: 0000000000000000 x16: ffffdc7e111bad04 x15: ffff00802b251008\n x14: ffffffffffffffff x13: ffff013f1fd63300 x12: 0000000000000006\n x11: ffffdc7e128f4420 x10: 0000000000000000 x9 : ffffdc7e111badec\n x8 : ffff00802b251980 x7 : 0000000000000000 x6 : ffff0080139d0028\n x5 : 0000000000000000 x4 : ffff0080139d0018 x3 : 00000000ffffffff\n x2 : 0000000000000008 x1 : ffff8000155ab7a0 x0 : 0000000000000000\n Kernel panic - not syncing: Asynchronous SError Interrupt\n CPU: 26 PID: 1510 Comm: systemd-udevd Not tainted\n5.15.2.1-13 #1\n Hardware name: MICROSOFT CORPORATION, BIOS MICROSOFT CORPORATION\n Call trace:\n dump_backtrace+0x0/0x1e0\n show_stack+0x24/0x30\n dump_stack_lvl+0x8c/0xb8\n dump_stack+0x18/0x34\n panic+0x16c/0x384\n add_taint+0x0/0xc0\n arm64_serror_panic+0x7c/0x90\n arm64_is_fatal_ras_serror+0x34/0xa4\n do_serror+0x50/0x6c\n el1h_64_error_handler+0x40/0x74\n el1h_64_error+0x7c/0x80\n cppc_get_perf_caps+0xec/0x410\n cppc_cpufreq_cpu_init+0x74/0x400 [cppc_cpufreq]\n cpufreq_online+0x2dc/0xa30\n cpufreq_add_dev+0xc0/0xd4\n subsys_interface_register+0x134/0x14c\n cpufreq_register_driver+0x1b0/0x354\n cppc_cpufreq_init+0x1a8/0x1000 [cppc_cpufreq]\n do_one_initcall+0x50/0x250\n do_init_module+0x60/0x27c\n load_module+0x2300/0x2570\n __do_sys_finit_module+0xa8/0x114\n __arm64_sys_finit_module+0x2c/0x3c\n invoke_syscall+0x78/0x100\n el0_svc_common.constprop.0+0x180/0x1a0\n do_el0_svc+0x84/0xa0\n el0_svc+0x2c/0xc0\n el0t_64_sync_handler+0xa4/0x12c\n el0t_64_sync+0x1a4/0x1a8\n\nInstead, use access_width to determine the size and use the offset and\nwidth to shift and mask the bits to read/write out. Make sure to add a\ncheck for system memory since pcc redefines the access_width to\nsubspace id.\n\nIf access_width is not set, then fall back to using bit_width.\n\n[ rjw: Subject and changelog edits, comment adjustments ]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35995', 'https://git.kernel.org/linus/2f4a4d63a193be6fd530d180bb13c3592052904c (6.9-rc1)', 'https://git.kernel.org/stable/c/01fc53be672acae37e611c80cc0b4f3939584de3', 'https://git.kernel.org/stable/c/1b890ae474d19800a6be1696df7fb4d9a41676e4', 'https://git.kernel.org/stable/c/2f4a4d63a193be6fd530d180bb13c3592052904c', 'https://git.kernel.org/stable/c/4949affd5288b867cdf115f5b08d6166b2027f87', 'https://git.kernel.org/stable/c/6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1', 'https://git.kernel.org/stable/c/6dfd79ed04c578f1d9a9a41ba5b2015cf9f03fc3', 'https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2', 'https://lore.kernel.org/linux-cve-announce/2024052021-CVE-2024-35995-abbc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35995', 'https://www.cve.org/CVERecord?id=CVE-2024-35995'], 'PublishedDate': '2024-05-20T10:15:13.597Z', 'LastModifiedDate': '2024-05-20T13:00:04.957Z'}, {'VulnerabilityID': 'CVE-2024-36885', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-36885', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()\n\nCurrently, enabling SG_DEBUG in the kernel will cause nouveau to hit a\nBUG() on startup:\n\n kernel BUG at include/linux/scatterlist.h:187!\n invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 7 PID: 930 Comm: (udev-worker) Not tainted 6.9.0-rc3Lyude-Test+ #30\n Hardware name: MSI MS-7A39/A320M GAMING PRO (MS-7A39), BIOS 1.I0 01/22/2019\n RIP: 0010:sg_init_one+0x85/0xa0\n Code: 69 88 32 01 83 e1 03 f6 c3 03 75 20 a8 01 75 1e 48 09 cb 41 89 54\n 24 08 49 89 1c 24 41 89 6c 24 0c 5b 5d 41 5c e9 7b b9 88 00 <0f> 0b 0f 0b\n 0f 0b 48 8b 05 5e 46 9a 01 eb b2 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffa776017bf6a0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffffa77600d87000 RCX: 000000000000002b\n RDX: 0000000000000001 RSI: 0000000000000000 RDI: ffffa77680d87000\n RBP: 000000000000e000 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff98f4c46aa508 R11: 0000000000000000 R12: ffff98f4c46aa508\n R13: ffff98f4c46aa008 R14: ffffa77600d4a000 R15: ffffa77600d4a018\n FS: 00007feeb5aae980(0000) GS:ffff98f5c4dc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f22cb9a4520 CR3: 00000001043ba000 CR4: 00000000003506f0\n Call Trace:\n \n ? die+0x36/0x90\n ? do_trap+0xdd/0x100\n ? sg_init_one+0x85/0xa0\n ? do_error_trap+0x65/0x80\n ? sg_init_one+0x85/0xa0\n ? exc_invalid_op+0x50/0x70\n ? sg_init_one+0x85/0xa0\n ? asm_exc_invalid_op+0x1a/0x20\n ? sg_init_one+0x85/0xa0\n nvkm_firmware_ctor+0x14a/0x250 [nouveau]\n nvkm_falcon_fw_ctor+0x42/0x70 [nouveau]\n ga102_gsp_booter_ctor+0xb4/0x1a0 [nouveau]\n r535_gsp_oneinit+0xb3/0x15f0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? nvkm_udevice_new+0x95/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? ktime_get+0x47/0xb0\n ? srso_return_thunk+0x5/0x5f\n nvkm_subdev_oneinit_+0x4f/0x120 [nouveau]\n nvkm_subdev_init_+0x39/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n nvkm_subdev_init+0x44/0x90 [nouveau]\n nvkm_device_init+0x166/0x2e0 [nouveau]\n nvkm_udevice_init+0x47/0x70 [nouveau]\n nvkm_object_init+0x41/0x1c0 [nouveau]\n nvkm_ioctl_new+0x16a/0x290 [nouveau]\n ? __pfx_nvkm_client_child_new+0x10/0x10 [nouveau]\n ? __pfx_nvkm_udevice_new+0x10/0x10 [nouveau]\n nvkm_ioctl+0x126/0x290 [nouveau]\n nvif_object_ctor+0x112/0x190 [nouveau]\n nvif_device_ctor+0x23/0x60 [nouveau]\n nouveau_cli_init+0x164/0x640 [nouveau]\n nouveau_drm_device_init+0x97/0x9e0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? pci_update_current_state+0x72/0xb0\n ? srso_return_thunk+0x5/0x5f\n nouveau_drm_probe+0x12c/0x280 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n local_pci_probe+0x45/0xa0\n pci_device_probe+0xc7/0x270\n really_probe+0xe6/0x3a0\n __driver_probe_device+0x87/0x160\n driver_probe_device+0x1f/0xc0\n __driver_attach+0xec/0x1f0\n ? __pfx___driver_attach+0x10/0x10\n bus_for_each_dev+0x88/0xd0\n bus_add_driver+0x116/0x220\n driver_register+0x59/0x100\n ? __pfx_nouveau_drm_init+0x10/0x10 [nouveau]\n do_one_initcall+0x5b/0x320\n do_init_module+0x60/0x250\n init_module_from_file+0x86/0xc0\n idempotent_init_module+0x120/0x2b0\n __x64_sys_finit_module+0x5e/0xb0\n do_syscall_64+0x83/0x160\n ? srso_return_thunk+0x5/0x5f\n entry_SYSCALL_64_after_hwframe+0x71/0x79\n RIP: 0033:0x7feeb5cc20cd\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0\n ff ff 73 01 c3 48 8b 0d 1b cd 0c 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffcf220b2c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n RAX: ffffffffffffffda RBX: 000055fdd2916aa0 RCX: 00007feeb5cc20cd\n RDX: 0000000000000000 RSI: 000055fdd29161e0 RDI: 0000000000000035\n RBP: 00007ffcf220b380 R08: 00007feeb5d8fb20 R09: 00007ffcf220b310\n R10: 000055fdd2909dc0 R11: 0000000000000246 R12: 000055\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-36885', 'https://git.kernel.org/linus/52a6947bf576b97ff8e14bb0a31c5eaf2d0d96e2 (6.9-rc7)', 'https://git.kernel.org/stable/c/1a88c18da464db0ba8ea25196d0a06490f65322e', 'https://git.kernel.org/stable/c/52a6947bf576b97ff8e14bb0a31c5eaf2d0d96e2', 'https://git.kernel.org/stable/c/e05af009302893f39b072811a68fa4a196284c75', 'https://lore.kernel.org/linux-cve-announce/2024053032-CVE-2024-36885-cb0b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-36885', 'https://www.cve.org/CVERecord?id=CVE-2024-36885'], 'PublishedDate': '2024-05-30T16:15:12.067Z', 'LastModifiedDate': '2024-05-30T18:18:58.87Z'}, {'VulnerabilityID': 'CVE-2024-36970', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-36970', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: Use request_module_nowait', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: Use request_module_nowait\n\nThis appears to work around a deadlock regression that came in\nwith the LED merge in 6.9.\n\nThe deadlock happens on my system with 24 iwlwifi radios, so maybe\nit something like all worker threads are busy and some work that needs\nto complete cannot complete.\n\n[also remove unnecessary "load_module" var and now-wrong comment]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-36970', 'https://git.kernel.org/linus/3d913719df14c28c4d3819e7e6d150760222bda4 (6.10-rc1)', 'https://git.kernel.org/stable/c/3d913719df14c28c4d3819e7e6d150760222bda4', 'https://git.kernel.org/stable/c/d20013259539e2fde2deeac85354851097afdf9e', 'https://lore.kernel.org/linux-cve-announce/2024060855-CVE-2024-36970-2eb9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-36970', 'https://www.cve.org/CVERecord?id=CVE-2024-36970'], 'PublishedDate': '2024-06-08T13:15:58.26Z', 'LastModifiedDate': '2024-06-10T02:52:08.267Z'}, {'VulnerabilityID': 'CVE-2024-38581', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-38581', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/mes: fix use-after-free issue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/mes: fix use-after-free issue\n\nDelete fence fallback timer to fix the ramdom\nuse-after-free issue.\n\nv2: move to amdgpu_mes.c', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-38581', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/948255282074d9367e01908b3f5dcf8c10fc9c3d (6.9-rc6)', 'https://git.kernel.org/stable/c/0f98c144c15c8fc0f3176c994bd4e727ef718a5c', 'https://git.kernel.org/stable/c/39cfce75168c11421d70b8c0c65f6133edccb82a', 'https://git.kernel.org/stable/c/70b1bf6d9edc8692d241f59a65f073aec6d501de', 'https://git.kernel.org/stable/c/948255282074d9367e01908b3f5dcf8c10fc9c3d', 'https://linux.oracle.com/cve/CVE-2024-38581.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024061948-CVE-2024-38581-592d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-38581', 'https://www.cve.org/CVERecord?id=CVE-2024-38581'], 'PublishedDate': '2024-06-19T14:15:18.15Z', 'LastModifiedDate': '2024-08-01T20:12:00.623Z'}, {'VulnerabilityID': 'CVE-2024-38608', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-38608', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Fix netif state handling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix netif state handling\n\nmlx5e_suspend cleans resources only if netif_device_present() returns\ntrue. However, mlx5e_resume changes the state of netif, via\nmlx5e_nic_enable, only if reg_state == NETREG_REGISTERED.\nIn the below case, the above leads to NULL-ptr Oops[1] and memory\nleaks:\n\nmlx5e_probe\n _mlx5e_resume\n mlx5e_attach_netdev\n mlx5e_nic_enable <-- netdev not reg, not calling netif_device_attach()\n register_netdev <-- failed for some reason.\nERROR_FLOW:\n _mlx5e_suspend <-- netif_device_present return false, resources aren't freed :(\n\nHence, clean resources in this case as well.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0010 [#1] SMP\nCPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at0xffffffffffffffd6.\nRSP: 0018:ffff888178aaf758 EFLAGS: 00010246\nCall Trace:\n \n ? __die+0x20/0x60\n ? page_fault_oops+0x14c/0x3c0\n ? exc_page_fault+0x75/0x140\n ? asm_exc_page_fault+0x22/0x30\n notifier_call_chain+0x35/0xb0\n blocking_notifier_call_chain+0x3d/0x60\n mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core]\n mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core]\n mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib]\n mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib]\n __mlx5_ib_add+0x34/0xd0 [mlx5_ib]\n mlx5r_probe+0xe1/0x210 [mlx5_ib]\n ? auxiliary_match_id+0x6a/0x90\n auxiliary_bus_probe+0x38/0x80\n ? driver_sysfs_add+0x51/0x80\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n bus_probe_device+0x86/0xa0\n device_add+0x637/0x840\n __auxiliary_device_add+0x3b/0xa0\n add_adev+0xc9/0x140 [mlx5_core]\n mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core]\n mlx5_register_device+0x53/0xa0 [mlx5_core]\n mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core]\n mlx5_init_one+0x3b/0x60 [mlx5_core]\n probe_one+0x44c/0x730 [mlx5_core]\n local_pci_probe+0x3e/0x90\n pci_device_probe+0xbf/0x210\n ? kernfs_create_link+0x5d/0xa0\n ? sysfs_do_create_link_sd+0x60/0xc0\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n pci_bus_add_device+0x54/0x80\n pci_iov_add_virtfn+0x2e6/0x320\n sriov_enable+0x208/0x420\n mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core]\n sriov_numvfs_store+0xae/0x1a0\n kernfs_fop_write_iter+0x10c/0x1a0\n vfs_write+0x291/0x3c0\n ksys_write+0x5f/0xe0\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n CR2: 0000000000000000\n ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-38608', 'https://git.kernel.org/linus/3d5918477f94e4c2f064567875c475468e264644 (6.10-rc1)', 'https://git.kernel.org/stable/c/3d5918477f94e4c2f064567875c475468e264644', 'https://git.kernel.org/stable/c/f7e6cfb864a53af71c5cc904f1cc22215d68f5c6', 'https://linux.oracle.com/cve/CVE-2024-38608.html', 'https://linux.oracle.com/errata/ELSA-2024-5928.html', 'https://lore.kernel.org/linux-cve-announce/2024061920-CVE-2024-38608-4068@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-38608', 'https://www.cve.org/CVERecord?id=CVE-2024-38608'], 'PublishedDate': '2024-06-19T14:15:20.737Z', 'LastModifiedDate': '2024-08-27T15:58:56.9Z'}, {'VulnerabilityID': 'CVE-2024-39293', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-39293', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "xsk: Support redirect to any socket bound to the same umem"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "xsk: Support redirect to any socket bound to the same umem"\n\nThis reverts commit 2863d665ea41282379f108e4da6c8a2366ba66db.\n\nThis patch introduced a potential kernel crash when multiple napi instances\nredirect to the same AF_XDP socket. By removing the queue_index check, it is\npossible for multiple napi instances to access the Rx ring at the same time,\nwhich will result in a corrupted ring state which can lead to a crash when\nflushing the rings in __xsk_flush(). This can happen when the linked list of\nsockets to flush gets corrupted by concurrent accesses. A quick and small fix\nis not possible, so let us revert this for now.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-39293', 'https://git.kernel.org/linus/7fcf26b315bbb728036da0862de6b335da83dff2 (6.10-rc3)', 'https://git.kernel.org/stable/c/19cb40b1064566ea09538289bfcf5bc7ecb9b6f5', 'https://git.kernel.org/stable/c/7fcf26b315bbb728036da0862de6b335da83dff2', 'https://lore.kernel.org/linux-cve-announce/2024062548-CVE-2024-39293-d42a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-39293', 'https://www.cve.org/CVERecord?id=CVE-2024-39293'], 'PublishedDate': '2024-06-25T15:15:13.993Z', 'LastModifiedDate': '2024-06-25T18:50:42.04Z'}, {'VulnerabilityID': 'CVE-2024-39472', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-39472', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix log recovery buffer allocation for the legacy h_size fixup\n\nCommit a70f9fe52daa ("xfs: detect and handle invalid iclog size set by\nmkfs") added a fixup for incorrect h_size values used for the initial\numount record in old xfsprogs versions. Later commit 0c771b99d6c9\n("xfs: clean up calculation of LR header blocks") cleaned up the log\nreover buffer calculation, but stoped using the fixed up h_size value\nto size the log recovery buffer, which can lead to an out of bounds\naccess when the incorrect h_size does not come from the old mkfs\ntool, but a fuzzer.\n\nFix this by open coding xlog_logrec_hblks and taking the fixed h_size\ninto account for this calculation.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:5102', 'https://access.redhat.com/security/cve/CVE-2024-39472', 'https://bugzilla.redhat.com/2263879', 'https://bugzilla.redhat.com/2265645', 'https://bugzilla.redhat.com/2265797', 'https://bugzilla.redhat.com/2266341', 'https://bugzilla.redhat.com/2266347', 'https://bugzilla.redhat.com/2266497', 'https://bugzilla.redhat.com/2267787', 'https://bugzilla.redhat.com/2268118', 'https://bugzilla.redhat.com/2269070', 'https://bugzilla.redhat.com/2269211', 'https://bugzilla.redhat.com/2270084', 'https://bugzilla.redhat.com/2270100', 'https://bugzilla.redhat.com/2271686', 'https://bugzilla.redhat.com/2271688', 'https://bugzilla.redhat.com/2272782', 'https://bugzilla.redhat.com/2272795', 'https://bugzilla.redhat.com/2273109', 'https://bugzilla.redhat.com/2273174', 'https://bugzilla.redhat.com/2273236', 'https://bugzilla.redhat.com/2273242', 'https://bugzilla.redhat.com/2273247', 'https://bugzilla.redhat.com/2273268', 'https://bugzilla.redhat.com/2273427', 'https://bugzilla.redhat.com/2273654', 'https://bugzilla.redhat.com/2275565', 'https://bugzilla.redhat.com/2275573', 'https://bugzilla.redhat.com/2275580', 'https://bugzilla.redhat.com/2275694', 'https://bugzilla.redhat.com/2275711', 'https://bugzilla.redhat.com/2275748', 'https://bugzilla.redhat.com/2275761', 'https://bugzilla.redhat.com/2275928', 'https://bugzilla.redhat.com/2277166', 'https://bugzilla.redhat.com/2277238', 'https://bugzilla.redhat.com/2277840', 'https://bugzilla.redhat.com/2278176', 'https://bugzilla.redhat.com/2278178', 'https://bugzilla.redhat.com/2278182', 'https://bugzilla.redhat.com/2278218', 'https://bugzilla.redhat.com/2278256', 'https://bugzilla.redhat.com/2278258', 'https://bugzilla.redhat.com/2278277', 'https://bugzilla.redhat.com/2278279', 'https://bugzilla.redhat.com/2278380', 'https://bugzilla.redhat.com/2278484', 'https://bugzilla.redhat.com/2278515', 'https://bugzilla.redhat.com/2278535', 'https://bugzilla.redhat.com/2278539', 'https://bugzilla.redhat.com/2278989', 'https://bugzilla.redhat.com/2280440', 'https://bugzilla.redhat.com/2281054', 'https://bugzilla.redhat.com/2281133', 'https://bugzilla.redhat.com/2281149', 'https://bugzilla.redhat.com/2281207', 'https://bugzilla.redhat.com/2281215', 'https://bugzilla.redhat.com/2281221', 'https://bugzilla.redhat.com/2281235', 'https://bugzilla.redhat.com/2281268', 'https://bugzilla.redhat.com/2281326', 'https://bugzilla.redhat.com/2281360', 'https://bugzilla.redhat.com/2281510', 'https://bugzilla.redhat.com/2281519', 'https://bugzilla.redhat.com/2281636', 'https://bugzilla.redhat.com/2281641', 'https://bugzilla.redhat.com/2281664', 'https://bugzilla.redhat.com/2281667', 'https://bugzilla.redhat.com/2281672', 'https://bugzilla.redhat.com/2281675', 'https://bugzilla.redhat.com/2281682', 'https://bugzilla.redhat.com/2281725', 'https://bugzilla.redhat.com/2281752', 'https://bugzilla.redhat.com/2281758', 'https://bugzilla.redhat.com/2281819', 'https://bugzilla.redhat.com/2281821', 'https://bugzilla.redhat.com/2281833', 'https://bugzilla.redhat.com/2281938', 'https://bugzilla.redhat.com/2281949', 'https://bugzilla.redhat.com/2281968', 'https://bugzilla.redhat.com/2281989', 'https://bugzilla.redhat.com/2282328', 'https://bugzilla.redhat.com/2282373', 'https://bugzilla.redhat.com/2282479', 'https://bugzilla.redhat.com/2282553', 'https://bugzilla.redhat.com/2282615', 'https://bugzilla.redhat.com/2282623', 'https://bugzilla.redhat.com/2282640', 'https://bugzilla.redhat.com/2282642', 'https://bugzilla.redhat.com/2282645', 'https://bugzilla.redhat.com/2282717', 'https://bugzilla.redhat.com/2282719', 'https://bugzilla.redhat.com/2282727', 'https://bugzilla.redhat.com/2282742', 'https://bugzilla.redhat.com/2282743', 'https://bugzilla.redhat.com/2282744', 'https://bugzilla.redhat.com/2282759', 'https://bugzilla.redhat.com/2282763', 'https://bugzilla.redhat.com/2282766', 'https://bugzilla.redhat.com/2282772', 'https://bugzilla.redhat.com/2282780', 'https://bugzilla.redhat.com/2282887', 'https://bugzilla.redhat.com/2282896', 'https://bugzilla.redhat.com/2282923', 'https://bugzilla.redhat.com/2282925', 'https://bugzilla.redhat.com/2282950', 'https://bugzilla.redhat.com/2283401', 'https://bugzilla.redhat.com/2283894', 'https://bugzilla.redhat.com/2284400', 'https://bugzilla.redhat.com/2284417', 'https://bugzilla.redhat.com/2284421', 'https://bugzilla.redhat.com/2284474', 'https://bugzilla.redhat.com/2284477', 'https://bugzilla.redhat.com/2284488', 'https://bugzilla.redhat.com/2284496', 'https://bugzilla.redhat.com/2284500', 'https://bugzilla.redhat.com/2284513', 'https://bugzilla.redhat.com/2284519', 'https://bugzilla.redhat.com/2284539', 'https://bugzilla.redhat.com/2284541', 'https://bugzilla.redhat.com/2284556', 'https://bugzilla.redhat.com/2284571', 'https://bugzilla.redhat.com/2284590', 'https://bugzilla.redhat.com/2284625', 'https://bugzilla.redhat.com/2290408', 'https://bugzilla.redhat.com/2292331', 'https://bugzilla.redhat.com/2293078', 'https://bugzilla.redhat.com/2293250', 'https://bugzilla.redhat.com/2293276', 'https://bugzilla.redhat.com/2293312', 'https://bugzilla.redhat.com/2293316', 'https://bugzilla.redhat.com/2293348', 'https://bugzilla.redhat.com/2293371', 'https://bugzilla.redhat.com/2293383', 'https://bugzilla.redhat.com/2293418', 'https://bugzilla.redhat.com/2293420', 'https://bugzilla.redhat.com/2293444', 'https://bugzilla.redhat.com/2293461', 'https://bugzilla.redhat.com/2293653', 'https://bugzilla.redhat.com/2293657', 'https://bugzilla.redhat.com/2293684', 'https://bugzilla.redhat.com/2293687', 'https://bugzilla.redhat.com/2293700', 'https://bugzilla.redhat.com/2293711', 'https://bugzilla.redhat.com/2294274', 'https://bugzilla.redhat.com/2295914', 'https://bugzilla.redhat.com/2296067', 'https://bugzilla.redhat.com/2297056', 'https://bugzilla.redhat.com/2297474', 'https://bugzilla.redhat.com/2297511', 'https://bugzilla.redhat.com/2298108', 'https://bugzilla.redhat.com/show_bug.cgi?id=2263879', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265650', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265797', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266341', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266347', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266497', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266594', 'https://bugzilla.redhat.com/show_bug.cgi?id=2267787', 'https://bugzilla.redhat.com/show_bug.cgi?id=2268118', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269070', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269211', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270084', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270100', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271686', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271688', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272782', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272795', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273109', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273117', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273174', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273242', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273247', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273427', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273654', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275565', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275573', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275580', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275694', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275748', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275761', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275928', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277840', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278176', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278182', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278218', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278256', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278258', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278277', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278279', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278380', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278484', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278515', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278535', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2280440', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281054', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281133', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281149', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281189', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281190', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281207', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281215', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281221', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281235', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281326', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281360', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281636', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281641', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281664', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281667', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281675', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281682', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281725', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281752', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281758', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281819', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281821', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281833', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281938', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281949', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281968', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282328', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282373', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282479', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282553', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282615', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282623', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282640', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282642', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282690', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282717', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282719', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282727', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282742', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282743', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282759', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282763', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282766', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282772', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282780', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282887', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282896', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282923', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282925', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282950', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283401', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283894', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284417', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284421', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284465', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284477', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284488', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284496', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284500', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284541', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284556', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284571', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284590', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284625', 'https://bugzilla.redhat.com/show_bug.cgi?id=2290408', 'https://bugzilla.redhat.com/show_bug.cgi?id=2292331', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293078', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293250', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293276', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293312', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293316', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293348', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293367', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293371', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293383', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293418', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293420', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293444', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293461', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293653', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293657', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293684', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293687', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2294274', 'https://bugzilla.redhat.com/show_bug.cgi?id=2295914', 'https://bugzilla.redhat.com/show_bug.cgi?id=2296067', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297056', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297558', 'https://bugzilla.redhat.com/show_bug.cgi?id=2298108', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47018', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47257', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47304', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47373', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47408', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47468', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47491', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47548', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47579', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48743', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48747', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52451', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52463', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52469', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52471', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52486', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52530', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52619', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52622', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52623', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52648', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52653', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52662', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52679', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52707', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52730', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52756', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52762', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52764', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52775', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52777', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52784', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52791', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52796', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52803', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52811', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52832', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52845', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52864', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2201', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25739', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26586', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26614', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26640', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26686', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26698', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26704', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26772', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26773', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26802', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26837', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26840', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26843', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26852', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26870', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26878', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26908', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26961', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27011', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27019', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27065', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27388', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27395', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27434', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31076', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33621', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35790', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35801', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35807', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35814', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35824', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35876', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35893', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35897', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35899', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35900', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35910', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35912', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35930', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35937', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35938', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35952', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36000', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36005', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36006', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36016', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36017', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36270', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36489', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36917', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36929', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36933', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36941', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36945', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36950', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36954', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36971', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36978', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36979', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38538', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38555', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38573', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38575', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38596', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38598', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38615', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38627', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39276', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39472', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39476', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39487', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39502', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40974', 'https://errata.almalinux.org/8/ALSA-2024-5102.html', 'https://errata.rockylinux.org/RLSA-2024:5101', 'https://git.kernel.org/linus/45cf976008ddef4a9c9a30310c9b4fb2a9a6602a (6.10-rc1)', 'https://git.kernel.org/stable/c/45cf976008ddef4a9c9a30310c9b4fb2a9a6602a', 'https://git.kernel.org/stable/c/57835c0e7152e36b03875dd6c56dfeed685c1b1f', 'https://git.kernel.org/stable/c/c2389c074973aa94e34992e7f66dac0de37595b5', 'https://git.kernel.org/stable/c/f754591b17d0ee91c2b45fe9509d0cdc420527cb', 'https://linux.oracle.com/cve/CVE-2024-39472.html', 'https://linux.oracle.com/errata/ELSA-2024-5101.html', 'https://lore.kernel.org/linux-cve-announce/2024070512-CVE-2024-39472-f977@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-39472', 'https://www.cve.org/CVERecord?id=CVE-2024-39472'], 'PublishedDate': '2024-07-05T07:15:10.02Z', 'LastModifiedDate': '2024-08-19T05:15:06.543Z'}, {'VulnerabilityID': 'CVE-2024-41008', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: change vm->task_info handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: change vm->task_info handling\n\nThis patch changes the handling and lifecycle of vm->task_info object.\nThe major changes are:\n- vm->task_info is a dynamically allocated ptr now, and its uasge is\n reference counted.\n- introducing two new helper funcs for task_info lifecycle management\n - amdgpu_vm_get_task_info: reference counts up task_info before\n returning this info\n - amdgpu_vm_put_task_info: reference counts down task_info\n- last put to task_info() frees task_info from the vm.\n\nThis patch also does logistical changes required for existing usage\nof vm->task_info.\n\nV2: Do not block all the prints when task_info not found (Felix)\n\nV3: Fixed review comments from Felix\n - Fix wrong indentation\n - No debug message for -ENOMEM\n - Add NULL check for task_info\n - Do not duplicate the debug messages (ti vs no ti)\n - Get first reference of task_info in vm_init(), put last\n in vm_fini()\n\nV4: Fixed review comments from Felix\n - fix double reference increment in create_task_info\n - change amdgpu_vm_get_task_info_pasid\n - additional changes in amdgpu_gem.c while porting', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41008', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c (6.9-rc1)', 'https://git.kernel.org/stable/c/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c', 'https://linux.oracle.com/cve/CVE-2024-41008.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/20240716080357.2696435-2-lee@kernel.org/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41008', 'https://www.cve.org/CVERecord?id=CVE-2024-41008'], 'PublishedDate': '2024-07-16T08:15:02.24Z', 'LastModifiedDate': '2024-07-16T13:43:58.773Z'}, {'VulnerabilityID': 'CVE-2024-41009', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41009', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix overrunning reservations in ringbuf', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix overrunning reservations in ringbuf\n\nThe BPF ring buffer internally is implemented as a power-of-2 sized circular\nbuffer, with two logical and ever-increasing counters: consumer_pos is the\nconsumer counter to show which logical position the consumer consumed the\ndata, and producer_pos which is the producer counter denoting the amount of\ndata reserved by all producers.\n\nEach time a record is reserved, the producer that "owns" the record will\nsuccessfully advance producer counter. In user space each time a record is\nread, the consumer of the data advanced the consumer counter once it finished\nprocessing. Both counters are stored in separate pages so that from user\nspace, the producer counter is read-only and the consumer counter is read-write.\n\nOne aspect that simplifies and thus speeds up the implementation of both\nproducers and consumers is how the data area is mapped twice contiguously\nback-to-back in the virtual memory, allowing to not take any special measures\nfor samples that have to wrap around at the end of the circular buffer data\narea, because the next page after the last data page would be first data page\nagain, and thus the sample will still appear completely contiguous in virtual\nmemory.\n\nEach record has a struct bpf_ringbuf_hdr { u32 len; u32 pg_off; } header for\nbook-keeping the length and offset, and is inaccessible to the BPF program.\nHelpers like bpf_ringbuf_reserve() return `(void *)hdr + BPF_RINGBUF_HDR_SZ`\nfor the BPF program to use. Bing-Jhong and Muhammad reported that it is however\npossible to make a second allocated memory chunk overlapping with the first\nchunk and as a result, the BPF program is now able to edit first chunk\'s\nheader.\n\nFor example, consider the creation of a BPF_MAP_TYPE_RINGBUF map with size\nof 0x4000. Next, the consumer_pos is modified to 0x3000 /before/ a call to\nbpf_ringbuf_reserve() is made. This will allocate a chunk A, which is in\n[0x0,0x3008], and the BPF program is able to edit [0x8,0x3008]. Now, lets\nallocate a chunk B with size 0x3000. This will succeed because consumer_pos\nwas edited ahead of time to pass the `new_prod_pos - cons_pos > rb->mask`\ncheck. Chunk B will be in range [0x3008,0x6010], and the BPF program is able\nto edit [0x3010,0x6010]. Due to the ring buffer memory layout mentioned\nearlier, the ranges [0x0,0x4000] and [0x4000,0x8000] point to the same data\npages. This means that chunk B at [0x4000,0x4008] is chunk A\'s header.\nbpf_ringbuf_submit() / bpf_ringbuf_discard() use the header\'s pg_off to then\nlocate the bpf_ringbuf itself via bpf_ringbuf_restore_from_rec(). Once chunk\nB modified chunk A\'s header, then bpf_ringbuf_commit() refers to the wrong\npage and could cause a crash.\n\nFix it by calculating the oldest pending_pos and check whether the range\nfrom the oldest outstanding record to the newest would span beyond the ring\nbuffer size. If that is the case, then reject the request. We\'ve tested with\nthe ring buffer benchmark in BPF selftests (./benchs/run_bench_ringbufs.sh)\nbefore/after the fix and while it seems a bit slower on some benchmarks, it\nis still not significantly enough to matter.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41009', 'https://git.kernel.org/linus/cfa1a2329a691ffd991fcf7248a57d752e712881 (6.10-rc6)', 'https://git.kernel.org/stable/c/0f98f40eb1ed52af8b81f61901b6c0289ff59de4', 'https://git.kernel.org/stable/c/47416c852f2a04d348ea66ee451cbdcf8119f225', 'https://git.kernel.org/stable/c/511804ab701c0503b72eac08217eabfd366ba069', 'https://git.kernel.org/stable/c/be35504b959f2749bab280f4671e8df96dcf836f', 'https://git.kernel.org/stable/c/cfa1a2329a691ffd991fcf7248a57d752e712881', 'https://git.kernel.org/stable/c/d1b9df0435bc61e0b44f578846516df8ef476686', 'https://lore.kernel.org/linux-cve-announce/2024071715-CVE-2024-41009-cac5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41009', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-41009'], 'PublishedDate': '2024-07-17T07:15:01.973Z', 'LastModifiedDate': '2024-07-29T07:15:04.56Z'}, {'VulnerabilityID': 'CVE-2024-41013', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: don't walk off the end of a directory data block', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't walk off the end of a directory data block\n\nThis adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry\nto make sure don't stray beyond valid memory region. Before patching, the\nloop simply checks that the start offset of the dup and dep is within the\nrange. So in a crafted image, if last entry is xfs_dir2_data_unused, we\ncan change dup->length to dup->length-1 and leave 1 byte of space. In the\nnext traversal, this space will be considered as dup or dep. We may\nencounter an out of bound read when accessing the fixed members.\n\nIn the patch, we make sure that the remaining bytes large enough to hold\nan unused entry before accessing xfs_dir2_data_unused and\nxfs_dir2_data_unused is XFS_DIR2_DATA_ALIGN byte aligned. We also make\nsure that the remaining bytes large enough to hold a dirent with a\nsingle-byte name before accessing xfs_dir2_data_entry.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41013', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/0c7fcdb6d06cdf8b19b57c17605215b06afa864a (6.11-rc1)', 'https://git.kernel.org/stable/c/0c7fcdb6d06cdf8b19b57c17605215b06afa864a', 'https://linux.oracle.com/cve/CVE-2024-41013.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024072908-CVE-2024-41013-2996@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41013', 'https://www.cve.org/CVERecord?id=CVE-2024-41013'], 'PublishedDate': '2024-07-29T07:15:05.43Z', 'LastModifiedDate': '2024-07-29T14:12:08.783Z'}, {'VulnerabilityID': 'CVE-2024-41014', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41014', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: add bounds checking to xlog_recover_process_data', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: add bounds checking to xlog_recover_process_data\n\nThere is a lack of verification of the space occupied by fixed members\nof xlog_op_header in the xlog_recover_process_data.\n\nWe can create a crafted image to trigger an out of bounds read by\nfollowing these steps:\n 1) Mount an image of xfs, and do some file operations to leave records\n 2) Before umounting, copy the image for subsequent steps to simulate\n abnormal exit. Because umount will ensure that tail_blk and\n head_blk are the same, which will result in the inability to enter\n xlog_recover_process_data\n 3) Write a tool to parse and modify the copied image in step 2\n 4) Make the end of the xlog_op_header entries only 1 byte away from\n xlog_rec_header->h_size\n 5) xlog_rec_header->h_num_logops++\n 6) Modify xlog_rec_header->h_crc\n\nFix:\nAdd a check to make sure there is sufficient space to access fixed members\nof xlog_op_header.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41014', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/fb63435b7c7dc112b1ae1baea5486e0a6e27b196 (6.11-rc1)', 'https://git.kernel.org/stable/c/fb63435b7c7dc112b1ae1baea5486e0a6e27b196', 'https://linux.oracle.com/cve/CVE-2024-41014.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41014-9186@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41014', 'https://www.cve.org/CVERecord?id=CVE-2024-41014'], 'PublishedDate': '2024-07-29T07:15:05.81Z', 'LastModifiedDate': '2024-07-29T14:12:08.783Z'}, {'VulnerabilityID': 'CVE-2024-41016', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41016', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()\n\nxattr in ocfs2 maybe 'non-indexed', which saved with additional space\nrequested. It's better to check if the memory is out of bound before\nmemcmp, although this possibility mainly comes from crafted poisonous\nimages.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41016', 'https://git.kernel.org/linus/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 (6.11-rc1)', 'https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637', 'https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262', 'https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e', 'https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e', 'https://git.kernel.org/stable/c/cfb926051fab19b10d1e65976211f364aa820180', 'https://git.kernel.org/stable/c/e4ffea01adf3323c821b6f37e9577d2d400adbaa', 'https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41016-fcf9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41016', 'https://www.cve.org/CVERecord?id=CVE-2024-41016'], 'PublishedDate': '2024-07-29T07:15:06.293Z', 'LastModifiedDate': '2024-10-17T14:15:07.01Z'}, {'VulnerabilityID': 'CVE-2024-41024', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41024', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: misc: fastrpc: Restrict untrusted app to attach to privileged PD', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Restrict untrusted app to attach to privileged PD\n\nUntrusted application with access to only non-secure fastrpc device\nnode can attach to root_pd or static PDs if it can make the respective\ninit request. This can cause problems as the untrusted application\ncan send bad requests to root_pd or static PDs. Add changes to reject\nattach to privileged PDs if the request is being made using non-secure\nfastrpc device node.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41024', 'https://git.kernel.org/linus/bab2f5e8fd5d2f759db26b78d9db57412888f187 (6.10)', 'https://git.kernel.org/stable/c/2eb973ee4770a26d9b5e292b58ad29822d321c7f', 'https://git.kernel.org/stable/c/5e305b5986dc52122a9368a1461f0c13e1de3fd6', 'https://git.kernel.org/stable/c/bab2f5e8fd5d2f759db26b78d9db57412888f187', 'https://git.kernel.org/stable/c/c69fd8afacebfdf2f8a1ee1ea7e0723786529874', 'https://git.kernel.org/stable/c/ea13bd807f1cef1af375d999980a9b9794c789b6', 'https://lore.kernel.org/all/20240628114501.14310-7-srinivas.kandagatla@linaro.org/', 'https://lore.kernel.org/linux-cve-announce/2024072919-CVE-2024-41024-be39@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41024', 'https://www.cve.org/CVERecord?id=CVE-2024-41024'], 'PublishedDate': '2024-07-29T15:15:11.27Z', 'LastModifiedDate': '2024-08-29T17:15:07.913Z'}, {'VulnerabilityID': 'CVE-2024-42107', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42107', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: ice: Don't process extts if PTP is disabled", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Don't process extts if PTP is disabled\n\nThe ice_ptp_extts_event() function can race with ice_ptp_release() and\nresult in a NULL pointer dereference which leads to a kernel panic.\n\nPanic occurs because the ice_ptp_extts_event() function calls\nptp_clock_event() with a NULL pointer. The ice driver has already\nreleased the PTP clock by the time the interrupt for the next external\ntimestamp event occurs.\n\nTo fix this, modify the ice_ptp_extts_event() function to check the\nPTP state and bail early if PTP is not ready.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42107', 'https://git.kernel.org/linus/996422e3230e41468f652d754fefd1bdbcd4604e (6.10-rc7)', 'https://git.kernel.org/stable/c/1c4e524811918600683b1ea87a5e0fc2db64fa9b', 'https://git.kernel.org/stable/c/996422e3230e41468f652d754fefd1bdbcd4604e', 'https://lore.kernel.org/linux-cve-announce/2024073020-CVE-2024-42107-65cc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42107', 'https://www.cve.org/CVERecord?id=CVE-2024-42107'], 'PublishedDate': '2024-07-30T08:15:03.22Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42116', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42116', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: igc: fix a log entry using uninitialized netdev', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nigc: fix a log entry using uninitialized netdev\n\nDuring successful probe, igc logs this:\n\n[ 5.133667] igc 0000:01:00.0 (unnamed net_device) (uninitialized): PHC added\n ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe reason is that igc_ptp_init() is called very early, even before\nregister_netdev() has been called. So the netdev_info() call works\non a partially uninitialized netdev.\n\nFix this by calling igc_ptp_init() after register_netdev(), right\nafter the media autosense check, just as in igb. Add a comment,\njust as in igb.\n\nNow the log message is fine:\n\n[ 5.200987] igc 0000:01:00.0 eth0: PHC added', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42116', 'https://git.kernel.org/linus/86167183a17e03ec77198897975e9fdfbd53cb0b (6.10-rc1)', 'https://git.kernel.org/stable/c/86167183a17e03ec77198897975e9fdfbd53cb0b', 'https://git.kernel.org/stable/c/96839f3f588236593de36465f142b0126267f8b6', 'https://git.kernel.org/stable/c/98c8958980e829f023a490b9a9816ca1fe2f8b79', 'https://git.kernel.org/stable/c/991f036cabc3d13e886a37faeea1b6800181fdda', 'https://git.kernel.org/stable/c/d478ec838cf2b1e1051a8709cfc744fe1c03110f', 'https://linux.oracle.com/cve/CVE-2024-42116.html', 'https://linux.oracle.com/errata/ELSA-2024-12618.html', 'https://lore.kernel.org/linux-cve-announce/2024073023-CVE-2024-42116-b420@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42116', 'https://www.cve.org/CVERecord?id=CVE-2024-42116'], 'PublishedDate': '2024-07-30T08:15:03.95Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42122', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42122', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add NULL pointer check for kzalloc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL pointer check for kzalloc\n\n[Why & How]\nCheck return pointer of kzalloc before using it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42122', 'https://git.kernel.org/linus/8e65a1b7118acf6af96449e1e66b7adbc9396912 (6.10-rc1)', 'https://git.kernel.org/stable/c/062edd612fcd300f0f79a36fca5b8b6a5e2fce70', 'https://git.kernel.org/stable/c/8e65a1b7118acf6af96449e1e66b7adbc9396912', 'https://lore.kernel.org/linux-cve-announce/2024073025-CVE-2024-42122-2f70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42122', 'https://www.cve.org/CVERecord?id=CVE-2024-42122'], 'PublishedDate': '2024-07-30T08:15:04.43Z', 'LastModifiedDate': '2024-09-16T13:49:27.837Z'}, {'VulnerabilityID': 'CVE-2024-42125', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42125', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw89: fw: scan offload prohibit all 6 GHz channel if no 6 GHz sband', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fw: scan offload prohibit all 6 GHz channel if no 6 GHz sband\n\nWe have some policy via BIOS to block uses of 6 GHz. In this case, 6 GHz\nsband will be NULL even if it is WiFi 7 chip. So, add NULL handling here\nto avoid crash.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42125', 'https://git.kernel.org/linus/bb38626f3f97e16e6d368a9ff6daf320f3fe31d9 (6.10-rc1)', 'https://git.kernel.org/stable/c/bb38626f3f97e16e6d368a9ff6daf320f3fe31d9', 'https://git.kernel.org/stable/c/ce4ba62f8bc5195a9a0d49c6235a9c99e619cadc', 'https://lore.kernel.org/linux-cve-announce/2024073026-CVE-2024-42125-b515@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42125', 'https://www.cve.org/CVERecord?id=CVE-2024-42125'], 'PublishedDate': '2024-07-30T08:15:04.667Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42139', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42139', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Fix improper extts handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix improper extts handling\n\nExtts events are disabled and enabled by the application ts2phc.\nHowever, in case where the driver is removed when the application is\nrunning, a specific extts event remains enabled and can cause a kernel\ncrash.\nAs a side effect, when the driver is reloaded and application is started\nagain, remaining extts event for the channel from a previous run will\nkeep firing and the message "extts on unexpected channel" might be\nprinted to the user.\n\nTo avoid that, extts events shall be disabled when PTP is released.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42139', 'https://git.kernel.org/linus/00d3b4f54582d4e4a02cda5886bb336eeab268cc (6.10-rc7)', 'https://git.kernel.org/stable/c/00d3b4f54582d4e4a02cda5886bb336eeab268cc', 'https://git.kernel.org/stable/c/9f69b31ae9e25dec27ad31fbc64dd99af16ee3d3', 'https://lore.kernel.org/linux-cve-announce/2024073030-CVE-2024-42139-f8ef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42139', 'https://www.cve.org/CVERecord?id=CVE-2024-42139'], 'PublishedDate': '2024-07-30T08:15:05.757Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42154', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42154', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp_metrics: validate source addr length', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_metrics: validate source addr length\n\nI don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4\nis at least 4 bytes long, and the policy doesn't have an entry\nfor this attribute at all (neither does it for IPv6 but v6 is\nmanually validated).", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42154', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/66be40e622e177316ae81717aa30057ba9e61dff (6.10-rc7)', 'https://git.kernel.org/stable/c/19d997b59fa1fd7a02e770ee0881c0652b9c32c9', 'https://git.kernel.org/stable/c/2a2e79dbe2236a1289412d2044994f7ab419b44c', 'https://git.kernel.org/stable/c/31f03bb04146c1c6df6c03e9f45401f5f5a985d3', 'https://git.kernel.org/stable/c/3d550dd5418729a6e77fe7721d27adea7152e321', 'https://git.kernel.org/stable/c/66be40e622e177316ae81717aa30057ba9e61dff', 'https://git.kernel.org/stable/c/8c2debdd170e395934ac0e039748576dfde14e99', 'https://git.kernel.org/stable/c/cdffc358717e436bb67122bb82c1a2a26e050f98', 'https://git.kernel.org/stable/c/ef7c428b425beeb52b894e16f1c4b629d6cebfb6', 'https://linux.oracle.com/cve/CVE-2024-42154.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024073034-CVE-2024-42154-cf82@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42154', 'https://ubuntu.com/security/notices/USN-7003-1', 'https://ubuntu.com/security/notices/USN-7003-2', 'https://ubuntu.com/security/notices/USN-7003-3', 'https://ubuntu.com/security/notices/USN-7003-4', 'https://ubuntu.com/security/notices/USN-7003-5', 'https://ubuntu.com/security/notices/USN-7006-1', 'https://ubuntu.com/security/notices/USN-7007-1', 'https://ubuntu.com/security/notices/USN-7007-2', 'https://ubuntu.com/security/notices/USN-7007-3', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://ubuntu.com/security/notices/USN-7019-1', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://ubuntu.com/security/notices/USN-7039-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42154'], 'PublishedDate': '2024-07-30T08:15:06.933Z', 'LastModifiedDate': '2024-10-01T19:32:18.31Z'}, {'VulnerabilityID': 'CVE-2024-42159', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42159', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: mpi3mr: Sanitise num_phys', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Sanitise num_phys\n\nInformation is stored in mr_sas_port->phy_mask, values larger then size of\nthis field shouldn't be allowed.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42159', 'https://git.kernel.org/linus/3668651def2c1622904e58b0280ee93121f2b10b (6.10-rc1)', 'https://git.kernel.org/stable/c/3668651def2c1622904e58b0280ee93121f2b10b', 'https://git.kernel.org/stable/c/586b41060113ae43032ec6c4a16d518cef5da6e0', 'https://git.kernel.org/stable/c/b869ec89d2ee923d46608b76e54c006680c9b4df', 'https://git.kernel.org/stable/c/c8707901b53a48106d7501bdbd0350cefaefa4cf', 'https://linux.oracle.com/cve/CVE-2024-42159.html', 'https://linux.oracle.com/errata/ELSA-2024-12682.html', 'https://lore.kernel.org/linux-cve-announce/2024073036-CVE-2024-42159-c19e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42159', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42159'], 'PublishedDate': '2024-07-30T08:15:07.3Z', 'LastModifiedDate': '2024-08-02T14:29:46.24Z'}, {'VulnerabilityID': 'CVE-2024-42160', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42160', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: check validation of fault attrs in f2fs_build_fault_attr()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: check validation of fault attrs in f2fs_build_fault_attr()\n\n- It missed to check validation of fault attrs in parse_options(),\nlet's fix to add check condition in f2fs_build_fault_attr().\n- Use f2fs_build_fault_attr() in __sbi_store() to clean up code.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42160', 'https://git.kernel.org/linus/4ed886b187f47447ad559619c48c086f432d2b77 (6.10-rc1)', 'https://git.kernel.org/stable/c/44958ca9e400f57bd0478115519ffc350fcee61e', 'https://git.kernel.org/stable/c/4ed886b187f47447ad559619c48c086f432d2b77', 'https://git.kernel.org/stable/c/bc84dd2c33e0c10fd90d60f0cfc0bfb504d4692d', 'https://git.kernel.org/stable/c/ecb641f424d6d1f055d149a15b892edcc92c504b', 'https://lore.kernel.org/linux-cve-announce/2024073036-CVE-2024-42160-c733@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42160', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7022-1', 'https://ubuntu.com/security/notices/USN-7022-2', 'https://ubuntu.com/security/notices/USN-7022-3', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42160'], 'PublishedDate': '2024-07-30T08:15:07.37Z', 'LastModifiedDate': '2024-08-02T14:29:26.33Z'}, {'VulnerabilityID': 'CVE-2024-42224', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42224', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: mv88e6xxx: Correct check for empty list', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Correct check for empty list\n\nSince commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO\nbusses") mv88e6xxx_default_mdio_bus() has checked that the\nreturn value of list_first_entry() is non-NULL.\n\nThis appears to be intended to guard against the list chip->mdios being\nempty. However, it is not the correct check as the implementation of\nlist_first_entry is not designed to return NULL for empty lists.\n\nInstead, use list_first_entry_or_null() which does return NULL if the\nlist is empty.\n\nFlagged by Smatch.\nCompile tested only.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 6.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42224', 'https://git.kernel.org/linus/4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b (6.10-rc1)', 'https://git.kernel.org/stable/c/2a2fe25a103cef73cde356e6d09da10f607e93f5', 'https://git.kernel.org/stable/c/3bf8d70e1455f87856640c3433b3660a31001618', 'https://git.kernel.org/stable/c/3f25b5f1635449036692a44b771f39f772190c1d', 'https://git.kernel.org/stable/c/47d28dde172696031c880c5778633cdca30394ee', 'https://git.kernel.org/stable/c/4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b', 'https://git.kernel.org/stable/c/8c2c3cca816d074c75a2801d1ca0dea7b0148114', 'https://git.kernel.org/stable/c/aa03f591ef31ba603a4a99d05d25a0f21ab1cd89', 'https://git.kernel.org/stable/c/f75625db838ade28f032dacd0f0c8baca42ecde4', 'https://linux.oracle.com/cve/CVE-2024-42224.html', 'https://linux.oracle.com/errata/ELSA-2024-12779.html', 'https://lore.kernel.org/linux-cve-announce/2024073037-CVE-2024-42224-863a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42224', 'https://ubuntu.com/security/notices/USN-7003-1', 'https://ubuntu.com/security/notices/USN-7003-2', 'https://ubuntu.com/security/notices/USN-7003-3', 'https://ubuntu.com/security/notices/USN-7003-4', 'https://ubuntu.com/security/notices/USN-7003-5', 'https://ubuntu.com/security/notices/USN-7006-1', 'https://ubuntu.com/security/notices/USN-7007-1', 'https://ubuntu.com/security/notices/USN-7007-2', 'https://ubuntu.com/security/notices/USN-7007-3', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://ubuntu.com/security/notices/USN-7019-1', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42224'], 'PublishedDate': '2024-07-30T08:15:07.667Z', 'LastModifiedDate': '2024-09-25T15:55:09.027Z'}, {'VulnerabilityID': 'CVE-2024-42228', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42228', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc\n\nInitialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001.\nV2: To really improve the handling we would actually\n need to have a separate value of 0xffffffff.(Christian)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 6.3}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42228', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/88a9a467c548d0b3c7761b4fd54a68e70f9c0944 (6.10-rc1)', 'https://git.kernel.org/stable/c/3b505759447637dcccb50cbd98ec6f8d2a04fc46', 'https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef', 'https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944', 'https://git.kernel.org/stable/c/9ee1534ecdd5b4c013064663502d7fde824d2144', 'https://git.kernel.org/stable/c/d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8', 'https://git.kernel.org/stable/c/da6a85d197888067e8d38b5d22c986b5b5cab712', 'https://git.kernel.org/stable/c/df02642c21c984303fe34c3f7d72965792fb1a15', 'https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440', 'https://linux.oracle.com/cve/CVE-2024-42228.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024073038-CVE-2024-42228-86f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42228', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7022-1', 'https://ubuntu.com/security/notices/USN-7022-2', 'https://ubuntu.com/security/notices/USN-7022-3', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://ubuntu.com/security/notices/USN-7039-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42228'], 'PublishedDate': '2024-07-30T08:15:07.96Z', 'LastModifiedDate': '2024-09-04T12:15:04.577Z'}, {'VulnerabilityID': 'CVE-2024-42258', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42258', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines\n\nYves-Alexis Perez reported commit 4ef9ad19e176 ("mm: huge_memory: don\'t\nforce huge page alignment on 32 bit") didn\'t work for x86_32 [1]. It is\nbecause x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT.\n\n!CONFIG_64BIT should cover all 32 bit machines.\n\n[1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42258', 'https://git.kernel.org/linus/d9592025000b3cf26c742f3505da7b83aedc26d5 (6.11-rc1)', 'https://git.kernel.org/stable/c/7e1f4efb8d6140b2ec79bf760c43e1fc186e8dfc', 'https://git.kernel.org/stable/c/89f2914dd4b47d2fad3deef0d700f9526d98d11f', 'https://git.kernel.org/stable/c/a5c399fe433a115e9d3693169b5f357f3194af0a', 'https://git.kernel.org/stable/c/d9592025000b3cf26c742f3505da7b83aedc26d5', 'https://lore.kernel.org/linux-cve-announce/2024081216-CVE-2024-42258-e3f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42258', 'https://www.cve.org/CVERecord?id=CVE-2024-42258'], 'PublishedDate': '2024-08-12T15:15:20.983Z', 'LastModifiedDate': '2024-08-14T14:15:27.727Z'}, {'VulnerabilityID': 'CVE-2024-42259', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42259', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/i915/gem: Fix Virtual Memory mapping boundaries calculation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix Virtual Memory mapping boundaries calculation\n\nCalculating the size of the mapped area as the lesser value\nbetween the requested size and the actual size does not consider\nthe partial mapping offset. This can cause page fault access.\n\nFix the calculation of the starting and ending addresses, the\ntotal size is now deduced from the difference between the end and\nstart addresses.\n\nAdditionally, the calculations have been rewritten in a clearer\nand more understandable form.\n\n[Joonas: Add Requires: tag]\nRequires: 60a2066c5005 ("drm/i915/gem: Adjust vma offset for framebuffer mmap offset")\n(cherry picked from commit 97b6784753da06d9d40232328efc5c5367e53417)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-131'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42259', 'https://git.kernel.org/linus/8bdd9ef7e9b1b2a73e394712b72b22055e0e26c3 (6.11-rc3)', 'https://git.kernel.org/stable/c/3e06073d24807f04b4694108a8474decb7b99e60', 'https://git.kernel.org/stable/c/4b09513ce93b3dcb590baaaff2ce96f2d098312d', 'https://git.kernel.org/stable/c/50111a8098fb9ade621eeff82228a997d42732ab', 'https://git.kernel.org/stable/c/8bdd9ef7e9b1b2a73e394712b72b22055e0e26c3', 'https://git.kernel.org/stable/c/911f8055f175c82775d0fd8cedcd0b75413f4ba7', 'https://git.kernel.org/stable/c/a256d019eaf044864c7e50312f0a65b323c24f39', 'https://git.kernel.org/stable/c/e8a68aa842d3f8dd04a46b9d632e5f67fde1da9b', 'https://git.kernel.org/stable/c/ead9289a51ea82eb5b27029fcf4c34b2dd60cf06', 'https://linux.oracle.com/cve/CVE-2024-42259.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081452-CVE-2024-42259-4cef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42259', 'https://project-zero.issues.chromium.org/issues/42451707', 'https://www.cve.org/CVERecord?id=CVE-2024-42259'], 'PublishedDate': '2024-08-14T15:15:31.673Z', 'LastModifiedDate': '2024-09-25T01:15:42.137Z'}, {'VulnerabilityID': 'CVE-2024-42260', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42260', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Validate passed in drm syncobj handles in the performance extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Validate passed in drm syncobj handles in the performance extension\n\nIf userspace provides an unknown or invalid handle anywhere in the handle\narray the rest of the driver will not handle that well.\n\nFix it by checking handle was looked up successfully or otherwise fail the\nextension by jumping into the existing unwind.\n\n(cherry picked from commit a546b7e4d73c23838d7e4d2c92882b3ca902d213)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42260', 'https://git.kernel.org/linus/4ecc24a84d7e0254efd150ec23e0b89638386516 (6.11-rc2)', 'https://git.kernel.org/stable/c/4ecc24a84d7e0254efd150ec23e0b89638386516', 'https://git.kernel.org/stable/c/5d4aa25f47cd05e9eeac272906588728588605dd', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-42260-0ce0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42260', 'https://www.cve.org/CVERecord?id=CVE-2024-42260'], 'PublishedDate': '2024-08-17T09:15:07.53Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42261', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42261', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Validate passed in drm syncobj handles in the timestamp extension\n\nIf userspace provides an unknown or invalid handle anywhere in the handle\narray the rest of the driver will not handle that well.\n\nFix it by checking handle was looked up successfully or otherwise fail the\nextension by jumping into the existing unwind.\n\n(cherry picked from commit 8d1276d1b8f738c3afe1457d4dff5cc66fc848a3)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42261', 'https://git.kernel.org/linus/023d22e8bb0cdd6900382ad1ed06df3b6c2ea791 (6.11-rc2)', 'https://git.kernel.org/stable/c/023d22e8bb0cdd6900382ad1ed06df3b6c2ea791', 'https://git.kernel.org/stable/c/5c56f104edd02a537e9327dc543574e55713e1d7', 'https://lore.kernel.org/linux-cve-announce/2024081736-CVE-2024-42261-f6a2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42261', 'https://www.cve.org/CVERecord?id=CVE-2024-42261'], 'PublishedDate': '2024-08-17T09:15:07.6Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42262', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42262', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix potential memory leak in the performance extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix potential memory leak in the performance extension\n\nIf fetching of userspace memory fails during the main loop, all drm sync\nobjs looked up until that point will be leaked because of the missing\ndrm_syncobj_put.\n\nFix it by exporting and using a common cleanup helper.\n\n(cherry picked from commit 484de39fa5f5b7bd0c5f2e2c5265167250ef7501)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42262', 'https://git.kernel.org/linus/32df4abc44f24dbec239d43e2b26d5768c5d1a78 (6.11-rc2)', 'https://git.kernel.org/stable/c/32df4abc44f24dbec239d43e2b26d5768c5d1a78', 'https://git.kernel.org/stable/c/ad5fdc48f7a63b8a98493c667505fe4d3864ae21', 'https://lore.kernel.org/linux-cve-announce/2024081736-CVE-2024-42262-7156@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42262', 'https://www.cve.org/CVERecord?id=CVE-2024-42262'], 'PublishedDate': '2024-08-17T09:15:07.68Z', 'LastModifiedDate': '2024-08-19T20:05:15.407Z'}, {'VulnerabilityID': 'CVE-2024-42263', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42263', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix potential memory leak in the timestamp extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix potential memory leak in the timestamp extension\n\nIf fetching of userspace memory fails during the main loop, all drm sync\nobjs looked up until that point will be leaked because of the missing\ndrm_syncobj_put.\n\nFix it by exporting and using a common cleanup helper.\n\n(cherry picked from commit 753ce4fea62182c77e1691ab4f9022008f25b62e)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42263', 'https://git.kernel.org/linus/0e50fcc20bd87584840266e8004f9064a8985b4f (6.11-rc2)', 'https://git.kernel.org/stable/c/0e50fcc20bd87584840266e8004f9064a8985b4f', 'https://git.kernel.org/stable/c/9b5033ee2c5af6d1135a403df32d219ab57e55f9', 'https://lore.kernel.org/linux-cve-announce/2024081737-CVE-2024-42263-31b3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42263', 'https://www.cve.org/CVERecord?id=CVE-2024-42263'], 'PublishedDate': '2024-08-17T09:15:07.77Z', 'LastModifiedDate': '2024-08-19T20:41:11.24Z'}, {'VulnerabilityID': 'CVE-2024-42264', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42264', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Prevent out of bounds access in performance query extensions', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Prevent out of bounds access in performance query extensions\n\nCheck that the number of perfmons userspace is passing in the copy and\nreset extensions is not greater than the internal kernel storage where\nthe ids will be copied into.\n\n(cherry picked from commit f32b5128d2c440368b5bf3a7a356823e235caabb)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42264', 'https://git.kernel.org/linus/6ce9efd12ae81cf46bf44eb0348594558dfbb9d2 (6.11-rc2)', 'https://git.kernel.org/stable/c/6ce9efd12ae81cf46bf44eb0348594558dfbb9d2', 'https://git.kernel.org/stable/c/73ad583bd4938bf37d2709fc36901eb6f22f2722', 'https://lore.kernel.org/linux-cve-announce/2024081737-CVE-2024-42264-5d23@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42264', 'https://www.cve.org/CVERecord?id=CVE-2024-42264'], 'PublishedDate': '2024-08-17T09:15:07.833Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42267', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42267', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv/mm: Add handling for VM_FAULT_SIGSEGV in mm_fault_error()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/mm: Add handling for VM_FAULT_SIGSEGV in mm_fault_error()\n\nHandle VM_FAULT_SIGSEGV in the page fault path so that we correctly\nkill the process and we don't BUG() the kernel.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42267', 'https://git.kernel.org/linus/0c710050c47d45eb77b28c271cddefc5c785cb40 (6.11-rc2)', 'https://git.kernel.org/stable/c/0c710050c47d45eb77b28c271cddefc5c785cb40', 'https://git.kernel.org/stable/c/20dbdebc5580cd472a310d56a6e252275ee4c864', 'https://git.kernel.org/stable/c/59be4a167782d68e21068a761b90b01fadc09146', 'https://git.kernel.org/stable/c/917f598209f3f5e4ab175d5079d8aeb523e58b1f', 'https://git.kernel.org/stable/c/d4e7db757e2d7f4c407a007e92c98477eab215d2', 'https://git.kernel.org/stable/c/d7ccf2ca772bfe33e2c53ef80fa20d2d87eb6144', 'https://lore.kernel.org/linux-cve-announce/2024081738-CVE-2024-42267-9f79@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42267', 'https://www.cve.org/CVERecord?id=CVE-2024-42267'], 'PublishedDate': '2024-08-17T09:15:08.047Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42268', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42268', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix missing lock on sync reset reload', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix missing lock on sync reset reload\n\nOn sync reset reload work, when remote host updates devlink on reload\nactions performed on that host, it misses taking devlink lock before\ncalling devlink_remote_reload_actions_performed() which results in\ntriggering lock assert like the following:\n\nWARNING: CPU: 4 PID: 1164 at net/devlink/core.c:261 devl_assert_locked+0x3e/0x50\n…\n CPU: 4 PID: 1164 Comm: kworker/u96:6 Tainted: G S W 6.10.0-rc2+ #116\n Hardware name: Supermicro SYS-2028TP-DECTR/X10DRT-PT, BIOS 2.0 12/18/2015\n Workqueue: mlx5_fw_reset_events mlx5_sync_reset_reload_work [mlx5_core]\n RIP: 0010:devl_assert_locked+0x3e/0x50\n…\n Call Trace:\n \n ? __warn+0xa4/0x210\n ? devl_assert_locked+0x3e/0x50\n ? report_bug+0x160/0x280\n ? handle_bug+0x3f/0x80\n ? exc_invalid_op+0x17/0x40\n ? asm_exc_invalid_op+0x1a/0x20\n ? devl_assert_locked+0x3e/0x50\n devlink_notify+0x88/0x2b0\n ? mlx5_attach_device+0x20c/0x230 [mlx5_core]\n ? __pfx_devlink_notify+0x10/0x10\n ? process_one_work+0x4b6/0xbb0\n process_one_work+0x4b6/0xbb0\n[…]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42268', 'https://git.kernel.org/linus/572f9caa9e7295f8c8822e4122c7ae8f1c412ff9 (6.11-rc2)', 'https://git.kernel.org/stable/c/091268f3c27a5b6d7858a3bb2a0dbcc9cd26ddb5', 'https://git.kernel.org/stable/c/572f9caa9e7295f8c8822e4122c7ae8f1c412ff9', 'https://git.kernel.org/stable/c/5d07d1d40aabfd61bab21115639bd4f641db6002', 'https://git.kernel.org/stable/c/98884e89c90d077f6fe6ba18e6cf6f914642f04e', 'https://lore.kernel.org/linux-cve-announce/2024081738-CVE-2024-42268-2084@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42268', 'https://www.cve.org/CVERecord?id=CVE-2024-42268'], 'PublishedDate': '2024-08-17T09:15:08.11Z', 'LastModifiedDate': '2024-08-19T20:52:49.323Z'}, {'VulnerabilityID': 'CVE-2024-42269', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42269', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().\n\nip6table_nat_table_init() accesses net->gen->ptr[ip6table_nat_net_ops.id],\nbut the function is exposed to user space before the entry is allocated\nvia register_pernet_subsys().\n\nLet's call register_pernet_subsys() before xt_register_template().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42269', 'https://git.kernel.org/linus/c22921df777de5606f1047b1345b8d22ef1c0b34 (6.11-rc2)', 'https://git.kernel.org/stable/c/419ee6274c5153b89c4393c1946faa4c3cad4f9e', 'https://git.kernel.org/stable/c/87dba44e9471b79b255d0736858a897332db9226', 'https://git.kernel.org/stable/c/91b6df6611b7edb28676c4f63f90c56c30d3e601', 'https://git.kernel.org/stable/c/c22921df777de5606f1047b1345b8d22ef1c0b34', 'https://git.kernel.org/stable/c/e85b9b6a87be4cb3710082038b677e97f2389003', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42269-7d0a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42269', 'https://www.cve.org/CVERecord?id=CVE-2024-42269'], 'PublishedDate': '2024-08-17T09:15:08.177Z', 'LastModifiedDate': '2024-08-19T20:53:51.717Z'}, {'VulnerabilityID': 'CVE-2024-42270', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42270', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().\n\nWe had a report that iptables-restore sometimes triggered null-ptr-deref\nat boot time. [0]\n\nThe problem is that iptable_nat_table_init() is exposed to user space\nbefore the kernel fully initialises netns.\n\nIn the small race window, a user could call iptable_nat_table_init()\nthat accesses net_generic(net, iptable_nat_net_id), which is available\nonly after registering iptable_nat_net_ops.\n\nLet's call register_pernet_subsys() before xt_register_template().\n\n[0]:\nbpfilter: Loaded bpfilter_umh pid 11702\nStarted bpfilter\nBUG: kernel NULL pointer dereference, address: 0000000000000013\n PF: supervisor write access in kernel mode\n PF: error_code(0x0002) - not-present page\nPGD 0 P4D 0\nPREEMPT SMP NOPTI\nCPU: 2 PID: 11879 Comm: iptables-restor Not tainted 6.1.92-99.174.amzn2023.x86_64 #1\nHardware name: Amazon EC2 c6i.4xlarge/, BIOS 1.0 10/16/2017\nRIP: 0010:iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat\nCode: 10 4c 89 f6 48 89 ef e8 0b 19 bb ff 41 89 c4 85 c0 75 38 41 83 c7 01 49 83 c6 28 41 83 ff 04 75 dc 48 8b 44 24 08 48 8b 0c 24 <48> 89 08 4c 89 ef e8 a2 3b a2 cf 48 83 c4 10 44 89 e0 5b 5d 41 5c\nRSP: 0018:ffffbef902843cd0 EFLAGS: 00010246\nRAX: 0000000000000013 RBX: ffff9f4b052caa20 RCX: ffff9f4b20988d80\nRDX: 0000000000000000 RSI: 0000000000000064 RDI: ffffffffc04201c0\nRBP: ffff9f4b29394000 R08: ffff9f4b07f77258 R09: ffff9f4b07f77240\nR10: 0000000000000000 R11: ffff9f4b09635388 R12: 0000000000000000\nR13: ffff9f4b1a3c6c00 R14: ffff9f4b20988e20 R15: 0000000000000004\nFS: 00007f6284340000(0000) GS:ffff9f51fe280000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000013 CR3: 00000001d10a6005 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? xt_find_table_lock (net/netfilter/x_tables.c:1259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? page_fault_oops (arch/x86/mm/fault.c:727)\n ? exc_page_fault (./arch/x86/include/asm/irqflags.h:40 ./arch/x86/include/asm/irqflags.h:75 arch/x86/mm/fault.c:1470 arch/x86/mm/fault.c:1518)\n ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570)\n ? iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat\n xt_find_table_lock (net/netfilter/x_tables.c:1259)\n xt_request_find_table_lock (net/netfilter/x_tables.c:1287)\n get_info (net/ipv4/netfilter/ip_tables.c:965)\n ? security_capable (security/security.c:809 (discriminator 13))\n ? ns_capable (kernel/capability.c:376 kernel/capability.c:397)\n ? do_ipt_get_ctl (net/ipv4/netfilter/ip_tables.c:1656)\n ? bpfilter_send_req (net/bpfilter/bpfilter_kern.c:52) bpfilter\n nf_getsockopt (net/netfilter/nf_sockopt.c:116)\n ip_getsockopt (net/ipv4/ip_sockglue.c:1827)\n __sys_getsockopt (net/socket.c:2327)\n __x64_sys_getsockopt (net/socket.c:2342 net/socket.c:2339 net/socket.c:2339)\n do_syscall_64 (arch/x86/entry/common.c:51 arch/x86/entry/common.c:81)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\nRIP: 0033:0x7f62844685ee\nCode: 48 8b 0d 45 28 0f 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 37 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 09\nRSP: 002b:00007ffd1f83d638 EFLAGS: 00000246 ORIG_RAX: 0000000000000037\nRAX: ffffffffffffffda RBX: 00007ffd1f83d680 RCX: 00007f62844685ee\nRDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000004\nRBP: 0000000000000004 R08: 00007ffd1f83d670 R09: 0000558798ffa2a0\nR10: 00007ffd1f83d680 R11: 0000000000000246 R12: 00007ffd1f83e3b2\nR13: 00007f6284\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42270', 'https://git.kernel.org/linus/5830aa863981d43560748aa93589c0695191d95d (6.11-rc2)', 'https://git.kernel.org/stable/c/08ed888b69a22647153fe2bec55b7cd0a46102cc', 'https://git.kernel.org/stable/c/5830aa863981d43560748aa93589c0695191d95d', 'https://git.kernel.org/stable/c/70014b73d7539fcbb6b4ff5f37368d7241d8e626', 'https://git.kernel.org/stable/c/95590a4929027769af35b153645c0ab6fd22b29b', 'https://git.kernel.org/stable/c/b98ddb65fa1674b0e6b52de8af9103b63f51b643', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42270-c752@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42270', 'https://ubuntu.com/security/notices/USN-7004-1', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://www.cve.org/CVERecord?id=CVE-2024-42270'], 'PublishedDate': '2024-08-17T09:15:08.24Z', 'LastModifiedDate': '2024-08-19T20:01:09.52Z'}, {'VulnerabilityID': 'CVE-2024-42272', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42272', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched: act_ct: take care of padding in struct zones_ht_key', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched: act_ct: take care of padding in struct zones_ht_key\n\nBlamed commit increased lookup key size from 2 bytes to 16 bytes,\nbecause zones_ht_key got a struct net pointer.\n\nMake sure rhashtable_lookup() is not using the padding bytes\nwhich are not initialized.\n\n BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline]\n BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline]\n BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329\n rht_ptr_rcu include/linux/rhashtable.h:376 [inline]\n __rhashtable_lookup include/linux/rhashtable.h:607 [inline]\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329\n tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408\n tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425\n tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488\n tcf_action_add net/sched/act_api.c:2061 [inline]\n tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118\n rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647\n netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550\n rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665\n netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]\n netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357\n netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n ____sys_sendmsg+0x877/0xb60 net/socket.c:2597\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651\n __sys_sendmsg net/socket.c:2680 [inline]\n __do_sys_sendmsg net/socket.c:2689 [inline]\n __se_sys_sendmsg net/socket.c:2687 [inline]\n __x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2687\n x64_sys_call+0x2dd6/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable key created at:\n tcf_ct_flow_table_get+0x4a/0x2260 net/sched/act_ct.c:324\n tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42272', 'https://git.kernel.org/linus/2191a54f63225b548fd8346be3611c3219a24738 (6.11-rc2)', 'https://git.kernel.org/stable/c/2191a54f63225b548fd8346be3611c3219a24738', 'https://git.kernel.org/stable/c/3a5b68869dbe14f1157c6a24ac71923db060eeab', 'https://git.kernel.org/stable/c/3ddefcb8f75e312535e2e7d5fef9932019ba60f2', 'https://git.kernel.org/stable/c/7c03ab555eb1ba26c77fd7c25bdf44a0ac23edee', 'https://git.kernel.org/stable/c/d06daf0ad645d9225a3ff6958dd82e1f3988fa64', 'https://git.kernel.org/stable/c/d7cc186d0973afce0e1237c37f7512c01981fb79', 'https://linux.oracle.com/cve/CVE-2024-42272.html', 'https://linux.oracle.com/errata/ELSA-2024-8162.html', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42272-c687@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42272', 'https://www.cve.org/CVERecord?id=CVE-2024-42272'], 'PublishedDate': '2024-08-17T09:15:08.37Z', 'LastModifiedDate': '2024-09-30T13:40:21.843Z'}, {'VulnerabilityID': 'CVE-2024-42273', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42273', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid\n\nmkdir /mnt/test/comp\nf2fs_io setflags compression /mnt/test/comp\ndd if=/dev/zero of=/mnt/test/comp/testfile bs=16k count=1\ntruncate --size 13 /mnt/test/comp/testfile\n\nIn the above scenario, we can get a BUG_ON.\n kernel BUG at fs/f2fs/segment.c:3589!\n Call Trace:\n do_write_page+0x78/0x390 [f2fs]\n f2fs_outplace_write_data+0x62/0xb0 [f2fs]\n f2fs_do_write_data_page+0x275/0x740 [f2fs]\n f2fs_write_single_data_page+0x1dc/0x8f0 [f2fs]\n f2fs_write_multi_pages+0x1e5/0xae0 [f2fs]\n f2fs_write_cache_pages+0xab1/0xc60 [f2fs]\n f2fs_write_data_pages+0x2d8/0x330 [f2fs]\n do_writepages+0xcf/0x270\n __writeback_single_inode+0x44/0x350\n writeback_sb_inodes+0x242/0x530\n __writeback_inodes_wb+0x54/0xf0\n wb_writeback+0x192/0x310\n wb_workfn+0x30d/0x400\n\nThe reason is we gave CURSEG_ALL_DATA_ATGC to COMPR_ADDR where the\npage was set the gcing flag by set_cluster_dirty().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42273', 'https://git.kernel.org/linus/8cb1f4080dd91c6e6b01dbea013a3f42341cb6a1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0cd106612396656d6f1ca17ef192c6759bb60791', 'https://git.kernel.org/stable/c/4239571c5db46a42f723b8fa8394039187c34439', 'https://git.kernel.org/stable/c/5fd057160ab240dd816ae09b625395d54c297de1', 'https://git.kernel.org/stable/c/8cb1f4080dd91c6e6b01dbea013a3f42341cb6a1', 'https://lore.kernel.org/linux-cve-announce/2024081740-CVE-2024-42273-9b87@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42273', 'https://www.cve.org/CVERecord?id=CVE-2024-42273'], 'PublishedDate': '2024-08-17T09:15:08.45Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42274', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42274', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "ALSA: firewire-lib: operate for period elapse event in process context"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "ALSA: firewire-lib: operate for period elapse event in process context"\n\nCommit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period elapse event\nin process context") removed the process context workqueue from\namdtp_domain_stream_pcm_pointer() and update_pcm_pointers() to remove\nits overhead.\n\nWith RME Fireface 800, this lead to a regression since\nKernels 5.14.0, causing an AB/BA deadlock competition for the\nsubstream lock with eventual system freeze under ALSA operation:\n\nthread 0:\n * (lock A) acquire substream lock by\n\tsnd_pcm_stream_lock_irq() in\n\tsnd_pcm_status64()\n * (lock B) wait for tasklet to finish by calling\n \ttasklet_unlock_spin_wait() in\n\ttasklet_disable_in_atomic() in\n\tohci_flush_iso_completions() of ohci.c\n\nthread 1:\n * (lock B) enter tasklet\n * (lock A) attempt to acquire substream lock,\n \twaiting for it to be released:\n\tsnd_pcm_stream_lock_irqsave() in\n \tsnd_pcm_period_elapsed() in\n\tupdate_pcm_pointers() in\n\tprocess_ctx_payloads() in\n\tprocess_rx_packets() of amdtp-stream.c\n\n? tasklet_unlock_spin_wait\n \n \nohci_flush_iso_completions firewire_ohci\namdtp_domain_stream_pcm_pointer snd_firewire_lib\nsnd_pcm_update_hw_ptr0 snd_pcm\nsnd_pcm_status64 snd_pcm\n\n? native_queued_spin_lock_slowpath\n \n \n_raw_spin_lock_irqsave\nsnd_pcm_period_elapsed snd_pcm\nprocess_rx_packets snd_firewire_lib\nirq_target_callback snd_firewire_lib\nhandle_it_packet firewire_ohci\ncontext_tasklet firewire_ohci\n\nRestore the process context work queue to prevent deadlock\nAB/BA deadlock competition for ALSA substream lock of\nsnd_pcm_stream_lock_irq() in snd_pcm_status64()\nand snd_pcm_stream_lock_irqsave() in snd_pcm_period_elapsed().\n\nrevert commit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period\nelapse event in process context")\n\nReplace inline description to prevent future deadlock.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42274', 'https://git.kernel.org/linus/3dab73ab925a51ab05543b491bf17463a48ca323 (6.11-rc2)', 'https://git.kernel.org/stable/c/36c255db5a25edd42d1aca48e38b8e95ee5fd9ef', 'https://git.kernel.org/stable/c/3dab73ab925a51ab05543b491bf17463a48ca323', 'https://git.kernel.org/stable/c/7c07220cf634002f93a87ca2252a32766850f2d1', 'https://git.kernel.org/stable/c/b239a37d68e8bc59f9516444da222841e3b13ba9', 'https://git.kernel.org/stable/c/f5043e69aeb2786f32e84132817a007a6430aa7d', 'https://lore.kernel.org/linux-cve-announce/2024081740-CVE-2024-42274-9dc6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42274', 'https://www.cve.org/CVERecord?id=CVE-2024-42274'], 'PublishedDate': '2024-08-17T09:15:08.53Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42276', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42276', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme-pci: add missing condition check for existence of mapped data', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: add missing condition check for existence of mapped data\n\nnvme_map_data() is called when request has physical segments, hence\nthe nvme_unmap_data() should have same condition to avoid dereference.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42276', 'https://git.kernel.org/linus/c31fad1470389666ac7169fe43aa65bf5b7e2cfd (6.11-rc1)', 'https://git.kernel.org/stable/c/3f8ec1d6b0ebd8268307d52be8301973fa5a01ec', 'https://git.kernel.org/stable/c/70100fe721840bf6d8e5abd25b8bffe4d2e049b7', 'https://git.kernel.org/stable/c/77848b379e9f85a08048a2c8b3b4a7e8396f5f83', 'https://git.kernel.org/stable/c/7cc1f4cd90a00b6191cb8cda2d1302fdce59361c', 'https://git.kernel.org/stable/c/be23ae63080e0bf9e246ab20207200bca6585eba', 'https://git.kernel.org/stable/c/c31fad1470389666ac7169fe43aa65bf5b7e2cfd', 'https://git.kernel.org/stable/c/d135c3352f7c947a922da93c8e763ee6bc208b64', 'https://linux.oracle.com/cve/CVE-2024-42276.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081741-CVE-2024-42276-cb0a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42276', 'https://www.cve.org/CVERecord?id=CVE-2024-42276'], 'PublishedDate': '2024-08-17T09:15:08.673Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42277', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42277', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu: sprd: Avoid NULL deref in sprd_iommu_hw_en\n\nIn sprd_iommu_cleanup() before calling function sprd_iommu_hw_en()\ndom->sdev is equal to NULL, which leads to null dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42277', 'https://git.kernel.org/linus/630482ee0653decf9e2482ac6181897eb6cde5b8 (6.11-rc1)', 'https://git.kernel.org/stable/c/630482ee0653decf9e2482ac6181897eb6cde5b8', 'https://git.kernel.org/stable/c/8c79ceb4ecf823e6ec10fee6febb0fca3de79922', 'https://git.kernel.org/stable/c/b62841e49a2b7938f6fdeaaf93fb57e4eb880bdb', 'https://git.kernel.org/stable/c/d5fe884ce28c5005f8582c35333c195a168f841c', 'https://git.kernel.org/stable/c/dfe90030a0cfa26dca4cb6510de28920e5ad22fb', 'https://lore.kernel.org/linux-cve-announce/2024081741-CVE-2024-42277-997a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42277', 'https://www.cve.org/CVERecord?id=CVE-2024-42277'], 'PublishedDate': '2024-08-17T09:15:08.75Z', 'LastModifiedDate': '2024-09-10T18:46:21.62Z'}, {'VulnerabilityID': 'CVE-2024-42278', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42278', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: TAS2781: Fix tasdev_load_calibrated_data()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: TAS2781: Fix tasdev_load_calibrated_data()\n\nThis function has a reversed if statement so it's either a no-op or it\nleads to a NULL dereference.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42278', 'https://git.kernel.org/linus/92c78222168e9035a9bfb8841c2e56ce23e51f73 (6.11-rc1)', 'https://git.kernel.org/stable/c/51be301d29d674ff328dfcf23705851f326f35b3', 'https://git.kernel.org/stable/c/6d98741dbd1309a6f2d7cffbb10a8f036ec3ca06', 'https://git.kernel.org/stable/c/92c78222168e9035a9bfb8841c2e56ce23e51f73', 'https://lore.kernel.org/linux-cve-announce/2024081742-CVE-2024-42278-e639@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42278', 'https://www.cve.org/CVERecord?id=CVE-2024-42278'], 'PublishedDate': '2024-08-17T09:15:08.813Z', 'LastModifiedDate': '2024-09-30T12:53:36.42Z'}, {'VulnerabilityID': 'CVE-2024-42279', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42279', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer\n\nWhile transmitting with rx_len == 0, the RX FIFO is not going to be\nemptied in the interrupt handler. A subsequent transfer could then\nread crap from the previous transfer out of the RX FIFO into the\nstart RX buffer. The core provides a register that will empty the RX and\nTX FIFOs, so do that before each transfer.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L', 'V3Score': 5.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42279', 'https://git.kernel.org/linus/9cf71eb0faef4bff01df4264841b8465382d7927 (6.11-rc1)', 'https://git.kernel.org/stable/c/3feda3677e8bbe833c3a62a4091377a08f015b80', 'https://git.kernel.org/stable/c/45e03d35229b680b79dfea1103a1f2f07d0b5d75', 'https://git.kernel.org/stable/c/9cf71eb0faef4bff01df4264841b8465382d7927', 'https://lore.kernel.org/linux-cve-announce/2024081742-CVE-2024-42279-91b0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42279', 'https://www.cve.org/CVERecord?id=CVE-2024-42279'], 'PublishedDate': '2024-08-17T09:15:08.88Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42281', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42281', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix a segment issue when downgrading gso_size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a segment issue when downgrading gso_size\n\nLinearize the skb when downgrading gso_size because it may trigger a\nBUG_ON() later when the skb is segmented as described in [1,2].', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42281', 'https://git.kernel.org/linus/fa5ef655615a01533035c6139248c5b33aa27028 (6.11-rc1)', 'https://git.kernel.org/stable/c/11ec79f5c7f74261874744039bc1551023edd6b2', 'https://git.kernel.org/stable/c/a689f5eb13a90f892a088865478b3cd39f53d5dc', 'https://git.kernel.org/stable/c/c3496314c53e7e82ddb544c825defc3e8c0e45cf', 'https://git.kernel.org/stable/c/dda518dea60d556a2d171c0122ca7d9fdb7d473a', 'https://git.kernel.org/stable/c/ec4eea14d75f7b0491194dd413f540dd19b8c733', 'https://git.kernel.org/stable/c/f6bb8c90cab97a3e03f8d30e3069efe6a742e0be', 'https://git.kernel.org/stable/c/fa5ef655615a01533035c6139248c5b33aa27028', 'https://linux.oracle.com/cve/CVE-2024-42281.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42281-780b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42281', 'https://www.cve.org/CVERecord?id=CVE-2024-42281'], 'PublishedDate': '2024-08-17T09:15:09.013Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42283', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42283', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: nexthop: Initialize all fields in dumped nexthops', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nexthop: Initialize all fields in dumped nexthops\n\nstruct nexthop_grp contains two reserved fields that are not initialized by\nnla_put_nh_group(), and carry garbage. This can be observed e.g. with\nstrace (edited for clarity):\n\n # ip nexthop add id 1 dev lo\n # ip nexthop add id 101 group 1\n # strace -e recvmsg ip nexthop get id 101\n ...\n recvmsg(... [{nla_len=12, nla_type=NHA_GROUP},\n [{id=1, weight=0, resvd1=0x69, resvd2=0x67}]] ...) = 52\n\nThe fields are reserved and therefore not currently used. But as they are, they\nleak kernel memory, and the fact they are not just zero complicates repurposing\nof the fields for new ends. Initialize the full structure.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42283', 'https://git.kernel.org/linus/6d745cd0e9720282cd291d36b9db528aea18add2 (6.11-rc1)', 'https://git.kernel.org/stable/c/1377de719652d868f5317ba8398b7e74c5f0430b', 'https://git.kernel.org/stable/c/5cc4d71dda2dd4f1520f40e634a527022e48ccd8', 'https://git.kernel.org/stable/c/6d745cd0e9720282cd291d36b9db528aea18add2', 'https://git.kernel.org/stable/c/7704460acd7f5d35eb07c52500987dc9b95313fb', 'https://git.kernel.org/stable/c/9e8f558a3afe99ce51a642ce0d3637ddc2b5d5d0', 'https://git.kernel.org/stable/c/a13d3864b76ac87085ec530b2ff8e37482a63a96', 'https://git.kernel.org/stable/c/fd06cb4a5fc7bda3dea31712618a62af72a1c6cb', 'https://linux.oracle.com/cve/CVE-2024-42283.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42283-15a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42283', 'https://www.cve.org/CVERecord?id=CVE-2024-42283'], 'PublishedDate': '2024-08-17T09:15:09.163Z', 'LastModifiedDate': '2024-08-19T19:54:33.213Z'}, {'VulnerabilityID': 'CVE-2024-42284', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42284', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Return non-zero value from tipc_udp_addr2str() on error\n\ntipc_udp_addr2str() should return non-zero value if the UDP media\naddress is invalid. Otherwise, a buffer overflow access can occur in\ntipc_media_addr_printf(). Fix this by returning 1 on an invalid UDP\nmedia address.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42284', 'https://git.kernel.org/linus/fa96c6baef1b5385e2f0c0677b32b3839e716076 (6.11-rc1)', 'https://git.kernel.org/stable/c/253405541be2f15ffebdeac2f4cf4b7e9144d12f', 'https://git.kernel.org/stable/c/2abe350db1aa599eeebc6892237d0bce0f1de62a', 'https://git.kernel.org/stable/c/5eea127675450583680c8170358bcba43227bd69', 'https://git.kernel.org/stable/c/728734352743a78b4c5a7285b282127696a4a813', 'https://git.kernel.org/stable/c/76ddf84a52f0d8ec3f5db6ccce08faf202a17d28', 'https://git.kernel.org/stable/c/7ec3335dd89c8d169e9650e4bac64fde71fdf15b', 'https://git.kernel.org/stable/c/aa38bf74899de07cf70b50cd17f8ad45fb6654c8', 'https://git.kernel.org/stable/c/fa96c6baef1b5385e2f0c0677b32b3839e716076', 'https://linux.oracle.com/cve/CVE-2024-42284.html', 'https://linux.oracle.com/errata/ELSA-2024-8162.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42284-bbfa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42284', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-42284'], 'PublishedDate': '2024-08-17T09:15:09.233Z', 'LastModifiedDate': '2024-08-19T19:47:55.623Z'}, {'VulnerabilityID': 'CVE-2024-42285', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42285', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/iwcm: Fix a use-after-free related to destroying CM IDs\n\niw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with\nan existing struct iw_cm_id (cm_id) as follows:\n\n conn_id->cm_id.iw = cm_id;\n cm_id->context = conn_id;\n cm_id->cm_handler = cma_iw_handler;\n\nrdma_destroy_id() frees both the cm_id and the struct rdma_id_private. Make\nsure that cm_work_handler() does not trigger a use-after-free by only\nfreeing of the struct rdma_id_private after all pending work has finished.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42285', 'https://git.kernel.org/linus/aee2424246f9f1dadc33faa78990c1e2eb7826e4 (6.11-rc1)', 'https://git.kernel.org/stable/c/557d035fe88d78dd51664f4dc0e1896c04c97cf6', 'https://git.kernel.org/stable/c/7f25f296fc9bd0435be14e89bf657cd615a23574', 'https://git.kernel.org/stable/c/94ee7ff99b87435ec63211f632918dc7f44dac79', 'https://git.kernel.org/stable/c/aee2424246f9f1dadc33faa78990c1e2eb7826e4', 'https://git.kernel.org/stable/c/d91d253c87fd1efece521ff2612078a35af673c6', 'https://git.kernel.org/stable/c/dc8074b8901caabb97c2d353abd6b4e7fa5a59a5', 'https://git.kernel.org/stable/c/ee39384ee787e86e9db4efb843818ef0ea9cb8ae', 'https://git.kernel.org/stable/c/ff5bbbdee08287d75d72e65b72a2b76d9637892a', 'https://linux.oracle.com/cve/CVE-2024-42285.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42285-37ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42285', 'https://www.cve.org/CVERecord?id=CVE-2024-42285'], 'PublishedDate': '2024-08-17T09:15:09.3Z', 'LastModifiedDate': '2024-08-19T19:45:41.59Z'}, {'VulnerabilityID': 'CVE-2024-42286', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42286', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: validate nvme_local_port correctly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: validate nvme_local_port correctly\n\nThe driver load failed with error message,\n\nqla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef\n\nand with a kernel crash,\n\n\tBUG: unable to handle kernel NULL pointer dereference at 0000000000000070\n\tWorkqueue: events_unbound qla_register_fcport_fn [qla2xxx]\n\tRIP: 0010:nvme_fc_register_remoteport+0x16/0x430 [nvme_fc]\n\tRSP: 0018:ffffaaa040eb3d98 EFLAGS: 00010282\n\tRAX: 0000000000000000 RBX: ffff9dfb46b78c00 RCX: 0000000000000000\n\tRDX: ffff9dfb46b78da8 RSI: ffffaaa040eb3e08 RDI: 0000000000000000\n\tRBP: ffff9dfb612a0a58 R08: ffffffffaf1d6270 R09: 3a34303a30303030\n\tR10: 34303a303030305b R11: 2078787832616c71 R12: ffff9dfb46b78dd4\n\tR13: ffff9dfb46b78c24 R14: ffff9dfb41525300 R15: ffff9dfb46b78da8\n\tFS: 0000000000000000(0000) GS:ffff9dfc67c00000(0000) knlGS:0000000000000000\n\tCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n\tCR2: 0000000000000070 CR3: 000000018da10004 CR4: 00000000000206f0\n\tCall Trace:\n\tqla_nvme_register_remote+0xeb/0x1f0 [qla2xxx]\n\t? qla2x00_dfs_create_rport+0x231/0x270 [qla2xxx]\n\tqla2x00_update_fcport+0x2a1/0x3c0 [qla2xxx]\n\tqla_register_fcport_fn+0x54/0xc0 [qla2xxx]\n\nExit the qla_nvme_register_remote() function when qla_nvme_register_hba()\nfails and correctly validate nvme_local_port.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42286', 'https://git.kernel.org/linus/eb1d4ce2609584eeb7694866f34d4b213caa3af9 (6.11-rc1)', 'https://git.kernel.org/stable/c/3eac973eb5cb2b874b3918f924798afc5affd46b', 'https://git.kernel.org/stable/c/549aac9655320c9b245a24271b204668c5d40430', 'https://git.kernel.org/stable/c/7cec2c3bfe84539c415f5e16f989228eba1d2f1e', 'https://git.kernel.org/stable/c/a3ab508a4853a9f5ae25a7816a4889f09938f63c', 'https://git.kernel.org/stable/c/cde43031df533751b4ead37d173922feee2f550f', 'https://git.kernel.org/stable/c/e1f010844443c389bc552884ac5cfa47de34d54c', 'https://git.kernel.org/stable/c/eb1d4ce2609584eeb7694866f34d4b213caa3af9', 'https://git.kernel.org/stable/c/f6be298cc1042f24d521197af29c7c4eb95af4d5', 'https://linux.oracle.com/cve/CVE-2024-42286.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42286-e856@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42286', 'https://www.cve.org/CVERecord?id=CVE-2024-42286'], 'PublishedDate': '2024-08-17T09:15:09.38Z', 'LastModifiedDate': '2024-09-10T19:02:12.36Z'}, {'VulnerabilityID': 'CVE-2024-42287', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42287', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: Complete command early within lock', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Complete command early within lock\n\nA crash was observed while performing NPIV and FW reset,\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 1 PREEMPT_RT SMP NOPTI\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffc90026f47b88 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000002\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8881041130d0\n RBP: ffff8881041130d0 R08: 0000000000000000 R09: 0000000000000034\n R10: ffffc90026f47c48 R11: 0000000000000031 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8881565e4a20 R15: 0000000000000000\n FS: 00007f4c69ed3d00(0000) GS:ffff889faac80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000000288a50002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die_body+0x1a/0x60\n ? page_fault_oops+0x16f/0x4a0\n ? do_user_addr_fault+0x174/0x7f0\n ? exc_page_fault+0x69/0x1a0\n ? asm_exc_page_fault+0x22/0x30\n ? dma_direct_unmap_sg+0x51/0x1e0\n ? preempt_count_sub+0x96/0xe0\n qla2xxx_qpair_sp_free_dma+0x29f/0x3b0 [qla2xxx]\n qla2xxx_qpair_sp_compl+0x60/0x80 [qla2xxx]\n __qla2x00_abort_all_cmds+0xa2/0x450 [qla2xxx]\n\nThe command completion was done early while aborting the commands in driver\nunload path but outside lock to avoid the WARN_ON condition of performing\ndma_free_attr within the lock. However this caused race condition while\ncommand completion via multiple paths causing system crash.\n\nHence complete the command early in unload path but within the lock to\navoid race condition.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42287', 'https://git.kernel.org/linus/4475afa2646d3fec176fc4d011d3879b26cb26e3 (6.11-rc1)', 'https://git.kernel.org/stable/c/314efe3f87949a568f512f05df20bf47b81cf232', 'https://git.kernel.org/stable/c/36fdc5319c4d0ec8b8938ec4769764098a246bfb', 'https://git.kernel.org/stable/c/4475afa2646d3fec176fc4d011d3879b26cb26e3', 'https://git.kernel.org/stable/c/57ba7563712227647f82a92547e82c96cd350553', 'https://git.kernel.org/stable/c/814f4a53cc86f7ea8b501bfb1723f24fd29ef5ee', 'https://git.kernel.org/stable/c/9117337b04d789bd08fdd9854a40bec2815cd3f6', 'https://git.kernel.org/stable/c/af46649304b0c9cede4ccfc2be2561ce8ed6a2ea', 'https://linux.oracle.com/cve/CVE-2024-42287.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42287-d635@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42287', 'https://www.cve.org/CVERecord?id=CVE-2024-42287'], 'PublishedDate': '2024-08-17T09:15:09.453Z', 'LastModifiedDate': '2024-09-10T19:05:07.67Z'}, {'VulnerabilityID': 'CVE-2024-42288', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42288', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: Fix for possible memory corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix for possible memory corruption\n\nInit Control Block is dereferenced incorrectly. Correctly dereference ICB', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42288', 'https://git.kernel.org/linus/c03d740152f78e86945a75b2ad541bf972fab92a (6.11-rc1)', 'https://git.kernel.org/stable/c/2a15b59a2c5afac89696e44acf5bbfc0599c6c5e', 'https://git.kernel.org/stable/c/571d7f2a08836698c2fb0d792236424575b9829b', 'https://git.kernel.org/stable/c/8192c533e89d9fb69b2490398939236b78cda79b', 'https://git.kernel.org/stable/c/87db8d7b7520e99de71791260989f06f9c94953d', 'https://git.kernel.org/stable/c/b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce', 'https://git.kernel.org/stable/c/c03d740152f78e86945a75b2ad541bf972fab92a', 'https://git.kernel.org/stable/c/dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb', 'https://linux.oracle.com/cve/CVE-2024-42288.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42288-c59b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42288', 'https://www.cve.org/CVERecord?id=CVE-2024-42288'], 'PublishedDate': '2024-08-17T09:15:09.523Z', 'LastModifiedDate': '2024-09-05T17:38:38.383Z'}, {'VulnerabilityID': 'CVE-2024-42289', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42289', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: During vport delete send async logout explicitly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: During vport delete send async logout explicitly\n\nDuring vport delete, it is observed that during unload we hit a crash\nbecause of stale entries in outstanding command array. For all these stale\nI/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but\nI/Os could not complete while vport delete is in process of deleting.\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n Workqueue: qla2xxx_wq qla_do_work [qla2xxx]\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0\n RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8\n R10: ffff8ce378aac8a0 R11: ffffa1e1e150f9d8 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8ce378aac9c8 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8d217f000000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000002089acc000 CR4: 0000000000350ee0\n Call Trace:\n \n qla2xxx_qpair_sp_free_dma+0x417/0x4e0\n ? qla2xxx_qpair_sp_compl+0x10d/0x1a0\n ? qla2x00_status_entry+0x768/0x2830\n ? newidle_balance+0x2f0/0x430\n ? dequeue_entity+0x100/0x3c0\n ? qla24xx_process_response_queue+0x6a1/0x19e0\n ? __schedule+0x2d5/0x1140\n ? qla_do_work+0x47/0x60\n ? process_one_work+0x267/0x440\n ? process_one_work+0x440/0x440\n ? worker_thread+0x2d/0x3d0\n ? process_one_work+0x440/0x440\n ? kthread+0x156/0x180\n ? set_kthread_struct+0x50/0x50\n ? ret_from_fork+0x22/0x30\n \n\nSend out async logout explicitly for all the ports during vport delete.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42289', 'https://git.kernel.org/linus/76f480d7c717368f29a3870f7d64471ce0ff8fb2 (6.11-rc1)', 'https://git.kernel.org/stable/c/086489256696eb774654a5410e86381c346356fe', 'https://git.kernel.org/stable/c/171ac4b495f9473bc134356a00095b47e6409e52', 'https://git.kernel.org/stable/c/76f480d7c717368f29a3870f7d64471ce0ff8fb2', 'https://git.kernel.org/stable/c/87c25fcb95aafabb6a4914239f4ab41b07a4f9b7', 'https://git.kernel.org/stable/c/b12c54e51ba83c1fbc619d35083d7872e42ecdef', 'https://git.kernel.org/stable/c/b35d6d5a2f38605cddea7d5c64cded894fbe8ede', 'https://git.kernel.org/stable/c/d28a2075bb530489715a3b011e1dd8765ba20313', 'https://git.kernel.org/stable/c/e5ed6a26ffdec0c91cf0b6138afbd675c00ad5fc', 'https://linux.oracle.com/cve/CVE-2024-42289.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42289-fe68@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42289', 'https://www.cve.org/CVERecord?id=CVE-2024-42289'], 'PublishedDate': '2024-08-17T09:15:09.59Z', 'LastModifiedDate': '2024-09-05T17:37:49.057Z'}, {'VulnerabilityID': 'CVE-2024-42290', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42290', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: irqchip/imx-irqsteer: Handle runtime power management correctly', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/imx-irqsteer: Handle runtime power management correctly\n\nThe power domain is automatically activated from clk_prepare(). However, on\ncertain platforms like i.MX8QM and i.MX8QXP, the power-on handling invokes\nsleeping functions, which triggers the 'scheduling while atomic' bug in the\ncontext switch path during device probing:\n\n BUG: scheduling while atomic: kworker/u13:1/48/0x00000002\n Call trace:\n __schedule_bug+0x54/0x6c\n __schedule+0x7f0/0xa94\n schedule+0x5c/0xc4\n schedule_preempt_disabled+0x24/0x40\n __mutex_lock.constprop.0+0x2c0/0x540\n __mutex_lock_slowpath+0x14/0x20\n mutex_lock+0x48/0x54\n clk_prepare_lock+0x44/0xa0\n clk_prepare+0x20/0x44\n imx_irqsteer_resume+0x28/0xe0\n pm_generic_runtime_resume+0x2c/0x44\n __genpd_runtime_resume+0x30/0x80\n genpd_runtime_resume+0xc8/0x2c0\n __rpm_callback+0x48/0x1d8\n rpm_callback+0x6c/0x78\n rpm_resume+0x490/0x6b4\n __pm_runtime_resume+0x50/0x94\n irq_chip_pm_get+0x2c/0xa0\n __irq_do_set_handler+0x178/0x24c\n irq_set_chained_handler_and_data+0x60/0xa4\n mxc_gpio_probe+0x160/0x4b0\n\nCure this by implementing the irq_bus_lock/sync_unlock() interrupt chip\ncallbacks and handle power management in them as they are invoked from\nnon-atomic context.\n\n[ tglx: Rewrote change log, added Fixes tag ]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42290', 'https://git.kernel.org/linus/33b1c47d1fc0b5f06a393bb915db85baacba18ea (6.11-rc1)', 'https://git.kernel.org/stable/c/21bd3f9e7f924cd2fc892a484e7a50c7e1847565', 'https://git.kernel.org/stable/c/33b1c47d1fc0b5f06a393bb915db85baacba18ea', 'https://git.kernel.org/stable/c/3a2884a44e5cda192df1b28e9925661f79f599a1', 'https://git.kernel.org/stable/c/58c56735facb225a5c46fa4b8bbbe7f31d1cb894', 'https://git.kernel.org/stable/c/a590e8dea3df2639921f874d763be961dd74e8f9', 'https://git.kernel.org/stable/c/f8ae38f1dfe652779c7c613facbc257cec00ac44', 'https://git.kernel.org/stable/c/fa1803401e1c360efe6342fb41d161cc51748a11', 'https://linux.oracle.com/cve/CVE-2024-42290.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42290-c966@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42290', 'https://www.cve.org/CVERecord?id=CVE-2024-42290'], 'PublishedDate': '2024-08-17T09:15:09.663Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42291', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42291', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Add a per-VF limit on number of FDIR filters', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add a per-VF limit on number of FDIR filters\n\nWhile the iavf driver adds a s/w limit (128) on the number of FDIR\nfilters that the VF can request, a malicious VF driver can request more\nthan that and exhaust the resources for other VFs.\n\nAdd a similar limit in ice.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42291', 'https://git.kernel.org/linus/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97 (6.11-rc1)', 'https://git.kernel.org/stable/c/292081c4e7f575a79017d5cbe1a0ec042783976f', 'https://git.kernel.org/stable/c/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97', 'https://git.kernel.org/stable/c/8e02cd98a6e24389d476e28436d41e620ed8e559', 'https://git.kernel.org/stable/c/d62389073a5b937413e2d1bc1da06ccff5103c0c', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42291-6f31@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42291', 'https://www.cve.org/CVERecord?id=CVE-2024-42291'], 'PublishedDate': '2024-08-17T09:15:09.73Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42292', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42292', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kobject_uevent: Fix OOB access within zap_modalias_env()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkobject_uevent: Fix OOB access within zap_modalias_env()\n\nzap_modalias_env() wrongly calculates size of memory block to move, so\nwill cause OOB memory access issue if variable MODALIAS is not the last\none within its @env parameter, fixed by correcting size to memmove.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42292', 'https://git.kernel.org/linus/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc (6.11-rc1)', 'https://git.kernel.org/stable/c/57fe01d3d04276875c7e3a6dc763517fc05b8762', 'https://git.kernel.org/stable/c/648d5490460d38436640da0812bf7f6351c150d2', 'https://git.kernel.org/stable/c/68d63ace80b76395e7935687ecdb86421adc2168', 'https://git.kernel.org/stable/c/81a15d28f32af01493ae8c5457e0d55314a4167d', 'https://git.kernel.org/stable/c/b59a5e86a3934f1b6a5bd1368902dbc79bdecc90', 'https://git.kernel.org/stable/c/c5ee8adc8d98a49703320d13878ba2b923b142f5', 'https://git.kernel.org/stable/c/d4663536754defff75ff1eca0aaebc41da165a8d', 'https://git.kernel.org/stable/c/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc', 'https://linux.oracle.com/cve/CVE-2024-42292.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42292-5387@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42292', 'https://www.cve.org/CVERecord?id=CVE-2024-42292'], 'PublishedDate': '2024-08-17T09:15:09.797Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42294', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42294', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: fix deadlock between sd_remove & sd_release', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix deadlock between sd_remove & sd_release\n\nOur test report the following hung task:\n\n[ 2538.459400] INFO: task "kworker/0:0":7 blocked for more than 188 seconds.\n[ 2538.459427] Call trace:\n[ 2538.459430] __switch_to+0x174/0x338\n[ 2538.459436] __schedule+0x628/0x9c4\n[ 2538.459442] schedule+0x7c/0xe8\n[ 2538.459447] schedule_preempt_disabled+0x24/0x40\n[ 2538.459453] __mutex_lock+0x3ec/0xf04\n[ 2538.459456] __mutex_lock_slowpath+0x14/0x24\n[ 2538.459459] mutex_lock+0x30/0xd8\n[ 2538.459462] del_gendisk+0xdc/0x350\n[ 2538.459466] sd_remove+0x30/0x60\n[ 2538.459470] device_release_driver_internal+0x1c4/0x2c4\n[ 2538.459474] device_release_driver+0x18/0x28\n[ 2538.459478] bus_remove_device+0x15c/0x174\n[ 2538.459483] device_del+0x1d0/0x358\n[ 2538.459488] __scsi_remove_device+0xa8/0x198\n[ 2538.459493] scsi_forget_host+0x50/0x70\n[ 2538.459497] scsi_remove_host+0x80/0x180\n[ 2538.459502] usb_stor_disconnect+0x68/0xf4\n[ 2538.459506] usb_unbind_interface+0xd4/0x280\n[ 2538.459510] device_release_driver_internal+0x1c4/0x2c4\n[ 2538.459514] device_release_driver+0x18/0x28\n[ 2538.459518] bus_remove_device+0x15c/0x174\n[ 2538.459523] device_del+0x1d0/0x358\n[ 2538.459528] usb_disable_device+0x84/0x194\n[ 2538.459532] usb_disconnect+0xec/0x300\n[ 2538.459537] hub_event+0xb80/0x1870\n[ 2538.459541] process_scheduled_works+0x248/0x4dc\n[ 2538.459545] worker_thread+0x244/0x334\n[ 2538.459549] kthread+0x114/0x1bc\n\n[ 2538.461001] INFO: task "fsck.":15415 blocked for more than 188 seconds.\n[ 2538.461014] Call trace:\n[ 2538.461016] __switch_to+0x174/0x338\n[ 2538.461021] __schedule+0x628/0x9c4\n[ 2538.461025] schedule+0x7c/0xe8\n[ 2538.461030] blk_queue_enter+0xc4/0x160\n[ 2538.461034] blk_mq_alloc_request+0x120/0x1d4\n[ 2538.461037] scsi_execute_cmd+0x7c/0x23c\n[ 2538.461040] ioctl_internal_command+0x5c/0x164\n[ 2538.461046] scsi_set_medium_removal+0x5c/0xb0\n[ 2538.461051] sd_release+0x50/0x94\n[ 2538.461054] blkdev_put+0x190/0x28c\n[ 2538.461058] blkdev_release+0x28/0x40\n[ 2538.461063] __fput+0xf8/0x2a8\n[ 2538.461066] __fput_sync+0x28/0x5c\n[ 2538.461070] __arm64_sys_close+0x84/0xe8\n[ 2538.461073] invoke_syscall+0x58/0x114\n[ 2538.461078] el0_svc_common+0xac/0xe0\n[ 2538.461082] do_el0_svc+0x1c/0x28\n[ 2538.461087] el0_svc+0x38/0x68\n[ 2538.461090] el0t_64_sync_handler+0x68/0xbc\n[ 2538.461093] el0t_64_sync+0x1a8/0x1ac\n\n T1:\t\t\t\tT2:\n sd_remove\n del_gendisk\n __blk_mark_disk_dead\n blk_freeze_queue_start\n ++q->mq_freeze_depth\n \t\t\t\tbdev_release\n \t\t\t\tmutex_lock(&disk->open_mutex)\n \t\t\t\tsd_release\n \t\t\t\tscsi_execute_cmd\n \t\t\t\tblk_queue_enter\n \t\t\t\twait_event(!q->mq_freeze_depth)\n mutex_lock(&disk->open_mutex)\n\nSCSI does not set GD_OWNS_QUEUE, so QUEUE_FLAG_DYING is not set in\nthis scenario. This is a classic ABBA deadlock. To fix the deadlock,\nmake sure we don\'t try to acquire disk->open_mutex after freezing\nthe queue.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42294', 'https://git.kernel.org/stable/c/5a5625a83eac91fdff1d5f0202ecfc45a31983c9', 'https://git.kernel.org/stable/c/7e04da2dc7013af50ed3a2beb698d5168d1e594b', 'https://git.kernel.org/stable/c/f5418f48a93b69ed9e6a2281eee06b412f14a544', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42294-0145@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42294', 'https://www.cve.org/CVERecord?id=CVE-2024-42294'], 'PublishedDate': '2024-08-17T09:15:09.947Z', 'LastModifiedDate': '2024-08-19T19:43:22.46Z'}, {'VulnerabilityID': 'CVE-2024-42295', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42295', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: handle inconsistent state in nilfs_btnode_create_block()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: handle inconsistent state in nilfs_btnode_create_block()\n\nSyzbot reported that a buffer state inconsistency was detected in\nnilfs_btnode_create_block(), triggering a kernel bug.\n\nIt is not appropriate to treat this inconsistency as a bug; it can occur\nif the argument block address (the buffer index of the newly created\nblock) is a virtual block number and has been reallocated due to\ncorruption of the bitmap used to manage its allocation state.\n\nSo, modify nilfs_btnode_create_block() and its callers to treat it as a\npossible filesystem error, rather than triggering a kernel bug.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42295', 'https://git.kernel.org/linus/4811f7af6090e8f5a398fbdd766f903ef6c0d787 (6.11-rc1)', 'https://git.kernel.org/stable/c/012be828a118bf496e666ef1fc47fc0e7358ada2', 'https://git.kernel.org/stable/c/02b87e6334a38c65eef49848d3f1ac422f0b2a44', 'https://git.kernel.org/stable/c/19cce46238ffe3546e44b9c74057103ff8b24c62', 'https://git.kernel.org/stable/c/366c3f688dd0288cbe38af1d3a886b5c62372e4a', 'https://git.kernel.org/stable/c/4811f7af6090e8f5a398fbdd766f903ef6c0d787', 'https://git.kernel.org/stable/c/5f0a6800b8aec1b453c7fe4c44fcaac5ffe9d52e', 'https://git.kernel.org/stable/c/be56dfc9be0604291267c07b0e27a69a6bda4899', 'https://git.kernel.org/stable/c/e34191cce3ee63dfa5fb241904aaf2a042d5b6d8', 'https://linux.oracle.com/cve/CVE-2024-42295.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42295-4f43@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42295', 'https://www.cve.org/CVERecord?id=CVE-2024-42295'], 'PublishedDate': '2024-08-17T09:15:10.017Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42296', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42296', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix return value of f2fs_convert_inline_inode()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix return value of f2fs_convert_inline_inode()\n\nIf device is readonly, make f2fs_convert_inline_inode()\nreturn EROFS instead of zero, otherwise it may trigger\npanic during writeback of inline inode's dirty page as\nbelow:\n\n f2fs_write_single_data_page+0xbb6/0x1e90 fs/f2fs/data.c:2888\n f2fs_write_cache_pages fs/f2fs/data.c:3187 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3342 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3369\n do_writepages+0x359/0x870 mm/page-writeback.c:2634\n filemap_fdatawrite_wbc+0x125/0x180 mm/filemap.c:397\n __filemap_fdatawrite_range mm/filemap.c:430 [inline]\n file_write_and_wait_range+0x1aa/0x290 mm/filemap.c:788\n f2fs_do_sync_file+0x68a/0x1ae0 fs/f2fs/file.c:276\n generic_write_sync include/linux/fs.h:2806 [inline]\n f2fs_file_write_iter+0x7bd/0x24e0 fs/f2fs/file.c:4977\n call_write_iter include/linux/fs.h:2114 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xa72/0xc90 fs/read_write.c:590\n ksys_write+0x1a0/0x2c0 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42296', 'https://git.kernel.org/linus/a8eb3de28e7a365690c61161e7a07a4fc7c60bbf (6.11-rc1)', 'https://git.kernel.org/stable/c/077f0e24b27c4b44841593c7edbd1993be9eecb5', 'https://git.kernel.org/stable/c/1e7725814361c8c008d131db195cef8274ff26b8', 'https://git.kernel.org/stable/c/47a8ddcdcaccd9b891db4574795e46a33a121ac2', 'https://git.kernel.org/stable/c/70f5ef5f33c333cfb286116fa3af74ac9bc84f1b', 'https://git.kernel.org/stable/c/a8eb3de28e7a365690c61161e7a07a4fc7c60bbf', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42296-3f50@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42296', 'https://www.cve.org/CVERecord?id=CVE-2024-42296'], 'PublishedDate': '2024-08-17T09:15:10.08Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42297', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42297', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: f2fs: fix to don't dirty inode for readonly filesystem", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to don't dirty inode for readonly filesystem\n\nsyzbot reports f2fs bug as below:\n\nkernel BUG at fs/f2fs/inode.c:933!\nRIP: 0010:f2fs_evict_inode+0x1576/0x1590 fs/f2fs/inode.c:933\nCall Trace:\n evict+0x2a4/0x620 fs/inode.c:664\n dispose_list fs/inode.c:697 [inline]\n evict_inodes+0x5f8/0x690 fs/inode.c:747\n generic_shutdown_super+0x9d/0x2c0 fs/super.c:675\n kill_block_super+0x44/0x90 fs/super.c:1667\n kill_f2fs_super+0x303/0x3b0 fs/f2fs/super.c:4894\n deactivate_locked_super+0xc1/0x130 fs/super.c:484\n cleanup_mnt+0x426/0x4c0 fs/namespace.c:1256\n task_work_run+0x24a/0x300 kernel/task_work.c:180\n ptrace_notify+0x2cd/0x380 kernel/signal.c:2399\n ptrace_report_syscall include/linux/ptrace.h:411 [inline]\n ptrace_report_syscall_exit include/linux/ptrace.h:473 [inline]\n syscall_exit_work kernel/entry/common.c:251 [inline]\n syscall_exit_to_user_mode_prepare kernel/entry/common.c:278 [inline]\n __syscall_exit_to_user_mode_work kernel/entry/common.c:283 [inline]\n syscall_exit_to_user_mode+0x15c/0x280 kernel/entry/common.c:296\n do_syscall_64+0x50/0x110 arch/x86/entry/common.c:88\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nThe root cause is:\n- do_sys_open\n - f2fs_lookup\n - __f2fs_find_entry\n - f2fs_i_depth_write\n - f2fs_mark_inode_dirty_sync\n - f2fs_dirty_inode\n - set_inode_flag(inode, FI_DIRTY_INODE)\n\n- umount\n - kill_f2fs_super\n - kill_block_super\n - generic_shutdown_super\n - sync_filesystem\n : sb is readonly, skip sync_filesystem()\n - evict_inodes\n - iput\n - f2fs_evict_inode\n - f2fs_bug_on(sbi, is_inode_flag_set(inode, FI_DIRTY_INODE))\n : trigger kernel panic\n\nWhen we try to repair i_current_depth in readonly filesystem, let's\nskip dirty inode to avoid panic in later f2fs_evict_inode().", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42297', 'https://git.kernel.org/linus/192b8fb8d1c8ca3c87366ebbef599fa80bb626b8 (6.11-rc1)', 'https://git.kernel.org/stable/c/192b8fb8d1c8ca3c87366ebbef599fa80bb626b8', 'https://git.kernel.org/stable/c/2434344559f6743efb3ac15d11af9a0db9543bd3', 'https://git.kernel.org/stable/c/2d2916516577f2239b3377d9e8d12da5e6ccdfcf', 'https://git.kernel.org/stable/c/54162974aea37a8cae00742470a78c7f6bd6f915', 'https://git.kernel.org/stable/c/54bc4e88447e385c4d4ffa85d93e0dce628fcfa6', 'https://git.kernel.org/stable/c/9ce8135accf103f7333af472709125878704fdd4', 'https://git.kernel.org/stable/c/e62ff092a42f4a1bae3b310cf46673b4f3aac3b5', 'https://git.kernel.org/stable/c/ec56571b4b146a1cfbedab49d5fcaf19fe8bf4f1', 'https://linux.oracle.com/cve/CVE-2024-42297.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42297-fcec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42297', 'https://www.cve.org/CVERecord?id=CVE-2024-42297'], 'PublishedDate': '2024-08-17T09:15:10.147Z', 'LastModifiedDate': '2024-09-30T13:41:26.463Z'}, {'VulnerabilityID': 'CVE-2024-42298', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42298', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value\n\ndevm_kasprintf() can return a NULL pointer on failure but this returned\nvalue is not checked.\n\nFix this lack and check the returned value.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42298', 'https://git.kernel.org/linus/e62599902327d27687693f6e5253a5d56583db58 (6.11-rc1)', 'https://git.kernel.org/stable/c/af466037fa2b263e8ea5c47285513d2487e17d90', 'https://git.kernel.org/stable/c/b4205dfcfe96182118e54343954827eda51b2135', 'https://git.kernel.org/stable/c/e62599902327d27687693f6e5253a5d56583db58', 'https://lore.kernel.org/linux-cve-announce/2024081748-CVE-2024-42298-d6a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42298', 'https://www.cve.org/CVERecord?id=CVE-2024-42298'], 'PublishedDate': '2024-08-17T09:15:10.23Z', 'LastModifiedDate': '2024-09-10T18:42:19.607Z'}, {'VulnerabilityID': 'CVE-2024-42299', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42299', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fs/ntfs3: Update log->page_{mask,bits} if log->page_size changed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Update log->page_{mask,bits} if log->page_size changed\n\nIf an NTFS file system is mounted to another system with different\nPAGE_SIZE from the original system, log->page_size will change in\nlog_replay(), but log->page_{mask,bits} don\'t change correspondingly.\nThis will cause a panic because "u32 bytes = log->page_size - page_off"\nwill get a negative value in the later read_log_page().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42299', 'https://git.kernel.org/linus/2fef55d8f78383c8e6d6d4c014b9597375132696 (6.11-rc1)', 'https://git.kernel.org/stable/c/0484adcb5fbcadd9ba0fd4485c42630f72e97da9', 'https://git.kernel.org/stable/c/0a4ae2644e2a3b3b219aad9639fb2b0691d08420', 'https://git.kernel.org/stable/c/2cac0df3324b5e287d8020bc0708f7d2dec88a6f', 'https://git.kernel.org/stable/c/2fef55d8f78383c8e6d6d4c014b9597375132696', 'https://git.kernel.org/stable/c/b90ceffdc975502bc085ce8e79c6adeff05f9521', 'https://lore.kernel.org/linux-cve-announce/2024081748-CVE-2024-42299-a588@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42299', 'https://www.cve.org/CVERecord?id=CVE-2024-42299'], 'PublishedDate': '2024-08-17T09:15:10.293Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42301', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42301', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dev/parport: fix the array out-of-bounds risk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndev/parport: fix the array out-of-bounds risk\n\nFixed array out-of-bounds issues caused by sprintf\nby replacing it with snprintf for safer data copying,\nensuring the destination buffer is not overflowed.\n\nBelow is the stack trace I encountered during the actual issue:\n\n[ 66.575408s] [pid:5118,cpu4,QThread,4]Kernel panic - not syncing: stack-protector:\nKernel stack is corrupted in: do_hardware_base_addr+0xcc/0xd0 [parport]\n[ 66.575408s] [pid:5118,cpu4,QThread,5]CPU: 4 PID: 5118 Comm:\nQThread Tainted: G S W O 5.10.97-arm64-desktop #7100.57021.2\n[ 66.575439s] [pid:5118,cpu4,QThread,6]TGID: 5087 Comm: EFileApp\n[ 66.575439s] [pid:5118,cpu4,QThread,7]Hardware name: HUAWEI HUAWEI QingYun\nPGUX-W515x-B081/SP1PANGUXM, BIOS 1.00.07 04/29/2024\n[ 66.575439s] [pid:5118,cpu4,QThread,8]Call trace:\n[ 66.575469s] [pid:5118,cpu4,QThread,9] dump_backtrace+0x0/0x1c0\n[ 66.575469s] [pid:5118,cpu4,QThread,0] show_stack+0x14/0x20\n[ 66.575469s] [pid:5118,cpu4,QThread,1] dump_stack+0xd4/0x10c\n[ 66.575500s] [pid:5118,cpu4,QThread,2] panic+0x1d8/0x3bc\n[ 66.575500s] [pid:5118,cpu4,QThread,3] __stack_chk_fail+0x2c/0x38\n[ 66.575500s] [pid:5118,cpu4,QThread,4] do_hardware_base_addr+0xcc/0xd0 [parport]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42301', 'https://git.kernel.org/linus/ab11dac93d2d568d151b1918d7b84c2d02bacbd5 (6.11-rc1)', 'https://git.kernel.org/stable/c/166a0bddcc27de41fe13f861c8348e8e53e988c8', 'https://git.kernel.org/stable/c/47b3dce100778001cd76f7e9188944b5cb27a76d', 'https://git.kernel.org/stable/c/7789a1d6792af410aa9b39a1eb237ed24fa2170a', 'https://git.kernel.org/stable/c/7f4da759092a1a6ce35fb085182d02de8cc4cc84', 'https://git.kernel.org/stable/c/a44f88f7576bc1916d8d6293f5c62fbe7cbe03e0', 'https://git.kernel.org/stable/c/ab11dac93d2d568d151b1918d7b84c2d02bacbd5', 'https://git.kernel.org/stable/c/b579ea3516c371ecf59d073772bc45dfd28c8a0e', 'https://git.kernel.org/stable/c/c719b393374d3763e64900ee19aaed767d5a08d6', 'https://linux.oracle.com/cve/CVE-2024-42301.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42301-4026@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42301', 'https://www.cve.org/CVERecord?id=CVE-2024-42301'], 'PublishedDate': '2024-08-17T09:15:10.423Z', 'LastModifiedDate': '2024-08-22T16:31:18.667Z'}, {'VulnerabilityID': 'CVE-2024-42302', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42302', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/DPC: Fix use-after-free on concurrent DPC and hot-removal\n\nKeith reports a use-after-free when a DPC event occurs concurrently to\nhot-removal of the same portion of the hierarchy:\n\nThe dpc_handler() awaits readiness of the secondary bus below the\nDownstream Port where the DPC event occurred. To do so, it polls the\nconfig space of the first child device on the secondary bus. If that\nchild device is concurrently removed, accesses to its struct pci_dev\ncause the kernel to oops.\n\nThat\'s because pci_bridge_wait_for_secondary_bus() neglects to hold a\nreference on the child device. Before v6.3, the function was only\ncalled on resume from system sleep or on runtime resume. Holding a\nreference wasn\'t necessary back then because the pciehp IRQ thread\ncould never run concurrently. (On resume from system sleep, IRQs are\nnot enabled until after the resume_noirq phase. And runtime resume is\nalways awaited before a PCI device is removed.)\n\nHowever starting with v6.3, pci_bridge_wait_for_secondary_bus() is also\ncalled on a DPC event. Commit 53b54ad074de ("PCI/DPC: Await readiness\nof secondary bus after reset"), which introduced that, failed to\nappreciate that pci_bridge_wait_for_secondary_bus() now needs to hold a\nreference on the child device because dpc_handler() and pciehp may\nindeed run concurrently. The commit was backported to v5.10+ stable\nkernels, so that\'s the oldest one affected.\n\nAdd the missing reference acquisition.\n\nAbridged stack trace:\n\n BUG: unable to handle page fault for address: 00000000091400c0\n CPU: 15 PID: 2464 Comm: irq/53-pcie-dpc 6.9.0\n RIP: pci_bus_read_config_dword+0x17/0x50\n pci_dev_wait()\n pci_bridge_wait_for_secondary_bus()\n dpc_reset_link()\n pcie_do_recovery()\n dpc_handler()', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42302', 'https://git.kernel.org/linus/11a1f4bc47362700fcbde717292158873fb847ed (6.11-rc1)', 'https://git.kernel.org/stable/c/11a1f4bc47362700fcbde717292158873fb847ed', 'https://git.kernel.org/stable/c/2c111413f38ca5cf87557cab89f6d82b0e3433e7', 'https://git.kernel.org/stable/c/2cc8973bdc4d6c928ebe38b88090a2cdfe81f42f', 'https://git.kernel.org/stable/c/b16f3ea1db47a6766a9f1169244cf1fc287a7c62', 'https://git.kernel.org/stable/c/c52f9e1a9eb40f13993142c331a6cfd334d4b91d', 'https://git.kernel.org/stable/c/f63df70b439bb8331358a306541893bf415bf1da', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42302-c0d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42302', 'https://www.cve.org/CVERecord?id=CVE-2024-42302'], 'PublishedDate': '2024-08-17T09:15:10.487Z', 'LastModifiedDate': '2024-08-22T16:37:26.237Z'}, {'VulnerabilityID': 'CVE-2024-42303', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42303', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: imx-pxp: Fix ERR_PTR dereference in pxp_probe()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: imx-pxp: Fix ERR_PTR dereference in pxp_probe()\n\ndevm_regmap_init_mmio() can fail, add a check and bail out in case of\nerror.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42303', 'https://git.kernel.org/linus/57e9ce68ae98551da9c161aaab12b41fe8601856 (6.11-rc1)', 'https://git.kernel.org/stable/c/358bc85269d6a359fea597ef9fbb429cd3626e08', 'https://git.kernel.org/stable/c/57e9ce68ae98551da9c161aaab12b41fe8601856', 'https://git.kernel.org/stable/c/5ab6ac4e9e165b0fe8a326308218337007224f05', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42303-4d12@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42303', 'https://www.cve.org/CVERecord?id=CVE-2024-42303'], 'PublishedDate': '2024-08-17T09:15:10.56Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42304', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42304', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: make sure the first directory block is not a hole', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: make sure the first directory block is not a hole\n\nThe syzbot constructs a directory that has no dirblock but is non-inline,\ni.e. the first directory block is a hole. And no errors are reported when\ncreating files in this directory in the following flow.\n\n ext4_mknod\n ...\n ext4_add_entry\n // Read block 0\n ext4_read_dirblock(dir, block, DIRENT)\n bh = ext4_bread(NULL, inode, block, 0)\n if (!bh && (type == INDEX || type == DIRENT_HTREE))\n // The first directory block is a hole\n // But type == DIRENT, so no error is reported.\n\nAfter that, we get a directory block without '.' and '..' but with a valid\ndentry. This may cause some code that relies on dot or dotdot (such as\nmake_indexed_dir()) to crash.\n\nTherefore when ext4_read_dirblock() finds that the first directory block\nis a hole report that the filesystem is corrupted and return an error to\navoid loading corrupted data from disk causing something bad.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42304', 'https://git.kernel.org/linus/f9ca51596bbfd0f9c386dd1c613c394c78d9e5e6 (6.11-rc1)', 'https://git.kernel.org/stable/c/299bc6ffa57e04e74c6cce866d6c0741fb4897a1', 'https://git.kernel.org/stable/c/9771e3d8365ae1dd5e8846a204cb9af14e3e656a', 'https://git.kernel.org/stable/c/b609753cbbd38f8c0affd4956c0af178348523ac', 'https://git.kernel.org/stable/c/c3893d9de8ee153baac56d127d844103488133b5', 'https://git.kernel.org/stable/c/d81d7e347d1f1f48a5634607d39eb90c161c8afe', 'https://git.kernel.org/stable/c/de2a011a13a46468a6e8259db58b1b62071fe136', 'https://git.kernel.org/stable/c/e02f9941e8c011aa3eafa799def6a134ce06bcfa', 'https://git.kernel.org/stable/c/f9ca51596bbfd0f9c386dd1c613c394c78d9e5e6', 'https://linux.oracle.com/cve/CVE-2024-42304.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42304-d0e4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42304', 'https://www.cve.org/CVERecord?id=CVE-2024-42304'], 'PublishedDate': '2024-08-17T09:15:10.617Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42305', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42305', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: check dot and dotdot of dx_root before making dir indexed', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: check dot and dotdot of dx_root before making dir indexed\n\nSyzbot reports a issue as follows:\n============================================\nBUG: unable to handle page fault for address: ffffed11022e24fe\nPGD 23ffee067 P4D 23ffee067 PUD 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 0 PID: 5079 Comm: syz-executor306 Not tainted 6.10.0-rc5-g55027e689933 #0\nCall Trace:\n \n make_indexed_dir+0xdaf/0x13c0 fs/ext4/namei.c:2341\n ext4_add_entry+0x222a/0x25d0 fs/ext4/namei.c:2451\n ext4_rename fs/ext4/namei.c:3936 [inline]\n ext4_rename2+0x26e5/0x4370 fs/ext4/namei.c:4214\n[...]\n============================================\n\nThe immediate cause of this problem is that there is only one valid dentry\nfor the block to be split during do_split, so split==0 results in out of\nbounds accesses to the map triggering the issue.\n\n do_split\n unsigned split\n dx_make_map\n count = 1\n split = count/2 = 0;\n continued = hash2 == map[split - 1].hash;\n ---> map[4294967295]\n\nThe maximum length of a filename is 255 and the minimum block size is 1024,\nso it is always guaranteed that the number of entries is greater than or\nequal to 2 when do_split() is called.\n\nBut syzbot's crafted image has no dot and dotdot in dir, and the dentry\ndistribution in dirblock is as follows:\n\n bus dentry1 hole dentry2 free\n|xx--|xx-------------|...............|xx-------------|...............|\n0 12 (8+248)=256 268 256 524 (8+256)=264 788 236 1024\n\nSo when renaming dentry1 increases its name_len length by 1, neither hole\nnor free is sufficient to hold the new dentry, and make_indexed_dir() is\ncalled.\n\nIn make_indexed_dir() it is assumed that the first two entries of the\ndirblock must be dot and dotdot, so bus and dentry1 are left in dx_root\nbecause they are treated as dot and dotdot, and only dentry2 is moved\nto the new leaf block. That's why count is equal to 1.\n\nTherefore add the ext4_check_dx_root() helper function to add more sanity\nchecks to dot and dotdot before starting the conversion to avoid the above\nissue.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42305', 'https://git.kernel.org/linus/50ea741def587a64e08879ce6c6a30131f7111e7 (6.11-rc1)', 'https://git.kernel.org/stable/c/19e13b4d7f0303186fcc891aba8d0de7c8fdbda8', 'https://git.kernel.org/stable/c/42d420517072028fb0eb852c358056b7717ba5aa', 'https://git.kernel.org/stable/c/50ea741def587a64e08879ce6c6a30131f7111e7', 'https://git.kernel.org/stable/c/8afe06ed3be7a874b3cd82ef5f8959aca8d6429a', 'https://git.kernel.org/stable/c/9d241b7a39af192d1bb422714a458982c7cc67a2', 'https://git.kernel.org/stable/c/abb411ac991810c0bcbe51c2e76d2502bf611b5c', 'https://git.kernel.org/stable/c/b80575ffa98b5bb3a5d4d392bfe4c2e03e9557db', 'https://git.kernel.org/stable/c/cdd345321699042ece4a9d2e70754d2397d378c5', 'https://linux.oracle.com/cve/CVE-2024-42305.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42305-94ed@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42305', 'https://www.cve.org/CVERecord?id=CVE-2024-42305'], 'PublishedDate': '2024-08-17T09:15:10.69Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42306', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42306', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Avoid using corrupted block bitmap buffer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid using corrupted block bitmap buffer\n\nWhen the filesystem block bitmap is corrupted, we detect the corruption\nwhile loading the bitmap and fail the allocation with error. However the\nnext allocation from the same bitmap will notice the bitmap buffer is\nalready loaded and tries to allocate from the bitmap with mixed results\n(depending on the exact nature of the bitmap corruption). Fix the\nproblem by using BH_verified bit to indicate whether the bitmap is valid\nor not.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42306', 'https://git.kernel.org/linus/a90d4471146de21745980cba51ce88e7926bcc4f (6.11-rc1)', 'https://git.kernel.org/stable/c/2199e157a465aaf98294d3932797ecd7fce942d5', 'https://git.kernel.org/stable/c/271cab2ca00652bc984e269cf1208699a1e09cdd', 'https://git.kernel.org/stable/c/57053b3bcf3403b80db6f65aba284d7dfe7326af', 'https://git.kernel.org/stable/c/6a43e3c210df6c5f00570f4be49a897677dbcb64', 'https://git.kernel.org/stable/c/8ca170c39eca7cad6e0cfeb24e351d8f8eddcd65', 'https://git.kernel.org/stable/c/a90d4471146de21745980cba51ce88e7926bcc4f', 'https://git.kernel.org/stable/c/cae9e59cc41683408b70b9ab569f8654866ba914', 'https://linux.oracle.com/cve/CVE-2024-42306.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42306-647c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42306', 'https://www.cve.org/CVERecord?id=CVE-2024-42306'], 'PublishedDate': '2024-08-17T09:15:10.777Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42307', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42307', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential null pointer use in destroy_workqueue in init_cifs error path\n\nDan Carpenter reported a Smack static checker warning:\n fs/smb/client/cifsfs.c:1981 init_cifs()\n error: we previously assumed 'serverclose_wq' could be null (see line 1895)\n\nThe patch which introduced the serverclose workqueue used the wrong\noredering in error paths in init_cifs() for freeing it on errors.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42307', 'https://git.kernel.org/linus/193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2 (6.11-rc1)', 'https://git.kernel.org/stable/c/160235efb4f9b55212dedff5de0094c606c4b303', 'https://git.kernel.org/stable/c/193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2', 'https://git.kernel.org/stable/c/3739d711246d8fbc95ff73dbdace9741cdce4777', 'https://git.kernel.org/stable/c/6018971710fdc7739f8655c1540832b4bb903671', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42307-7c2c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42307', 'https://www.cve.org/CVERecord?id=CVE-2024-42307'], 'PublishedDate': '2024-08-17T09:15:10.843Z', 'LastModifiedDate': '2024-09-05T17:49:58.257Z'}, {'VulnerabilityID': 'CVE-2024-42308', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42308', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check for NULL pointer', 'Description': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42308', 'https://git.kernel.org/linus/4ab68e168ae1695f7c04fae98930740aaf7c50fa (6.11-rc1)', 'https://git.kernel.org/stable/c/185616085b12e651cdfd11ef00d1449f54552d89', 'https://git.kernel.org/stable/c/4ab68e168ae1695f7c04fae98930740aaf7c50fa', 'https://git.kernel.org/stable/c/4ccd37085976ea5d3c499b1e6d0b3f4deaf2cd5a', 'https://git.kernel.org/stable/c/6b5ed0648213e9355cc78f4a264d9afe8536d692', 'https://git.kernel.org/stable/c/71dbf95359347c2ecc5a6dfc02783fcfccb2e9fb', 'https://git.kernel.org/stable/c/9ce89824ff04d261fc855e0ca6e6025251d9fa40', 'https://git.kernel.org/stable/c/f068494430d15b5fc551ac928de9dac7e5e27602', 'https://linux.oracle.com/cve/CVE-2024-42308.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42308-562d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42308', 'https://www.cve.org/CVERecord?id=CVE-2024-42308'], 'PublishedDate': '2024-08-17T09:15:10.92Z', 'LastModifiedDate': '2024-10-09T14:15:05.227Z'}, {'VulnerabilityID': 'CVE-2024-42309', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42309', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes\n\nIn psb_intel_lvds_get_modes(), the return value of drm_mode_duplicate() is\nassigned to mode, which will lead to a possible NULL pointer dereference\non failure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42309', 'https://git.kernel.org/linus/2df7aac81070987b0f052985856aa325a38debf6 (6.11-rc1)', 'https://git.kernel.org/stable/c/13b5f3ee94bdbdc4b5f40582aab62977905aedee', 'https://git.kernel.org/stable/c/2df7aac81070987b0f052985856aa325a38debf6', 'https://git.kernel.org/stable/c/46d2ef272957879cbe30a884574320e7f7d78692', 'https://git.kernel.org/stable/c/475a5b3b7c8edf6e583a9eb59cf28ea770602e14', 'https://git.kernel.org/stable/c/6735d02ead7dd3adf74eb8b70aebd09e0ce78ec9', 'https://git.kernel.org/stable/c/7e52c62ff029f95005915c0a11863b5fb5185c8c', 'https://git.kernel.org/stable/c/d6ad202f73f8edba0cbc0065aa57a79ffe8fdcdc', 'https://git.kernel.org/stable/c/f70ffeca546452d1acd3a70ada56ecb2f3e7f811', 'https://linux.oracle.com/cve/CVE-2024-42309.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42309-9560@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42309', 'https://www.cve.org/CVERecord?id=CVE-2024-42309'], 'PublishedDate': '2024-08-17T09:15:10.987Z', 'LastModifiedDate': '2024-08-22T16:01:29.287Z'}, {'VulnerabilityID': 'CVE-2024-42310', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42310', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes\n\nIn cdv_intel_lvds_get_modes(), the return value of drm_mode_duplicate()\nis assigned to mode, which will lead to a NULL pointer dereference on\nfailure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42310', 'https://git.kernel.org/linus/cb520c3f366c77e8d69e4e2e2781a8ce48d98e79 (6.11-rc1)', 'https://git.kernel.org/stable/c/08f45102c81ad8bc9f85f7a25e9f64e128edb87d', 'https://git.kernel.org/stable/c/2d209b2f862f6b8bff549ede541590a8d119da23', 'https://git.kernel.org/stable/c/977ee4fe895e1729cd36cc26916bbb10084713d6', 'https://git.kernel.org/stable/c/a658ae2173ab74667c009e2550455e6de5b33ddc', 'https://git.kernel.org/stable/c/b6ac46a00188cde50ffba233e6efb366354a1de5', 'https://git.kernel.org/stable/c/cb520c3f366c77e8d69e4e2e2781a8ce48d98e79', 'https://git.kernel.org/stable/c/e74eb5e8089427c8c49e0dd5067e5f39ce3a4d56', 'https://git.kernel.org/stable/c/f392c36cebf4c1d6997a4cc2c0f205254acef42a', 'https://linux.oracle.com/cve/CVE-2024-42310.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42310-58b0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42310', 'https://www.cve.org/CVERecord?id=CVE-2024-42310'], 'PublishedDate': '2024-08-17T09:15:11.067Z', 'LastModifiedDate': '2024-08-22T16:01:46.263Z'}, {'VulnerabilityID': 'CVE-2024-42311', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42311', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()\n\nSyzbot reports uninitialized value access issue as below:\n\nloop0: detected capacity change from 0 to 64\n=====================================================\nBUG: KMSAN: uninit-value in hfs_revalidate_dentry+0x307/0x3f0 fs/hfs/sysdep.c:30\n hfs_revalidate_dentry+0x307/0x3f0 fs/hfs/sysdep.c:30\n d_revalidate fs/namei.c:862 [inline]\n lookup_fast+0x89e/0x8e0 fs/namei.c:1649\n walk_component fs/namei.c:2001 [inline]\n link_path_walk+0x817/0x1480 fs/namei.c:2332\n path_lookupat+0xd9/0x6f0 fs/namei.c:2485\n filename_lookup+0x22e/0x740 fs/namei.c:2515\n user_path_at_empty+0x8b/0x390 fs/namei.c:2924\n user_path_at include/linux/namei.h:57 [inline]\n do_mount fs/namespace.c:3689 [inline]\n __do_sys_mount fs/namespace.c:3898 [inline]\n __se_sys_mount+0x66b/0x810 fs/namespace.c:3875\n __x64_sys_mount+0xe4/0x140 fs/namespace.c:3875\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nBUG: KMSAN: uninit-value in hfs_ext_read_extent fs/hfs/extent.c:196 [inline]\nBUG: KMSAN: uninit-value in hfs_get_block+0x92d/0x1620 fs/hfs/extent.c:366\n hfs_ext_read_extent fs/hfs/extent.c:196 [inline]\n hfs_get_block+0x92d/0x1620 fs/hfs/extent.c:366\n block_read_full_folio+0x4ff/0x11b0 fs/buffer.c:2271\n hfs_read_folio+0x55/0x60 fs/hfs/inode.c:39\n filemap_read_folio+0x148/0x4f0 mm/filemap.c:2426\n do_read_cache_folio+0x7c8/0xd90 mm/filemap.c:3553\n do_read_cache_page mm/filemap.c:3595 [inline]\n read_cache_page+0xfb/0x2f0 mm/filemap.c:3604\n read_mapping_page include/linux/pagemap.h:755 [inline]\n hfs_btree_open+0x928/0x1ae0 fs/hfs/btree.c:78\n hfs_mdb_get+0x260c/0x3000 fs/hfs/mdb.c:204\n hfs_fill_super+0x1fb1/0x2790 fs/hfs/super.c:406\n mount_bdev+0x628/0x920 fs/super.c:1359\n hfs_mount+0xcd/0xe0 fs/hfs/super.c:456\n legacy_get_tree+0x167/0x2e0 fs/fs_context.c:610\n vfs_get_tree+0xdc/0x5d0 fs/super.c:1489\n do_new_mount+0x7a9/0x16f0 fs/namespace.c:3145\n path_mount+0xf98/0x26a0 fs/namespace.c:3475\n do_mount fs/namespace.c:3488 [inline]\n __do_sys_mount fs/namespace.c:3697 [inline]\n __se_sys_mount+0x919/0x9e0 fs/namespace.c:3674\n __ia32_sys_mount+0x15b/0x1b0 fs/namespace.c:3674\n do_syscall_32_irqs_on arch/x86/entry/common.c:112 [inline]\n __do_fast_syscall_32+0xa2/0x100 arch/x86/entry/common.c:178\n do_fast_syscall_32+0x37/0x80 arch/x86/entry/common.c:203\n do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:246\n entry_SYSENTER_compat_after_hwframe+0x70/0x82\n\nUninit was created at:\n __alloc_pages+0x9a6/0xe00 mm/page_alloc.c:4590\n __alloc_pages_node include/linux/gfp.h:238 [inline]\n alloc_pages_node include/linux/gfp.h:261 [inline]\n alloc_slab_page mm/slub.c:2190 [inline]\n allocate_slab mm/slub.c:2354 [inline]\n new_slab+0x2d7/0x1400 mm/slub.c:2407\n ___slab_alloc+0x16b5/0x3970 mm/slub.c:3540\n __slab_alloc mm/slub.c:3625 [inline]\n __slab_alloc_node mm/slub.c:3678 [inline]\n slab_alloc_node mm/slub.c:3850 [inline]\n kmem_cache_alloc_lru+0x64d/0xb30 mm/slub.c:3879\n alloc_inode_sb include/linux/fs.h:3018 [inline]\n hfs_alloc_inode+0x5a/0xc0 fs/hfs/super.c:165\n alloc_inode+0x83/0x440 fs/inode.c:260\n new_inode_pseudo fs/inode.c:1005 [inline]\n new_inode+0x38/0x4f0 fs/inode.c:1031\n hfs_new_inode+0x61/0x1010 fs/hfs/inode.c:186\n hfs_mkdir+0x54/0x250 fs/hfs/dir.c:228\n vfs_mkdir+0x49a/0x700 fs/namei.c:4126\n do_mkdirat+0x529/0x810 fs/namei.c:4149\n __do_sys_mkdirat fs/namei.c:4164 [inline]\n __se_sys_mkdirat fs/namei.c:4162 [inline]\n __x64_sys_mkdirat+0xc8/0x120 fs/namei.c:4162\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nIt missed to initialize .tz_secondswest, .cached_start and .cached_blocks\nfields in struct hfs_inode_info after hfs_alloc_inode(), fix it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42311', 'https://git.kernel.org/linus/26a2ed107929a855155429b11e1293b83e6b2a8b (6.11-rc1)', 'https://git.kernel.org/stable/c/10f7163bfb5f8b4e0c9c05a939f20b8540e33c65', 'https://git.kernel.org/stable/c/26a2ed107929a855155429b11e1293b83e6b2a8b', 'https://git.kernel.org/stable/c/4a52861cd76e79f1a593beb23d096523eb9732c2', 'https://git.kernel.org/stable/c/58d83fc160505a7009c39dec64effaac5129b971', 'https://git.kernel.org/stable/c/9c4e40b9b731220f9464975e49da75496e3865c4', 'https://git.kernel.org/stable/c/d3493d6f0dfb1ab5225b62faa77732983f2187a1', 'https://git.kernel.org/stable/c/d55aae5c1730d6b70d5d8eaff00113cd34772ea3', 'https://git.kernel.org/stable/c/f7316b2b2f11cf0c6de917beee8d3de728be24db', 'https://linux.oracle.com/cve/CVE-2024-42311.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42311-f825@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42311', 'https://www.cve.org/CVERecord?id=CVE-2024-42311'], 'PublishedDate': '2024-08-17T09:15:11.147Z', 'LastModifiedDate': '2024-09-03T17:38:24.21Z'}, {'VulnerabilityID': 'CVE-2024-42312', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42312', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sysctl: always initialize i_uid/i_gid', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsysctl: always initialize i_uid/i_gid\n\nAlways initialize i_uid/i_gid inside the sysfs core so set_ownership()\ncan safely skip setting them.\n\nCommit 5ec27ec735ba ("fs/proc/proc_sysctl.c: fix the default values of\ni_uid/i_gid on /proc/sys inodes.") added defaults for i_uid/i_gid when\nset_ownership() was not implemented. It also missed adjusting\nnet_ctl_set_ownership() to use the same default values in case the\ncomputation of a better value failed.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42312', 'https://git.kernel.org/linus/98ca62ba9e2be5863c7d069f84f7166b45a5b2f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/1deae34db9f4f8e0e03f891be2e2e15c15c8ac05', 'https://git.kernel.org/stable/c/34a86adea1f2b3c3f9d864c8cce09dca644601ab', 'https://git.kernel.org/stable/c/98ca62ba9e2be5863c7d069f84f7166b45a5b2f4', 'https://git.kernel.org/stable/c/b2591c89a6e2858796111138c38fcb6851aa1955', 'https://git.kernel.org/stable/c/c7e2f43d182f5dde473389dbb39f16c9f0d64536', 'https://git.kernel.org/stable/c/ffde3af4b29bf97d62d82e1d45275587e10a991a', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42312-bddc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42312', 'https://www.cve.org/CVERecord?id=CVE-2024-42312'], 'PublishedDate': '2024-08-17T09:15:11.24Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42313', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42313', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: venus: fix use after free in vdec_close', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: fix use after free in vdec_close\n\nThere appears to be a possible use after free with vdec_close().\nThe firmware will add buffer release work to the work queue through\nHFI callbacks as a normal part of decoding. Randomly closing the\ndecoder device from userspace during normal decoding can incur\na read after free for inst.\n\nFix it by cancelling the work in vdec_close.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42313', 'https://git.kernel.org/linus/a0157b5aa34eb43ec4c5510f9c260bbb03be937e (6.11-rc1)', 'https://git.kernel.org/stable/c/4c9d235630d35db762b85a4149bbb0be9d504c36', 'https://git.kernel.org/stable/c/66fa52edd32cdbb675f0803b3c4da10ea19b6635', 'https://git.kernel.org/stable/c/6a96041659e834dc0b172dda4b2df512d63920c2', 'https://git.kernel.org/stable/c/72aff311194c8ceda934f24fd6f250b8827d7567', 'https://git.kernel.org/stable/c/a0157b5aa34eb43ec4c5510f9c260bbb03be937e', 'https://git.kernel.org/stable/c/ad8cf035baf29467158e0550c7a42b7bb43d1db6', 'https://git.kernel.org/stable/c/da55685247f409bf7f976cc66ba2104df75d8dad', 'https://git.kernel.org/stable/c/f8e9a63b982a8345470c225679af4ba86e4a7282', 'https://linux.oracle.com/cve/CVE-2024-42313.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42313-09b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42313', 'https://www.cve.org/CVERecord?id=CVE-2024-42313'], 'PublishedDate': '2024-08-17T09:15:11.32Z', 'LastModifiedDate': '2024-08-22T16:01:59.467Z'}, {'VulnerabilityID': 'CVE-2024-42314', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42314', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix extent map use-after-free when adding pages to compressed bio', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix extent map use-after-free when adding pages to compressed bio\n\nAt add_ra_bio_pages() we are accessing the extent map to calculate\n'add_size' after we dropped our reference on the extent map, resulting\nin a use-after-free. Fix this by computing 'add_size' before dropping our\nextent map reference.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42314', 'https://git.kernel.org/linus/8e7860543a94784d744c7ce34b78a2e11beefa5c (6.11-rc1)', 'https://git.kernel.org/stable/c/8e7860543a94784d744c7ce34b78a2e11beefa5c', 'https://git.kernel.org/stable/c/b7859ff398b6b656e1689daa860eb34837b4bb89', 'https://git.kernel.org/stable/c/c1cc3326e27b0bd7a2806b40bc48e49afaf951e7', 'https://git.kernel.org/stable/c/c205565e0f2f439f278a4a94ee97b67ef7b56ae8', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42314-de1f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42314', 'https://www.cve.org/CVERecord?id=CVE-2024-42314'], 'PublishedDate': '2024-08-17T09:15:11.397Z', 'LastModifiedDate': '2024-09-04T12:15:04.723Z'}, {'VulnerabilityID': 'CVE-2024-42315', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42315', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: exfat: fix potential deadlock on __exfat_get_dentry_set', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix potential deadlock on __exfat_get_dentry_set\n\nWhen accessing a file with more entries than ES_MAX_ENTRY_NUM, the bh-array\nis allocated in __exfat_get_entry_set. The problem is that the bh-array is\nallocated with GFP_KERNEL. It does not make sense. In the following cases,\na deadlock for sbi->s_lock between the two processes may occur.\n\n CPU0 CPU1\n ---- ----\n kswapd\n balance_pgdat\n lock(fs_reclaim)\n exfat_iterate\n lock(&sbi->s_lock)\n exfat_readdir\n exfat_get_uniname_from_ext_entry\n exfat_get_dentry_set\n __exfat_get_dentry_set\n kmalloc_array\n ...\n lock(fs_reclaim)\n ...\n evict\n exfat_evict_inode\n lock(&sbi->s_lock)\n\nTo fix this, let's allocate bh-array with GFP_NOFS.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42315', 'https://git.kernel.org/linus/89fc548767a2155231128cb98726d6d2ea1256c9 (6.11-rc1)', 'https://git.kernel.org/stable/c/1d1970493c289e3f44b9ec847ed26a5dbdf56a62', 'https://git.kernel.org/stable/c/89fc548767a2155231128cb98726d6d2ea1256c9', 'https://git.kernel.org/stable/c/a7ac198f8dba791e3144c4da48a5a9b95773ee4b', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42315-a707@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42315', 'https://www.cve.org/CVERecord?id=CVE-2024-42315'], 'PublishedDate': '2024-08-17T09:15:11.47Z', 'LastModifiedDate': '2024-08-22T15:51:03.077Z'}, {'VulnerabilityID': 'CVE-2024-42316', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42316', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/mglru: fix div-by-zero in vmpressure_calc_level()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mglru: fix div-by-zero in vmpressure_calc_level()\n\nevict_folios() uses a second pass to reclaim folios that have gone through\npage writeback and become clean before it finishes the first pass, since\nfolio_rotate_reclaimable() cannot handle those folios due to the\nisolation.\n\nThe second pass tries to avoid potential double counting by deducting\nscan_control->nr_scanned. However, this can result in underflow of\nnr_scanned, under a condition where shrink_folio_list() does not increment\nnr_scanned, i.e., when folio_trylock() fails.\n\nThe underflow can cause the divisor, i.e., scale=scanned+reclaimed in\nvmpressure_calc_level(), to become zero, resulting in the following crash:\n\n [exception RIP: vmpressure_work_fn+101]\n process_one_work at ffffffffa3313f2b\n\nSince scan_control->nr_scanned has no established semantics, the potential\ndouble counting has minimal risks. Therefore, fix the problem by not\ndeducting scan_control->nr_scanned in evict_folios().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42316', 'https://git.kernel.org/linus/8b671fe1a879923ecfb72dda6caf01460dd885ef (6.11-rc1)', 'https://git.kernel.org/stable/c/8b671fe1a879923ecfb72dda6caf01460dd885ef', 'https://git.kernel.org/stable/c/8de7bf77f21068a5f602bb1e59adbc5ab533509d', 'https://git.kernel.org/stable/c/a39e38be632f0e1c908d70d1c9cd071c03faf895', 'https://git.kernel.org/stable/c/d6510f234c7d117790397f9bb150816b0a954a04', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42316-8b49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42316', 'https://www.cve.org/CVERecord?id=CVE-2024-42316'], 'PublishedDate': '2024-08-17T09:15:11.547Z', 'LastModifiedDate': '2024-08-22T15:52:38.52Z'}, {'VulnerabilityID': 'CVE-2024-42317', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42317', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/huge_memory: avoid PMD-size page cache if needed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: avoid PMD-size page cache if needed\n\nxarray can\'t support arbitrary page cache size. the largest and supported\npage cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71\n("mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray"). However,\nit\'s possible to have 512MB page cache in the huge memory\'s collapsing\npath on ARM64 system whose base page size is 64KB. 512MB page cache is\nbreaking the limitation and a warning is raised when the xarray entry is\nsplit as shown in the following example.\n\n[root@dhcp-10-26-1-207 ~]# cat /proc/1/smaps | grep KernelPageSize\nKernelPageSize: 64 kB\n[root@dhcp-10-26-1-207 ~]# cat /tmp/test.c\n :\nint main(int argc, char **argv)\n{\n\tconst char *filename = TEST_XFS_FILENAME;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret = 0;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stdout, "System with 64KB base page size is required!\\n");\n\t\treturn -EPERM;\n\t}\n\n\tsystem("echo 0 > /sys/devices/virtual/bdi/253:0/read_ahead_kb");\n\tsystem("echo 1 > /proc/sys/vm/drop_caches");\n\n\t/* Open the xfs file */\n\tfd = open(filename, O_RDONLY);\n\tassert(fd > 0);\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE, PROT_READ, MAP_SHARED, fd, 0);\n\tassert(buf != (void *)-1);\n\tfprintf(stdout, "mapped buffer at 0x%p\\n", buf);\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_NOHUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_READ);\n\tassert(ret == 0);\n\n\t/* Collapse VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_COLLAPSE);\n\tif (ret) {\n\t\tfprintf(stdout, "Error %d to madvise(MADV_COLLAPSE)\\n", errno);\n\t\tgoto out;\n\t}\n\n\t/* Split xarray entry. Write permission is needed */\n\tmunmap(buf, TEST_MEM_SIZE);\n\tbuf = (void *)-1;\n\tclose(fd);\n\tfd = open(filename, O_RDWR);\n\tassert(fd > 0);\n\tfallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n \t\t TEST_MEM_SIZE - pgsize, pgsize);\nout:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn ret;\n}\n\n[root@dhcp-10-26-1-207 ~]# gcc /tmp/test.c -o /tmp/test\n[root@dhcp-10-26-1-207 ~]# /tmp/test\n ------------[ cut here ]------------\n WARNING: CPU: 25 PID: 7560 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\n Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\\n nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\\n nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\n ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse \\\n xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 virtio_net \\\n sha1_ce net_failover virtio_blk virtio_console failover dimlib virtio_mmio\n CPU: 25 PID: 7560 Comm: test Kdump: loaded Not tainted 6.10.0-rc7-gavin+ #9\n Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\n pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : xas_split_alloc+0xf8/0x128\n lr : split_huge_page_to_list_to_order+0x1c4/0x780\n sp : ffff8000ac32f660\n x29: ffff8000ac32f660 x28: ffff0000e0969eb0 x27: ffff8000ac32f6c0\n x26: 0000000000000c40 x25: ffff0000e0969eb0 x24: 000000000000000d\n x23: ffff8000ac32f6c0 x22: ffffffdfc0700000 x21: 0000000000000000\n x20: 0000000000000000 x19: ffffffdfc0700000 x18: 0000000000000000\n x17: 0000000000000000 x16: ffffd5f3708ffc70 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: ffffffffffffffc0 x10: 0000000000000040 x9 : ffffd5f3708e692c\n x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff0000e0969eb8\n x5 : ffffd5f37289e378 x4 : 0000000000000000 x3 : 0000000000000c40\n x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\n Call trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x780\n truncate_inode_partial_folio+0xdc/0x160\n truncate_inode_pages_range+0x1b4/0x4a8\n truncate_pagecache_range+0x84/0xa\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42317', 'https://git.kernel.org/linus/d659b715e94ac039803d7601505d3473393fc0be (6.11-rc1)', 'https://git.kernel.org/stable/c/d659b715e94ac039803d7601505d3473393fc0be', 'https://git.kernel.org/stable/c/e60f62f75c99740a28e2bf7e6044086033012a16', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42317-cf87@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42317', 'https://www.cve.org/CVERecord?id=CVE-2024-42317'], 'PublishedDate': '2024-08-17T09:15:11.633Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42318', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42318', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: landlock: Don't lose track of restrictions on cred_transfer', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Don't lose track of restrictions on cred_transfer\n\nWhen a process' cred struct is replaced, this _almost_ always invokes\nthe cred_prepare LSM hook; but in one special case (when\nKEYCTL_SESSION_TO_PARENT updates the parent's credentials), the\ncred_transfer LSM hook is used instead. Landlock only implements the\ncred_prepare hook, not cred_transfer, so KEYCTL_SESSION_TO_PARENT causes\nall information on Landlock restrictions to be lost.\n\nThis basically means that a process with the ability to use the fork()\nand keyctl() syscalls can get rid of all Landlock restrictions on\nitself.\n\nFix it by adding a cred_transfer hook that does the same thing as the\nexisting cred_prepare hook. (Implemented by having hook_cred_prepare()\ncall hook_cred_transfer() so that the two functions are less likely to\naccidentally diverge in the future.)", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42318', 'https://bugs.chromium.org/p/project-zero/issues/detail?id=2566', 'https://git.kernel.org/linus/39705a6c29f8a2b93cf5b99528a55366c50014d1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c', 'https://git.kernel.org/stable/c/16896914bace82d7811c62f3b6d5320132384f49', 'https://git.kernel.org/stable/c/39705a6c29f8a2b93cf5b99528a55366c50014d1', 'https://git.kernel.org/stable/c/916c648323fa53b89eedb34a0988ddaf01406117', 'https://git.kernel.org/stable/c/b14cc2cf313bd29056fadbc8ecd7f957cf5791ff', 'https://lore.kernel.org/all/20240817.shahka3Ee1iy@digikod.net/', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42318-f0c9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42318', 'https://www.cve.org/CVERecord?id=CVE-2024-42318', 'https://www.openwall.com/lists/oss-security/2024/08/17/2'], 'PublishedDate': '2024-08-17T09:15:11.7Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42319', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42319', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()\n\nWhen mtk-cmdq unbinds, a WARN_ON message with condition\npm_runtime_get_sync() < 0 occurs.\n\nAccording to the call tracei below:\n cmdq_mbox_shutdown\n mbox_free_channel\n mbox_controller_unregister\n __devm_mbox_controller_unregister\n ...\n\nThe root cause can be deduced to be calling pm_runtime_get_sync() after\ncalling pm_runtime_disable() as observed below:\n1. CMDQ driver uses devm_mbox_controller_register() in cmdq_probe()\n to bind the cmdq device to the mbox_controller, so\n devm_mbox_controller_unregister() will automatically unregister\n the device bound to the mailbox controller when the device-managed\n resource is removed. That means devm_mbox_controller_unregister()\n and cmdq_mbox_shoutdown() will be called after cmdq_remove().\n2. CMDQ driver also uses devm_pm_runtime_enable() in cmdq_probe() after\n devm_mbox_controller_register(), so that devm_pm_runtime_disable()\n will be called after cmdq_remove(), but before\n devm_mbox_controller_unregister().\n\nTo fix this problem, cmdq_probe() needs to move\ndevm_mbox_controller_register() after devm_pm_runtime_enable() to make\ndevm_pm_runtime_disable() be called after\ndevm_mbox_controller_unregister().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42319', 'https://git.kernel.org/linus/a8bd68e4329f9a0ad1b878733e0f80be6a971649 (6.11-rc1)', 'https://git.kernel.org/stable/c/11fa625b45faf0649118b9deaf2d31c86ac41911', 'https://git.kernel.org/stable/c/a8bd68e4329f9a0ad1b878733e0f80be6a971649', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42319-ec7c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42319', 'https://www.cve.org/CVERecord?id=CVE-2024-42319'], 'PublishedDate': '2024-08-17T09:15:11.767Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42320', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42320', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/dasd: fix error checks in dasd_copy_pair_store()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix error checks in dasd_copy_pair_store()\n\ndasd_add_busid() can return an error via ERR_PTR() if an allocation\nfails. However, two callsites in dasd_copy_pair_store() do not check\nthe result, potentially resulting in a NULL pointer dereference. Fix\nthis by checking the result with IS_ERR() and returning the error up\nthe stack.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42320', 'https://git.kernel.org/linus/8e64d2356cbc800b4cd0e3e614797f76bcf0cdb8 (6.11-rc1)', 'https://git.kernel.org/stable/c/68d4c3722290ad300c295fb3435e835d200d5cb2', 'https://git.kernel.org/stable/c/8e64d2356cbc800b4cd0e3e614797f76bcf0cdb8', 'https://git.kernel.org/stable/c/cc8b7284d5076722e0b8062373b68d8e47c3bace', 'https://git.kernel.org/stable/c/e511167e65d332d07b3c7a3d5a741ee9c19a8c27', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42320-cdea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42320', 'https://www.cve.org/CVERecord?id=CVE-2024-42320'], 'PublishedDate': '2024-08-17T09:15:11.833Z', 'LastModifiedDate': '2024-09-30T12:54:12.897Z'}, {'VulnerabilityID': 'CVE-2024-42321', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42321', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: flow_dissector: use DEBUG_NET_WARN_ON_ONCE', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: flow_dissector: use DEBUG_NET_WARN_ON_ONCE\n\nThe following splat is easy to reproduce upstream as well as in -stable\nkernels. Florian Westphal provided the following commit:\n\n d1dab4f71d37 ("net: add and use __skb_get_hash_symmetric_net")\n\nbut this complementary fix has been also suggested by Willem de Bruijn\nand it can be easily backported to -stable kernel which consists in\nusing DEBUG_NET_WARN_ON_ONCE instead to silence the following splat\ngiven __skb_get_hash() is used by the nftables tracing infrastructure to\nto identify packets in traces.\n\n[69133.561393] ------------[ cut here ]------------\n[69133.561404] WARNING: CPU: 0 PID: 43576 at net/core/flow_dissector.c:1104 __skb_flow_dissect+0x134f/\n[...]\n[69133.561944] CPU: 0 PID: 43576 Comm: socat Not tainted 6.10.0-rc7+ #379\n[69133.561959] RIP: 0010:__skb_flow_dissect+0x134f/0x2ad0\n[69133.561970] Code: 83 f9 04 0f 84 b3 00 00 00 45 85 c9 0f 84 aa 00 00 00 41 83 f9 02 0f 84 81 fc ff\nff 44 0f b7 b4 24 80 00 00 00 e9 8b f9 ff ff <0f> 0b e9 20 f3 ff ff 41 f6 c6 20 0f 84 e4 ef ff ff 48 8d 7b 12 e8\n[69133.561979] RSP: 0018:ffffc90000006fc0 EFLAGS: 00010246\n[69133.561988] RAX: 0000000000000000 RBX: ffffffff82f33e20 RCX: ffffffff81ab7e19\n[69133.561994] RDX: dffffc0000000000 RSI: ffffc90000007388 RDI: ffff888103a1b418\n[69133.562001] RBP: ffffc90000007310 R08: 0000000000000000 R09: 0000000000000000\n[69133.562007] R10: ffffc90000007388 R11: ffffffff810cface R12: ffff888103a1b400\n[69133.562013] R13: 0000000000000000 R14: ffffffff82f33e2a R15: ffffffff82f33e28\n[69133.562020] FS: 00007f40f7131740(0000) GS:ffff888390800000(0000) knlGS:0000000000000000\n[69133.562027] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[69133.562033] CR2: 00007f40f7346ee0 CR3: 000000015d200001 CR4: 00000000001706f0\n[69133.562040] Call Trace:\n[69133.562044] \n[69133.562049] ? __warn+0x9f/0x1a0\n[ 1211.841384] ? __skb_flow_dissect+0x107e/0x2860\n[...]\n[ 1211.841496] ? bpf_flow_dissect+0x160/0x160\n[ 1211.841753] __skb_get_hash+0x97/0x280\n[ 1211.841765] ? __skb_get_hash_symmetric+0x230/0x230\n[ 1211.841776] ? mod_find+0xbf/0xe0\n[ 1211.841786] ? get_stack_info_noinstr+0x12/0xe0\n[ 1211.841798] ? bpf_ksym_find+0x56/0xe0\n[ 1211.841807] ? __rcu_read_unlock+0x2a/0x70\n[ 1211.841819] nft_trace_init+0x1b9/0x1c0 [nf_tables]\n[ 1211.841895] ? nft_trace_notify+0x830/0x830 [nf_tables]\n[ 1211.841964] ? get_stack_info+0x2b/0x80\n[ 1211.841975] ? nft_do_chain_arp+0x80/0x80 [nf_tables]\n[ 1211.842044] nft_do_chain+0x79c/0x850 [nf_tables]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42321', 'https://git.kernel.org/linus/120f1c857a73e52132e473dee89b340440cb692b (6.11-rc1)', 'https://git.kernel.org/stable/c/120f1c857a73e52132e473dee89b340440cb692b', 'https://git.kernel.org/stable/c/4afbac11f2f629d1e62817c4e210bdfaa7521107', 'https://git.kernel.org/stable/c/c5d21aabf1b31a79f228508af33aee83456bc1b0', 'https://git.kernel.org/stable/c/eb03d9826aa646577342a952d658d4598381c035', 'https://lore.kernel.org/linux-cve-announce/2024081755-CVE-2024-42321-4b46@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42321', 'https://www.cve.org/CVERecord?id=CVE-2024-42321'], 'PublishedDate': '2024-08-17T09:15:11.917Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42322', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42322', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipvs: properly dereference pe in ip_vs_add_service', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: properly dereference pe in ip_vs_add_service\n\nUse pe directly to resolve sparse warning:\n\n net/netfilter/ipvs/ip_vs_ctl.c:1471:27: warning: dereference of noderef expression', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42322', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/cbd070a4ae62f119058973f6d2c984e325bce6e7 (6.11-rc1)', 'https://git.kernel.org/stable/c/3dd428039e06e1967ce294e2cd6342825aaaad77', 'https://git.kernel.org/stable/c/c420cd5d5bc6797f3a8824e7d74f38f0c286fca5', 'https://git.kernel.org/stable/c/cbd070a4ae62f119058973f6d2c984e325bce6e7', 'https://linux.oracle.com/cve/CVE-2024-42322.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024081755-CVE-2024-42322-e2ef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42322', 'https://www.cve.org/CVERecord?id=CVE-2024-42322'], 'PublishedDate': '2024-08-17T09:15:11.977Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43817', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43817', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: missing check virtio', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: missing check virtio\n\nTwo missing check in virtio_net_hdr_to_skb() allowed syzbot\nto crash kernels again\n\n1. After the skb_segment function the buffer may become non-linear\n(nr_frags != 0), but since the SKBTX_SHARED_FRAG flag is not set anywhere\nthe __skb_linearize function will not be executed, then the buffer will\nremain non-linear. Then the condition (offset >= skb_headlen(skb))\nbecomes true, which causes WARN_ON_ONCE in skb_checksum_help.\n\n2. The struct sk_buff and struct virtio_net_hdr members must be\nmathematically related.\n(gso_size) must be greater than (needed) otherwise WARN_ON_ONCE.\n(remainder) must be greater than (needed) otherwise WARN_ON_ONCE.\n(remainder) may be 0 if division is without remainder.\n\noffset+2 (4191) > skb_headlen() (1116)\nWARNING: CPU: 1 PID: 5084 at net/core/dev.c:3303 skb_checksum_help+0x5e2/0x740 net/core/dev.c:3303\nModules linked in:\nCPU: 1 PID: 5084 Comm: syz-executor336 Not tainted 6.7.0-rc3-syzkaller-00014-gdf60cee26a2e #0\nHardware name: Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023\nRIP: 0010:skb_checksum_help+0x5e2/0x740 net/core/dev.c:3303\nCode: 89 e8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 52 01 00 00 44 89 e2 2b 53 74 4c 89 ee 48 c7 c7 40 57 e9 8b e8 af 8f dd f8 90 <0f> 0b 90 90 e9 87 fe ff ff e8 40 0f 6e f9 e9 4b fa ff ff 48 89 ef\nRSP: 0018:ffffc90003a9f338 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff888025125780 RCX: ffffffff814db209\nRDX: ffff888015393b80 RSI: ffffffff814db216 RDI: 0000000000000001\nRBP: ffff8880251257f4 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000001 R12: 000000000000045c\nR13: 000000000000105f R14: ffff8880251257f0 R15: 000000000000105d\nFS: 0000555555c24380(0000) GS:ffff8880b9900000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000002000f000 CR3: 0000000023151000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ip_do_fragment+0xa1b/0x18b0 net/ipv4/ip_output.c:777\n ip_fragment.constprop.0+0x161/0x230 net/ipv4/ip_output.c:584\n ip_finish_output_gso net/ipv4/ip_output.c:286 [inline]\n __ip_finish_output net/ipv4/ip_output.c:308 [inline]\n __ip_finish_output+0x49c/0x650 net/ipv4/ip_output.c:295\n ip_finish_output+0x31/0x310 net/ipv4/ip_output.c:323\n NF_HOOK_COND include/linux/netfilter.h:303 [inline]\n ip_output+0x13b/0x2a0 net/ipv4/ip_output.c:433\n dst_output include/net/dst.h:451 [inline]\n ip_local_out+0xaf/0x1a0 net/ipv4/ip_output.c:129\n iptunnel_xmit+0x5b4/0x9b0 net/ipv4/ip_tunnel_core.c:82\n ipip6_tunnel_xmit net/ipv6/sit.c:1034 [inline]\n sit_tunnel_xmit+0xed2/0x28f0 net/ipv6/sit.c:1076\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3545 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3561\n __dev_queue_xmit+0x7c1/0x3d60 net/core/dev.c:4346\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n packet_xmit+0x257/0x380 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3087 [inline]\n packet_sendmsg+0x24ca/0x5240 net/packet/af_packet.c:3119\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0xd5/0x180 net/socket.c:745\n __sys_sendto+0x255/0x340 net/socket.c:2190\n __do_sys_sendto net/socket.c:2202 [inline]\n __se_sys_sendto net/socket.c:2198 [inline]\n __x64_sys_sendto+0xe0/0x1b0 net/socket.c:2198\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x40/0x110 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43817', 'https://git.kernel.org/linus/e269d79c7d35aa3808b1f3c1737d63dab504ddc8 (6.11-rc1)', 'https://git.kernel.org/stable/c/27874ca77bd2b05a3779c7b3a5c75d8dd7f0b40f', 'https://git.kernel.org/stable/c/5b1997487a3f3373b0f580c8a20b56c1b64b0775', 'https://git.kernel.org/stable/c/90d41ebe0cd4635f6410471efc1dd71b33e894cf', 'https://git.kernel.org/stable/c/e269d79c7d35aa3808b1f3c1737d63dab504ddc8', 'https://git.kernel.org/stable/c/e9164903b8b303c34723177b02fe91e49e3c4cd7', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43817-2e95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43817', 'https://www.cve.org/CVERecord?id=CVE-2024-43817'], 'PublishedDate': '2024-08-17T10:15:08.01Z', 'LastModifiedDate': '2024-09-03T17:41:46.407Z'}, {'VulnerabilityID': 'CVE-2024-43818', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43818', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: amd: Adjust error handling in case of absent codec device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: Adjust error handling in case of absent codec device\n\nacpi_get_first_physical_node() can return NULL in several cases (no such\ndevice, ACPI table error, reference count drop to 0, etc).\nExisting check just emit error message, but doesn't perform return.\nThen this NULL pointer is passed to devm_acpi_dev_add_driver_gpios()\nwhere it is dereferenced.\n\nAdjust this error handling by adding error code return.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43818', 'https://git.kernel.org/linus/5080808c3339de2220c602ab7c7fa23dc6c1a5a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/1ba9856cf7f6492b47c1edf853137f320d583db5', 'https://git.kernel.org/stable/c/5080808c3339de2220c602ab7c7fa23dc6c1a5a3', 'https://git.kernel.org/stable/c/99b642dac24f6d09ba3ebf1d690be8aefff86164', 'https://git.kernel.org/stable/c/b1173d64edd276c957b6d09e1f971c85b38f1519', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43818-71ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43818', 'https://www.cve.org/CVERecord?id=CVE-2024-43818'], 'PublishedDate': '2024-08-17T10:15:08.08Z', 'LastModifiedDate': '2024-09-03T17:45:30Z'}, {'VulnerabilityID': 'CVE-2024-43819', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43819', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kvm: s390: Reject memory region operations for ucontrol VMs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkvm: s390: Reject memory region operations for ucontrol VMs\n\nThis change rejects the KVM_SET_USER_MEMORY_REGION and\nKVM_SET_USER_MEMORY_REGION2 ioctls when called on a ucontrol VM.\nThis is necessary since ucontrol VMs have kvm->arch.gmap set to 0 and\nwould thus result in a null pointer dereference further in.\nMemory management needs to be performed in userspace and using the\nioctls KVM_S390_UCAS_MAP and KVM_S390_UCAS_UNMAP.\n\nAlso improve s390 specific documentation for KVM_SET_USER_MEMORY_REGION\nand KVM_SET_USER_MEMORY_REGION2.\n\n[frankja@linux.ibm.com: commit message spelling fix, subject prefix fix]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43819', 'https://git.kernel.org/linus/7816e58967d0e6cadce05c8540b47ed027dc2499 (6.11-rc1)', 'https://git.kernel.org/stable/c/49c9945c054df4c22008e2bf87ca74d3e2507aa6', 'https://git.kernel.org/stable/c/7816e58967d0e6cadce05c8540b47ed027dc2499', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43819-88ce@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43819', 'https://www.cve.org/CVERecord?id=CVE-2024-43819'], 'PublishedDate': '2024-08-17T10:15:08.147Z', 'LastModifiedDate': '2024-09-03T17:47:10.54Z'}, {'VulnerabilityID': 'CVE-2024-43820', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43820', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume\n\nrm-raid devices will occasionally trigger the following warning when\nbeing resumed after a table load because DM_RECOVERY_RUNNING is set:\n\nWARNING: CPU: 7 PID: 5660 at drivers/md/dm-raid.c:4105 raid_resume+0xee/0x100 [dm_raid]\n\nThe failing check is:\nWARN_ON_ONCE(test_bit(MD_RECOVERY_RUNNING, &mddev->recovery));\n\nThis check is designed to make sure that the sync thread isn't\nregistered, but md_check_recovery can set MD_RECOVERY_RUNNING without\nthe sync_thread ever getting registered. Instead of checking if\nMD_RECOVERY_RUNNING is set, check if sync_thread is non-NULL.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43820', 'https://git.kernel.org/linus/3199a34bfaf7561410e0be1e33a61eba870768fc (6.11-rc1)', 'https://git.kernel.org/stable/c/3199a34bfaf7561410e0be1e33a61eba870768fc', 'https://git.kernel.org/stable/c/a5c15a78c0e1631b7df822b56e8b6424e4d1ca3e', 'https://lore.kernel.org/linux-cve-announce/2024081724-CVE-2024-43820-1bd6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43820', 'https://www.cve.org/CVERecord?id=CVE-2024-43820'], 'PublishedDate': '2024-08-17T10:15:08.207Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43821', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43821', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: lpfc: Fix a possible null pointer dereference', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix a possible null pointer dereference\n\nIn function lpfc_xcvr_data_show, the memory allocation with kmalloc might\nfail, thereby making rdp_context a null pointer. In the following context\nand functions that use this pointer, there are dereferencing operations,\nleading to null pointer dereference.\n\nTo fix this issue, a null pointer check should be added. If it is null,\nuse scnprintf to notify the user and return len.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43821', 'https://git.kernel.org/linus/5e0bf3e8aec2cbc51123f84b29aaacbd91fc56fa (6.11-rc1)', 'https://git.kernel.org/stable/c/45b2a23e00d448a9e6d1f371ca3a4d4b073fe78c', 'https://git.kernel.org/stable/c/57600a7dd2b52c904f7c8d2cac0fd8c23868e680', 'https://git.kernel.org/stable/c/5e0bf3e8aec2cbc51123f84b29aaacbd91fc56fa', 'https://lore.kernel.org/linux-cve-announce/2024081724-CVE-2024-43821-6ffc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43821', 'https://www.cve.org/CVERecord?id=CVE-2024-43821'], 'PublishedDate': '2024-08-17T10:15:08.277Z', 'LastModifiedDate': '2024-09-03T17:49:54.28Z'}, {'VulnerabilityID': 'CVE-2024-43823', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43823', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()\n\nIf IORESOURCE_MEM is not provided in Device Tree due to\nany error, resource_list_first_type() will return NULL and\npci_parse_request_of_pci_ranges() will just emit a warning.\n\nThis will cause a NULL pointer dereference. Fix this bug by adding NULL\nreturn check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43823', 'https://git.kernel.org/linus/a231707a91f323af1e5d9f1722055ec2fc1c7775 (6.11-rc1)', 'https://git.kernel.org/stable/c/0a6f1b5fe8ef8268aaa069035639968ceeea0a23', 'https://git.kernel.org/stable/c/a231707a91f323af1e5d9f1722055ec2fc1c7775', 'https://git.kernel.org/stable/c/bbba48ad67c53feea05936ea1e029dcca8057506', 'https://git.kernel.org/stable/c/dbcdd1863ba2ec9b76ec131df25d797709e05597', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43823-4bdd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43823', 'https://www.cve.org/CVERecord?id=CVE-2024-43823'], 'PublishedDate': '2024-08-17T10:15:08.4Z', 'LastModifiedDate': '2024-09-03T17:49:03.91Z'}, {'VulnerabilityID': 'CVE-2024-43824', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43824', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: pci-epf-test: Make use of cached \'epc_features\' in pci_epf_test_core_init()\n\nInstead of getting the epc_features from pci_epc_get_features() API, use\nthe cached pci_epf_test::epc_features value to avoid the NULL check. Since\nthe NULL check is already performed in pci_epf_test_bind(), having one more\ncheck in pci_epf_test_core_init() is redundant and it is not possible to\nhit the NULL pointer dereference.\n\nAlso with commit a01e7214bef9 ("PCI: endpoint: Remove "core_init_notifier"\nflag"), \'epc_features\' got dereferenced without the NULL check, leading to\nthe following false positive Smatch warning:\n\n drivers/pci/endpoint/functions/pci-epf-test.c:784 pci_epf_test_core_init() error: we previously assumed \'epc_features\' could be null (see line 747)\n\nThus, remove the redundant NULL check and also use the epc_features::\n{msix_capable/msi_capable} flags directly to avoid local variables.\n\n[kwilczynski: commit log]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43824', 'https://git.kernel.org/linus/5a5095a8bd1bd349cce1c879e5e44407a34dda8a (6.11-rc1)', 'https://git.kernel.org/stable/c/5a5095a8bd1bd349cce1c879e5e44407a34dda8a', 'https://git.kernel.org/stable/c/af4ad016abb1632ff7ee598a6037952b495e5b80', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43824-fc04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43824', 'https://www.cve.org/CVERecord?id=CVE-2024-43824'], 'PublishedDate': '2024-08-17T10:15:08.477Z', 'LastModifiedDate': '2024-09-03T17:48:39.16Z'}, {'VulnerabilityID': 'CVE-2024-43825', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43825', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iio: Fix the sorting functionality in iio_gts_build_avail_time_table', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: Fix the sorting functionality in iio_gts_build_avail_time_table\n\nThe sorting in iio_gts_build_avail_time_table is not working as intended.\nIt could result in an out-of-bounds access when the time is zero.\n\nHere are more details:\n\n1. When the gts->itime_table[i].time_us is zero, e.g., the time\nsequence is `3, 0, 1`, the inner for-loop will not terminate and do\nout-of-bound writes. This is because once `times[j] > new`, the value\n`new` will be added in the current position and the `times[j]` will be\nmoved to `j+1` position, which makes the if-condition always hold.\nMeanwhile, idx will be added one, making the loop keep running without\ntermination and out-of-bound write.\n2. If none of the gts->itime_table[i].time_us is zero, the elements\nwill just be copied without being sorted as described in the comment\n"Sort times from all tables to one and remove duplicates".\n\nFor more details, please refer to\nhttps://lore.kernel.org/all/6dd0d822-046c-4dd2-9532-79d7ab96ec05@gmail.com.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 5.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43825', 'https://git.kernel.org/linus/5acc3f971a01be48d5ff4252d8f9cdb87998cdfb (6.11-rc1)', 'https://git.kernel.org/stable/c/31ff8464ef540785344994986a010031410f9ff3', 'https://git.kernel.org/stable/c/5acc3f971a01be48d5ff4252d8f9cdb87998cdfb', 'https://git.kernel.org/stable/c/b5046de32fd1532c3f67065197fc1da82f0b5193', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43825-20fc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43825', 'https://www.cve.org/CVERecord?id=CVE-2024-43825'], 'PublishedDate': '2024-08-17T10:15:08.533Z', 'LastModifiedDate': '2024-09-30T13:53:21.44Z'}, {'VulnerabilityID': 'CVE-2024-43826', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43826', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfs: pass explicit offset/count to trace events', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: pass explicit offset/count to trace events\n\nnfs_folio_length is unsafe to use without having the folio locked and a\ncheck for a NULL ->f_mapping that protects against truncations and can\nlead to kernel crashes. E.g. when running xfstests generic/065 with\nall nfs trace points enabled.\n\nFollow the model of the XFS trace points and pass in an explіcit offset\nand length. This has the additional benefit that these values can\nbe more accurate as some of the users touch partial folio ranges.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43826', 'https://git.kernel.org/linus/fada32ed6dbc748f447c8d050a961b75d946055a (6.11-rc1)', 'https://git.kernel.org/stable/c/387e6e9d110250946df4d4ebef9c2def5c7a4722', 'https://git.kernel.org/stable/c/fada32ed6dbc748f447c8d050a961b75d946055a', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43826-2a5f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43826', 'https://www.cve.org/CVERecord?id=CVE-2024-43826'], 'PublishedDate': '2024-08-17T10:15:08.593Z', 'LastModifiedDate': '2024-09-12T18:15:09.137Z'}, {'VulnerabilityID': 'CVE-2024-43827', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43827', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null check before access structs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check before access structs\n\nIn enable_phantom_plane, we should better check null pointer before\naccessing various structs.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43827', 'https://git.kernel.org/linus/c96140000915b610d86f941450e15ca552de154a (6.11-rc1)', 'https://git.kernel.org/stable/c/081ff4c0ef1884ae55f7adb8944efd22e22d8724', 'https://git.kernel.org/stable/c/c96140000915b610d86f941450e15ca552de154a', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43827-6486@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43827', 'https://www.cve.org/CVERecord?id=CVE-2024-43827'], 'PublishedDate': '2024-08-17T10:15:08.653Z', 'LastModifiedDate': '2024-09-30T12:51:34.97Z'}, {'VulnerabilityID': 'CVE-2024-43828', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43828', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: fix infinite loop when replaying fast_commit', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix infinite loop when replaying fast_commit\n\nWhen doing fast_commit replay an infinite loop may occur due to an\nuninitialized extent_status struct. ext4_ext_determine_insert_hole() does\nnot detect the replay and calls ext4_es_find_extent_range(), which will\nreturn immediately without initializing the 'es' variable.\n\nBecause 'es' contains garbage, an integer overflow may happen causing an\ninfinite loop in this function, easily reproducible using fstest generic/039.\n\nThis commit fixes this issue by unconditionally initializing the structure\nin function ext4_es_find_extent_range().\n\nThanks to Zhang Yi, for figuring out the real problem!", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43828', 'https://git.kernel.org/linus/907c3fe532253a6ef4eb9c4d67efb71fab58c706 (6.11-rc1)', 'https://git.kernel.org/stable/c/0619f7750f2b178a1309808832ab20d85e0ad121', 'https://git.kernel.org/stable/c/181e63cd595c688194e07332f9944b3a63193de2', 'https://git.kernel.org/stable/c/5ed0496e383cb6de120e56991385dce70bbb87c1', 'https://git.kernel.org/stable/c/81f819c537d29932e4b9267f02411cbc8b355178', 'https://git.kernel.org/stable/c/907c3fe532253a6ef4eb9c4d67efb71fab58c706', 'https://git.kernel.org/stable/c/c6e67df64783e99a657ef2b8c834ba2bf54c539c', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43828-6bcb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43828', 'https://www.cve.org/CVERecord?id=CVE-2024-43828'], 'PublishedDate': '2024-08-17T10:15:08.72Z', 'LastModifiedDate': '2024-08-22T15:41:50.87Z'}, {'VulnerabilityID': 'CVE-2024-43829', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43829', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/qxl: Add check for drm_cvt_mode', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/qxl: Add check for drm_cvt_mode\n\nAdd check for the return value of drm_cvt_mode() and return the error if\nit fails in order to avoid NULL pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43829', 'https://git.kernel.org/linus/7bd09a2db0f617377027a2bb0b9179e6959edff3 (6.11-rc1)', 'https://git.kernel.org/stable/c/3efe34f95b1ac8c138a46b14ce75956db0d6ee7c', 'https://git.kernel.org/stable/c/4b1f303bdeceac049e56e4b20eb5280bd9e02f4f', 'https://git.kernel.org/stable/c/4e87f592a46bb804d8f833da6ce702ae4b55053f', 'https://git.kernel.org/stable/c/62ef8d7816c8e4a6088275553818b9afc0ffaa03', 'https://git.kernel.org/stable/c/7bd09a2db0f617377027a2bb0b9179e6959edff3', 'https://git.kernel.org/stable/c/d4c57354a06cb4a77998ff8aa40af89eee30e07b', 'https://git.kernel.org/stable/c/f28b353c0c6c7831a70ccca881bf2db5e6785cdd', 'https://linux.oracle.com/cve/CVE-2024-43829.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43829-72cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43829', 'https://www.cve.org/CVERecord?id=CVE-2024-43829'], 'PublishedDate': '2024-08-17T10:15:08.787Z', 'LastModifiedDate': '2024-09-30T12:51:56.77Z'}, {'VulnerabilityID': 'CVE-2024-43830', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43830', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: leds: trigger: Unregister sysfs attributes before calling deactivate()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nleds: trigger: Unregister sysfs attributes before calling deactivate()\n\nTriggers which have trigger specific sysfs attributes typically store\nrelated data in trigger-data allocated by the activate() callback and\nfreed by the deactivate() callback.\n\nCalling device_remove_groups() after calling deactivate() leaves a window\nwhere the sysfs attributes show/store functions could be called after\ndeactivation and then operate on the just freed trigger-data.\n\nMove the device_remove_groups() call to before deactivate() to close\nthis race window.\n\nThis also makes the deactivation path properly do things in reverse order\nof the activation path which calls the activate() callback before calling\ndevice_add_groups().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7000', 'https://access.redhat.com/security/cve/CVE-2024-43830', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2265838', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2270103', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275558', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282648', 'https://bugzilla.redhat.com/2282669', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282764', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284511', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284630', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293414', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300381', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300439', 'https://bugzilla.redhat.com/2300440', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300709', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301543', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305410', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2305488', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7000.html', 'https://git.kernel.org/linus/c0dc9adf9474ecb7106e60e5472577375aedaed3 (6.11-rc1)', 'https://git.kernel.org/stable/c/0788a6f3523d3686a9eed5ea1e6fcce6841277b2', 'https://git.kernel.org/stable/c/09c1583f0e10c918855d6e7540a79461a353e5d6', 'https://git.kernel.org/stable/c/3fb6a9d67cfd812a547ac73ec02e1077c26c640d', 'https://git.kernel.org/stable/c/734ba6437e80dfc780e9ee9d95f912392d12b5ea', 'https://git.kernel.org/stable/c/c0dc9adf9474ecb7106e60e5472577375aedaed3', 'https://git.kernel.org/stable/c/c3b7a650c8717aa89df318364609c86cbc040156', 'https://git.kernel.org/stable/c/cb8aa9d2a4c8a15d6a43ccf901ef3d094aa60374', 'https://git.kernel.org/stable/c/d1415125b701ef13370e2761f691ec632a5eb93a', 'https://linux.oracle.com/cve/CVE-2024-43830.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43830-3b85@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43830', 'https://www.cve.org/CVERecord?id=CVE-2024-43830'], 'PublishedDate': '2024-08-17T10:15:08.857Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43831', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43831', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: mediatek: vcodec: Handle invalid decoder vsi', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: Handle invalid decoder vsi\n\nHandle an invalid decoder vsi in vpu_dec_init to ensure the decoder vsi\nis valid for future use.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43831', 'https://git.kernel.org/linus/59d438f8e02ca641c58d77e1feffa000ff809e9f (6.11-rc1)', 'https://git.kernel.org/stable/c/1c109f23b271a02b9bb195c173fab41e3285a8db', 'https://git.kernel.org/stable/c/59d438f8e02ca641c58d77e1feffa000ff809e9f', 'https://git.kernel.org/stable/c/cdf05ae76198c513836bde4eb55f099c44773280', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43831-b13e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43831', 'https://www.cve.org/CVERecord?id=CVE-2024-43831'], 'PublishedDate': '2024-08-17T10:15:08.917Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43832', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43832', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: s390/uv: Don't call folio_wait_writeback() without a folio reference", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/uv: Don't call folio_wait_writeback() without a folio reference\n\nfolio_wait_writeback() requires that no spinlocks are held and that\na folio reference is held, as documented. After we dropped the PTL, the\nfolio could get freed concurrently. So grab a temporary reference.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43832', 'https://git.kernel.org/linus/3f29f6537f54d74e64bac0a390fb2e26da25800d (6.11-rc1)', 'https://git.kernel.org/stable/c/1a1eb2f3fc453dcd52726d13e863938561489cb7', 'https://git.kernel.org/stable/c/3f29f6537f54d74e64bac0a390fb2e26da25800d', 'https://git.kernel.org/stable/c/8736604ef53359a718c246087cd21dcec232d2fb', 'https://git.kernel.org/stable/c/b21aba72aadd94bdac275deab021fc84d6c72b16', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43832-7746@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43832', 'https://www.cve.org/CVERecord?id=CVE-2024-43832'], 'PublishedDate': '2024-08-17T10:15:08.98Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43833', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43833', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: v4l: async: Fix NULL pointer dereference in adding ancillary links', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l: async: Fix NULL pointer dereference in adding ancillary links\n\nIn v4l2_async_create_ancillary_links(), ancillary links are created for\nlens and flash sub-devices. These are sub-device to sub-device links and\nif the async notifier is related to a V4L2 device, the source sub-device\nof the ancillary link is NULL, leading to a NULL pointer dereference.\nCheck the notifier's sd field is non-NULL in\nv4l2_async_create_ancillary_links().\n\n[Sakari Ailus: Reword the subject and commit messages slightly.]", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43833', 'https://git.kernel.org/linus/9b4667ea67854f0b116fe22ad11ef5628c5b5b5f (6.11-rc1)', 'https://git.kernel.org/stable/c/249212ceb4187783af3801c57b92a5a25d410621', 'https://git.kernel.org/stable/c/9b4667ea67854f0b116fe22ad11ef5628c5b5b5f', 'https://git.kernel.org/stable/c/b87e28050d9b0959de24574d587825cfab2f13fb', 'https://git.kernel.org/stable/c/fe0f92fd5320b393e44ca210805e653ea90cc982', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43833-4e73@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43833', 'https://www.cve.org/CVERecord?id=CVE-2024-43833'], 'PublishedDate': '2024-08-17T10:15:09.04Z', 'LastModifiedDate': '2024-08-22T15:42:46.827Z'}, {'VulnerabilityID': 'CVE-2024-43834', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43834', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xdp: fix invalid wait context of page_pool_destroy()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix invalid wait context of page_pool_destroy()\n\nIf the driver uses a page pool, it creates a page pool with\npage_pool_create().\nThe reference count of page pool is 1 as default.\nA page pool will be destroyed only when a reference count reaches 0.\npage_pool_destroy() is used to destroy page pool, it decreases a\nreference count.\nWhen a page pool is destroyed, ->disconnect() is called, which is\nmem_allocator_disconnect().\nThis function internally acquires mutex_lock().\n\nIf the driver uses XDP, it registers a memory model with\nxdp_rxq_info_reg_mem_model().\nThe xdp_rxq_info_reg_mem_model() internally increases a page pool\nreference count if a memory model is a page pool.\nNow the reference count is 2.\n\nTo destroy a page pool, the driver should call both page_pool_destroy()\nand xdp_unreg_mem_model().\nThe xdp_unreg_mem_model() internally calls page_pool_destroy().\nOnly page_pool_destroy() decreases a reference count.\n\nIf a driver calls page_pool_destroy() then xdp_unreg_mem_model(), we\nwill face an invalid wait context warning.\nBecause xdp_unreg_mem_model() calls page_pool_destroy() with\nrcu_read_lock().\nThe page_pool_destroy() internally acquires mutex_lock().\n\nSplat looks like:\n=============================\n[ BUG: Invalid wait context ]\n6.10.0-rc6+ #4 Tainted: G W\n-----------------------------\nethtool/1806 is trying to lock:\nffffffff90387b90 (mem_id_lock){+.+.}-{4:4}, at: mem_allocator_disconnect+0x73/0x150\nother info that might help us debug this:\ncontext-{5:5}\n3 locks held by ethtool/1806:\nstack backtrace:\nCPU: 0 PID: 1806 Comm: ethtool Tainted: G W 6.10.0-rc6+ #4 f916f41f172891c800f2fed\nHardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021\nCall Trace:\n\ndump_stack_lvl+0x7e/0xc0\n__lock_acquire+0x1681/0x4de0\n? _printk+0x64/0xe0\n? __pfx_mark_lock.part.0+0x10/0x10\n? __pfx___lock_acquire+0x10/0x10\nlock_acquire+0x1b3/0x580\n? mem_allocator_disconnect+0x73/0x150\n? __wake_up_klogd.part.0+0x16/0xc0\n? __pfx_lock_acquire+0x10/0x10\n? dump_stack_lvl+0x91/0xc0\n__mutex_lock+0x15c/0x1690\n? mem_allocator_disconnect+0x73/0x150\n? __pfx_prb_read_valid+0x10/0x10\n? mem_allocator_disconnect+0x73/0x150\n? __pfx_llist_add_batch+0x10/0x10\n? console_unlock+0x193/0x1b0\n? lockdep_hardirqs_on+0xbe/0x140\n? __pfx___mutex_lock+0x10/0x10\n? tick_nohz_tick_stopped+0x16/0x90\n? __irq_work_queue_local+0x1e5/0x330\n? irq_work_queue+0x39/0x50\n? __wake_up_klogd.part.0+0x79/0xc0\n? mem_allocator_disconnect+0x73/0x150\nmem_allocator_disconnect+0x73/0x150\n? __pfx_mem_allocator_disconnect+0x10/0x10\n? mark_held_locks+0xa5/0xf0\n? rcu_is_watching+0x11/0xb0\npage_pool_release+0x36e/0x6d0\npage_pool_destroy+0xd7/0x440\nxdp_unreg_mem_model+0x1a7/0x2a0\n? __pfx_xdp_unreg_mem_model+0x10/0x10\n? kfree+0x125/0x370\n? bnxt_free_ring.isra.0+0x2eb/0x500\n? bnxt_free_mem+0x5ac/0x2500\nxdp_rxq_info_unreg+0x4a/0xd0\nbnxt_free_mem+0x1356/0x2500\nbnxt_close_nic+0xf0/0x3b0\n? __pfx_bnxt_close_nic+0x10/0x10\n? ethnl_parse_bit+0x2c6/0x6d0\n? __pfx___nla_validate_parse+0x10/0x10\n? __pfx_ethnl_parse_bit+0x10/0x10\nbnxt_set_features+0x2a8/0x3e0\n__netdev_update_features+0x4dc/0x1370\n? ethnl_parse_bitset+0x4ff/0x750\n? __pfx_ethnl_parse_bitset+0x10/0x10\n? __pfx___netdev_update_features+0x10/0x10\n? mark_held_locks+0xa5/0xf0\n? _raw_spin_unlock_irqrestore+0x42/0x70\n? __pm_runtime_resume+0x7d/0x110\nethnl_set_features+0x32d/0xa20\n\nTo fix this problem, it uses rhashtable_lookup_fast() instead of\nrhashtable_lookup() with rcu_read_lock().\nUsing xa without rcu_read_lock() here is safe.\nxa is freed by __xdp_mem_allocator_rcu_free() and this is called by\ncall_rcu() of mem_xa_remove().\nThe mem_xa_remove() is called by page_pool_destroy() if a reference\ncount reaches 0.\nThe xa is already protected by the reference count mechanism well in the\ncontrol plane.\nSo removing rcu_read_lock() for page_pool_destroy() is safe.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43834', 'https://git.kernel.org/linus/59a931c5b732ca5fc2ca727f5a72aeabaafa85ec (6.11-rc1)', 'https://git.kernel.org/stable/c/12144069209eec7f2090ce9afa15acdcc2c2a537', 'https://git.kernel.org/stable/c/3fc1be360b99baeea15cdee3cf94252cd3a72d26', 'https://git.kernel.org/stable/c/59a931c5b732ca5fc2ca727f5a72aeabaafa85ec', 'https://git.kernel.org/stable/c/6c390ef198aa69795427a5cb5fd7cb4bc7e6cd7a', 'https://git.kernel.org/stable/c/be9d08ff102df3ac4f66e826ea935cf3af63a4bd', 'https://git.kernel.org/stable/c/bf0ce5aa5f2525ed1b921ba36de96e458e77f482', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43834-0140@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43834', 'https://www.cve.org/CVERecord?id=CVE-2024-43834'], 'PublishedDate': '2024-08-17T10:15:09.113Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43835', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43835', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: virtio_net: Fix napi_skb_cache_put warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Fix napi_skb_cache_put warning\n\nAfter the commit bdacf3e34945 ("net: Use nested-BH locking for\nnapi_alloc_cache.") was merged, the following warning began to appear:\n\n\t WARNING: CPU: 5 PID: 1 at net/core/skbuff.c:1451 napi_skb_cache_put+0x82/0x4b0\n\n\t __warn+0x12f/0x340\n\t napi_skb_cache_put+0x82/0x4b0\n\t napi_skb_cache_put+0x82/0x4b0\n\t report_bug+0x165/0x370\n\t handle_bug+0x3d/0x80\n\t exc_invalid_op+0x1a/0x50\n\t asm_exc_invalid_op+0x1a/0x20\n\t __free_old_xmit+0x1c8/0x510\n\t napi_skb_cache_put+0x82/0x4b0\n\t __free_old_xmit+0x1c8/0x510\n\t __free_old_xmit+0x1c8/0x510\n\t __pfx___free_old_xmit+0x10/0x10\n\nThe issue arises because virtio is assuming it\'s running in NAPI context\neven when it\'s not, such as in the netpoll case.\n\nTo resolve this, modify virtnet_poll_tx() to only set NAPI when budget\nis available. Same for virtnet_poll_cleantx(), which always assumed that\nit was in a NAPI context.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43835', 'https://git.kernel.org/linus/f8321fa75102246d7415a6af441872f6637c93ab (6.11-rc1)', 'https://git.kernel.org/stable/c/19ac6f29bf64304ef04630c8ab56ecd2059d7aa1', 'https://git.kernel.org/stable/c/468a729b78895893d0e580ceea49bed8ada2a2bd', 'https://git.kernel.org/stable/c/6b5325f2457521bbece29499970c0117a648c620', 'https://git.kernel.org/stable/c/842a97b5e44f0c8a9fc356fe976e0e13ddcf7783', 'https://git.kernel.org/stable/c/cc7340f18e45886121c131227985d64ef666012f', 'https://git.kernel.org/stable/c/d3af435e8ace119e58d8e21d3d2d6a4e7c4a4baa', 'https://git.kernel.org/stable/c/f5e9a22d19bb98a7e86034db85eb295e94187caa', 'https://git.kernel.org/stable/c/f8321fa75102246d7415a6af441872f6637c93ab', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43835-5f11@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43835', 'https://www.cve.org/CVERecord?id=CVE-2024-43835'], 'PublishedDate': '2024-08-17T10:15:09.183Z', 'LastModifiedDate': '2024-09-12T12:15:48.653Z'}, {'VulnerabilityID': 'CVE-2024-43837', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43837', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT\n\nWhen loading a EXT program without specifying `attr->attach_prog_fd`,\nthe `prog->aux->dst_prog` will be null. At this time, calling\nresolve_prog_type() anywhere will result in a null pointer dereference.\n\nExample stack trace:\n\n[ 8.107863] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004\n[ 8.108262] Mem abort info:\n[ 8.108384] ESR = 0x0000000096000004\n[ 8.108547] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 8.108722] SET = 0, FnV = 0\n[ 8.108827] EA = 0, S1PTW = 0\n[ 8.108939] FSC = 0x04: level 0 translation fault\n[ 8.109102] Data abort info:\n[ 8.109203] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 8.109399] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 8.109614] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 8.109836] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101354000\n[ 8.110011] [0000000000000004] pgd=0000000000000000, p4d=0000000000000000\n[ 8.112624] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 8.112783] Modules linked in:\n[ 8.113120] CPU: 0 PID: 99 Comm: may_access_dire Not tainted 6.10.0-rc3-next-20240613-dirty #1\n[ 8.113230] Hardware name: linux,dummy-virt (DT)\n[ 8.113390] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 8.113429] pc : may_access_direct_pkt_data+0x24/0xa0\n[ 8.113746] lr : add_subprog_and_kfunc+0x634/0x8e8\n[ 8.113798] sp : ffff80008283b9f0\n[ 8.113813] x29: ffff80008283b9f0 x28: ffff800082795048 x27: 0000000000000001\n[ 8.113881] x26: ffff0000c0bb2600 x25: 0000000000000000 x24: 0000000000000000\n[ 8.113897] x23: ffff0000c1134000 x22: 000000000001864f x21: ffff0000c1138000\n[ 8.113912] x20: 0000000000000001 x19: ffff0000c12b8000 x18: ffffffffffffffff\n[ 8.113929] x17: 0000000000000000 x16: 0000000000000000 x15: 0720072007200720\n[ 8.113944] x14: 0720072007200720 x13: 0720072007200720 x12: 0720072007200720\n[ 8.113958] x11: 0720072007200720 x10: 0000000000f9fca4 x9 : ffff80008021f4e4\n[ 8.113991] x8 : 0101010101010101 x7 : 746f72705f6d656d x6 : 000000001e0e0f5f\n[ 8.114006] x5 : 000000000001864f x4 : ffff0000c12b8000 x3 : 000000000000001c\n[ 8.114020] x2 : 0000000000000002 x1 : 0000000000000000 x0 : 0000000000000000\n[ 8.114126] Call trace:\n[ 8.114159] may_access_direct_pkt_data+0x24/0xa0\n[ 8.114202] bpf_check+0x3bc/0x28c0\n[ 8.114214] bpf_prog_load+0x658/0xa58\n[ 8.114227] __sys_bpf+0xc50/0x2250\n[ 8.114240] __arm64_sys_bpf+0x28/0x40\n[ 8.114254] invoke_syscall.constprop.0+0x54/0xf0\n[ 8.114273] do_el0_svc+0x4c/0xd8\n[ 8.114289] el0_svc+0x3c/0x140\n[ 8.114305] el0t_64_sync_handler+0x134/0x150\n[ 8.114331] el0t_64_sync+0x168/0x170\n[ 8.114477] Code: 7100707f 54000081 f9401c00 f9403800 (b9400403)\n[ 8.118672] ---[ end trace 0000000000000000 ]---\n\nOne way to fix it is by forcing `attach_prog_fd` non-empty when\nbpf_prog_load(). But this will lead to `libbpf_probe_bpf_prog_type`\nAPI broken which use verifier log to probe prog type and will log\nnothing if we reject invalid EXT prog before bpf_check().\n\nAnother way is by adding null check in resolve_prog_type().\n\nThe issue was introduced by commit 4a9c7bbe2ed4 ("bpf: Resolve to\nprog->aux->dst_prog->type only for BPF_PROG_TYPE_EXT") which wanted\nto correct type resolution for BPF_PROG_TYPE_TRACING programs. Before\nthat, the type resolution of BPF_PROG_TYPE_EXT prog actually follows\nthe logic below:\n\n prog->aux->dst_prog ? prog->aux->dst_prog->type : prog->type;\n\nIt implies that when EXT program is not yet attached to `dst_prog`,\nthe prog type should be EXT itself. This code worked fine in the past.\nSo just keep using it.\n\nFix this by returning `prog->type` for BPF_PROG_TYPE_EXT if `dst_prog`\nis not present in resolve_prog_type().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43837', 'https://git.kernel.org/linus/f7866c35873377313ff94398f17d425b28b71de1 (6.11-rc1)', 'https://git.kernel.org/stable/c/9d40fd516aeae6779e3c84c6b96700ca76285847', 'https://git.kernel.org/stable/c/b29a880bb145e1f1c1df5ab88ed26b1495ff9f09', 'https://git.kernel.org/stable/c/f7866c35873377313ff94398f17d425b28b71de1', 'https://git.kernel.org/stable/c/fcac5feb06f31ee4c88bca9bf98d8bc3ca7d2615', 'https://lore.kernel.org/linux-cve-announce/2024081729-CVE-2024-43837-63d2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43837', 'https://www.cve.org/CVERecord?id=CVE-2024-43837'], 'PublishedDate': '2024-08-17T10:15:09.32Z', 'LastModifiedDate': '2024-08-22T15:44:03.417Z'}, {'VulnerabilityID': 'CVE-2024-43839', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43839', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: bna: adjust 'name' buf size of bna_tcb and bna_ccb structures", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbna: adjust 'name' buf size of bna_tcb and bna_ccb structures\n\nTo have enough space to write all possible sprintf() args. Currently\n'name' size is 16, but the first '%s' specifier may already need at\nleast 16 characters, since 'bnad->netdev->name' is used there.\n\nFor '%d' specifiers, assume that they require:\n * 1 char for 'tx_id + tx_info->tcb[i]->id' sum, BNAD_MAX_TXQ_PER_TX is 8\n * 2 chars for 'rx_id + rx_info->rx_ctrl[i].ccb->id', BNAD_MAX_RXP_PER_RX\n is 16\n\nAnd replace sprintf with snprintf.\n\nDetected using the static analysis tool - Svace.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43839', 'https://git.kernel.org/linus/c9741a03dc8e491e57b95fba0058ab46b7e506da (6.11-rc1)', 'https://git.kernel.org/stable/c/6ce46045f9b90d952602e2c0b8886cfadf860bf1', 'https://git.kernel.org/stable/c/6d20c4044ab4d0e6a99aa35853e66f0aed5589e3', 'https://git.kernel.org/stable/c/ab748dd10d8742561f2980fea08ffb4f0cacfdef', 'https://git.kernel.org/stable/c/b0ff0cd0847b03c0a0abe20cfa900eabcfcb9e43', 'https://git.kernel.org/stable/c/c90b1cd7758fd4839909e838ae195d19f8065d76', 'https://git.kernel.org/stable/c/c9741a03dc8e491e57b95fba0058ab46b7e506da', 'https://git.kernel.org/stable/c/e0f48f51d55fb187400e9787192eda09fa200ff5', 'https://git.kernel.org/stable/c/f121740f69eda4da2de9a20a6687a13593e72540', 'https://linux.oracle.com/cve/CVE-2024-43839.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081729-CVE-2024-43839-ea03@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43839', 'https://www.cve.org/CVERecord?id=CVE-2024-43839'], 'PublishedDate': '2024-08-17T10:15:09.447Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43840', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43840', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG\n\nWhen BPF_TRAMP_F_CALL_ORIG is set, the trampoline calls\n__bpf_tramp_enter() and __bpf_tramp_exit() functions, passing them\nthe struct bpf_tramp_image *im pointer as an argument in R0.\n\nThe trampoline generation code uses emit_addr_mov_i64() to emit\ninstructions for moving the bpf_tramp_image address into R0, but\nemit_addr_mov_i64() assumes the address to be in the vmalloc() space\nand uses only 48 bits. Because bpf_tramp_image is allocated using\nkzalloc(), its address can use more than 48-bits, in this case the\ntrampoline will pass an invalid address to __bpf_tramp_enter/exit()\ncausing a kernel crash.\n\nFix this by using emit_a64_mov_i64() in place of emit_addr_mov_i64()\nas it can work with addresses that are greater than 48-bits.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43840', 'https://git.kernel.org/linus/19d3c179a37730caf600a97fed3794feac2b197b (6.11-rc1)', 'https://git.kernel.org/stable/c/19d3c179a37730caf600a97fed3794feac2b197b', 'https://git.kernel.org/stable/c/6d218fcc707d6b2c3616b6cd24b948fd4825cfec', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43840-69cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43840', 'https://www.cve.org/CVERecord?id=CVE-2024-43840'], 'PublishedDate': '2024-08-17T10:15:09.517Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43841', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43841', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: virt_wifi: avoid reporting connection success with wrong SSID', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: avoid reporting connection success with wrong SSID\n\nWhen user issues a connection with a different SSID than the one\nvirt_wifi has advertised, the __cfg80211_connect_result() will\ntrigger the warning: WARN_ON(bss_not_found).\n\nThe issue is because the connection code in virt_wifi does not\ncheck the SSID from user space (it only checks the BSSID), and\nvirt_wifi will call cfg80211_connect_result() with WLAN_STATUS_SUCCESS\neven if the SSID is different from the one virt_wifi has advertised.\nEventually cfg80211 won't be able to find the cfg80211_bss and generate\nthe warning.\n\nFixed it by checking the SSID (from user space) in the connection code.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43841', 'https://git.kernel.org/linus/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7 (6.11-rc1)', 'https://git.kernel.org/stable/c/05c4488a0e446c6ccde9f22b573950665e1cd414', 'https://git.kernel.org/stable/c/36e92b5edc8e0daa18e9325674313802ce3fbc29', 'https://git.kernel.org/stable/c/416d3c1538df005195721a200b0371d39636e05d', 'https://git.kernel.org/stable/c/93e898a264b4e0a475552ba9f99a016eb43ef942', 'https://git.kernel.org/stable/c/994fc2164a03200c3bf42fb45b3d49d9d6d33a4d', 'https://git.kernel.org/stable/c/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7', 'https://git.kernel.org/stable/c/d3cc85a10abc8eae48988336cdd3689ab92581b3', 'https://linux.oracle.com/cve/CVE-2024-43841.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43841-8143@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43841', 'https://www.cve.org/CVERecord?id=CVE-2024-43841'], 'PublishedDate': '2024-08-17T10:15:09.58Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43842', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43842', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()\n\nIn rtw89_sta_info_get_iter() \'status->he_gi\' is compared to array size.\nBut then \'rate->he_gi\' is used as array index instead of \'status->he_gi\'.\nThis can lead to go beyond array boundaries in case of \'rate->he_gi\' is\nnot equal to \'status->he_gi\' and is bigger than array size. Looks like\n"copy-paste" mistake.\n\nFix this mistake by replacing \'rate->he_gi\' with \'status->he_gi\'.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43842', 'https://git.kernel.org/linus/85099c7ce4f9e64c66aa397cd9a37473637ab891 (6.11-rc1)', 'https://git.kernel.org/stable/c/7a0edc3d83aff3a48813d78c9cad9daf38decc74', 'https://git.kernel.org/stable/c/85099c7ce4f9e64c66aa397cd9a37473637ab891', 'https://git.kernel.org/stable/c/96ae4de5bc4c8ba39fd072369398f59495b73f58', 'https://git.kernel.org/stable/c/a2a095c08b95372d6d0c5819b77f071af5e75366', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43842-31e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43842', 'https://www.cve.org/CVERecord?id=CVE-2024-43842'], 'PublishedDate': '2024-08-17T10:15:09.647Z', 'LastModifiedDate': '2024-09-30T13:55:17.007Z'}, {'VulnerabilityID': 'CVE-2024-43843', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43843', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv, bpf: Fix out-of-bounds issue when preparing trampoline image', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix out-of-bounds issue when preparing trampoline image\n\nWe get the size of the trampoline image during the dry run phase and\nallocate memory based on that size. The allocated image will then be\npopulated with instructions during the real patch phase. But after\ncommit 26ef208c209a ("bpf: Use arch_bpf_trampoline_size"), the `im`\nargument is inconsistent in the dry run and real patch phase. This may\ncause emit_imm in RV64 to generate a different number of instructions\nwhen generating the \'im\' address, potentially causing out-of-bounds\nissues. Let\'s emit the maximum number of instructions for the "im"\naddress during dry run to fix this problem.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43843', 'https://git.kernel.org/linus/9f1e16fb1fc9826001c69e0551d51fbbcd2d74e9 (6.11-rc1)', 'https://git.kernel.org/stable/c/3e6a1b1b179abb643ec3560c02bc3082bc92285f', 'https://git.kernel.org/stable/c/9f1e16fb1fc9826001c69e0551d51fbbcd2d74e9', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43843-e436@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43843', 'https://www.cve.org/CVERecord?id=CVE-2024-43843'], 'PublishedDate': '2024-08-17T10:15:09.707Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43844', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43844', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi rtw89 wow: fix GTK offload H2C skbuff issue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: wow: fix GTK offload H2C skbuff issue\n\nWe mistakenly put skb too large and that may exceed skb->end.\nTherefore, we fix it.\n\nskbuff: skb_over_panic: text:ffffffffc09e9a9d len:416 put:204 head:ffff8fba04eca780 data:ffff8fba04eca7e0 tail:0x200 end:0x140 dev:\n------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:192!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 4747 Comm: kworker/u4:44 Tainted: G O 6.6.30-02659-gc18865c4dfbd #1 86547039b47e46935493f615ee31d0b2d711d35e\nHardware name: HP Meep/Meep, BIOS Google_Meep.11297.262.0 03/18/2021\nWorkqueue: events_unbound async_run_entry_fn\nRIP: 0010:skb_panic+0x5d/0x60\nCode: c6 63 8b 8f bb 4c 0f 45 f6 48 c7 c7 4d 89 8b bb 48 89 ce 44 89 d1 41 56 53 41 53 ff b0 c8 00 00 00 e8 27 5f 23 00 48 83 c4 20 <0f> 0b 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44\nRSP: 0018:ffffaa700144bad0 EFLAGS: 00010282\nRAX: 0000000000000089 RBX: 0000000000000140 RCX: 14432c5aad26c900\nRDX: 0000000000000000 RSI: 00000000ffffdfff RDI: 0000000000000001\nRBP: ffffaa700144bae0 R08: 0000000000000000 R09: ffffaa700144b920\nR10: 00000000ffffdfff R11: ffffffffbc28fbc0 R12: ffff8fba4e57a010\nR13: 0000000000000000 R14: ffffffffbb8f8b63 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff8fba7bd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007999c4ad1000 CR3: 000000015503a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? __die_body+0x1f/0x70\n ? die+0x3d/0x60\n ? do_trap+0xa4/0x110\n ? skb_panic+0x5d/0x60\n ? do_error_trap+0x6d/0x90\n ? skb_panic+0x5d/0x60\n ? handle_invalid_op+0x30/0x40\n ? skb_panic+0x5d/0x60\n ? exc_invalid_op+0x3c/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_panic+0x5d/0x60\n skb_put+0x49/0x50\n rtw89_fw_h2c_wow_gtk_ofld+0xbd/0x220 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_wow_resume+0x31f/0x540 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_ops_resume+0x2b/0xa0 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n ieee80211_reconfig+0x84/0x13e0 [mac80211 818a894e3b77da6298269c59ed7cdff065a4ed52]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? dev_printk_emit+0x51/0x70\n ? _dev_info+0x6e/0x90\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n wiphy_resume+0x89/0x180 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n dpm_run_callback+0x3c/0x140\n device_resume+0x1f9/0x3c0\n ? __pfx_dpm_watchdog_handler+0x10/0x10\n async_resume+0x1d/0x30\n async_run_entry_fn+0x29/0xd0\n process_scheduled_works+0x1d8/0x3d0\n worker_thread+0x1fc/0x2f0\n kthread+0xed/0x110\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x38/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \nModules linked in: ccm 8021q r8153_ecm cdc_ether usbnet r8152 mii dm_integrity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmalloc uinput rfcomm cmac algif_hash rtw89_8922ae(O) algif_skcipher rtw89_8922a(O) af_alg rtw89_pci(O) rtw89_core(O) btusb(O) snd_soc_sst_bxt_da7219_max98357a btbcm(O) snd_soc_hdac_hdmi btintel(O) snd_soc_intel_hda_dsp_common snd_sof_probes btrtl(O) btmtk(O) snd_hda_codec_hdmi snd_soc_dmic uvcvideo videobuf2_vmalloc uvc videobuf2_memops videobuf2_v4l2 videobuf2_common snd_sof_pci_intel_apl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda soundwire_intel soundwire_generic_allocation snd_sof_intel_hda_mlink soundwire_cadence snd_sof_pci snd_sof_xtensa_dsp mac80211 snd_soc_acpi_intel_match snd_soc_acpi snd_sof snd_sof_utils soundwire_bus snd_soc_max98357a snd_soc_avs snd_soc_hda_codec snd_hda_ext_core snd_intel_dspcfg snd_intel_sdw_acpi snd_soc_da7219 snd_hda_codec snd_hwdep snd_hda_core veth ip6table_nat xt_MASQUERADE xt_cgroup fuse bluetooth ecdh_generic\n cfg80211 ecc\ngsmi: Log Shutdown \n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43844', 'https://git.kernel.org/linus/dda364c345913fe03ddbe4d5ae14a2754c100296 (6.11-rc1)', 'https://git.kernel.org/stable/c/dda364c345913fe03ddbe4d5ae14a2754c100296', 'https://git.kernel.org/stable/c/ef0d9d2f0dc1133db3d3a1c5167190c6627146b2', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43844-97ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43844', 'https://www.cve.org/CVERecord?id=CVE-2024-43844'], 'PublishedDate': '2024-08-17T10:15:09.763Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43845', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43845', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Fix bogus checksum computation in udf_rename()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix bogus checksum computation in udf_rename()\n\nSyzbot reports uninitialized memory access in udf_rename() when updating\nchecksum of '..' directory entry of a moved directory. This is indeed\ntrue as we pass on-stack diriter.fi to the udf_update_tag() and because\nthat has only struct fileIdentDesc included in it and not the impUse or\nname fields, the checksumming function is going to checksum random stack\ncontents beyond the end of the structure. This is actually harmless\nbecause the following udf_fiiter_write_fi() will recompute the checksum\nfrom on-disk buffers where everything is properly included. So all that\nis needed is just removing the bogus calculation.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43845', 'https://git.kernel.org/linus/27ab33854873e6fb958cb074681a0107cc2ecc4c (6.11-rc1)', 'https://git.kernel.org/stable/c/27ab33854873e6fb958cb074681a0107cc2ecc4c', 'https://git.kernel.org/stable/c/40d7b3ed52449d36143bab8d3e70926aa61a60f4', 'https://git.kernel.org/stable/c/c996b570305e7a6910c2ce4cdcd4c22757ffe241', 'https://git.kernel.org/stable/c/fe2ead240c31e8d158713beca9d0681a6e6a53ab', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43845-a85d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43845', 'https://www.cve.org/CVERecord?id=CVE-2024-43845'], 'PublishedDate': '2024-08-17T10:15:09.837Z', 'LastModifiedDate': '2024-08-29T17:15:08.397Z'}, {'VulnerabilityID': 'CVE-2024-43846', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: lib: objagg: Fix general protection fault', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlib: objagg: Fix general protection fault\n\nThe library supports aggregation of objects into other objects only if\nthe parent object does not have a parent itself. That is, nesting is not\nsupported.\n\nAggregation happens in two cases: Without and with hints, where hints\nare a pre-computed recommendation on how to aggregate the provided\nobjects.\n\nNesting is not possible in the first case due to a check that prevents\nit, but in the second case there is no check because the assumption is\nthat nesting cannot happen when creating objects based on hints. The\nviolation of this assumption leads to various warnings and eventually to\na general protection fault [1].\n\nBefore fixing the root cause, error out when nesting happens and warn.\n\n[1]\ngeneral protection fault, probably for non-canonical address 0xdead000000000d90: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 1083 Comm: kworker/1:9 Tainted: G W 6.9.0-rc6-custom-gd9b4f1cca7fb #7\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:mlxsw_sp_acl_erp_bf_insert+0x25/0x80\n[...]\nCall Trace:\n \n mlxsw_sp_acl_atcam_entry_add+0x256/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370\n worker_thread+0x2cb/0x3e0\n kthread+0xd0/0x100\n ret_from_fork+0x34/0x50\n ret_from_fork_asm+0x1a/0x30\n ', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43846', 'https://git.kernel.org/linus/b4a3a89fffcdf09702b1f161b914e52abca1894d (6.11-rc1)', 'https://git.kernel.org/stable/c/1936fa05a180834c3b52e0439a6bddc07814d3eb', 'https://git.kernel.org/stable/c/22ae17a267f4812861f0c644186c3421ff97dbfc', 'https://git.kernel.org/stable/c/499f742fed42e74f1321f4b12ca196a66a2b49fc', 'https://git.kernel.org/stable/c/565213e005557eb6cc4e42189d26eb300e02f170', 'https://git.kernel.org/stable/c/5adc61d29bbb461d7f7c2b48dceaa90ecd182eb7', 'https://git.kernel.org/stable/c/8161263362154cbebfbf4808097b956a6a8cb98a', 'https://git.kernel.org/stable/c/b4a3a89fffcdf09702b1f161b914e52abca1894d', 'https://linux.oracle.com/cve/CVE-2024-43846.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43846-2bd0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43846', 'https://www.cve.org/CVERecord?id=CVE-2024-43846'], 'PublishedDate': '2024-08-17T10:15:09.9Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43847', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43847', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: fix invalid memory access while processing fragmented packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix invalid memory access while processing fragmented packets\n\nThe monitor ring and the reo reinject ring share the same ring mask index.\nWhen the driver receives an interrupt for the reo reinject ring, the\nmonitor ring is also processed, leading to invalid memory access. Since\nmonitor support is not yet enabled in ath12k, the ring mask for the monitor\nring should be removed.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 2.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43847', 'https://git.kernel.org/linus/073f9f249eecd64ab9d59c91c4a23cfdcc02afe4 (6.11-rc1)', 'https://git.kernel.org/stable/c/073f9f249eecd64ab9d59c91c4a23cfdcc02afe4', 'https://git.kernel.org/stable/c/36fc66a7d9ca3e5c6eac25362cac63f83df8bed6', 'https://git.kernel.org/stable/c/8126f82dab7bd8b2e04799342b19fff0a1fd8575', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43847-6828@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43847', 'https://www.cve.org/CVERecord?id=CVE-2024-43847'], 'PublishedDate': '2024-08-17T10:15:09.963Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43849', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43849', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: pdr: protect locator_addr with the main mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pdr: protect locator_addr with the main mutex\n\nIf the service locator server is restarted fast enough, the PDR can\nrewrite locator_addr fields concurrently. Protect them by placing\nmodification of those fields under the main pdr->lock.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43849', 'https://git.kernel.org/linus/107924c14e3ddd85119ca43c26a4ee1056fa9b84 (6.11-rc1)', 'https://git.kernel.org/stable/c/107924c14e3ddd85119ca43c26a4ee1056fa9b84', 'https://git.kernel.org/stable/c/3e815626d73e05152a8142f6e44aecc4133e6e08', 'https://git.kernel.org/stable/c/475a77fb3f0e1d527f56c60b79f5879661df5b80', 'https://git.kernel.org/stable/c/8543269567e2fb3d976a8255c5e348aed14f98bc', 'https://git.kernel.org/stable/c/d0870c4847e77a49c2f91bb2a8e0fa3c1f8dea5c', 'https://git.kernel.org/stable/c/eab05737ee22216250fe20d27f5a596da5ea6eb7', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43849-fef0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43849', 'https://www.cve.org/CVERecord?id=CVE-2024-43849'], 'PublishedDate': '2024-08-17T10:15:10.093Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43850', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43850', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove\n\nThe following warning is seen during bwmon_remove due to refcount\nimbalance, fix this by releasing the OPPs after use.\n\nLogs:\nWARNING: at drivers/opp/core.c:1640 _opp_table_kref_release+0x150/0x158\nHardware name: Qualcomm Technologies, Inc. X1E80100 CRD (DT)\n...\nCall trace:\n_opp_table_kref_release+0x150/0x158\ndev_pm_opp_remove_table+0x100/0x1b4\ndevm_pm_opp_of_table_release+0x10/0x1c\ndevm_action_release+0x14/0x20\ndevres_release_all+0xa4/0x104\ndevice_unbind_cleanup+0x18/0x60\ndevice_release_driver_internal+0x1ec/0x228\ndriver_detach+0x50/0x98\nbus_remove_driver+0x6c/0xbc\ndriver_unregister+0x30/0x60\nplatform_driver_unregister+0x14/0x20\nbwmon_driver_exit+0x18/0x524 [icc_bwmon]\n__arm64_sys_delete_module+0x184/0x264\ninvoke_syscall+0x48/0x118\nel0_svc_common.constprop.0+0xc8/0xe8\ndo_el0_svc+0x20/0x2c\nel0_svc+0x34/0xdc\nel0t_64_sync_handler+0x13c/0x158\nel0t_64_sync+0x190/0x194\n--[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43850', 'https://git.kernel.org/linus/24086640ab39396eb1a92d1cb1cd2f31b2677c52 (6.11-rc1)', 'https://git.kernel.org/stable/c/24086640ab39396eb1a92d1cb1cd2f31b2677c52', 'https://git.kernel.org/stable/c/4100d4d019f8e140be1d4d3a9d8d93c1285f5d1c', 'https://git.kernel.org/stable/c/aad41f4c169bcb800ae88123799bdf8cdec3d366', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43850-4eec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43850', 'https://www.cve.org/CVERecord?id=CVE-2024-43850'], 'PublishedDate': '2024-08-17T10:15:10.157Z', 'LastModifiedDate': '2024-09-30T13:57:33.4Z'}, {'VulnerabilityID': 'CVE-2024-43852', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43852', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (ltc2991) re-order conditions to fix off by one bug', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ltc2991) re-order conditions to fix off by one bug\n\nLTC2991_T_INT_CH_NR is 4. The st->temp_en[] array has LTC2991_MAX_CHANNEL\n(4) elements. Thus if "channel" is equal to LTC2991_T_INT_CH_NR then we\nhave read one element beyond the end of the array. Flip the conditions\naround so that we check if "channel" is valid before using it as an array\nindex.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-193'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43852', 'https://git.kernel.org/linus/99bf7c2eccff82760fa23ce967cc67c8c219c6a6 (6.11-rc1)', 'https://git.kernel.org/stable/c/99bf7c2eccff82760fa23ce967cc67c8c219c6a6', 'https://git.kernel.org/stable/c/c180311c0a520692e2d0e9ca44dcd6c2ff1b41c4', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43852-61e2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43852', 'https://www.cve.org/CVERecord?id=CVE-2024-43852'], 'PublishedDate': '2024-08-17T10:15:10.31Z', 'LastModifiedDate': '2024-08-20T19:32:55.747Z'}, {'VulnerabilityID': 'CVE-2024-43853', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43853', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cgroup/cpuset: Prevent UAF in proc_cpuset_show()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: Prevent UAF in proc_cpuset_show()\n\nAn UAF can happen when /proc/cpuset is read as reported in [1].\n\nThis can be reproduced by the following methods:\n1.add an mdelay(1000) before acquiring the cgroup_lock In the\n cgroup_path_ns function.\n2.$cat /proc//cpuset repeatly.\n3.$mount -t cgroup -o cpuset cpuset /sys/fs/cgroup/cpuset/\n$umount /sys/fs/cgroup/cpuset/ repeatly.\n\nThe race that cause this bug can be shown as below:\n\n(umount)\t\t|\t(cat /proc//cpuset)\ncss_release\t\t|\tproc_cpuset_show\ncss_release_work_fn\t|\tcss = task_get_css(tsk, cpuset_cgrp_id);\ncss_free_rwork_fn\t|\tcgroup_path_ns(css->cgroup, ...);\ncgroup_destroy_root\t|\tmutex_lock(&cgroup_mutex);\nrebind_subsystems\t|\ncgroup_free_root \t|\n\t\t\t|\t// cgrp was freed, UAF\n\t\t\t|\tcgroup_path_ns_locked(cgrp,..);\n\nWhen the cpuset is initialized, the root node top_cpuset.css.cgrp\nwill point to &cgrp_dfl_root.cgrp. In cgroup v1, the mount operation will\nallocate cgroup_root, and top_cpuset.css.cgrp will point to the allocated\n&cgroup_root.cgrp. When the umount operation is executed,\ntop_cpuset.css.cgrp will be rebound to &cgrp_dfl_root.cgrp.\n\nThe problem is that when rebinding to cgrp_dfl_root, there are cases\nwhere the cgroup_root allocated by setting up the root for cgroup v1\nis cached. This could lead to a Use-After-Free (UAF) if it is\nsubsequently freed. The descendant cgroups of cgroup v1 can only be\nfreed after the css is released. However, the css of the root will never\nbe released, yet the cgroup_root should be freed when it is unmounted.\nThis means that obtaining a reference to the css of the root does\nnot guarantee that css.cgrp->root will not be freed.\n\nFix this problem by using rcu_read_lock in proc_cpuset_show().\nAs cgroup_root is kfree_rcu after commit d23b5c577715\n("cgroup: Make operations on the cgroup root_list RCU safe"),\ncss->cgroup won\'t be freed during the critical section.\nTo call cgroup_path_ns_locked, css_set_lock is needed, so it is safe to\nreplace task_get_css with task_css.\n\n[1] https://syzkaller.appspot.com/bug?extid=9b1ff7be974a403aa4cd', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43853', 'https://git.kernel.org/linus/1be59c97c83ccd67a519d8a49486b3a8a73ca28a (6.11-rc1)', 'https://git.kernel.org/stable/c/10aeaa47e4aa2432f29b3e5376df96d7dac5537a', 'https://git.kernel.org/stable/c/1be59c97c83ccd67a519d8a49486b3a8a73ca28a', 'https://git.kernel.org/stable/c/27d6dbdc6485d68075a0ebf8544d6425c1ed84bb', 'https://git.kernel.org/stable/c/29a8d4e02fd4840028c38ceb1536cc8f82a257d4', 'https://git.kernel.org/stable/c/29ac1d238b3bf126af36037df80d7ecc4822341e', 'https://git.kernel.org/stable/c/4e8d6ac8fc9f843e940ab7389db8136634e07989', 'https://git.kernel.org/stable/c/688325078a8b5badd6e07ae22b27cd04e9947aec', 'https://git.kernel.org/stable/c/96226fbed566f3f686f53a489a29846f2d538080', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43853-da5b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43853', 'https://www.cve.org/CVERecord?id=CVE-2024-43853'], 'PublishedDate': '2024-08-17T10:15:10.383Z', 'LastModifiedDate': '2024-09-04T12:15:04.827Z'}, {'VulnerabilityID': 'CVE-2024-43854', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43854', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: initialize integrity buffer to zero before writing it to media', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: initialize integrity buffer to zero before writing it to media\n\nMetadata added by bio_integrity_prep is using plain kmalloc, which leads\nto random kernel memory being written media. For PI metadata this is\nlimited to the app tag that isn't used by kernel generated metadata,\nbut for non-PI metadata the entire buffer leaks kernel memory.\n\nFix this by adding the __GFP_ZERO flag to allocations for writes.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43854', 'https://git.kernel.org/linus/899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f (6.11-rc1)', 'https://git.kernel.org/stable/c/129f95948a96105c1fad8e612c9097763e88ac5f', 'https://git.kernel.org/stable/c/23a19655fb56f241e592041156dfb1c6d04da644', 'https://git.kernel.org/stable/c/3fd11fe4f20756b4c0847f755a64cd96f8c6a005', 'https://git.kernel.org/stable/c/899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f', 'https://git.kernel.org/stable/c/9f4af4cf08f9a0329ade3d938f55d2220c40d0a6', 'https://git.kernel.org/stable/c/cf6b45ea7a8df0f61bded1dc4a8561ac6ad143d2', 'https://git.kernel.org/stable/c/d418313bd8f55c079a7da12651951b489a638ac1', 'https://git.kernel.org/stable/c/ebc0e91ba76dc6544fff9f5b66408b1982806a00', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43854-5586@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43854', 'https://www.cve.org/CVERecord?id=CVE-2024-43854'], 'PublishedDate': '2024-08-17T10:15:10.447Z', 'LastModifiedDate': '2024-09-12T12:15:49.423Z'}, {'VulnerabilityID': 'CVE-2024-43856', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43856', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dma: fix call order in dmam_free_coherent', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndma: fix call order in dmam_free_coherent\n\ndmam_free_coherent() frees a DMA allocation, which makes the\nfreed vaddr available for reuse, then calls devres_destroy()\nto remove and free the data structure used to track the DMA\nallocation. Between the two calls, it is possible for a\nconcurrent task to make an allocation with the same vaddr\nand add it to the devres list.\n\nIf this happens, there will be two entries in the devres list\nwith the same vaddr and devres_destroy() can free the wrong\nentry, triggering the WARN_ON() in dmam_match.\n\nFix by destroying the devres entry before freeing the DMA\nallocation.\n\n kokonut //net/encryption\n http://sponge2/b9145fe6-0f72-4325-ac2f-a84d81075b03', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43856', 'https://git.kernel.org/linus/28e8b7406d3a1f5329a03aa25a43aa28e087cb20 (6.11-rc1)', 'https://git.kernel.org/stable/c/1fe97f68fce1ba24bf823bfb0eb0956003473130', 'https://git.kernel.org/stable/c/22094f5f52e7bc16c5bf9613365049383650b02e', 'https://git.kernel.org/stable/c/257193083e8f43907e99ea633820fc2b3bcd24c7', 'https://git.kernel.org/stable/c/28e8b7406d3a1f5329a03aa25a43aa28e087cb20', 'https://git.kernel.org/stable/c/2f7bbdc744f2e7051d1cb47c8e082162df1923c9', 'https://git.kernel.org/stable/c/87b34c8c94e29fa01d744e5147697f592998d954', 'https://git.kernel.org/stable/c/f993a4baf6b622232e4c190d34c220179e5d61eb', 'https://git.kernel.org/stable/c/fe2d246080f035e0af5793cb79067ba125e4fb63', 'https://linux.oracle.com/cve/CVE-2024-43856.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43856-9087@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43856', 'https://www.cve.org/CVERecord?id=CVE-2024-43856'], 'PublishedDate': '2024-08-17T10:15:10.613Z', 'LastModifiedDate': '2024-08-22T17:57:08.64Z'}, {'VulnerabilityID': 'CVE-2024-43857', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43857', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix null reference error when checking end of zone', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix null reference error when checking end of zone\n\nThis patch fixes a potentially null pointer being accessed by\nis_end_zone_blkaddr() that checks the last block of a zone\nwhen f2fs is mounted as a single device.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43857', 'https://git.kernel.org/linus/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38 (6.11-rc1)', 'https://git.kernel.org/stable/c/381cbe85592c78fbaeb3e770e3e9f3bfa3e67efb', 'https://git.kernel.org/stable/c/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43857-b71b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43857', 'https://www.cve.org/CVERecord?id=CVE-2024-43857'], 'PublishedDate': '2024-08-17T10:15:10.687Z', 'LastModifiedDate': '2024-08-22T17:38:21.003Z'}, {'VulnerabilityID': 'CVE-2024-43859', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43859', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to truncate preallocated blocks in f2fs_file_open()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to truncate preallocated blocks in f2fs_file_open()\n\nchenyuwen reports a f2fs bug as below:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000011\n fscrypt_set_bio_crypt_ctx+0x78/0x1e8\n f2fs_grab_read_bio+0x78/0x208\n f2fs_submit_page_read+0x44/0x154\n f2fs_get_read_data_page+0x288/0x5f4\n f2fs_get_lock_data_page+0x60/0x190\n truncate_partial_data_page+0x108/0x4fc\n f2fs_do_truncate_blocks+0x344/0x5f0\n f2fs_truncate_blocks+0x6c/0x134\n f2fs_truncate+0xd8/0x200\n f2fs_iget+0x20c/0x5ac\n do_garbage_collect+0x5d0/0xf6c\n f2fs_gc+0x22c/0x6a4\n f2fs_disable_checkpoint+0xc8/0x310\n f2fs_fill_super+0x14bc/0x1764\n mount_bdev+0x1b4/0x21c\n f2fs_mount+0x20/0x30\n legacy_get_tree+0x50/0xbc\n vfs_get_tree+0x5c/0x1b0\n do_new_mount+0x298/0x4cc\n path_mount+0x33c/0x5fc\n __arm64_sys_mount+0xcc/0x15c\n invoke_syscall+0x60/0x150\n el0_svc_common+0xb8/0xf8\n do_el0_svc+0x28/0xa0\n el0_svc+0x24/0x84\n el0t_64_sync_handler+0x88/0xec\n\nIt is because inode.i_crypt_info is not initialized during below path:\n- mount\n - f2fs_fill_super\n - f2fs_disable_checkpoint\n - f2fs_gc\n - f2fs_iget\n - f2fs_truncate\n\nSo, let's relocate truncation of preallocated blocks to f2fs_file_open(),\nafter fscrypt_file_open().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43859', 'https://git.kernel.org/linus/298b1e4182d657c3e388adcc29477904e9600ed5 (6.11-rc1)', 'https://git.kernel.org/stable/c/298b1e4182d657c3e388adcc29477904e9600ed5', 'https://git.kernel.org/stable/c/3ba0ae885215b325605ff7ebf6de12ac2adf204d', 'https://git.kernel.org/stable/c/5f04969136db674f133781626e0b692c5f2bf2f0', 'https://git.kernel.org/stable/c/f44a25a8bfe0c15d33244539696cd9119cf44d18', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43859-62b4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43859', 'https://www.cve.org/CVERecord?id=CVE-2024-43859'], 'PublishedDate': '2024-08-17T10:15:10.817Z', 'LastModifiedDate': '2024-09-08T08:15:12.96Z'}, {'VulnerabilityID': 'CVE-2024-43860', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43860', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: remoteproc: imx_rproc: Skip over memory region when node value is NULL', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: imx_rproc: Skip over memory region when node value is NULL\n\nIn imx_rproc_addr_init() "nph = of_count_phandle_with_args()" just counts\nnumber of phandles. But phandles may be empty. So of_parse_phandle() in\nthe parsing loop (0 < a < nph) may return NULL which is later dereferenced.\nAdjust this issue by adding NULL-return check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[Fixed title to fit within the prescribed 70-75 charcters]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43860', 'https://git.kernel.org/linus/2fa26ca8b786888673689ccc9da6094150939982 (6.11-rc1)', 'https://git.kernel.org/stable/c/2fa26ca8b786888673689ccc9da6094150939982', 'https://git.kernel.org/stable/c/4e13b7c23988c0a13fdca92e94296a3bc2ff9f21', 'https://git.kernel.org/stable/c/6884fd0283e0831be153fb8d82d9eda8a55acaaa', 'https://git.kernel.org/stable/c/6b50462b473fdccdc0dfad73001147e40ff19a66', 'https://git.kernel.org/stable/c/6c9ea3547fad252fe9ae5d3ed7e066e2085bf3a2', 'https://git.kernel.org/stable/c/84beb7738459cac0ff9f8a7c4654b8ff82a702c0', 'https://git.kernel.org/stable/c/9a17cf8b2ce483fa75258bc2cdcf628f24bcf5f8', 'https://git.kernel.org/stable/c/c877a5f5268d4ab8224b9c9fbce3d746e4e72bc9', 'https://linux.oracle.com/cve/CVE-2024-43860.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43860-d72f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43860', 'https://www.cve.org/CVERecord?id=CVE-2024-43860'], 'PublishedDate': '2024-08-17T10:15:10.887Z', 'LastModifiedDate': '2024-08-22T17:08:15.097Z'}, {'VulnerabilityID': 'CVE-2024-43861', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43861', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: usb: qmi_wwan: fix memory leak for not ip packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: qmi_wwan: fix memory leak for not ip packets\n\nFree the unused skb when not ip packets arrive.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43861', 'https://git.kernel.org/linus/7ab107544b777c3bd7feb9fe447367d8edd5b202 (6.11-rc3)', 'https://git.kernel.org/stable/c/37c093449704017870604994ba9b813cdb9475a4', 'https://git.kernel.org/stable/c/3c90a69533b5bba73401ef884d033ea49ee99662', 'https://git.kernel.org/stable/c/7ab107544b777c3bd7feb9fe447367d8edd5b202', 'https://git.kernel.org/stable/c/c4251a3deccad852b27e60625f31fba6cc14372f', 'https://git.kernel.org/stable/c/c6c5b91424fafc0f83852d961c10c7e43a001882', 'https://git.kernel.org/stable/c/da518cc9b64df391795d9952aed551e0f782e446', 'https://git.kernel.org/stable/c/e87f52225e04a7001bf55bbd7a330fa4252327b5', 'https://git.kernel.org/stable/c/f2c353227de14b0289298ffc3ba92058c4768384', 'https://linux.oracle.com/cve/CVE-2024-43861.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43861-1958@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43861', 'https://www.cve.org/CVERecord?id=CVE-2024-43861'], 'PublishedDate': '2024-08-20T22:15:04.917Z', 'LastModifiedDate': '2024-09-03T13:45:12.667Z'}, {'VulnerabilityID': 'CVE-2024-43863', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43863', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Fix a deadlock in dma buf fence polling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix a deadlock in dma buf fence polling\n\nIntroduce a version of the fence ops that on release doesn't remove\nthe fence from the pending list, and thus doesn't require a lock to\nfix poll->fence wait->fence unref deadlocks.\n\nvmwgfx overwrites the wait callback to iterate over the list of all\nfences and update their status, to do that it holds a lock to prevent\nthe list modifcations from other threads. The fence destroy callback\nboth deletes the fence and removes it from the list of pending\nfences, for which it holds a lock.\n\ndma buf polling cb unrefs a fence after it's been signaled: so the poll\ncalls the wait, which signals the fences, which are being destroyed.\nThe destruction tries to acquire the lock on the pending fences list\nwhich it can never get because it's held by the wait from which it\nwas called.\n\nOld bug, but not a lot of userspace apps were using dma-buf polling\ninterfaces. Fix those, in particular this fixes KDE stalls/deadlock.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43863', 'https://git.kernel.org/linus/e58337100721f3cc0c7424a18730e4f39844934f (6.11-rc2)', 'https://git.kernel.org/stable/c/3b933b16c996af8adb6bc1b5748a63dfb41a82bc', 'https://git.kernel.org/stable/c/9e20d028d8d1deb1e7fed18f22ffc01669cf3237', 'https://git.kernel.org/stable/c/a8943969f9ead2fd3044fc826140a21622ef830e', 'https://git.kernel.org/stable/c/c98ab18b9f315ff977c2c65d7c71298ef98be8e3', 'https://git.kernel.org/stable/c/e58337100721f3cc0c7424a18730e4f39844934f', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43863-9124@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43863', 'https://www.cve.org/CVERecord?id=CVE-2024-43863'], 'PublishedDate': '2024-08-21T00:15:04.847Z', 'LastModifiedDate': '2024-09-03T13:42:44.727Z'}, {'VulnerabilityID': 'CVE-2024-43864', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43864', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Fix CT entry update leaks of modify header context', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix CT entry update leaks of modify header context\n\nThe cited commit allocates a new modify header to replace the old\none when updating CT entry. But if failed to allocate a new one, eg.\nexceed the max number firmware can support, modify header will be\nan error pointer that will trigger a panic when deallocating it. And\nthe old modify header point is copied to old attr. When the old\nattr is freed, the old modify header is lost.\n\nFix it by restoring the old attr to attr when failed to allocate a\nnew modify header context. So when the CT entry is freed, the right\nmodify header context will be freed. And the panic of accessing\nerror pointer is also fixed.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43864', 'https://git.kernel.org/linus/025f2b85a5e5a46df14ecf162c3c80a957a36d0b (6.11-rc2)', 'https://git.kernel.org/stable/c/025f2b85a5e5a46df14ecf162c3c80a957a36d0b', 'https://git.kernel.org/stable/c/89064d09c56b44c668509bf793c410484f63f5ad', 'https://git.kernel.org/stable/c/daab2cc17b6b6ab158566bba037e9551fd432b59', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43864-81ad@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43864', 'https://www.cve.org/CVERecord?id=CVE-2024-43864'], 'PublishedDate': '2024-08-21T00:15:04.91Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43866', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43866', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Always drain health in shutdown callback', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Always drain health in shutdown callback\n\nThere is no point in recovery during device shutdown. if health\nwork started need to wait for it to avoid races and NULL pointer\naccess.\n\nHence, drain health WQ on shutdown callback.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43866', 'https://git.kernel.org/linus/1b75da22ed1e6171e261bc9265370162553d5393 (6.11-rc2)', 'https://git.kernel.org/stable/c/1b75da22ed1e6171e261bc9265370162553d5393', 'https://git.kernel.org/stable/c/5005e2e159b300c1b8c6820a1e13a62eb0127b9b', 'https://git.kernel.org/stable/c/6048dec754554a1303d632be6042d3feb3295285', 'https://git.kernel.org/stable/c/6b6c2ebd83f2bf97e8f221479372aaca97a4a9b2', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43866-66ed@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43866', 'https://www.cve.org/CVERecord?id=CVE-2024-43866'], 'PublishedDate': '2024-08-21T00:15:05.023Z', 'LastModifiedDate': '2024-10-17T14:15:07.297Z'}, {'VulnerabilityID': 'CVE-2024-43867', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43867', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/nouveau: prime: fix refcount underflow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: prime: fix refcount underflow\n\nCalling nouveau_bo_ref() on a nouveau_bo without initializing it (and\nhence the backing ttm_bo) leads to a refcount underflow.\n\nInstead of calling nouveau_bo_ref() in the unwind path of\ndrm_gem_object_init(), clean things up manually.\n\n(cherry picked from commit 1b93f3e89d03cfc576636e195466a0d728ad8de5)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43867', 'https://git.kernel.org/linus/a9bf3efc33f1fbf88787a277f7349459283c9b95 (6.11-rc2)', 'https://git.kernel.org/stable/c/16998763c62bb465ebc409d0373b9cdcef1a61a6', 'https://git.kernel.org/stable/c/2a1b327d57a8ac080977633a18999f032d7e9e3f', 'https://git.kernel.org/stable/c/3bcb8bba72ce89667fa863054956267c450c47ef', 'https://git.kernel.org/stable/c/906372e753c5027a1dc88743843b6aa2ad1aaecf', 'https://git.kernel.org/stable/c/a9bf3efc33f1fbf88787a277f7349459283c9b95', 'https://git.kernel.org/stable/c/ebebba4d357b6c67f96776a48ddbaf0060fa4c10', 'https://git.kernel.org/stable/c/f23cd66933fe76b84d8e282e5606b4d99068c320', 'https://linux.oracle.com/cve/CVE-2024-43867.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43867-0620@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43867', 'https://www.cve.org/CVERecord?id=CVE-2024-43867'], 'PublishedDate': '2024-08-21T00:15:05.087Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43868', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43868', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv/purgatory: align riscv_kernel_entry', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/purgatory: align riscv_kernel_entry\n\nWhen alignment handling is delegated to the kernel, everything must be\nword-aligned in purgatory, since the trap handler is then set to the\nkexec one. Without the alignment, hitting the exception would\nultimately crash. On other occasions, the kernel's handler would take\ncare of exceptions.\nThis has been tested on a JH7110 SoC with oreboot and its SBI delegating\nunaligned access exceptions and the kernel configured to handle them.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43868', 'https://git.kernel.org/linus/fb197c5d2fd24b9af3d4697d0cf778645846d6d5 (6.11-rc2)', 'https://git.kernel.org/stable/c/5d4aaf16a8255f7c71790e211724ba029609c5ff', 'https://git.kernel.org/stable/c/fb197c5d2fd24b9af3d4697d0cf778645846d6d5', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43868-9a44@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43868', 'https://www.cve.org/CVERecord?id=CVE-2024-43868'], 'PublishedDate': '2024-08-21T00:15:05.15Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43869', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43869', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf: Fix event leak upon exec and file release', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix event leak upon exec and file release\n\nThe perf pending task work is never waited upon the matching event\nrelease. In the case of a child event, released via free_event()\ndirectly, this can potentially result in a leaked event, such as in the\nfollowing scenario that doesn't even require a weak IRQ work\nimplementation to trigger:\n\nschedule()\n prepare_task_switch()\n=======> \n perf_event_overflow()\n event->pending_sigtrap = ...\n irq_work_queue(&event->pending_irq)\n<======= \n perf_event_task_sched_out()\n event_sched_out()\n event->pending_sigtrap = 0;\n atomic_long_inc_not_zero(&event->refcount)\n task_work_add(&event->pending_task)\n finish_lock_switch()\n=======> \n perf_pending_irq()\n //do nothing, rely on pending task work\n<======= \n\nbegin_new_exec()\n perf_event_exit_task()\n perf_event_exit_event()\n // If is child event\n free_event()\n WARN(atomic_long_cmpxchg(&event->refcount, 1, 0) != 1)\n // event is leaked\n\nSimilar scenarios can also happen with perf_event_remove_on_exec() or\nsimply against concurrent perf_event_release().\n\nFix this with synchonizing against the possibly remaining pending task\nwork while freeing the event, just like is done with remaining pending\nIRQ work. This means that the pending task callback neither need nor\nshould hold a reference to the event, preventing it from ever beeing\nfreed.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43869', 'https://git.kernel.org/linus/3a5465418f5fd970e86a86c7f4075be262682840 (6.11-rc1)', 'https://git.kernel.org/stable/c/104e258a004037bc7dba9f6085c71dad6af57ad4', 'https://git.kernel.org/stable/c/3a5465418f5fd970e86a86c7f4075be262682840', 'https://git.kernel.org/stable/c/9ad46f1fef421d43cdab3a7d1744b2f43b54dae0', 'https://git.kernel.org/stable/c/ed2c202dac55423a52d7e2290f2888bf08b8ee99', 'https://git.kernel.org/stable/c/f34d8307a73a18de5320fcc6f40403146d061891', 'https://lore.kernel.org/linux-cve-announce/2024082133-CVE-2024-43869-26aa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43869', 'https://www.cve.org/CVERecord?id=CVE-2024-43869'], 'PublishedDate': '2024-08-21T01:15:11.55Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43870', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43870', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf: Fix event leak upon exit', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix event leak upon exit\n\nWhen a task is scheduled out, pending sigtrap deliveries are deferred\nto the target task upon resume to userspace via task_work.\n\nHowever failures while adding an event's callback to the task_work\nengine are ignored. And since the last call for events exit happen\nafter task work is eventually closed, there is a small window during\nwhich pending sigtrap can be queued though ignored, leaking the event\nrefcount addition such as in the following scenario:\n\n TASK A\n -----\n\n do_exit()\n exit_task_work(tsk);\n\n \n perf_event_overflow()\n event->pending_sigtrap = pending_id;\n irq_work_queue(&event->pending_irq);\n \n =========> PREEMPTION: TASK A -> TASK B\n event_sched_out()\n event->pending_sigtrap = 0;\n atomic_long_inc_not_zero(&event->refcount)\n // FAILS: task work has exited\n task_work_add(&event->pending_task)\n [...]\n \n perf_pending_irq()\n // early return: event->oncpu = -1\n \n [...]\n =========> TASK B -> TASK A\n perf_event_exit_task(tsk)\n perf_event_exit_event()\n free_event()\n WARN(atomic_long_cmpxchg(&event->refcount, 1, 0) != 1)\n // leak event due to unexpected refcount == 2\n\nAs a result the event is never released while the task exits.\n\nFix this with appropriate task_work_add()'s error handling.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43870', 'https://git.kernel.org/linus/2fd5ad3f310de22836cdacae919dd99d758a1f1b (6.11-rc1)', 'https://git.kernel.org/stable/c/05d3fd599594abf79aad4484bccb2b26e1cb0b51', 'https://git.kernel.org/stable/c/2fd5ad3f310de22836cdacae919dd99d758a1f1b', 'https://git.kernel.org/stable/c/3d7a63352a93bdb8a1cdf29606bf617d3ac1c22a', 'https://git.kernel.org/stable/c/67fad724f1b568b356c1065d50df46e6b30eb2f7', 'https://git.kernel.org/stable/c/70882d7fa74f0731492a0d493e8515a4f7131831', 'https://lore.kernel.org/linux-cve-announce/2024082135-CVE-2024-43870-2b6f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43870', 'https://www.cve.org/CVERecord?id=CVE-2024-43870'], 'PublishedDate': '2024-08-21T01:15:11.62Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43871', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43871', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: devres: Fix memory leakage caused by driver API devm_free_percpu()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndevres: Fix memory leakage caused by driver API devm_free_percpu()\n\nIt will cause memory leakage when use driver API devm_free_percpu()\nto free memory allocated by devm_alloc_percpu(), fixed by using\ndevres_release() instead of devres_destroy() within devm_free_percpu().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-43871', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/bd50a974097bb82d52a458bd3ee39fb723129a0c (6.11-rc1)', 'https://git.kernel.org/stable/c/3047f99caec240a88ccd06197af2868da1af6a96', 'https://git.kernel.org/stable/c/3dcd0673e47664bc6c719ad47dadac6d55d5950d', 'https://git.kernel.org/stable/c/700e8abd65b10792b2f179ce4e858f2ca2880f85', 'https://git.kernel.org/stable/c/95065edb8ebb27771d5f1e898eef6ab43dc6c87c', 'https://git.kernel.org/stable/c/b044588a16a978cd891cb3d665dd7ae06850d5bf', 'https://git.kernel.org/stable/c/b67552d7c61f52f1271031adfa7834545ae99701', 'https://git.kernel.org/stable/c/bd50a974097bb82d52a458bd3ee39fb723129a0c', 'https://git.kernel.org/stable/c/ef56dcdca8f2a53abc3a83d388b8336447533d85', 'https://linux.oracle.com/cve/CVE-2024-43871.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43871-c2cd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43871', 'https://www.cve.org/CVERecord?id=CVE-2024-43871'], 'PublishedDate': '2024-08-21T01:15:11.68Z', 'LastModifiedDate': '2024-09-03T13:39:19.553Z'}, {'VulnerabilityID': 'CVE-2024-43872', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43872', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/hns: Fix soft lockup under heavy CEQE load', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix soft lockup under heavy CEQE load\n\nCEQEs are handled in interrupt handler currently. This may cause the\nCPU core staying in interrupt context too long and lead to soft lockup\nunder heavy load.\n\nHandle CEQEs in BH workqueue and set an upper limit for the number of\nCEQE handled by a single call of work handler.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43872', 'https://git.kernel.org/linus/2fdf34038369c0a27811e7b4680662a14ada1d6b (6.11-rc1)', 'https://git.kernel.org/stable/c/06580b33c183c9f98e2a2ca96a86137179032c08', 'https://git.kernel.org/stable/c/2fdf34038369c0a27811e7b4680662a14ada1d6b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43872-c87e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43872', 'https://www.cve.org/CVERecord?id=CVE-2024-43872'], 'PublishedDate': '2024-08-21T01:15:11.74Z', 'LastModifiedDate': '2024-09-03T13:38:34.867Z'}, {'VulnerabilityID': 'CVE-2024-43873', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43873', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: vhost/vsock: always initialize seqpacket_allow', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/vsock: always initialize seqpacket_allow\n\nThere are two issues around seqpacket_allow:\n1. seqpacket_allow is not initialized when socket is\n created. Thus if features are never set, it will be\n read uninitialized.\n2. if VIRTIO_VSOCK_F_SEQPACKET is set and then cleared,\n then seqpacket_allow will not be cleared appropriately\n (existing apps I know about don't usually do this but\n it's legal and there's no way to be sure no one relies\n on this).\n\nTo fix:\n\t- initialize seqpacket_allow after allocation\n\t- set it unconditionally in set_features", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-909'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43873', 'https://git.kernel.org/linus/1e1fdcbdde3b7663e5d8faeb2245b9b151417d22 (6.11-rc1)', 'https://git.kernel.org/stable/c/1e1fdcbdde3b7663e5d8faeb2245b9b151417d22', 'https://git.kernel.org/stable/c/3062cb100787a9ddf45de30004b962035cd497fb', 'https://git.kernel.org/stable/c/30bd4593669443ac58515e23557dc8cef70d8582', 'https://git.kernel.org/stable/c/ea558f10fb05a6503c6e655a1b7d81fdf8e5924c', 'https://git.kernel.org/stable/c/eab96e8716cbfc2834b54f71cc9501ad4eec963b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43873-c547@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43873', 'https://www.cve.org/CVERecord?id=CVE-2024-43873'], 'PublishedDate': '2024-08-21T01:15:11.79Z', 'LastModifiedDate': '2024-09-03T13:35:44.897Z'}, {'VulnerabilityID': 'CVE-2024-43875', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43875', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: endpoint: Clean up error handling in vpci_scan_bus()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: Clean up error handling in vpci_scan_bus()\n\nSmatch complains about inconsistent NULL checking in vpci_scan_bus():\n\n drivers/pci/endpoint/functions/pci-epf-vntb.c:1024 vpci_scan_bus() error: we previously assumed 'vpci_bus' could be null (see line 1021)\n\nInstead of printing an error message and then crashing we should return\nan error code and clean up.\n\nAlso the NULL check is reversed so it prints an error for success\ninstead of failure.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43875', 'https://git.kernel.org/linus/8e0f5a96c534f781e8c57ca30459448b3bfe5429 (6.11-rc1)', 'https://git.kernel.org/stable/c/0e27e2e8697b8ce96cdef43f135426525d9d1f8f', 'https://git.kernel.org/stable/c/24414c842a24d0fd498f9db6d2a762a8dddf1832', 'https://git.kernel.org/stable/c/7d368de78b60088ec9031c60c88976c0063ea4c0', 'https://git.kernel.org/stable/c/8e0f5a96c534f781e8c57ca30459448b3bfe5429', 'https://git.kernel.org/stable/c/b9e8695246bcfc028341470cbf92630cdc1ba36b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43875-1257@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43875', 'https://www.cve.org/CVERecord?id=CVE-2024-43875'], 'PublishedDate': '2024-08-21T01:15:11.91Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43876', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43876', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()\n\nAvoid large backtrace, it is sufficient to warn the user that there has\nbeen a link problem. Either the link has failed and the system is in need\nof maintenance, or the link continues to work and user has been informed.\nThe message from the warning can be looked up in the sources.\n\nThis makes an actual link issue less verbose.\n\nFirst of all, this controller has a limitation in that the controller\ndriver has to assist the hardware with transition to L1 link state by\nwriting L1IATN to PMCTRL register, the L1 and L0 link state switching\nis not fully automatic on this controller.\n\nIn case of an ASMedia ASM1062 PCIe SATA controller which does not support\nASPM, on entry to suspend or during platform pm_test, the SATA controller\nenters D3hot state and the link enters L1 state. If the SATA controller\nwakes up before rcar_pcie_wakeup() was called and returns to D0, the link\nreturns to L0 before the controller driver even started its transition to\nL1 link state. At this point, the SATA controller did send an PM_ENTER_L1\nDLLP to the PCIe controller and the PCIe controller received it, and the\nPCIe controller did set PMSR PMEL1RX bit.\n\nOnce rcar_pcie_wakeup() is called, if the link is already back in L0 state\nand PMEL1RX bit is set, the controller driver has no way to determine if\nit should perform the link transition to L1 state, or treat the link as if\nit is in L0 state. Currently the driver attempts to perform the transition\nto L1 link state unconditionally, which in this specific case fails with a\nPMSR L1FAEG poll timeout, however the link still works as it is already\nback in L0 state.\n\nReduce this warning verbosity. In case the link is really broken, the\nrcar_pcie_config_access() would fail, otherwise it will succeed and any\nsystem with this controller and ASM1062 can suspend without generating\na backtrace.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 2.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43876', 'https://git.kernel.org/linus/c93637e6a4c4e1d0e85ef7efac78d066bbb24d96 (6.11-rc1)', 'https://git.kernel.org/stable/c/2ae4769332dfdb97f4b6f5dc9ac8f46d02aaa3df', 'https://git.kernel.org/stable/c/3ff3bdde950f1840df4030726cef156758a244d7', 'https://git.kernel.org/stable/c/526a877c6273d4cd0d0aede84c1d620479764b1c', 'https://git.kernel.org/stable/c/c93637e6a4c4e1d0e85ef7efac78d066bbb24d96', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43876-793b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43876', 'https://www.cve.org/CVERecord?id=CVE-2024-43876'], 'PublishedDate': '2024-08-21T01:15:11.973Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43877', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43877', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: pci: ivtv: Add check for DMA map result', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: ivtv: Add check for DMA map result\n\nIn case DMA fails, 'dma->SG_length' is 0. This value is later used to\naccess 'dma->SGarray[dma->SG_length - 1]', which will cause out of\nbounds access.\n\nAdd check to return early on invalid value. Adjust warnings accordingly.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43877', 'https://git.kernel.org/linus/629913d6d79508b166c66e07e4857e20233d85a9 (6.11-rc1)', 'https://git.kernel.org/stable/c/24062aa7407091dee3e45a8e8037df437e848718', 'https://git.kernel.org/stable/c/3d8fd92939e21ff0d45100ab208f8124af79402a', 'https://git.kernel.org/stable/c/629913d6d79508b166c66e07e4857e20233d85a9', 'https://git.kernel.org/stable/c/c766065e8272085ea9c436414b7ddf1f12e7787b', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43877-e8e4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43877', 'https://www.cve.org/CVERecord?id=CVE-2024-43877'], 'PublishedDate': '2024-08-21T01:15:12.033Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43879', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43879', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()\n\nCurrently NL80211_RATE_INFO_HE_RU_ALLOC_2x996 is not handled in\ncfg80211_calculate_bitrate_he(), leading to below warning:\n\nkernel: invalid HE MCS: bw:6, ru:6\nkernel: WARNING: CPU: 0 PID: 2312 at net/wireless/util.c:1501 cfg80211_calculate_bitrate_he+0x22b/0x270 [cfg80211]\n\nFix it by handling 2x996 RU allocation in the same way as 160 MHz bandwidth.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43879', 'https://git.kernel.org/linus/bcbd771cd5d68c0c52567556097d75f9fc4e7cd6 (6.11-rc1)', 'https://git.kernel.org/stable/c/16ad67e73309db0c20cc2a651992bd01c05e6b27', 'https://git.kernel.org/stable/c/19eaf4f2f5a981f55a265242ada2bf92b0c742dd', 'https://git.kernel.org/stable/c/2e201b3d162c6c49417c438ffb30b58c9f85769f', 'https://git.kernel.org/stable/c/45d20a1c54be4f3173862c7b950d4468447814c9', 'https://git.kernel.org/stable/c/576c64622649f3ec07e97bac8fec8b8a2ef4d086', 'https://git.kernel.org/stable/c/67b5f1054197e4f5553047759c15c1d67d4c8142', 'https://git.kernel.org/stable/c/b289ebb0516526cb4abae081b7ec29fd4fa1209d', 'https://git.kernel.org/stable/c/bcbd771cd5d68c0c52567556097d75f9fc4e7cd6', 'https://linux.oracle.com/cve/CVE-2024-43879.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43879-95cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43879', 'https://www.cve.org/CVERecord?id=CVE-2024-43879'], 'PublishedDate': '2024-08-21T01:15:12.153Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43880', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43880', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mlxsw: spectrum_acl_erp: Fix object nesting warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_erp: Fix object nesting warning\n\nACLs in Spectrum-2 and newer ASICs can reside in the algorithmic TCAM\n(A-TCAM) or in the ordinary circuit TCAM (C-TCAM). The former can\ncontain more ACLs (i.e., tc filters), but the number of masks in each\nregion (i.e., tc chain) is limited.\n\nIn order to mitigate the effects of the above limitation, the device\nallows filters to share a single mask if their masks only differ in up\nto 8 consecutive bits. For example, dst_ip/25 can be represented using\ndst_ip/24 with a delta of 1 bit. The C-TCAM does not have a limit on the\nnumber of masks being used (and therefore does not support mask\naggregation), but can contain a limited number of filters.\n\nThe driver uses the "objagg" library to perform the mask aggregation by\npassing it objects that consist of the filter\'s mask and whether the\nfilter is to be inserted into the A-TCAM or the C-TCAM since filters in\ndifferent TCAMs cannot share a mask.\n\nThe set of created objects is dependent on the insertion order of the\nfilters and is not necessarily optimal. Therefore, the driver will\nperiodically ask the library to compute a more optimal set ("hints") by\nlooking at all the existing objects.\n\nWhen the library asks the driver whether two objects can be aggregated\nthe driver only compares the provided masks and ignores the A-TCAM /\nC-TCAM indication. This is the right thing to do since the goal is to\nmove as many filters as possible to the A-TCAM. The driver also forbids\ntwo identical masks from being aggregated since this can only happen if\none was intentionally put in the C-TCAM to avoid a conflict in the\nA-TCAM.\n\nThe above can result in the following set of hints:\n\nH1: {mask X, A-TCAM} -> H2: {mask Y, A-TCAM} // X is Y + delta\nH3: {mask Y, C-TCAM} -> H4: {mask Z, A-TCAM} // Y is Z + delta\n\nAfter getting the hints from the library the driver will start migrating\nfilters from one region to another while consulting the computed hints\nand instructing the device to perform a lookup in both regions during\nthe transition.\n\nAssuming a filter with mask X is being migrated into the A-TCAM in the\nnew region, the hints lookup will return H1. Since H2 is the parent of\nH1, the library will try to find the object associated with it and\ncreate it if necessary in which case another hints lookup (recursive)\nwill be performed. This hints lookup for {mask Y, A-TCAM} will either\nreturn H2 or H3 since the driver passes the library an object comparison\nfunction that ignores the A-TCAM / C-TCAM indication.\n\nThis can eventually lead to nested objects which are not supported by\nthe library [1].\n\nFix by removing the object comparison function from both the driver and\nthe library as the driver was the only user. That way the lookup will\nonly return exact matches.\n\nI do not have a reliable reproducer that can reproduce the issue in a\ntimely manner, but before the fix the issue would reproduce in several\nminutes and with the fix it does not reproduce in over an hour.\n\nNote that the current usefulness of the hints is limited because they\ninclude the C-TCAM indication and represent aggregation that cannot\nactually happen. This will be addressed in net-next.\n\n[1]\nWARNING: CPU: 0 PID: 153 at lib/objagg.c:170 objagg_obj_parent_assign+0xb5/0xd0\nModules linked in:\nCPU: 0 PID: 153 Comm: kworker/0:18 Not tainted 6.9.0-rc6-custom-g70fbc2c1c38b #42\nHardware name: Mellanox Technologies Ltd. MSN3700C/VMOD0008, BIOS 5.11 10/10/2018\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:objagg_obj_parent_assign+0xb5/0xd0\n[...]\nCall Trace:\n \n __objagg_obj_get+0x2bb/0x580\n objagg_obj_get+0xe/0x80\n mlxsw_sp_acl_erp_mask_get+0xb5/0xf0\n mlxsw_sp_acl_atcam_entry_add+0xe8/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43880', 'https://git.kernel.org/linus/97d833ceb27dc19f8777d63f90be4a27b5daeedf (6.11-rc1)', 'https://git.kernel.org/stable/c/0e59c2d22853266704e127915653598f7f104037', 'https://git.kernel.org/stable/c/25c6fd9648ad05da493a5d30881896a78a08b624', 'https://git.kernel.org/stable/c/36a9996e020dd5aa325e0ecc55eb2328288ea6bb', 'https://git.kernel.org/stable/c/4dc09f6f260db3c4565a4ec52ba369393598f2fb', 'https://git.kernel.org/stable/c/97d833ceb27dc19f8777d63f90be4a27b5daeedf', 'https://git.kernel.org/stable/c/9a5261a984bba4f583d966c550fa72c33ff3714e', 'https://git.kernel.org/stable/c/fb5d4fc578e655d113f09565f6f047e15f7ab578', 'https://linux.oracle.com/cve/CVE-2024-43880.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43880-78ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43880', 'https://www.cve.org/CVERecord?id=CVE-2024-43880'], 'PublishedDate': '2024-08-21T01:15:12.213Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43881', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43881', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: change DMA direction while mapping reinjected packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: change DMA direction while mapping reinjected packets\n\nFor fragmented packets, ath12k reassembles each fragment as a normal\npacket and then reinjects it into HW ring. In this case, the DMA\ndirection should be DMA_TO_DEVICE, not DMA_FROM_DEVICE. Otherwise,\nan invalid payload may be reinjected into the HW and\nsubsequently delivered to the host.\n\nGiven that arbitrary memory can be allocated to the skb buffer,\nknowledge about the data contained in the reinjected buffer is lacking.\nConsequently, there’s a risk of private information being leaked.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43881', 'https://git.kernel.org/linus/33322e3ef07409278a18c6919c448e369d66a18e (6.11-rc1)', 'https://git.kernel.org/stable/c/33322e3ef07409278a18c6919c448e369d66a18e', 'https://git.kernel.org/stable/c/6925320fcd40d8042d32bf4ede8248e7a5315c3b', 'https://git.kernel.org/stable/c/e99d9b16ff153de9540073239d24adc3b0a3a997', 'https://lore.kernel.org/linux-cve-announce/2024082138-CVE-2024-43881-ead4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43881', 'https://www.cve.org/CVERecord?id=CVE-2024-43881'], 'PublishedDate': '2024-08-21T01:15:12.28Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43883', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43883', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: vhci-hcd: Do not drop references before new references are gained', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: vhci-hcd: Do not drop references before new references are gained\n\nAt a few places the driver carries stale pointers\nto references that can still be used. Make sure that does not happen.\nThis strictly speaking closes ZDI-CAN-22273, though there may be\nsimilar races in the driver.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43883', 'https://git.kernel.org/stable/c/128e82e41cf7d74a562726c1587d9d2ede1a0a37', 'https://git.kernel.org/stable/c/4dacdb9720aaab10b6be121eae55820174d97174', 'https://git.kernel.org/stable/c/585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14', 'https://git.kernel.org/stable/c/5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89', 'https://git.kernel.org/stable/c/9c3746ce8d8fcb3a2405644fc0eec7fc5312de80', 'https://git.kernel.org/stable/c/afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a', 'https://git.kernel.org/stable/c/c3d0857b7fc2c49f68f89128a5440176089a8f54', 'https://git.kernel.org/stable/c/e8c1e606dab8c56cf074b43b98d0805de7322ba2', 'https://linux.oracle.com/cve/CVE-2024-43883.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082313-CVE-2024-43883-a594@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43883', 'https://www.cve.org/CVERecord?id=CVE-2024-43883'], 'PublishedDate': '2024-08-23T13:15:03.873Z', 'LastModifiedDate': '2024-08-23T16:18:28.547Z'}, {'VulnerabilityID': 'CVE-2024-43884', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43884', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: MGMT: Add error handling to pair_device()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Add error handling to pair_device()\n\nhci_conn_params_add() never checks for a NULL value and could lead to a NULL\npointer dereference causing a crash.\n\nFixed by adding error handling in the function.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43884', 'https://git.kernel.org/linus/538fd3921afac97158d4177139a0ad39f056dbb2 (6.11-rc5)', 'https://git.kernel.org/stable/c/064dd929c76532359d2905d90a7c12348043cfd4', 'https://git.kernel.org/stable/c/11b4b0e63f2621b33b2e107407a7d67a65994ca1', 'https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2', 'https://git.kernel.org/stable/c/5da2884292329bc9be32a7778e0e119f06abe503', 'https://git.kernel.org/stable/c/90e1ff1c15e5a8f3023ca8266e3a85869ed03ee9', 'https://git.kernel.org/stable/c/951d6cb5eaac5130d076c728f2a6db420621afdb', 'https://git.kernel.org/stable/c/9df9783bd85610d3d6e126a1aca221531f6f6dcb', 'https://git.kernel.org/stable/c/ee0799103b1ae4bcfd80dc11a15df085f6ee1b61', 'https://lore.kernel.org/linux-cve-announce/2024082621-CVE-2024-43884-43fa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43884', 'https://www.cve.org/CVERecord?id=CVE-2024-43884'], 'PublishedDate': '2024-08-26T08:15:03.827Z', 'LastModifiedDate': '2024-09-04T12:15:04.927Z'}, {'VulnerabilityID': 'CVE-2024-43886', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43886', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null check in resource_log_pipe_topology_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check in resource_log_pipe_topology_update\n\n[WHY]\nWhen switching from "Extend" to "Second Display Only" we sometimes\ncall resource_get_otg_master_for_stream on a stream for the eDP,\nwhich is disconnected. This leads to a null pointer dereference.\n\n[HOW]\nAdded a null check in dc_resource.c/resource_log_pipe_topology_update.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43886', 'https://git.kernel.org/linus/899d92fd26fe780aad711322aa671f68058207a6 (6.11-rc1)', 'https://git.kernel.org/stable/c/899d92fd26fe780aad711322aa671f68058207a6', 'https://git.kernel.org/stable/c/c36e922a36bdf69765c340a0857ca74092003bee', 'https://lore.kernel.org/linux-cve-announce/2024082657-CVE-2024-43886-0726@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43886', 'https://www.cve.org/CVERecord?id=CVE-2024-43886'], 'PublishedDate': '2024-08-26T11:15:03.83Z', 'LastModifiedDate': '2024-08-27T14:37:45.377Z'}, {'VulnerabilityID': 'CVE-2024-43887', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43887', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/tcp: Disable TCP-AO static key after RCU grace period', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp: Disable TCP-AO static key after RCU grace period\n\nThe lifetime of TCP-AO static_key is the same as the last\ntcp_ao_info. On the socket destruction tcp_ao_info ceases to be\nwith RCU grace period, while tcp-ao static branch is currently deferred\ndestructed. The static key definition is\n: DEFINE_STATIC_KEY_DEFERRED_FALSE(tcp_ao_needed, HZ);\n\nwhich means that if RCU grace period is delayed by more than a second\nand tcp_ao_needed is in the process of disablement, other CPUs may\nyet see tcp_ao_info which atent dead, but soon-to-be.\nAnd that breaks the assumption of static_key_fast_inc_not_disabled().\n\nSee the comment near the definition:\n> * The caller must make sure that the static key can\'t get disabled while\n> * in this function. It doesn\'t patch jump labels, only adds a user to\n> * an already enabled static key.\n\nOriginally it was introduced in commit eb8c507296f6 ("jump_label:\nPrevent key->enabled int overflow"), which is needed for the atomic\ncontexts, one of which would be the creation of a full socket from a\nrequest socket. In that atomic context, it\'s known by the presence\nof the key (md5/ao) that the static branch is already enabled.\nSo, the ref counter for that static branch is just incremented\ninstead of holding the proper mutex.\nstatic_key_fast_inc_not_disabled() is just a helper for such usage\ncase. But it must not be used if the static branch could get disabled\nin parallel as it\'s not protected by jump_label_mutex and as a result,\nraces with jump_label_update() implementation details.\n\nHappened on netdev test-bot[1], so not a theoretical issue:\n\n[] jump_label: Fatal kernel bug, unexpected op at tcp_inbound_hash+0x1a7/0x870 [ffffffffa8c4e9b7] (eb 50 0f 1f 44 != 66 90 0f 1f 00)) size:2 type:1\n[] ------------[ cut here ]------------\n[] kernel BUG at arch/x86/kernel/jump_label.c:73!\n[] Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[] CPU: 3 PID: 243 Comm: kworker/3:3 Not tainted 6.10.0-virtme #1\n[] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[] Workqueue: events jump_label_update_timeout\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n...\n[] Call Trace:\n[] \n[] arch_jump_label_transform_queue+0x6c/0x110\n[] __jump_label_update+0xef/0x350\n[] __static_key_slow_dec_cpuslocked.part.0+0x3c/0x60\n[] jump_label_update_timeout+0x2c/0x40\n[] process_one_work+0xe3b/0x1670\n[] worker_thread+0x587/0xce0\n[] kthread+0x28a/0x350\n[] ret_from_fork+0x31/0x70\n[] ret_from_fork_asm+0x1a/0x30\n[] \n[] Modules linked in: veth\n[] ---[ end trace 0000000000000000 ]---\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n\n[1]: https://netdev-3.bots.linux.dev/vmksft-tcp-ao-dbg/results/696681/5-connect-deny-ipv6/stderr', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43887', 'https://git.kernel.org/linus/14ab4792ee120c022f276a7e4768f4dcb08f0cdd (6.11-rc3)', 'https://git.kernel.org/stable/c/14ab4792ee120c022f276a7e4768f4dcb08f0cdd', 'https://git.kernel.org/stable/c/954d55a59b2501f4a9bd693b40ce45a1c46cb2b3', 'https://lore.kernel.org/linux-cve-announce/2024082658-CVE-2024-43887-93bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43887', 'https://www.cve.org/CVERecord?id=CVE-2024-43887'], 'PublishedDate': '2024-08-26T11:15:03.877Z', 'LastModifiedDate': '2024-09-05T19:43:44.197Z'}, {'VulnerabilityID': 'CVE-2024-43888', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43888', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: list_lru: fix UAF for memory cgroup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: list_lru: fix UAF for memory cgroup\n\nThe mem_cgroup_from_slab_obj() is supposed to be called under rcu lock or\ncgroup_mutex or others which could prevent returned memcg from being\nfreed. Fix it by adding missing rcu read lock.\n\nFound by code inspection.\n\n[songmuchun@bytedance.com: only grab rcu lock when necessary, per Vlastimil]\n Link: https://lkml.kernel.org/r/20240801024603.1865-1-songmuchun@bytedance.com', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43888', 'https://git.kernel.org/linus/5161b48712dcd08ec427c450399d4d1483e21dea (6.11-rc3)', 'https://git.kernel.org/stable/c/4589f77c18dd98b65f45617b6d1e95313cf6fcab', 'https://git.kernel.org/stable/c/5161b48712dcd08ec427c450399d4d1483e21dea', 'https://lore.kernel.org/linux-cve-announce/2024082659-CVE-2024-43888-5beb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43888', 'https://www.cve.org/CVERecord?id=CVE-2024-43888'], 'PublishedDate': '2024-08-26T11:15:03.93Z', 'LastModifiedDate': '2024-08-27T14:37:52.61Z'}, {'VulnerabilityID': 'CVE-2024-43889', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43889', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npadata: Fix possible divide-by-0 panic in padata_mt_helper()\n\nWe are hit with a not easily reproducible divide-by-0 panic in padata.c at\nbootup time.\n\n [ 10.017908] Oops: divide error: 0000 1 PREEMPT SMP NOPTI\n [ 10.017908] CPU: 26 PID: 2627 Comm: kworker/u1666:1 Not tainted 6.10.0-15.el10.x86_64 #1\n [ 10.017908] Hardware name: Lenovo ThinkSystem SR950 [7X12CTO1WW]/[7X12CTO1WW], BIOS [PSE140J-2.30] 07/20/2021\n [ 10.017908] Workqueue: events_unbound padata_mt_helper\n [ 10.017908] RIP: 0010:padata_mt_helper+0x39/0xb0\n :\n [ 10.017963] Call Trace:\n [ 10.017968] \n [ 10.018004] ? padata_mt_helper+0x39/0xb0\n [ 10.018084] process_one_work+0x174/0x330\n [ 10.018093] worker_thread+0x266/0x3a0\n [ 10.018111] kthread+0xcf/0x100\n [ 10.018124] ret_from_fork+0x31/0x50\n [ 10.018138] ret_from_fork_asm+0x1a/0x30\n [ 10.018147] \n\nLooking at the padata_mt_helper() function, the only way a divide-by-0\npanic can happen is when ps->chunk_size is 0. The way that chunk_size is\ninitialized in padata_do_multithreaded(), chunk_size can be 0 when the\nmin_chunk in the passed-in padata_mt_job structure is 0.\n\nFix this divide-by-0 panic by making sure that chunk_size will be at least\n1 no matter what the input parameters are.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43889', 'https://git.kernel.org/linus/6d45e1c948a8b7ed6ceddb14319af69424db730c (6.11-rc3)', 'https://git.kernel.org/stable/c/6d45e1c948a8b7ed6ceddb14319af69424db730c', 'https://git.kernel.org/stable/c/8f5ffd2af7274853ff91d6cd62541191d9fbd10d', 'https://git.kernel.org/stable/c/924f788c906dccaca30acab86c7124371e1d6f2c', 'https://git.kernel.org/stable/c/a29cfcb848c31f22b4de6a531c3e1d68c9bfe09f', 'https://git.kernel.org/stable/c/ab8b397d5997d8c37610252528edc54bebf9f6d3', 'https://git.kernel.org/stable/c/da0ffe84fcc1627a7dff82c80b823b94236af905', 'https://lore.kernel.org/linux-cve-announce/2024082600-CVE-2024-43889-4d0b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43889', 'https://www.cve.org/CVERecord?id=CVE-2024-43889'], 'PublishedDate': '2024-08-26T11:15:03.98Z', 'LastModifiedDate': '2024-08-27T14:38:09.34Z'}, {'VulnerabilityID': 'CVE-2024-43890', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43890', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Fix overflow in get_free_elt()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix overflow in get_free_elt()\n\n"tracing_map->next_elt" in get_free_elt() is at risk of overflowing.\n\nOnce it overflows, new elements can still be inserted into the tracing_map\neven though the maximum number of elements (`max_elts`) has been reached.\nContinuing to insert elements after the overflow could result in the\ntracing_map containing "tracing_map->max_size" elements, leaving no empty\nentries.\nIf any attempt is made to insert an element into a full tracing_map using\n`__tracing_map_insert()`, it will cause an infinite loop with preemption\ndisabled, leading to a CPU hang problem.\n\nFix this by preventing any further increments to "tracing_map->next_elt"\nonce it reaches "tracing_map->max_elt".', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43890', 'https://git.kernel.org/linus/bcf86c01ca4676316557dd482c8416ece8c2e143 (6.11-rc3)', 'https://git.kernel.org/stable/c/236bb4690773ab6869b40bedc7bc8d889e36f9d6', 'https://git.kernel.org/stable/c/302ceb625d7b990db205a15e371f9a71238de91c', 'https://git.kernel.org/stable/c/788ea62499b3c18541fd6d621964d8fafbc4aec5', 'https://git.kernel.org/stable/c/a172c7b22bc2feaf489cfc6d6865f7237134fdf8', 'https://git.kernel.org/stable/c/bcf86c01ca4676316557dd482c8416ece8c2e143', 'https://git.kernel.org/stable/c/cd10d186a5409a1fe6e976df82858e9773a698da', 'https://git.kernel.org/stable/c/d3e4dbc2858fe85d1dbd2e72a9fc5dea988b5c18', 'https://git.kernel.org/stable/c/eb223bf01e688dfe37e813c8988ee11c8c9f8d0a', 'https://linux.oracle.com/cve/CVE-2024-43890.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082601-CVE-2024-43890-1c3a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43890', 'https://www.cve.org/CVERecord?id=CVE-2024-43890'], 'PublishedDate': '2024-08-26T11:15:04.04Z', 'LastModifiedDate': '2024-09-05T18:48:30.32Z'}, {'VulnerabilityID': 'CVE-2024-43891', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43891', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Have format file honor EVENT_FILE_FL_FREED', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have format file honor EVENT_FILE_FL_FREED\n\nWhen eventfs was introduced, special care had to be done to coordinate the\nfreeing of the file meta data with the files that are exposed to user\nspace. The file meta data would have a ref count that is set when the file\nis created and would be decremented and freed after the last user that\nopened the file closed it. When the file meta data was to be freed, it\nwould set a flag (EVENT_FILE_FL_FREED) to denote that the file is freed,\nand any new references made (like new opens or reads) would fail as it is\nmarked freed. This allowed other meta data to be freed after this flag was\nset (under the event_mutex).\n\nAll the files that were dynamically created in the events directory had a\npointer to the file meta data and would call event_release() when the last\nreference to the user space file was closed. This would be the time that it\nis safe to free the file meta data.\n\nA shortcut was made for the "format" file. It\'s i_private would point to\nthe "call" entry directly and not point to the file\'s meta data. This is\nbecause all format files are the same for the same "call", so it was\nthought there was no reason to differentiate them. The other files\nmaintain state (like the "enable", "trigger", etc). But this meant if the\nfile were to disappear, the "format" file would be unaware of it.\n\nThis caused a race that could be trigger via the user_events test (that\nwould create dynamic events and free them), and running a loop that would\nread the user_events format files:\n\nIn one console run:\n\n # cd tools/testing/selftests/user_events\n # while true; do ./ftrace_test; done\n\nAnd in another console run:\n\n # cd /sys/kernel/tracing/\n # while true; do cat events/user_events/__test_event/format; done 2>/dev/null\n\nWith KASAN memory checking, it would trigger a use-after-free bug report\n(which was a real bug). This was because the format file was not checking\nthe file\'s meta data flag "EVENT_FILE_FL_FREED", so it would access the\nevent that the file meta data pointed to after the event was freed.\n\nAfter inspection, there are other locations that were found to not check\nthe EVENT_FILE_FL_FREED flag when accessing the trace_event_file. Add a\nnew helper function: event_file_file() that will make sure that the\nevent_mutex is held, and will return NULL if the trace_event_file has the\nEVENT_FILE_FL_FREED flag set. Have the first reference of the struct file\npointer use event_file_file() and check for NULL. Later uses can still use\nthe event_file_data() helper function if the event_mutex is still held and\nwas not released since the event_file_file() call.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43891', 'https://git.kernel.org/linus/b1560408692cd0ab0370cfbe9deb03ce97ab3f6d (6.11-rc3)', 'https://git.kernel.org/stable/c/4ed03758ddf0b19d69eed69386d65a92d0091e0c', 'https://git.kernel.org/stable/c/531dc6780d94245af037c25c2371c8caf652f0f9', 'https://git.kernel.org/stable/c/b1560408692cd0ab0370cfbe9deb03ce97ab3f6d', 'https://lore.kernel.org/linux-cve-announce/2024082603-CVE-2024-43891-a69d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43891', 'https://www.cve.org/CVERecord?id=CVE-2024-43891'], 'PublishedDate': '2024-08-26T11:15:04.103Z', 'LastModifiedDate': '2024-09-05T18:46:18.44Z'}, {'VulnerabilityID': 'CVE-2024-43892', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43892', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg: protect concurrent access to mem_cgroup_idr', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: protect concurrent access to mem_cgroup_idr\n\nCommit 73f576c04b94 ("mm: memcontrol: fix cgroup creation failure after\nmany small jobs") decoupled the memcg IDs from the CSS ID space to fix the\ncgroup creation failures. It introduced IDR to maintain the memcg ID\nspace. The IDR depends on external synchronization mechanisms for\nmodifications. For the mem_cgroup_idr, the idr_alloc() and idr_replace()\nhappen within css callback and thus are protected through cgroup_mutex\nfrom concurrent modifications. However idr_remove() for mem_cgroup_idr\nwas not protected against concurrency and can be run concurrently for\ndifferent memcgs when they hit their refcnt to zero. Fix that.\n\nWe have been seeing list_lru based kernel crashes at a low frequency in\nour fleet for a long time. These crashes were in different part of\nlist_lru code including list_lru_add(), list_lru_del() and reparenting\ncode. Upon further inspection, it looked like for a given object (dentry\nand inode), the super_block\'s list_lru didn\'t have list_lru_one for the\nmemcg of that object. The initial suspicions were either the object is\nnot allocated through kmem_cache_alloc_lru() or somehow\nmemcg_list_lru_alloc() failed to allocate list_lru_one() for a memcg but\nreturned success. No evidence were found for these cases.\n\nLooking more deeply, we started seeing situations where valid memcg\'s id\nis not present in mem_cgroup_idr and in some cases multiple valid memcgs\nhave same id and mem_cgroup_idr is pointing to one of them. So, the most\nreasonable explanation is that these situations can happen due to race\nbetween multiple idr_remove() calls or race between\nidr_alloc()/idr_replace() and idr_remove(). These races are causing\nmultiple memcgs to acquire the same ID and then offlining of one of them\nwould cleanup list_lrus on the system for all of them. Later access from\nother memcgs to the list_lru cause crashes due to missing list_lru_one.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43892', 'https://git.kernel.org/linus/9972605a238339b85bd16b084eed5f18414d22db (6.11-rc3)', 'https://git.kernel.org/stable/c/37a060b64ae83b76600d187d76591ce488ab836b', 'https://git.kernel.org/stable/c/51c0b1bb7541f8893ec1accba59eb04361a70946', 'https://git.kernel.org/stable/c/56fd70f4aa8b82199dbe7e99366b1fd7a04d86fb', 'https://git.kernel.org/stable/c/912736a0435ef40e6a4ae78197ccb5553cb80b05', 'https://git.kernel.org/stable/c/9972605a238339b85bd16b084eed5f18414d22db', 'https://git.kernel.org/stable/c/e6cc9ff2ac0b5df9f25eb790934c3104f6710278', 'https://lore.kernel.org/linux-cve-announce/2024082604-CVE-2024-43892-584a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43892', 'https://www.cve.org/CVERecord?id=CVE-2024-43892'], 'PublishedDate': '2024-08-26T11:15:04.157Z', 'LastModifiedDate': '2024-09-12T12:15:49.593Z'}, {'VulnerabilityID': 'CVE-2024-43893', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43893', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: core: check uartclk for zero to avoid divide by zero', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: check uartclk for zero to avoid divide by zero\n\nCalling ioctl TIOCSSERIAL with an invalid baud_base can\nresult in uartclk being zero, which will result in a\ndivide by zero error in uart_get_divisor(). The check for\nuartclk being zero in uart_set_info() needs to be done\nbefore other settings are made as subsequent calls to\nioctl TIOCSSERIAL for the same port would be impacted if\nthe uartclk check was done where uartclk gets set.\n\nOops: divide error: 0000 PREEMPT SMP KASAN PTI\nRIP: 0010:uart_get_divisor (drivers/tty/serial/serial_core.c:580)\nCall Trace:\n \nserial8250_get_divisor (drivers/tty/serial/8250/8250_port.c:2576\n drivers/tty/serial/8250/8250_port.c:2589)\nserial8250_do_set_termios (drivers/tty/serial/8250/8250_port.c:502\n drivers/tty/serial/8250/8250_port.c:2741)\nserial8250_set_termios (drivers/tty/serial/8250/8250_port.c:2862)\nuart_change_line_settings (./include/linux/spinlock.h:376\n ./include/linux/serial_core.h:608 drivers/tty/serial/serial_core.c:222)\nuart_port_startup (drivers/tty/serial/serial_core.c:342)\nuart_startup (drivers/tty/serial/serial_core.c:368)\nuart_set_info (drivers/tty/serial/serial_core.c:1034)\nuart_set_info_user (drivers/tty/serial/serial_core.c:1059)\ntty_set_serial (drivers/tty/tty_io.c:2637)\ntty_ioctl (drivers/tty/tty_io.c:2647 drivers/tty/tty_io.c:2791)\n__x64_sys_ioctl (fs/ioctl.c:52 fs/ioctl.c:907\n fs/ioctl.c:893 fs/ioctl.c:893)\ndo_syscall_64 (arch/x86/entry/common.c:52\n (discriminator 1) arch/x86/entry/common.c:83 (discriminator 1))\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nRule: add', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43893', 'https://git.kernel.org/linus/6eabce6608d6f3440f4c03aa3d3ef50a47a3d193 (6.11-rc3)', 'https://git.kernel.org/stable/c/3bbd90fca824e6fd61fb20f6dd2b0fa5f8b14bba', 'https://git.kernel.org/stable/c/52b138f1021113e593ee6ad258ce08fe90693a9e', 'https://git.kernel.org/stable/c/55b2a5d331a6ceb1c4372945fdb77181265ba24f', 'https://git.kernel.org/stable/c/68dc02f319b9ee54dc23caba742a5c754d1cccc8', 'https://git.kernel.org/stable/c/6eabce6608d6f3440f4c03aa3d3ef50a47a3d193', 'https://git.kernel.org/stable/c/9196e42a3b8eeff1707e6ef769112b4b6096be49', 'https://git.kernel.org/stable/c/e13ba3fe5ee070f8a9dab60029d52b1f61da5051', 'https://git.kernel.org/stable/c/e3ad503876283ac3fcca922a1bf243ef9eb0b0e2', 'https://linux.oracle.com/cve/CVE-2024-43893.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082605-CVE-2024-43893-25dd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43893', 'https://www.cve.org/CVERecord?id=CVE-2024-43893'], 'PublishedDate': '2024-08-26T11:15:04.213Z', 'LastModifiedDate': '2024-09-10T18:13:21.92Z'}, {'VulnerabilityID': 'CVE-2024-43894', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43894', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/client: fix null pointer dereference in drm_client_modeset_probe', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/client: fix null pointer dereference in drm_client_modeset_probe\n\nIn drm_client_modeset_probe(), the return value of drm_mode_duplicate() is\nassigned to modeset->mode, which will lead to a possible NULL pointer\ndereference on failure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43894', 'https://git.kernel.org/linus/113fd6372a5bb3689aba8ef5b8a265ed1529a78f (6.11-rc3)', 'https://git.kernel.org/stable/c/113fd6372a5bb3689aba8ef5b8a265ed1529a78f', 'https://git.kernel.org/stable/c/24ddda932c43ffe156c7f3c568bed85131c63ae6', 'https://git.kernel.org/stable/c/5291d4f73452c91e8a11f71207617e3e234d418e', 'https://git.kernel.org/stable/c/612cae53e99ce32a58cb821b3b67199eb6e92dff', 'https://git.kernel.org/stable/c/c763dfe09425152b6bb0e348900a637c62c2ce52', 'https://git.kernel.org/stable/c/d64847c383100423aecb6ac5f18be5f4316d9d62', 'https://git.kernel.org/stable/c/d64fc94f7bb24fc2be0d6bd5df8df926da461a6d', 'https://linux.oracle.com/cve/CVE-2024-43894.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082607-CVE-2024-43894-aeee@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43894', 'https://www.cve.org/CVERecord?id=CVE-2024-43894'], 'PublishedDate': '2024-08-26T11:15:04.28Z', 'LastModifiedDate': '2024-09-10T18:09:41.23Z'}, {'VulnerabilityID': 'CVE-2024-43895', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43895', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip Recompute DSC Params if no Stream on Link', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip Recompute DSC Params if no Stream on Link\n\n[why]\nEncounter NULL pointer dereference uner mst + dsc setup.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 4 PID: 917 Comm: sway Not tainted 6.3.9-arch1-1 #1 124dc55df4f5272ccb409f39ef4872fc2b3376a2\n Hardware name: LENOVO 20NKS01Y00/20NKS01Y00, BIOS R12ET61W(1.31 ) 07/28/2022\n RIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\n Code: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\n RSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\n RAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\n RDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\n RBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\n R10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\n R13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\n FS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000010ddc6000 CR4: 00000000003506e0\n Call Trace:\n\n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? plist_add+0xbe/0x100\n ? exc_page_fault+0x7c/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n ? drm_dp_atomic_find_time_slots+0x28/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n compute_mst_dsc_configs_for_link+0x2ff/0xa40 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n ? fill_plane_buffer_attributes+0x419/0x510 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n compute_mst_dsc_configs_for_state+0x1e1/0x250 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n amdgpu_dm_atomic_check+0xecd/0x1190 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n drm_atomic_check_only+0x5c5/0xa40\n drm_mode_atomic_ioctl+0x76e/0xbc0\n\n[how]\ndsc recompute should be skipped if no mode change detected on the new\nrequest. If detected, keep checking whether the stream is already on\ncurrent state or not.\n\n(cherry picked from commit 8151a6c13111b465dbabe07c19f572f7cbd16fef)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43895', 'https://git.kernel.org/linus/50e376f1fe3bf571d0645ddf48ad37eb58323919 (6.11-rc3)', 'https://git.kernel.org/stable/c/282f0a482ee61d5e863512f3c4fcec90216c20d9', 'https://git.kernel.org/stable/c/50e376f1fe3bf571d0645ddf48ad37eb58323919', 'https://git.kernel.org/stable/c/5357141b4c2e2b332b6f11607ba8c5fbc2669a10', 'https://git.kernel.org/stable/c/70275bb960c71d313254473d38c14e7101cee5ad', 'https://git.kernel.org/stable/c/718d83f66fb07b2cab89a1fc984613a00e3db18f', 'https://lore.kernel.org/linux-cve-announce/2024082608-CVE-2024-43895-d3c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43895', 'https://www.cve.org/CVERecord?id=CVE-2024-43895'], 'PublishedDate': '2024-08-26T11:15:04.333Z', 'LastModifiedDate': '2024-10-10T12:15:04.35Z'}, {'VulnerabilityID': 'CVE-2024-43898', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43898', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: sanity check for NULL pointer after ext4_force_shutdown', 'Description': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43898', 'https://git.kernel.org/linus/83f4414b8f84249d538905825b088ff3ae555652 (6.11-rc1)', 'https://git.kernel.org/stable/c/3f6bbe6e07e5239294ecc3d2efa70d1f98aed52e', 'https://git.kernel.org/stable/c/83f4414b8f84249d538905825b088ff3ae555652', 'https://git.kernel.org/stable/c/f619876ccbfd329ae785fe5d3289b9dcd6eb5901', 'https://lore.kernel.org/linux-cve-announce/2024082613-CVE-2024-43898-52c2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43898', 'https://www.cve.org/CVERecord?id=CVE-2024-43898'], 'PublishedDate': '2024-08-26T11:15:04.493Z', 'LastModifiedDate': '2024-09-10T08:15:02.96Z'}, {'VulnerabilityID': 'CVE-2024-43899', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43899', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix null pointer deref in dcn20_resource.c', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null pointer deref in dcn20_resource.c\n\nFixes a hang thats triggered when MPV is run on a DCN401 dGPU:\n\nmpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all\n\nand then enabling fullscreen playback (double click on the video)\n\nThe following calltrace will be seen:\n\n[ 181.843989] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 181.843997] #PF: supervisor instruction fetch in kernel mode\n[ 181.844003] #PF: error_code(0x0010) - not-present page\n[ 181.844009] PGD 0 P4D 0\n[ 181.844020] Oops: 0010 [#1] PREEMPT SMP NOPTI\n[ 181.844028] CPU: 6 PID: 1892 Comm: gnome-shell Tainted: G W OE 6.5.0-41-generic #41~22.04.2-Ubuntu\n[ 181.844038] Hardware name: System manufacturer System Product Name/CROSSHAIR VI HERO, BIOS 6302 10/23/2018\n[ 181.844044] RIP: 0010:0x0\n[ 181.844079] Code: Unable to access opcode bytes at 0xffffffffffffffd6.\n[ 181.844084] RSP: 0018:ffffb593c2b8f7b0 EFLAGS: 00010246\n[ 181.844093] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004\n[ 181.844099] RDX: ffffb593c2b8f804 RSI: ffffb593c2b8f7e0 RDI: ffff9e3c8e758400\n[ 181.844105] RBP: ffffb593c2b8f7b8 R08: ffffb593c2b8f9c8 R09: ffffb593c2b8f96c\n[ 181.844110] R10: 0000000000000000 R11: 0000000000000000 R12: ffffb593c2b8f9c8\n[ 181.844115] R13: 0000000000000001 R14: ffff9e3c88000000 R15: 0000000000000005\n[ 181.844121] FS: 00007c6e323bb5c0(0000) GS:ffff9e3f85f80000(0000) knlGS:0000000000000000\n[ 181.844128] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 181.844134] CR2: ffffffffffffffd6 CR3: 0000000140fbe000 CR4: 00000000003506e0\n[ 181.844141] Call Trace:\n[ 181.844146] \n[ 181.844153] ? show_regs+0x6d/0x80\n[ 181.844167] ? __die+0x24/0x80\n[ 181.844179] ? page_fault_oops+0x99/0x1b0\n[ 181.844192] ? do_user_addr_fault+0x31d/0x6b0\n[ 181.844204] ? exc_page_fault+0x83/0x1b0\n[ 181.844216] ? asm_exc_page_fault+0x27/0x30\n[ 181.844237] dcn20_get_dcc_compression_cap+0x23/0x30 [amdgpu]\n[ 181.845115] amdgpu_dm_plane_validate_dcc.constprop.0+0xe5/0x180 [amdgpu]\n[ 181.845985] amdgpu_dm_plane_fill_plane_buffer_attributes+0x300/0x580 [amdgpu]\n[ 181.846848] fill_dc_plane_info_and_addr+0x258/0x350 [amdgpu]\n[ 181.847734] fill_dc_plane_attributes+0x162/0x350 [amdgpu]\n[ 181.848748] dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[ 181.849791] ? dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[ 181.850840] amdgpu_dm_atomic_check+0xdfe/0x1760 [amdgpu]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43899', 'https://git.kernel.org/linus/ecbf60782662f0a388493685b85a645a0ba1613c (6.11-rc1)', 'https://git.kernel.org/stable/c/974fccd61758599a9716c4b909d9226749efe37e', 'https://git.kernel.org/stable/c/ecbf60782662f0a388493685b85a645a0ba1613c', 'https://lore.kernel.org/linux-cve-announce/2024082614-CVE-2024-43899-2339@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43899', 'https://www.cve.org/CVERecord?id=CVE-2024-43899'], 'PublishedDate': '2024-08-26T11:15:04.557Z', 'LastModifiedDate': '2024-08-27T14:38:19.74Z'}, {'VulnerabilityID': 'CVE-2024-43900', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43900', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: xc2028: avoid use-after-free in load_firmware_cb()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: xc2028: avoid use-after-free in load_firmware_cb()\n\nsyzkaller reported use-after-free in load_firmware_cb() [1].\nThe reason is because the module allocated a struct tuner in tuner_probe(),\nand then the module initialization failed, the struct tuner was released.\nA worker which created during module initialization accesses this struct\ntuner later, it caused use-after-free.\n\nThe process is as follows:\n\ntask-6504 worker_thread\ntuner_probe <= alloc dvb_frontend [2]\n...\nrequest_firmware_nowait <= create a worker\n...\ntuner_remove <= free dvb_frontend\n...\n request_firmware_work_func <= the firmware is ready\n load_firmware_cb <= but now the dvb_frontend has been freed\n\nTo fix the issue, check the dvd_frontend in load_firmware_cb(), if it is\nnull, report a warning and just return.\n\n[1]:\n ==================================================================\n BUG: KASAN: use-after-free in load_firmware_cb+0x1310/0x17a0\n Read of size 8 at addr ffff8000d7ca2308 by task kworker/2:3/6504\n\n Call trace:\n load_firmware_cb+0x1310/0x17a0\n request_firmware_work_func+0x128/0x220\n process_one_work+0x770/0x1824\n worker_thread+0x488/0xea0\n kthread+0x300/0x430\n ret_from_fork+0x10/0x20\n\n Allocated by task 6504:\n kzalloc\n tuner_probe+0xb0/0x1430\n i2c_device_probe+0x92c/0xaf0\n really_probe+0x678/0xcd0\n driver_probe_device+0x280/0x370\n __device_attach_driver+0x220/0x330\n bus_for_each_drv+0x134/0x1c0\n __device_attach+0x1f4/0x410\n device_initial_probe+0x20/0x30\n bus_probe_device+0x184/0x200\n device_add+0x924/0x12c0\n device_register+0x24/0x30\n i2c_new_device+0x4e0/0xc44\n v4l2_i2c_new_subdev_board+0xbc/0x290\n v4l2_i2c_new_subdev+0xc8/0x104\n em28xx_v4l2_init+0x1dd0/0x3770\n\n Freed by task 6504:\n kfree+0x238/0x4e4\n tuner_remove+0x144/0x1c0\n i2c_device_remove+0xc8/0x290\n __device_release_driver+0x314/0x5fc\n device_release_driver+0x30/0x44\n bus_remove_device+0x244/0x490\n device_del+0x350/0x900\n device_unregister+0x28/0xd0\n i2c_unregister_device+0x174/0x1d0\n v4l2_device_unregister+0x224/0x380\n em28xx_v4l2_init+0x1d90/0x3770\n\n The buggy address belongs to the object at ffff8000d7ca2000\n which belongs to the cache kmalloc-2k of size 2048\n The buggy address is located 776 bytes inside of\n 2048-byte region [ffff8000d7ca2000, ffff8000d7ca2800)\n The buggy address belongs to the page:\n page:ffff7fe00035f280 count:1 mapcount:0 mapping:ffff8000c001f000 index:0x0\n flags: 0x7ff800000000100(slab)\n raw: 07ff800000000100 ffff7fe00049d880 0000000300000003 ffff8000c001f000\n raw: 0000000000000000 0000000080100010 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8000d7ca2200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8000d7ca2280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8000d7ca2300: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8000d7ca2380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8000d7ca2400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\n[2]\n Actually, it is allocated for struct tuner, and dvb_frontend is inside.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43900', 'https://git.kernel.org/linus/68594cec291ff9523b9feb3f43fd853dcddd1f60 (6.11-rc1)', 'https://git.kernel.org/stable/c/208deb6d8c3cb8c3acb1f41eb31cf68ea08726d5', 'https://git.kernel.org/stable/c/68594cec291ff9523b9feb3f43fd853dcddd1f60', 'https://git.kernel.org/stable/c/850304152d367f104d21c77cfbcc05806504218b', 'https://git.kernel.org/stable/c/ef517bdfc01818419f7bd426969a0c86b14f3e0e', 'https://lore.kernel.org/linux-cve-announce/2024082616-CVE-2024-43900-029c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43900', 'https://www.cve.org/CVERecord?id=CVE-2024-43900'], 'PublishedDate': '2024-08-26T11:15:04.613Z', 'LastModifiedDate': '2024-08-27T14:38:32.967Z'}, {'VulnerabilityID': 'CVE-2024-43902', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43902', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null checker before passing variables', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null checker before passing variables\n\nChecks null pointer before passing variables to functions.\n\nThis fixes 3 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43902', 'https://git.kernel.org/linus/8092aa3ab8f7b737a34b71f91492c676a843043a (6.11-rc1)', 'https://git.kernel.org/stable/c/1686675405d07f35eae7ff3d13a530034b899df2', 'https://git.kernel.org/stable/c/4cc2a94d96caeb3c975acdae7351c2f997c32175', 'https://git.kernel.org/stable/c/8092aa3ab8f7b737a34b71f91492c676a843043a', 'https://git.kernel.org/stable/c/83c7f509ef087041604e9572938f82e18b724c9d', 'https://git.kernel.org/stable/c/d0b8b23b9c2ebec693a36fea518d8f13493ad655', 'https://lore.kernel.org/linux-cve-announce/2024082618-CVE-2024-43902-eb6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43902', 'https://www.cve.org/CVERecord?id=CVE-2024-43902'], 'PublishedDate': '2024-08-26T11:15:04.733Z', 'LastModifiedDate': '2024-08-27T14:38:51.73Z'}, {'VulnerabilityID': 'CVE-2024-43903', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43903', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update\n\nThis commit adds a null check for the 'afb' variable in the\namdgpu_dm_plane_handle_cursor_update function. Previously, 'afb' was\nassumed to be null, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed 'afb' could be null (see line 1252)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43903', 'https://git.kernel.org/linus/38e6f715b02b572f74677eb2f29d3b4bc6f1ddff (6.11-rc1)', 'https://git.kernel.org/stable/c/31a679a880102dee6e10985a7b1789af8dc328cc', 'https://git.kernel.org/stable/c/38e6f715b02b572f74677eb2f29d3b4bc6f1ddff', 'https://git.kernel.org/stable/c/94220b35aeba2b68da81deeefbb784d94eeb5c04', 'https://git.kernel.org/stable/c/ce5d090af683137cb779ed7e3683839f9c778b35', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-43903-3644@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43903', 'https://www.cve.org/CVERecord?id=CVE-2024-43903'], 'PublishedDate': '2024-08-26T11:15:04.793Z', 'LastModifiedDate': '2024-08-27T13:39:48.683Z'}, {'VulnerabilityID': 'CVE-2024-43904', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43904', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing\n\nThis commit adds null checks for the 'stream' and 'plane' variables in\nthe dcn30_apply_idle_power_optimizations function. These variables were\npreviously assumed to be null at line 922, but they were used later in\nthe code without checking if they were null. This could potentially lead\nto a null pointer dereference, which would cause a crash.\n\nThe null checks ensure that 'stream' and 'plane' are not null before\nthey are used, preventing potential crashes.\n\nFixes the below static smatch checker:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:938 dcn30_apply_idle_power_optimizations() error: we previously assumed 'stream' could be null (see line 922)\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:940 dcn30_apply_idle_power_optimizations() error: we previously assumed 'plane' could be null (see line 922)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43904', 'https://git.kernel.org/linus/15c2990e0f0108b9c3752d7072a97d45d4283aea (6.11-rc1)', 'https://git.kernel.org/stable/c/15c2990e0f0108b9c3752d7072a97d45d4283aea', 'https://git.kernel.org/stable/c/16a8a2a839d19c4cf7253642b493ffb8eee1d857', 'https://lore.kernel.org/linux-cve-announce/2024082621-CVE-2024-43904-63a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43904', 'https://www.cve.org/CVERecord?id=CVE-2024-43904'], 'PublishedDate': '2024-08-26T11:15:04.847Z', 'LastModifiedDate': '2024-08-27T13:40:50.577Z'}, {'VulnerabilityID': 'CVE-2024-43905', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43905', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: Fix the null pointer dereference for vega10_hwmgr', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Fix the null pointer dereference for vega10_hwmgr\n\nCheck return value and conduct null pointer handling to avoid null pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43905', 'https://git.kernel.org/linus/50151b7f1c79a09117837eb95b76c2de76841dab (6.11-rc1)', 'https://git.kernel.org/stable/c/0fa11f9df96217c2785b040629ff1a16900fb51c', 'https://git.kernel.org/stable/c/2ac9deb7e087f0b461c3559d9eaa6b9cf19d3fa8', 'https://git.kernel.org/stable/c/2e538944996d0dd497faf8ee81f8bfcd3aca7d80', 'https://git.kernel.org/stable/c/50151b7f1c79a09117837eb95b76c2de76841dab', 'https://git.kernel.org/stable/c/69a441473fec2fc2aa2cf56122d6c42c4266a239', 'https://git.kernel.org/stable/c/c2629daf218a325f4d69754452cd42fe8451c15b', 'https://lore.kernel.org/linux-cve-announce/2024082623-CVE-2024-43905-008f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43905', 'https://www.cve.org/CVERecord?id=CVE-2024-43905'], 'PublishedDate': '2024-08-26T11:15:04.897Z', 'LastModifiedDate': '2024-09-12T12:15:51.26Z'}, {'VulnerabilityID': 'CVE-2024-43906', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43906', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/admgpu: fix dereferencing null pointer context', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/admgpu: fix dereferencing null pointer context\n\nWhen user space sets an invalid ta type, the pointer context will be empty.\nSo it need to check the pointer context before using it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43906', 'https://git.kernel.org/linus/030ffd4d43b433bc6671d9ec34fc12c59220b95d (6.11-rc1)', 'https://git.kernel.org/stable/c/030ffd4d43b433bc6671d9ec34fc12c59220b95d', 'https://git.kernel.org/stable/c/4fd52f7c2c11d330571c6bde06e5ea508ec25c9d', 'https://git.kernel.org/stable/c/641dac64178ccdb9e45c92b67120316896294d05', 'https://lore.kernel.org/linux-cve-announce/2024082624-CVE-2024-43906-27ab@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43906', 'https://www.cve.org/CVERecord?id=CVE-2024-43906'], 'PublishedDate': '2024-08-26T11:15:04.947Z', 'LastModifiedDate': '2024-08-27T13:41:30.093Z'}, {'VulnerabilityID': 'CVE-2024-43907', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43907', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/pm: Fix the null pointer dereference in apply_state_adjust_rules', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm: Fix the null pointer dereference in apply_state_adjust_rules\n\nCheck the pointer value to fix potential null pointer\ndereference', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43907', 'https://git.kernel.org/linus/d19fb10085a49b77578314f69fff21562f7cd054 (6.11-rc1)', 'https://git.kernel.org/stable/c/0c065e50445aea2e0a1815f12e97ee49e02cbaac', 'https://git.kernel.org/stable/c/13937a40aae4efe64592ba48c057ac3c72f7fe82', 'https://git.kernel.org/stable/c/3a01bf2ca9f860fdc88c358567b8fa3033efcf30', 'https://git.kernel.org/stable/c/c1749313f35b98e2e655479f037db37f19756622', 'https://git.kernel.org/stable/c/d19fb10085a49b77578314f69fff21562f7cd054', 'https://git.kernel.org/stable/c/e04d18c29954441aa1054af649f957ffad90a201', 'https://lore.kernel.org/linux-cve-announce/2024082626-CVE-2024-43907-91a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43907', 'https://www.cve.org/CVERecord?id=CVE-2024-43907'], 'PublishedDate': '2024-08-26T11:15:05Z', 'LastModifiedDate': '2024-08-27T13:41:40.497Z'}, {'VulnerabilityID': 'CVE-2024-43908', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43908', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix the null pointer dereference to ras_manager', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the null pointer dereference to ras_manager\n\nCheck ras_manager before using it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43908', 'https://git.kernel.org/linus/4c11d30c95576937c6c35e6f29884761f2dddb43 (6.11-rc1)', 'https://git.kernel.org/stable/c/033187a70ba9743c73a810a006816e5553d1e7d4', 'https://git.kernel.org/stable/c/48cada0ac79e4775236d642e9ec5998a7c7fb7a4', 'https://git.kernel.org/stable/c/4c11d30c95576937c6c35e6f29884761f2dddb43', 'https://git.kernel.org/stable/c/56e848034ccabe44e8f22ffcf49db771c17b0d0a', 'https://git.kernel.org/stable/c/b89616333979114bb0da5fa40fb6e4a2f5294ca2', 'https://git.kernel.org/stable/c/d81c1eeb333d84b3012a91c0500189dc1d71e46c', 'https://git.kernel.org/stable/c/ff5c4eb71ee8951c789b079f6e948f86708b04ed', 'https://linux.oracle.com/cve/CVE-2024-43908.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082627-CVE-2024-43908-4406@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43908', 'https://www.cve.org/CVERecord?id=CVE-2024-43908'], 'PublishedDate': '2024-08-26T11:15:05.057Z', 'LastModifiedDate': '2024-08-27T13:41:55.26Z'}, {'VulnerabilityID': 'CVE-2024-43909', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43909', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/pm: Fix the null pointer dereference for smu7', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm: Fix the null pointer dereference for smu7\n\noptimize the code to avoid pass a null pointer (hwmgr->backend)\nto function smu7_update_edc_leakage_table.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43909', 'https://git.kernel.org/linus/c02c1960c93eede587576625a1221205a68a904f (6.11-rc1)', 'https://git.kernel.org/stable/c/09544cd95c688d3041328a4253bd7514972399bb', 'https://git.kernel.org/stable/c/1b8aa82b80bd947b68a8ab051d960a0c7935e22d', 'https://git.kernel.org/stable/c/37b9df457cbcf095963d18f17d6cb7dfa0a03fce', 'https://git.kernel.org/stable/c/7f56f050f02c27ed89cce1ea0c04b34abce32751', 'https://git.kernel.org/stable/c/c02c1960c93eede587576625a1221205a68a904f', 'https://lore.kernel.org/linux-cve-announce/2024082628-CVE-2024-43909-acb8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43909', 'https://www.cve.org/CVERecord?id=CVE-2024-43909'], 'PublishedDate': '2024-08-26T11:15:05.117Z', 'LastModifiedDate': '2024-08-27T13:41:48.467Z'}, {'VulnerabilityID': 'CVE-2024-43910', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43910', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses\n\nCurrently, it's possible to pass in a modified CONST_PTR_TO_DYNPTR to\na global function as an argument. The adverse effects of this is that\nBPF helpers can continue to make use of this modified\nCONST_PTR_TO_DYNPTR from within the context of the global function,\nwhich can unintentionally result in out-of-bounds memory accesses and\ntherefore compromise overall system stability i.e.\n\n[ 244.157771] BUG: KASAN: slab-out-of-bounds in bpf_dynptr_data+0x137/0x140\n[ 244.161345] Read of size 8 at addr ffff88810914be68 by task test_progs/302\n[ 244.167151] CPU: 0 PID: 302 Comm: test_progs Tainted: G O E 6.10.0-rc3-00131-g66b586715063 #533\n[ 244.174318] Call Trace:\n[ 244.175787] \n[ 244.177356] dump_stack_lvl+0x66/0xa0\n[ 244.179531] print_report+0xce/0x670\n[ 244.182314] ? __virt_addr_valid+0x200/0x3e0\n[ 244.184908] kasan_report+0xd7/0x110\n[ 244.187408] ? bpf_dynptr_data+0x137/0x140\n[ 244.189714] ? bpf_dynptr_data+0x137/0x140\n[ 244.192020] bpf_dynptr_data+0x137/0x140\n[ 244.194264] bpf_prog_b02a02fdd2bdc5fa_global_call_bpf_dynptr_data+0x22/0x26\n[ 244.198044] bpf_prog_b0fe7b9d7dc3abde_callback_adjust_bpf_dynptr_reg_off+0x1f/0x23\n[ 244.202136] bpf_user_ringbuf_drain+0x2c7/0x570\n[ 244.204744] ? 0xffffffffc0009e58\n[ 244.206593] ? __pfx_bpf_user_ringbuf_drain+0x10/0x10\n[ 244.209795] bpf_prog_33ab33f6a804ba2d_user_ringbuf_callback_const_ptr_to_dynptr_reg_off+0x47/0x4b\n[ 244.215922] bpf_trampoline_6442502480+0x43/0xe3\n[ 244.218691] __x64_sys_prlimit64+0x9/0xf0\n[ 244.220912] do_syscall_64+0xc1/0x1d0\n[ 244.223043] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 244.226458] RIP: 0033:0x7ffa3eb8f059\n[ 244.228582] Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8f 1d 0d 00 f7 d8 64 89 01 48\n[ 244.241307] RSP: 002b:00007ffa3e9c6eb8 EFLAGS: 00000206 ORIG_RAX: 000000000000012e\n[ 244.246474] RAX: ffffffffffffffda RBX: 00007ffa3e9c7cdc RCX: 00007ffa3eb8f059\n[ 244.250478] RDX: 00007ffa3eb162b4 RSI: 0000000000000000 RDI: 00007ffa3e9c7fb0\n[ 244.255396] RBP: 00007ffa3e9c6ed0 R08: 00007ffa3e9c76c0 R09: 0000000000000000\n[ 244.260195] R10: 0000000000000000 R11: 0000000000000206 R12: ffffffffffffff80\n[ 244.264201] R13: 000000000000001c R14: 00007ffc5d6b4260 R15: 00007ffa3e1c7000\n[ 244.268303] \n\nAdd a check_func_arg_reg_off() to the path in which the BPF verifier\nverifies the arguments of global function arguments, specifically\nthose which take an argument of type ARG_PTR_TO_DYNPTR |\nMEM_RDONLY. Also, process_dynptr_func() doesn't appear to perform any\nexplicit and strict type matching on the supplied register type, so\nlet's also enforce that a register either type PTR_TO_STACK or\nCONST_PTR_TO_DYNPTR is by the caller.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43910', 'https://git.kernel.org/linus/ec2b9a5e11e51fea1bb04c1e7e471952e887e874 (6.11-rc1)', 'https://git.kernel.org/stable/c/13663a7c644bf1dedaf461d07252db5d76c8759a', 'https://git.kernel.org/stable/c/ec2b9a5e11e51fea1bb04c1e7e471952e887e874', 'https://lore.kernel.org/linux-cve-announce/2024082630-CVE-2024-43910-c6ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43910', 'https://www.cve.org/CVERecord?id=CVE-2024-43910'], 'PublishedDate': '2024-08-26T11:15:05.177Z', 'LastModifiedDate': '2024-09-05T18:30:23.437Z'}, {'VulnerabilityID': 'CVE-2024-43911', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43911', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mac80211: fix NULL dereference at band check in starting tx ba session', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix NULL dereference at band check in starting tx ba session\n\nIn MLD connection, link_data/link_conf are dynamically allocated. They\ndon't point to vif->bss_conf. So, there will be no chanreq assigned to\nvif->bss_conf and then the chan will be NULL. Tweak the code to check\nht_supported/vht_supported/has_he/has_eht on sta deflink.\n\nCrash log (with rtw89 version under MLO development):\n[ 9890.526087] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 9890.526102] #PF: supervisor read access in kernel mode\n[ 9890.526105] #PF: error_code(0x0000) - not-present page\n[ 9890.526109] PGD 0 P4D 0\n[ 9890.526114] Oops: 0000 [#1] PREEMPT SMP PTI\n[ 9890.526119] CPU: 2 PID: 6367 Comm: kworker/u16:2 Kdump: loaded Tainted: G OE 6.9.0 #1\n[ 9890.526123] Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB3WW (2.73 ) 11/28/2018\n[ 9890.526126] Workqueue: phy2 rtw89_core_ba_work [rtw89_core]\n[ 9890.526203] RIP: 0010:ieee80211_start_tx_ba_session (net/mac80211/agg-tx.c:618 (discriminator 1)) mac80211\n[ 9890.526279] Code: f7 e8 d5 93 3e ea 48 83 c4 28 89 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 49 8b 84 24 e0 f1 ff ff 48 8b 80 90 1b 00 00 <83> 38 03 0f 84 37 fe ff ff bb ea ff ff ff eb cc 49 8b 84 24 10 f3\nAll code\n========\n 0:\tf7 e8 \timul %eax\n 2:\td5 \t(bad)\n 3:\t93 \txchg %eax,%ebx\n 4:\t3e ea \tds (bad)\n 6:\t48 83 c4 28 \tadd $0x28,%rsp\n a:\t89 d8 \tmov %ebx,%eax\n c:\t5b \tpop %rbx\n d:\t41 5c \tpop %r12\n f:\t41 5d \tpop %r13\n 11:\t41 5e \tpop %r14\n 13:\t41 5f \tpop %r15\n 15:\t5d \tpop %rbp\n 16:\tc3 \tretq\n 17:\tcc \tint3\n 18:\tcc \tint3\n 19:\tcc \tint3\n 1a:\tcc \tint3\n 1b:\t49 8b 84 24 e0 f1 ff \tmov -0xe20(%r12),%rax\n 22:\tff\n 23:\t48 8b 80 90 1b 00 00 \tmov 0x1b90(%rax),%rax\n 2a:*\t83 38 03 \tcmpl $0x3,(%rax)\t\t<-- trapping instruction\n 2d:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe6a\n 33:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n 38:\teb cc \tjmp 0x6\n 3a:\t49 \trex.WB\n 3b:\t8b \t.byte 0x8b\n 3c:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 3f:\tf3 \trepz\n\nCode starting with the faulting instruction\n===========================================\n 0:\t83 38 03 \tcmpl $0x3,(%rax)\n 3:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe40\n 9:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n e:\teb cc \tjmp 0xffffffffffffffdc\n 10:\t49 \trex.WB\n 11:\t8b \t.byte 0x8b\n 12:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 15:\tf3 \trepz\n[ 9890.526285] RSP: 0018:ffffb8db09013d68 EFLAGS: 00010246\n[ 9890.526291] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff9308e0d656c8\n[ 9890.526295] RDX: 0000000000000000 RSI: ffffffffab99460b RDI: ffffffffab9a7685\n[ 9890.526300] RBP: ffffb8db09013db8 R08: 0000000000000000 R09: 0000000000000873\n[ 9890.526304] R10: ffff9308e0d64800 R11: 0000000000000002 R12: ffff9308e5ff6e70\n[ 9890.526308] R13: ffff930952500e20 R14: ffff9309192a8c00 R15: 0000000000000000\n[ 9890.526313] FS: 0000000000000000(0000) GS:ffff930b4e700000(0000) knlGS:0000000000000000\n[ 9890.526316] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9890.526318] CR2: 0000000000000000 CR3: 0000000391c58005 CR4: 00000000001706f0\n[ 9890.526321] Call Trace:\n[ 9890.526324] \n[ 9890.526327] ? show_regs (arch/x86/kernel/dumpstack.c:479)\n[ 9890.526335] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n[ 9890.526340] ? page_fault_oops (arch/x86/mm/fault.c:713)\n[ 9890.526347] ? search_module_extables (kernel/module/main.c:3256 (discriminator\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43911', 'https://git.kernel.org/linus/021d53a3d87eeb9dbba524ac515651242a2a7e3b (6.11-rc1)', 'https://git.kernel.org/stable/c/021d53a3d87eeb9dbba524ac515651242a2a7e3b', 'https://git.kernel.org/stable/c/a5594c1e03b0df3908b1e1202a1ba34422eed0f6', 'https://lore.kernel.org/linux-cve-announce/2024082631-CVE-2024-43911-96bb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43911', 'https://www.cve.org/CVERecord?id=CVE-2024-43911'], 'PublishedDate': '2024-08-26T11:15:05.227Z', 'LastModifiedDate': '2024-08-27T16:08:52.493Z'}, {'VulnerabilityID': 'CVE-2024-43912', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43912', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: nl80211: disallow setting special AP channel widths', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: disallow setting special AP channel widths\n\nSetting the AP channel width is meant for use with the normal\n20/40/... MHz channel width progression, and switching around\nin S1G or narrow channels isn't supported. Disallow that.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'V3Score': 4.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43912', 'https://git.kernel.org/linus/23daf1b4c91db9b26f8425cc7039cf96d22ccbfe (6.11-rc1)', 'https://git.kernel.org/stable/c/23daf1b4c91db9b26f8425cc7039cf96d22ccbfe', 'https://git.kernel.org/stable/c/3d42f2125f6c89e1e71c87b9f23412afddbba45e', 'https://git.kernel.org/stable/c/ac3bf6e47fd8da9bfe8027e1acfe0282a91584fc', 'https://git.kernel.org/stable/c/c6ea738e3feb407a3283197d9a25d0788f4f3cee', 'https://lore.kernel.org/linux-cve-announce/2024082632-CVE-2024-43912-801f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43912', 'https://www.cve.org/CVERecord?id=CVE-2024-43912'], 'PublishedDate': '2024-08-26T11:15:05.28Z', 'LastModifiedDate': '2024-09-05T18:19:17.067Z'}, {'VulnerabilityID': 'CVE-2024-43913', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43913', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: apple: fix device reference counting', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: apple: fix device reference counting\n\nDrivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.\nSplit the allocation side out to make the error handling boundary easier\nto navigate. The apple driver had been doing this wrong, leaking the\ncontroller device memory on a tagset failure.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43913', 'https://git.kernel.org/linus/b9ecbfa45516182cd062fecd286db7907ba84210 (6.11-rc1)', 'https://git.kernel.org/stable/c/b9ecbfa45516182cd062fecd286db7907ba84210', 'https://git.kernel.org/stable/c/d59c4d0eb6adc24c2201f153ccb7fd0a335b0d3d', 'https://lore.kernel.org/linux-cve-announce/2024082633-CVE-2024-43913-6ec7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43913', 'https://www.cve.org/CVERecord?id=CVE-2024-43913'], 'PublishedDate': '2024-08-26T11:15:05.33Z', 'LastModifiedDate': '2024-09-05T18:12:55.68Z'}, {'VulnerabilityID': 'CVE-2024-43914', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43914', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: md/raid5: avoid BUG_ON() while continue reshape after reassembling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid BUG_ON() while continue reshape after reassembling\n\nCurrently, mdadm support --revert-reshape to abort the reshape while\nreassembling, as the test 07revert-grow. However, following BUG_ON()\ncan be triggerred by the test:\n\nkernel BUG at drivers/md/raid5.c:6278!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nirq event stamp: 158985\nCPU: 6 PID: 891 Comm: md0_reshape Not tainted 6.9.0-03335-g7592a0b0049a #94\nRIP: 0010:reshape_request+0x3f1/0xe60\nCall Trace:\n \n raid5_sync_request+0x43d/0x550\n md_do_sync+0xb7a/0x2110\n md_thread+0x294/0x2b0\n kthread+0x147/0x1c0\n ret_from_fork+0x59/0x70\n ret_from_fork_asm+0x1a/0x30\n \n\nRoot cause is that --revert-reshape update the raid_disks from 5 to 4,\nwhile reshape position is still set, and after reassembling the array,\nreshape position will be read from super block, then during reshape the\nchecking of 'writepos' that is caculated by old reshape position will\nfail.\n\nFix this panic the easy way first, by converting the BUG_ON() to\nWARN_ON(), and stop the reshape if checkings fail.\n\nNoted that mdadm must fix --revert-shape as well, and probably md/raid\nshould enhance metadata validation as well, however this means\nreassemble will fail and there must be user tools to fix the wrong\nmetadata.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43914', 'https://git.kernel.org/linus/305a5170dc5cf3d395bb4c4e9239bca6d0b54b49 (6.11-rc1)', 'https://git.kernel.org/stable/c/2c92f8c1c456d556f15cbf51667b385026b2e6a0', 'https://git.kernel.org/stable/c/305a5170dc5cf3d395bb4c4e9239bca6d0b54b49', 'https://git.kernel.org/stable/c/3b33740c1750a39e046339ff9240e954f0156707', 'https://git.kernel.org/stable/c/4811d6e5d9f4090c3e0ff9890eb24077108046ab', 'https://git.kernel.org/stable/c/6b33c468d543f6a83de2d61f09fec74b27e19fd2', 'https://git.kernel.org/stable/c/775a9ba16c9ffe98fe54ebf14e55d5660f2bf600', 'https://git.kernel.org/stable/c/bf0ff69a42a3d2d46876d0514ecf13dffc516666', 'https://git.kernel.org/stable/c/c384dd4f1fb3b14a2fd199360701cc163ea88705', 'https://linux.oracle.com/cve/CVE-2024-43914.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082635-CVE-2024-43914-a664@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43914', 'https://www.cve.org/CVERecord?id=CVE-2024-43914'], 'PublishedDate': '2024-08-26T11:15:05.38Z', 'LastModifiedDate': '2024-09-05T18:03:49.997Z'}, {'VulnerabilityID': 'CVE-2024-44931', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44931', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gpio: prevent potential speculation leaks in gpio_device_get_desc()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: prevent potential speculation leaks in gpio_device_get_desc()\n\nUserspace may trigger a speculative read of an address outside the gpio\ndescriptor array.\nUsers can do that by calling gpio_ioctl() with an offset out of range.\nOffset is copied from user and then used as an array index to get\nthe gpio descriptor without sanitization in gpio_device_get_desc().\n\nThis change ensures that the offset is sanitized by using\narray_index_nospec() to mitigate any possibility of speculative\ninformation leaks.\n\nThis bug was discovered and resolved using Coverity Static Analysis\nSecurity Testing (SAST) by Synopsys, Inc.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44931', 'https://git.kernel.org/linus/d795848ecce24a75dfd46481aee066ae6fe39775 (6.11-rc1)', 'https://git.kernel.org/stable/c/1b955f786a4bcde8c0ccb2b7d519def2acb6f3cc', 'https://git.kernel.org/stable/c/672c19165fc96dfad531a5458e0b3cdab414aae4', 'https://git.kernel.org/stable/c/9d682e89c44bd5819b01f3fbb45a8e3681a4b6d0', 'https://git.kernel.org/stable/c/c65ab97efcd438cb4e9f299400f2ea55251f3a67', 'https://git.kernel.org/stable/c/d776c0486b03a5c4afca65b8ff44573592bf93bb', 'https://git.kernel.org/stable/c/d795848ecce24a75dfd46481aee066ae6fe39775', 'https://lore.kernel.org/linux-cve-announce/2024082636-CVE-2024-44931-8212@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44931', 'https://www.cve.org/CVERecord?id=CVE-2024-44931'], 'PublishedDate': '2024-08-26T11:15:05.447Z', 'LastModifiedDate': '2024-10-17T14:15:07.39Z'}, {'VulnerabilityID': 'CVE-2024-44932', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44932', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: idpf: fix UAFs when destroying the queues', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix UAFs when destroying the queues\n\nThe second tagged commit started sometimes (very rarely, but possible)\nthrowing WARNs from\nnet/core/page_pool.c:page_pool_disable_direct_recycling().\nTurned out idpf frees interrupt vectors with embedded NAPIs *before*\nfreeing the queues making page_pools' NAPI pointers lead to freed\nmemory before these pools are destroyed by libeth.\nIt's not clear whether there are other accesses to the freed vectors\nwhen destroying the queues, but anyway, we usually free queue/interrupt\nvectors only when the queues are destroyed and the NAPIs are guaranteed\nto not be referenced anywhere.\n\nInvert the allocation and freeing logic making queue/interrupt vectors\nbe allocated first and freed last. Vectors don't require queues to be\npresent, so this is safe. Additionally, this change allows to remove\nthat useless queue->q_vector pointer cleanup, as vectors are still\nvalid when freeing the queues (+ both are freed within one function,\nso it's not clear why nullify the pointers at all).", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44932', 'https://git.kernel.org/linus/290f1c033281c1a502a3cd1c53c3a549259c491f (6.11-rc3)', 'https://git.kernel.org/stable/c/290f1c033281c1a502a3cd1c53c3a549259c491f', 'https://git.kernel.org/stable/c/3cde714b0e77206ed1b5cf31f28c18ba9ae946fd', 'https://lore.kernel.org/linux-cve-announce/2024082638-CVE-2024-44932-2659@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44932', 'https://www.cve.org/CVERecord?id=CVE-2024-44932'], 'PublishedDate': '2024-08-26T11:15:05.5Z', 'LastModifiedDate': '2024-08-27T16:08:45.02Z'}, {'VulnerabilityID': 'CVE-2024-44934', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44934', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: bridge: mcast: wait for previous gc cycles when removing port', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: wait for previous gc cycles when removing port\n\nsyzbot hit a use-after-free[1] which is caused because the bridge doesn't\nmake sure that all previous garbage has been collected when removing a\nport. What happens is:\n CPU 1 CPU 2\n start gc cycle remove port\n acquire gc lock first\n wait for lock\n call br_multicasg_gc() directly\n acquire lock now but free port\n the port can be freed\n while grp timers still\n running\n\nMake sure all previous gc cycles have finished by using flush_work before\nfreeing the port.\n\n[1]\n BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699\n\n CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024\n Call Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n call_timer_fn+0x1a3/0x610 kernel/time/timer.c:1792\n expire_timers kernel/time/timer.c:1843 [inline]\n __run_timers+0x74b/0xaf0 kernel/time/timer.c:2417\n __run_timer_base kernel/time/timer.c:2428 [inline]\n __run_timer_base kernel/time/timer.c:2421 [inline]\n run_timer_base+0x111/0x190 kernel/time/timer.c:2437", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44934', 'https://git.kernel.org/linus/92c4ee25208d0f35dafc3213cdf355fbe449e078 (6.11-rc3)', 'https://git.kernel.org/stable/c/0d8b26e10e680c01522d7cc14abe04c3265a928f', 'https://git.kernel.org/stable/c/1e16828020c674b3be85f52685e8b80f9008f50f', 'https://git.kernel.org/stable/c/92c4ee25208d0f35dafc3213cdf355fbe449e078', 'https://git.kernel.org/stable/c/b2f794b168cf560682ff976b255aa6d29d14a658', 'https://git.kernel.org/stable/c/e3145ca904fa8dbfd1a5bf0187905bc117b0efce', 'https://lore.kernel.org/linux-cve-announce/2024082641-CVE-2024-44934-a7fe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44934', 'https://www.cve.org/CVERecord?id=CVE-2024-44934'], 'PublishedDate': '2024-08-26T11:15:05.593Z', 'LastModifiedDate': '2024-08-27T16:07:58.727Z'}, {'VulnerabilityID': 'CVE-2024-44935', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44935', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sctp: Fix null-ptr-deref in reuseport_add_sock().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Fix null-ptr-deref in reuseport_add_sock().\n\nsyzbot reported a null-ptr-deref while accessing sk2->sk_reuseport_cb in\nreuseport_add_sock(). [0]\n\nThe repro first creates a listener with SO_REUSEPORT. Then, it creates\nanother listener on the same port and concurrently closes the first\nlistener.\n\nThe second listen() calls reuseport_add_sock() with the first listener as\nsk2, where sk2->sk_reuseport_cb is not expected to be cleared concurrently,\nbut the close() does clear it by reuseport_detach_sock().\n\nThe problem is SCTP does not properly synchronise reuseport_alloc(),\nreuseport_add_sock(), and reuseport_detach_sock().\n\nThe caller of reuseport_alloc() and reuseport_{add,detach}_sock() must\nprovide synchronisation for sockets that are classified into the same\nreuseport group.\n\nOtherwise, such sockets form multiple identical reuseport groups, and\nall groups except one would be silently dead.\n\n 1. Two sockets call listen() concurrently\n 2. No socket in the same group found in sctp_ep_hashtable[]\n 3. Two sockets call reuseport_alloc() and form two reuseport groups\n 4. Only one group hit first in __sctp_rcv_lookup_endpoint() receives\n incoming packets\n\nAlso, the reported null-ptr-deref could occur.\n\nTCP/UDP guarantees that would not happen by holding the hash bucket lock.\n\nLet's apply the locking strategy to __sctp_hash_endpoint() and\n__sctp_unhash_endpoint().\n\n[0]:\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nCPU: 1 UID: 0 PID: 10230 Comm: syz-executor119 Not tainted 6.10.0-syzkaller-12585-g301927d2d2eb #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024\nRIP: 0010:reuseport_add_sock+0x27e/0x5e0 net/core/sock_reuseport.c:350\nCode: 00 0f b7 5d 00 bf 01 00 00 00 89 de e8 1b a4 ff f7 83 fb 01 0f 85 a3 01 00 00 e8 6d a0 ff f7 49 8d 7e 12 48 89 f8 48 c1 e8 03 <42> 0f b6 04 28 84 c0 0f 85 4b 02 00 00 41 0f b7 5e 12 49 8d 7e 14\nRSP: 0018:ffffc9000b947c98 EFLAGS: 00010202\nRAX: 0000000000000002 RBX: ffff8880252ddf98 RCX: ffff888079478000\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000012\nRBP: 0000000000000001 R08: ffffffff8993e18d R09: 1ffffffff1fef385\nR10: dffffc0000000000 R11: fffffbfff1fef386 R12: ffff8880252ddac0\nR13: dffffc0000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f24e45b96c0(0000) GS:ffff8880b9300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffcced5f7b8 CR3: 00000000241be000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __sctp_hash_endpoint net/sctp/input.c:762 [inline]\n sctp_hash_endpoint+0x52a/0x600 net/sctp/input.c:790\n sctp_listen_start net/sctp/socket.c:8570 [inline]\n sctp_inet_listen+0x767/0xa20 net/sctp/socket.c:8625\n __sys_listen_socket net/socket.c:1883 [inline]\n __sys_listen+0x1b7/0x230 net/socket.c:1894\n __do_sys_listen net/socket.c:1902 [inline]\n __se_sys_listen net/socket.c:1900 [inline]\n __x64_sys_listen+0x5a/0x70 net/socket.c:1900\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f24e46039b9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 91 1a 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f24e45b9228 EFLAGS: 00000246 ORIG_RAX: 0000000000000032\nRAX: ffffffffffffffda RBX: 00007f24e468e428 RCX: 00007f24e46039b9\nRDX: 00007f24e46039b9 RSI: 0000000000000003 RDI: 0000000000000004\nRBP: 00007f24e468e420 R08: 00007f24e45b96c0 R09: 00007f24e45b96c0\nR10: 00007f24e45b96c0 R11: 0000000000000246 R12: 00007f24e468e42c\nR13:\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44935', 'https://git.kernel.org/linus/9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18 (6.11-rc3)', 'https://git.kernel.org/stable/c/05e4a0fa248240efd99a539853e844f0f0a9e6a5', 'https://git.kernel.org/stable/c/1407be30fc17eff918a98e0a990c0e988f11dc84', 'https://git.kernel.org/stable/c/52319d9d2f522ed939af31af70f8c3a0f0f67e6c', 'https://git.kernel.org/stable/c/54b303d8f9702b8ab618c5032fae886b16356928', 'https://git.kernel.org/stable/c/9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18', 'https://git.kernel.org/stable/c/c9b3fc4f157867e858734e31022ebee8a24f0de7', 'https://git.kernel.org/stable/c/e809a84c802377ef61525a298a1ec1728759b913', 'https://linux.oracle.com/cve/CVE-2024-44935.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082642-CVE-2024-44935-3452@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44935', 'https://www.cve.org/CVERecord?id=CVE-2024-44935'], 'PublishedDate': '2024-08-26T11:15:05.643Z', 'LastModifiedDate': '2024-08-27T16:09:01.633Z'}, {'VulnerabilityID': 'CVE-2024-44937', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44937', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: platform/x86: intel-vbtn: Protect ACPI notify handler against recursion', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: intel-vbtn: Protect ACPI notify handler against recursion\n\nSince commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on\nall CPUs") ACPI notify handlers like the intel-vbtn notify_handler() may\nrun on multiple CPU cores racing with themselves.\n\nThis race gets hit on Dell Venue 7140 tablets when undocking from\nthe keyboard, causing the handler to try and register priv->switches_dev\ntwice, as can be seen from the dev_info() message getting logged twice:\n\n[ 83.861800] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n[ 83.861858] input: Intel Virtual Switches as /devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\n[ 83.861865] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n\nAfter which things go seriously wrong:\n[ 83.861872] sysfs: cannot create duplicate filename \'/devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\'\n...\n[ 83.861967] kobject: kobject_add_internal failed for input17 with -EEXIST, don\'t try to register things with the same name in the same directory.\n[ 83.877338] BUG: kernel NULL pointer dereference, address: 0000000000000018\n...\n\nProtect intel-vbtn notify_handler() from racing with itself with a mutex\nto fix this.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44937', 'https://git.kernel.org/linus/e075c3b13a0a142dcd3151b25d29a24f31b7b640 (6.11-rc3)', 'https://git.kernel.org/stable/c/5c9618a3b6ea94cf7bdff7702aca8bf2d777d97b', 'https://git.kernel.org/stable/c/e075c3b13a0a142dcd3151b25d29a24f31b7b640', 'https://lore.kernel.org/linux-cve-announce/2024082645-CVE-2024-44937-5c1d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44937', 'https://www.cve.org/CVERecord?id=CVE-2024-44937'], 'PublishedDate': '2024-08-26T11:15:05.753Z', 'LastModifiedDate': '2024-08-27T16:10:11.423Z'}, {'VulnerabilityID': 'CVE-2024-44938', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44938', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: jfs: Fix shift-out-of-bounds in dbDiscardAG', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix shift-out-of-bounds in dbDiscardAG\n\nWhen searching for the next smaller log2 block, BLKSTOL2() returned 0,\ncausing shift exponent -1 to be negative.\n\nThis patch fixes the issue by exiting the loop directly when negative\nshift is found.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44938', 'https://git.kernel.org/linus/7063b80268e2593e58bee8a8d709c2f3ff93e2f2 (6.11-rc1)', 'https://git.kernel.org/stable/c/234e6ea0855cdb5673d54ecaf7dc5c78f3e84630', 'https://git.kernel.org/stable/c/7063b80268e2593e58bee8a8d709c2f3ff93e2f2', 'https://git.kernel.org/stable/c/bd04a149e3a29e7f71b7956ed41dba34e42d539e', 'https://git.kernel.org/stable/c/f650148b43949ca9e37e820804bb6026fff404f3', 'https://lore.kernel.org/linux-cve-announce/2024082616-CVE-2024-44938-fc08@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44938', 'https://www.cve.org/CVERecord?id=CVE-2024-44938'], 'PublishedDate': '2024-08-26T12:15:05.96Z', 'LastModifiedDate': '2024-09-12T14:05:44.31Z'}, {'VulnerabilityID': 'CVE-2024-44939', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44939', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: jfs: fix null ptr deref in dtInsertEntry', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix null ptr deref in dtInsertEntry\n\n[syzbot reported]\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nRIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713\n...\n[Analyze]\nIn dtInsertEntry(), when the pointer h has the same value as p, after writing\nname in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the\npreviously true judgment "p->header.flag & BT-LEAF" to change to no after writing\nthe name operation, this leads to entering an incorrect branch and accessing the\nuninitialized object ih when judging this condition for the second time.\n\n[Fix]\nAfter got the page, check freelist first, if freelist == 0 then exit dtInsert()\nand return -EINVAL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44939', 'https://git.kernel.org/linus/ce6dede912f064a855acf6f04a04cbb2c25b8c8c (6.11-rc1)', 'https://git.kernel.org/stable/c/53023ab11836ac56fd75f7a71ec1356e50920fa9', 'https://git.kernel.org/stable/c/6ea10dbb1e6c58384136e9adfd75f81951e423f6', 'https://git.kernel.org/stable/c/9c2ac38530d1a3ee558834dfa16c85a40fd0e702', 'https://git.kernel.org/stable/c/ce6dede912f064a855acf6f04a04cbb2c25b8c8c', 'https://lore.kernel.org/linux-cve-announce/2024082619-CVE-2024-44939-cf96@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44939', 'https://www.cve.org/CVERecord?id=CVE-2024-44939'], 'PublishedDate': '2024-08-26T12:15:06.007Z', 'LastModifiedDate': '2024-09-12T20:58:03.783Z'}, {'VulnerabilityID': 'CVE-2024-44940', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44940', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fou: remove warn in gue_gro_receive on unsupported protocol', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfou: remove warn in gue_gro_receive on unsupported protocol\n\nDrop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is\nnot known or does not have a GRO handler.\n\nSuch a packet is easily constructed. Syzbot generates them and sets\noff this warning.\n\nRemove the warning as it is expected and not actionable.\n\nThe warning was previously reduced from WARN_ON to WARN_ON_ONCE in\ncommit 270136613bf7 ("fou: Do WARN_ON_ONCE in gue_gro_receive for bad\nproto callbacks").', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44940', 'https://git.kernel.org/linus/dd89a81d850fa9a65f67b4527c0e420d15bf836c (6.11-rc1)', 'https://git.kernel.org/stable/c/3db4395332e7050ef9ddeb3052e6b5019f2a2a59', 'https://git.kernel.org/stable/c/440ab7f97261bc28501636a13998e1b1946d2e79', 'https://git.kernel.org/stable/c/5a2e37bc648a2503bf6d687aed27b9f4455d82eb', 'https://git.kernel.org/stable/c/dd89a81d850fa9a65f67b4527c0e420d15bf836c', 'https://lore.kernel.org/linux-cve-announce/2024082619-CVE-2024-44940-249f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44940', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-44940'], 'PublishedDate': '2024-08-26T12:15:06.053Z', 'LastModifiedDate': '2024-09-12T14:10:00.857Z'}, {'VulnerabilityID': 'CVE-2024-44941', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44941', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to cover read extent cache access with lock', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to cover read extent cache access with lock\n\nsyzbot reports a f2fs bug as below:\n\nBUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\nRead of size 4 at addr ffff8880739ab220 by task syz-executor200/5097\n\nCPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\n do_read_inode fs/f2fs/inode.c:509 [inline]\n f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560\n f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237\n generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413\n exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444\n exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584\n do_handle_to_path fs/fhandle.c:155 [inline]\n handle_to_path fs/fhandle.c:210 [inline]\n do_handle_open+0x495/0x650 fs/fhandle.c:226\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWe missed to cover sanity_check_extent_cache() w/ extent cache lock,\nso, below race case may happen, result in use after free issue.\n\n- f2fs_iget\n - do_read_inode\n - f2fs_init_read_extent_tree\n : add largest extent entry in to cache\n\t\t\t\t\t- shrink\n\t\t\t\t\t - f2fs_shrink_read_extent_tree\n\t\t\t\t\t - __shrink_extent_tree\n\t\t\t\t\t - __detach_extent_node\n\t\t\t\t\t : drop largest extent entry\n - sanity_check_extent_cache\n : access et->largest w/o lock\n\nlet's refactor sanity_check_extent_cache() to avoid extent cache access\nand call it before f2fs_init_read_extent_tree() to fix this issue.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44941', 'https://git.kernel.org/linus/d7409b05a64f212735f0d33f5f1602051a886eab (6.11-rc1)', 'https://git.kernel.org/stable/c/263df78166d3a9609b97d28c34029bd01874cbb8', 'https://git.kernel.org/stable/c/323ef20b5558b9d9fd10c1224327af6f11a8177d', 'https://git.kernel.org/stable/c/d7409b05a64f212735f0d33f5f1602051a886eab', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-44941-143e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44941', 'https://www.cve.org/CVERecord?id=CVE-2024-44941'], 'PublishedDate': '2024-08-26T12:15:06.107Z', 'LastModifiedDate': '2024-09-12T20:57:26.143Z'}, {'VulnerabilityID': 'CVE-2024-44942', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44942', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/inline.c:258!\nCPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0\nRIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258\nCall Trace:\n f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834\n f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315\n do_writepages+0x35b/0x870 mm/page-writeback.c:2612\n __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650\n writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941\n wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117\n wb_do_writeback fs/fs-writeback.c:2264 [inline]\n wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335\n worker_thread+0x86d/0xd70 kernel/workqueue.c:3416\n kthread+0x2f2/0x390 kernel/kthread.c:388\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nThe root cause is: inline_data inode can be fuzzed, so that there may\nbe valid blkaddr in its direct node, once f2fs triggers background GC\nto migrate the block, it will hit f2fs_bug_on() during dirty page\nwriteback.\n\nLet's add sanity check on F2FS_INLINE_DATA flag in inode during GC,\nso that, it can forbid migrating inline_data inode's data block for\nfixing.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44942', 'https://git.kernel.org/linus/fc01008c92f40015aeeced94750855a7111b6929 (6.11-rc1)', 'https://git.kernel.org/stable/c/26c07775fb5dc74351d1c3a2bc3cdf609b03e49f', 'https://git.kernel.org/stable/c/ae00e6536a2dd54b64b39e9a39548870cf835745', 'https://git.kernel.org/stable/c/fc01008c92f40015aeeced94750855a7111b6929', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-44942-651a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44942', 'https://www.cve.org/CVERecord?id=CVE-2024-44942'], 'PublishedDate': '2024-08-26T12:15:06.157Z', 'LastModifiedDate': '2024-08-27T16:09:10.01Z'}, {'VulnerabilityID': 'CVE-2024-44943', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'In the Linux kernel, the following vulnerability has been resolved: m ...', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: gup: stop abusing try_grab_folio\n\nA kernel warning was reported when pinning folio in CMA memory when\nlaunching SEV virtual machine. The splat looks like:\n\n[ 464.325306] WARNING: CPU: 13 PID: 6734 at mm/gup.c:1313 __get_user_pages+0x423/0x520\n[ 464.325464] CPU: 13 PID: 6734 Comm: qemu-kvm Kdump: loaded Not tainted 6.6.33+ #6\n[ 464.325477] RIP: 0010:__get_user_pages+0x423/0x520\n[ 464.325515] Call Trace:\n[ 464.325520] \n[ 464.325523] ? __get_user_pages+0x423/0x520\n[ 464.325528] ? __warn+0x81/0x130\n[ 464.325536] ? __get_user_pages+0x423/0x520\n[ 464.325541] ? report_bug+0x171/0x1a0\n[ 464.325549] ? handle_bug+0x3c/0x70\n[ 464.325554] ? exc_invalid_op+0x17/0x70\n[ 464.325558] ? asm_exc_invalid_op+0x1a/0x20\n[ 464.325567] ? __get_user_pages+0x423/0x520\n[ 464.325575] __gup_longterm_locked+0x212/0x7a0\n[ 464.325583] internal_get_user_pages_fast+0xfb/0x190\n[ 464.325590] pin_user_pages_fast+0x47/0x60\n[ 464.325598] sev_pin_memory+0xca/0x170 [kvm_amd]\n[ 464.325616] sev_mem_enc_register_region+0x81/0x130 [kvm_amd]\n\nPer the analysis done by yangge, when starting the SEV virtual machine, it\nwill call pin_user_pages_fast(..., FOLL_LONGTERM, ...) to pin the memory. \nBut the page is in CMA area, so fast GUP will fail then fallback to the\nslow path due to the longterm pinnalbe check in try_grab_folio().\n\nThe slow path will try to pin the pages then migrate them out of CMA area.\nBut the slow path also uses try_grab_folio() to pin the page, it will\nalso fail due to the same check then the above warning is triggered.\n\nIn addition, the try_grab_folio() is supposed to be used in fast path and\nit elevates folio refcount by using add ref unless zero. We are guaranteed\nto have at least one stable reference in slow path, so the simple atomic add\ncould be used. The performance difference should be trivial, but the\nmisuse may be confusing and misleading.\n\nRedefined try_grab_folio() to try_grab_folio_fast(), and try_grab_page()\nto try_grab_folio(), and use them in the proper paths. This solves both\nthe abuse and the kernel warning.\n\nThe proper naming makes their usecase more clear and should prevent from\nabusing in the future.\n\npeterx said:\n\n: The user will see the pin fails, for gpu-slow it further triggers the WARN\n: right below that failure (as in the original report):\n: \n: folio = try_grab_folio(page, page_increm - 1,\n: foll_flags);\n: if (WARN_ON_ONCE(!folio)) { <------------------------ here\n: /*\n: * Release the 1st page ref if the\n: * folio is problematic, fail hard.\n: */\n: gup_put_folio(page_folio(page), 1,\n: foll_flags);\n: ret = -EFAULT;\n: goto out;\n: }\n\n[1] https://lore.kernel.org/linux-mm/1719478388-31917-1-git-send-email-yangge1116@126.com/\n\n[shy828301@gmail.com: fix implicit declaration of function try_grab_folio_fast]\n Link: https://lkml.kernel.org/r/CAHbLzkowMSso-4Nufc9hcMehQsK9PNz3OSu-+eniU-2Mm-xjhA@mail.gmail.com', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44943', 'https://git.kernel.org/linus/f442fa6141379a20b48ae3efabee827a3d260787 (6.10)', 'https://git.kernel.org/stable/c/26273f5f4cf68b29414e403837093408a9c98e1f', 'https://git.kernel.org/stable/c/f442fa6141379a20b48ae3efabee827a3d260787', 'https://lore.kernel.org/linux-cve-announce/2024082853-CVE-2024-44943-234f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44943', 'https://www.cve.org/CVERecord?id=CVE-2024-44943'], 'PublishedDate': '2024-08-28T08:15:06.963Z', 'LastModifiedDate': '2024-09-10T18:12:43.38Z'}, {'VulnerabilityID': 'CVE-2024-44944', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44944', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: ctnetlink: use helper function to calculate expect ID', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: use helper function to calculate expect ID\n\nDelete expectation path is missing a call to the nf_expect_get_id()\nhelper function to calculate the expectation ID, otherwise LSB of the\nexpectation object address is leaked to userspace.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44944', 'https://git.kernel.org/linus/782161895eb4ac45cf7cfa8db375bd4766cb8299 (6.11-rc1)', 'https://git.kernel.org/stable/c/24f407042cf90b0872de667460230d8d50c06c39', 'https://git.kernel.org/stable/c/27662b46f2adaa52c1665a82af4b21c42c4337fd', 'https://git.kernel.org/stable/c/5e2c24f7b0911b15c29aefce760bcf770542fb61', 'https://git.kernel.org/stable/c/64c0b8e64be8368617ef08dfc59a3160563a1435', 'https://git.kernel.org/stable/c/66e7650dbbb8e236e781c670b167edc81e771450', 'https://git.kernel.org/stable/c/74de442b8e12a207c07953ee068009a7701aff8f', 'https://git.kernel.org/stable/c/782161895eb4ac45cf7cfa8db375bd4766cb8299', 'https://git.kernel.org/stable/c/eb4ca1a97e08ff5b920664ba292e576257e2d184', 'https://linux.oracle.com/cve/CVE-2024-44944.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024083044-CVE-2024-44944-56c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44944', 'https://www.cve.org/CVERecord?id=CVE-2024-44944', 'https://www.zerodayinitiative.com/advisories/ZDI-24-1182/'], 'PublishedDate': '2024-08-30T08:15:04.58Z', 'LastModifiedDate': '2024-09-10T08:15:03.23Z'}, {'VulnerabilityID': 'CVE-2024-44946', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44946', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kcm: Serialise kcm_sendmsg() for the same socket.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: Serialise kcm_sendmsg() for the same socket.\n\nsyzkaller reported UAF in kcm_release(). [0]\n\nThe scenario is\n\n 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb.\n\n 2. Thread A resumes building skb from kcm->seq_skb but is blocked\n by sk_stream_wait_memory()\n\n 3. Thread B calls sendmsg() concurrently, finishes building kcm->seq_skb\n and puts the skb to the write queue\n\n 4. Thread A faces an error and finally frees skb that is already in the\n write queue\n\n 5. kcm_release() does double-free the skb in the write queue\n\nWhen a thread is building a MSG_MORE skb, another thread must not touch it.\n\nLet's add a per-sk mutex and serialise kcm_sendmsg().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __skb_unlink include/linux/skbuff.h:2366 [inline]\nBUG: KASAN: slab-use-after-free in __skb_dequeue include/linux/skbuff.h:2385 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge include/linux/skbuff.h:3181 [inline]\nBUG: KASAN: slab-use-after-free in kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\nRead of size 8 at addr ffff0000ced0fc80 by task syz-executor329/6167\n\nCPU: 1 PID: 6167 Comm: syz-executor329 Tainted: G B 6.8.0-rc5-syzkaller-g9abbc24128bc #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nCall trace:\n dump_backtrace+0x1b8/0x1e4 arch/arm64/kernel/stacktrace.c:291\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:298\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd0/0x124 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x178/0x518 mm/kasan/report.c:488\n kasan_report+0xd8/0x138 mm/kasan/report.c:601\n __asan_report_load8_noabort+0x20/0x2c mm/kasan/report_generic.c:381\n __skb_unlink include/linux/skbuff.h:2366 [inline]\n __skb_dequeue include/linux/skbuff.h:2385 [inline]\n __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\n __skb_queue_purge include/linux/skbuff.h:3181 [inline]\n kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\n __sock_release net/socket.c:659 [inline]\n sock_close+0xa4/0x1e8 net/socket.c:1421\n __fput+0x30c/0x738 fs/file_table.c:376\n ____fput+0x20/0x30 fs/file_table.c:404\n task_work_run+0x230/0x2e0 kernel/task_work.c:180\n exit_task_work include/linux/task_work.h:38 [inline]\n do_exit+0x618/0x1f64 kernel/exit.c:871\n do_group_exit+0x194/0x22c kernel/exit.c:1020\n get_signal+0x1500/0x15ec kernel/signal.c:2893\n do_signal+0x23c/0x3b44 arch/arm64/kernel/signal.c:1249\n do_notify_resume+0x74/0x1f4 arch/arm64/kernel/entry-common.c:148\n exit_to_user_mode_prepare arch/arm64/kernel/entry-common.c:169 [inline]\n exit_to_user_mode arch/arm64/kernel/entry-common.c:178 [inline]\n el0_svc+0xac/0x168 arch/arm64/kernel/entry-common.c:713\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\n\nAllocated by task 6166:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x70/0x84 mm/kasan/generic.c:626\n unpoison_slab_object mm/kasan/common.c:314 [inline]\n __kasan_slab_alloc+0x74/0x8c mm/kasan/common.c:340\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3813 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_node+0x204/0x4c0 mm/slub.c:3903\n __alloc_skb+0x19c/0x3d8 net/core/skbuff.c:641\n alloc_skb include/linux/skbuff.h:1296 [inline]\n kcm_sendmsg+0x1d3c/0x2124 net/kcm/kcmsock.c:783\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n sock_sendmsg+0x220/0x2c0 net/socket.c:768\n splice_to_socket+0x7cc/0xd58 fs/splice.c:889\n do_splice_from fs/splice.c:941 [inline]\n direct_splice_actor+0xec/0x1d8 fs/splice.c:1164\n splice_direct_to_actor+0x438/0xa0c fs/splice.c:1108\n do_splice_direct_actor \n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44946', 'https://git.kernel.org/linus/807067bf014d4a3ae2cc55bd3de16f22a01eb580 (6.11-rc5)', 'https://git.kernel.org/stable/c/00425508f30baa5ab6449a1f478480ca7cffa6da', 'https://git.kernel.org/stable/c/6633b17840bf828921254d788ccd15602843fe9b', 'https://git.kernel.org/stable/c/72da240aafb142630cf16adc803ccdacb3780849', 'https://git.kernel.org/stable/c/807067bf014d4a3ae2cc55bd3de16f22a01eb580', 'https://git.kernel.org/stable/c/8c9cdbf600143bd6835c8b8351e5ac956da79aec', 'https://git.kernel.org/stable/c/9c8d544ed619f704e2b70e63e08ab75630c2ea23', 'https://git.kernel.org/stable/c/eb06c8d3022ce6738711191c89f9b3e9cfb91914', 'https://git.kernel.org/stable/c/fa6c23fe6dcac8c8bd63920ee8681292a2bd544e', 'https://lore.kernel.org/linux-cve-announce/2024083150-CVE-2024-44946-9cf1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44946', 'https://www.cve.org/CVERecord?id=CVE-2024-44946'], 'PublishedDate': '2024-08-31T14:15:04.32Z', 'LastModifiedDate': '2024-09-04T12:15:05.15Z'}, {'VulnerabilityID': 'CVE-2024-44947', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44947', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fuse: Initialize beyond-EOF page contents before setting uptodate', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: Initialize beyond-EOF page contents before setting uptodate\n\nfuse_notify_store(), unlike fuse_do_readpage(), does not enable page\nzeroing (because it can be used to change partial page contents).\n\nSo fuse_notify_store() must be more careful to fully initialize page\ncontents (including parts of the page that are beyond end-of-file)\nbefore marking the page uptodate.\n\nThe current code can leave beyond-EOF page contents uninitialized, which\nmakes these uninitialized page contents visible to userspace via mmap().\n\nThis is an information leak, but only affects systems which do not\nenable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the\ncorresponding kernel command line parameter).', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44947', 'https://git.kernel.org/stable/c/18a067240817bee8a9360539af5d79a4bf5398a5', 'https://git.kernel.org/stable/c/33168db352c7b56ae18aa55c2cae1a1c5905d30e', 'https://git.kernel.org/stable/c/3c0da3d163eb32f1f91891efaade027fa9b245b9', 'https://git.kernel.org/stable/c/4690e2171f651e2b415e3941ce17f2f7b813aff6', 'https://git.kernel.org/stable/c/49934861514d36d0995be8e81bb3312a499d8d9a', 'https://git.kernel.org/stable/c/831433527773e665bdb635ab5783d0b95d1246f4', 'https://git.kernel.org/stable/c/8c78303eafbf85a728dd84d1750e89240c677dd9', 'https://git.kernel.org/stable/c/ac42e0f0eb66af966015ee33fd355bc6f5d80cd6', 'https://lore.kernel.org/linux-cve-announce/2024090219-CVE-2024-44947-f49c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44947', 'https://www.cve.org/CVERecord?id=CVE-2024-44947'], 'PublishedDate': '2024-09-02T18:15:36.577Z', 'LastModifiedDate': '2024-09-16T17:52:37.563Z'}, {'VulnerabilityID': 'CVE-2024-44948', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44948', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/mtrr: Check if fixed MTRRs exist before saving them', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mtrr: Check if fixed MTRRs exist before saving them\n\nMTRRs have an obsolete fixed variant for fine grained caching control\nof the 640K-1MB region that uses separate MSRs. This fixed variant has\na separate capability bit in the MTRR capability MSR.\n\nSo far all x86 CPUs which support MTRR have this separate bit set, so it\nwent unnoticed that mtrr_save_state() does not check the capability bit\nbefore accessing the fixed MTRR MSRs.\n\nThough on a CPU that does not support the fixed MTRR capability this\nresults in a #GP. The #GP itself is harmless because the RDMSR fault is\nhandled gracefully, but results in a WARN_ON().\n\nAdd the missing capability check to prevent this.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44948', 'https://git.kernel.org/linus/919f18f961c03d6694aa726c514184f2311a4614 (6.11-rc3)', 'https://git.kernel.org/stable/c/06c1de44d378ec5439db17bf476507d68589bfe9', 'https://git.kernel.org/stable/c/34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e', 'https://git.kernel.org/stable/c/388f1c954019f253a8383f7eb733f38d541e10b6', 'https://git.kernel.org/stable/c/450b6b22acdaac67a18eaf5ed498421ffcf10051', 'https://git.kernel.org/stable/c/8a90d3fc7c24608548d3a750671f9dac21d1a462', 'https://git.kernel.org/stable/c/8aa79dfb216b865e96ff890bc4ea71650f9bc8d7', 'https://git.kernel.org/stable/c/919f18f961c03d6694aa726c514184f2311a4614', 'https://git.kernel.org/stable/c/ca7d00c5656d1791e28369919e3e10febe9c3b16', 'https://linux.oracle.com/cve/CVE-2024-44948.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090407-CVE-2024-44948-5554@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44948', 'https://www.cve.org/CVERecord?id=CVE-2024-44948'], 'PublishedDate': '2024-09-04T19:15:29.95Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-44949', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44949', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: parisc: fix a possible DMA corruption', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: fix a possible DMA corruption\n\nARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be\npossible that two unrelated 16-byte allocations share a cache line. If\none of these allocations is written using DMA and the other is written\nusing cached write, the value that was written with DMA may be\ncorrupted.\n\nThis commit changes ARCH_DMA_MINALIGN to be 128 on PA20 and 32 on PA1.1 -\nthat's the largest possible cache line size.\n\nAs different parisc microarchitectures have different cache line size, we\ndefine arch_slab_minalign(), cache_line_size() and\ndma_get_cache_alignment() so that the kernel may tune slab cache\nparameters dynamically, based on the detected cache line size.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44949', 'https://git.kernel.org/linus/7ae04ba36b381bffe2471eff3a93edced843240f (6.11-rc2)', 'https://git.kernel.org/stable/c/533de2f470baac40d3bf622fe631f15231a03c9f', 'https://git.kernel.org/stable/c/642a0b7453daff0295310774016fcb56d1f5bc7f', 'https://git.kernel.org/stable/c/7ae04ba36b381bffe2471eff3a93edced843240f', 'https://lore.kernel.org/linux-cve-announce/2024090410-CVE-2024-44949-8f05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44949', 'https://www.cve.org/CVERecord?id=CVE-2024-44949'], 'PublishedDate': '2024-09-04T19:15:30.04Z', 'LastModifiedDate': '2024-10-09T13:53:32.513Z'}, {'VulnerabilityID': 'CVE-2024-44950', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44950', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: sc16is7xx: fix invalid FIFO access with special register set', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix invalid FIFO access with special register set\n\nWhen enabling access to the special register set, Receiver time-out and\nRHR interrupts can happen. In this case, the IRQ handler will try to read\nfrom the FIFO thru the RHR register at address 0x00, but address 0x00 is\nmapped to DLL register, resulting in erroneous FIFO reading.\n\nCall graph example:\n sc16is7xx_startup(): entry\n sc16is7xx_ms_proc(): entry\n sc16is7xx_set_termios(): entry\n sc16is7xx_set_baud(): DLH/DLL = $009C --> access special register set\n sc16is7xx_port_irq() entry --> IIR is 0x0C\n sc16is7xx_handle_rx() entry\n sc16is7xx_fifo_read(): --> unable to access FIFO (RHR) because it is\n mapped to DLL (LCR=LCR_CONF_MODE_A)\n sc16is7xx_set_baud(): exit --> Restore access to general register set\n\nFix the problem by claiming the efr_lock mutex when accessing the Special\nregister set.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 5.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44950', 'https://git.kernel.org/linus/7d3b793faaab1305994ce568b59d61927235f57b (6.11-rc3)', 'https://git.kernel.org/stable/c/6a6730812220a9a5ce4003eb347da1ee5abd06b0', 'https://git.kernel.org/stable/c/7d3b793faaab1305994ce568b59d61927235f57b', 'https://lore.kernel.org/linux-cve-announce/2024090410-CVE-2024-44950-67fb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44950', 'https://www.cve.org/CVERecord?id=CVE-2024-44950'], 'PublishedDate': '2024-09-04T19:15:30.1Z', 'LastModifiedDate': '2024-10-09T14:21:16.773Z'}, {'VulnerabilityID': 'CVE-2024-44951', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44951', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: sc16is7xx: fix TX fifo corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix TX fifo corruption\n\nSometimes, when a packet is received on channel A at almost the same time\nas a packet is about to be transmitted on channel B, we observe with a\nlogic analyzer that the received packet on channel A is transmitted on\nchannel B. In other words, the Tx buffer data on channel B is corrupted\nwith data from channel A.\n\nThe problem appeared since commit 4409df5866b7 ("serial: sc16is7xx: change\nEFR lock to operate on each channels"), which changed the EFR locking to\noperate on each channel instead of chip-wise.\n\nThis commit has introduced a regression, because the EFR lock is used not\nonly to protect the EFR registers access, but also, in a very obscure and\nundocumented way, to protect access to the data buffer, which is shared by\nthe Tx and Rx handlers, but also by each channel of the IC.\n\nFix this regression first by switching to kfifo_out_linear_ptr() in\nsc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer.\n\nSecondly, replace the chip-wise Rx buffer with a separate Rx buffer for\neach channel.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44951', 'https://git.kernel.org/linus/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4 (6.11-rc3)', 'https://git.kernel.org/stable/c/09cfe05e9907f3276887a20e267cc40e202f4fdd', 'https://git.kernel.org/stable/c/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44951-9121@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44951', 'https://www.cve.org/CVERecord?id=CVE-2024-44951'], 'PublishedDate': '2024-09-04T19:15:30.153Z', 'LastModifiedDate': '2024-10-09T14:27:43.973Z'}, {'VulnerabilityID': 'CVE-2024-44952', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44952', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: driver core: Fix uevent_show() vs driver detach race', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: Fix uevent_show() vs driver detach race\n\nuevent_show() wants to de-reference dev->driver->name. There is no clean\nway for a device attribute to de-reference dev->driver unless that\nattribute is defined via (struct device_driver).dev_groups. Instead, the\nanti-pattern of taking the device_lock() in the attribute handler risks\ndeadlocks with code paths that remove device attributes while holding\nthe lock.\n\nThis deadlock is typically invisible to lockdep given the device_lock()\nis marked lockdep_set_novalidate_class(), but some subsystems allocate a\nlocal lockdep key for @dev->mutex to reveal reports of the form:\n\n ======================================================\n WARNING: possible circular locking dependency detected\n 6.10.0-rc7+ #275 Tainted: G OE N\n ------------------------------------------------------\n modprobe/2374 is trying to acquire lock:\n ffff8c2270070de0 (kn->active#6){++++}-{0:0}, at: __kernfs_remove+0xde/0x220\n\n but task is already holding lock:\n ffff8c22016e88f8 (&cxl_root_key){+.+.}-{3:3}, at: device_release_driver_internal+0x39/0x210\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #1 (&cxl_root_key){+.+.}-{3:3}:\n __mutex_lock+0x99/0xc30\n uevent_show+0xac/0x130\n dev_attr_show+0x18/0x40\n sysfs_kf_seq_show+0xac/0xf0\n seq_read_iter+0x110/0x450\n vfs_read+0x25b/0x340\n ksys_read+0x67/0xf0\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n -> #0 (kn->active#6){++++}-{0:0}:\n __lock_acquire+0x121a/0x1fa0\n lock_acquire+0xd6/0x2e0\n kernfs_drain+0x1e9/0x200\n __kernfs_remove+0xde/0x220\n kernfs_remove_by_name_ns+0x5e/0xa0\n device_del+0x168/0x410\n device_unregister+0x13/0x60\n devres_release_all+0xb8/0x110\n device_unbind_cleanup+0xe/0x70\n device_release_driver_internal+0x1c7/0x210\n driver_detach+0x47/0x90\n bus_remove_driver+0x6c/0xf0\n cxl_acpi_exit+0xc/0x11 [cxl_acpi]\n __do_sys_delete_module.isra.0+0x181/0x260\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe observation though is that driver objects are typically much longer\nlived than device objects. It is reasonable to perform lockless\nde-reference of a @driver pointer even if it is racing detach from a\ndevice. Given the infrequency of driver unregistration, use\nsynchronize_rcu() in module_remove_driver() to close any potential\nraces. It is potentially overkill to suffer synchronize_rcu() just to\nhandle the rare module removal racing uevent_show() event.\n\nThanks to Tetsuo Handa for the debug analysis of the syzbot report [1].', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44952', 'https://git.kernel.org/linus/15fffc6a5624b13b428bb1c6e9088e32a55eb82c (6.11-rc3)', 'https://git.kernel.org/stable/c/15fffc6a5624b13b428bb1c6e9088e32a55eb82c', 'https://git.kernel.org/stable/c/49ea4e0d862632d51667da5e7a9c88a560e9c5a1', 'https://git.kernel.org/stable/c/4a7c2a8387524942171037e70b80e969c3b5c05b', 'https://git.kernel.org/stable/c/4d035c743c3e391728a6f81cbf0f7f9ca700cf62', 'https://git.kernel.org/stable/c/9c23fc327d6ec67629b4ad323bd64d3834c0417d', 'https://git.kernel.org/stable/c/cd490a247ddf325325fd0de8898659400c9237ef', 'https://git.kernel.org/stable/c/dd98c9630b7ee273da87e9a244f94ddf947161e2', 'https://git.kernel.org/stable/c/f098e8fc7227166206256c18d56ab622039108b1', 'https://linux.oracle.com/cve/CVE-2024-44952.html', 'https://linux.oracle.com/errata/ELSA-2024-12779.html', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44952-6290@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44952', 'https://www.cve.org/CVERecord?id=CVE-2024-44952'], 'PublishedDate': '2024-09-04T19:15:30.213Z', 'LastModifiedDate': '2024-09-06T16:37:38.37Z'}, {'VulnerabilityID': 'CVE-2024-44953', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44953', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: ufs: core: Fix deadlock during RTC update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix deadlock during RTC update\n\nThere is a deadlock when runtime suspend waits for the flush of RTC work,\nand the RTC work calls ufshcd_rpm_get_sync() to wait for runtime resume.\n\nHere is deadlock backtrace:\n\nkworker/0:1 D 4892.876354 10 10971 4859 0x4208060 0x8 10 0 120 670730152367\nptr f0ffff80c2e40000 0 1 0x00000001 0x000000ff 0x000000ff 0x000000ff\n __switch_to+0x1a8/0x2d4\n __schedule+0x684/0xa98\n schedule+0x48/0xc8\n schedule_timeout+0x48/0x170\n do_wait_for_common+0x108/0x1b0\n wait_for_completion+0x44/0x60\n __flush_work+0x39c/0x424\n __cancel_work_sync+0xd8/0x208\n cancel_delayed_work_sync+0x14/0x28\n __ufshcd_wl_suspend+0x19c/0x480\n ufshcd_wl_runtime_suspend+0x3c/0x1d4\n scsi_runtime_suspend+0x78/0xc8\n __rpm_callback+0x94/0x3e0\n rpm_suspend+0x2d4/0x65c\n __pm_runtime_suspend+0x80/0x114\n scsi_runtime_idle+0x38/0x6c\n rpm_idle+0x264/0x338\n __pm_runtime_idle+0x80/0x110\n ufshcd_rtc_work+0x128/0x1e4\n process_one_work+0x26c/0x650\n worker_thread+0x260/0x3d8\n kthread+0x110/0x134\n ret_from_fork+0x10/0x20\n\nSkip updating RTC if RPM state is not RPM_ACTIVE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44953', 'https://git.kernel.org/linus/3911af778f208e5f49d43ce739332b91e26bc48e (6.11-rc2)', 'https://git.kernel.org/stable/c/3911af778f208e5f49d43ce739332b91e26bc48e', 'https://git.kernel.org/stable/c/f13f1858a28c68b7fc0d72c2008d5c1f80d2e8d5', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44953-1a10@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44953', 'https://www.cve.org/CVERecord?id=CVE-2024-44953'], 'PublishedDate': '2024-09-04T19:15:30.297Z', 'LastModifiedDate': '2024-09-06T16:37:33.65Z'}, {'VulnerabilityID': 'CVE-2024-44954', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44954', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ALSA: line6: Fix racy access to midibuf', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: line6: Fix racy access to midibuf\n\nThere can be concurrent accesses to line6 midibuf from both the URB\ncompletion callback and the rawmidi API access. This could be a cause\nof KMSAN warning triggered by syzkaller below (so put as reported-by\nhere).\n\nThis patch protects the midibuf call of the former code path with a\nspinlock for avoiding the possible races.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-362'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44954', 'https://git.kernel.org/linus/15b7a03205b31bc5623378c190d22b7ff60026f1 (6.11-rc3)', 'https://git.kernel.org/stable/c/15b7a03205b31bc5623378c190d22b7ff60026f1', 'https://git.kernel.org/stable/c/40f3d5cb0e0cbf7fa697913a27d5d361373bdcf5', 'https://git.kernel.org/stable/c/51d87f11dd199bbc6a85982b088ff27bde53b48a', 'https://git.kernel.org/stable/c/535df7f896a568a8a1564114eaea49d002cb1747', 'https://git.kernel.org/stable/c/643293b68fbb6c03f5e907736498da17d43f0d81', 'https://git.kernel.org/stable/c/a54da4b787dcac60b598da69c9c0072812b8282d', 'https://git.kernel.org/stable/c/c80f454a805443c274394b1db0d1ebf477abd94e', 'https://git.kernel.org/stable/c/e7e7d2b180d8f297cea6db43ea72402fd33e1a29', 'https://linux.oracle.com/cve/CVE-2024-44954.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44954-6838@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44954', 'https://www.cve.org/CVERecord?id=CVE-2024-44954'], 'PublishedDate': '2024-09-04T19:15:30.353Z', 'LastModifiedDate': '2024-10-10T18:02:42.307Z'}, {'VulnerabilityID': 'CVE-2024-44955', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44955', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute\n\n[Why]\nWhen unplug one of monitors connected after mst hub, encounter null pointer dereference.\n\nIt's due to dc_sink get released immediately in early_unregister() or detect_ctx(). When\ncommit new state which directly referring to info stored in dc_sink will cause null pointer\ndereference.\n\n[how]\nRemove redundant checking condition. Relevant condition should already be covered by checking\nif dsc_aux is null or not. Also reset dsc_aux to NULL when the connector is disconnected.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44955', 'https://git.kernel.org/linus/fcf6a49d79923a234844b8efe830a61f3f0584e4 (6.11-rc1)', 'https://git.kernel.org/stable/c/39b217193729aa45eded8de24d9245468a0c0263', 'https://git.kernel.org/stable/c/fcf6a49d79923a234844b8efe830a61f3f0584e4', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44955-20e8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44955', 'https://www.cve.org/CVERecord?id=CVE-2024-44955'], 'PublishedDate': '2024-09-04T19:15:30.423Z', 'LastModifiedDate': '2024-10-10T17:57:00.267Z'}, {'VulnerabilityID': 'CVE-2024-44956', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44956', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/preempt_fence: enlarge the fence critical section', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/preempt_fence: enlarge the fence critical section\n\nIt is really easy to introduce subtle deadlocks in\npreempt_fence_work_func() since we operate on single global ordered-wq\nfor signalling our preempt fences behind the scenes, so even though we\nsignal a particular fence, everything in the callback should be in the\nfence critical section, since blocking in the callback will prevent\nother published fences from signalling. If we enlarge the fence critical\nsection to cover the entire callback, then lockdep should be able to\nunderstand this better, and complain if we grab a sensitive lock like\nvm->lock, which is also held when waiting on preempt fences.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44956', 'https://git.kernel.org/linus/3cd1585e57908b6efcd967465ef7685f40b2a294 (6.11-rc1)', 'https://git.kernel.org/stable/c/3cd1585e57908b6efcd967465ef7685f40b2a294', 'https://git.kernel.org/stable/c/458bb83119dfee5d14c677f7846dd9363817006f', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44956-8bcf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44956', 'https://www.cve.org/CVERecord?id=CVE-2024-44956'], 'PublishedDate': '2024-09-04T19:15:30.48Z', 'LastModifiedDate': '2024-09-06T16:37:11.777Z'}, {'VulnerabilityID': 'CVE-2024-44957', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44957', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xen: privcmd: Switch from mutex to spinlock for irqfds', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Switch from mutex to spinlock for irqfds\n\nirqfd_wakeup() gets EPOLLHUP, when it is called by\neventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which\ngets called under spin_lock_irqsave(). We can't use a mutex here as it\nwill lead to a deadlock.\n\nFix it by switching over to a spin lock.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44957', 'https://git.kernel.org/linus/1c682593096a487fd9aebc079a307ff7a6d054a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/1c682593096a487fd9aebc079a307ff7a6d054a3', 'https://git.kernel.org/stable/c/49f2a5da6785b2dbde93e291cae037662440346e', 'https://git.kernel.org/stable/c/c2775ae4d9227729f8ca9ee2a068f62a00d5ea9c', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44957-5c8e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44957', 'https://www.cve.org/CVERecord?id=CVE-2024-44957'], 'PublishedDate': '2024-09-04T19:15:30.523Z', 'LastModifiedDate': '2024-09-06T16:37:00.077Z'}, {'VulnerabilityID': 'CVE-2024-44958', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44958', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched/smt: Fix unbalance sched_smt_present dec/inc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched/smt: Fix unbalance sched_smt_present dec/inc\n\nI got the following warn report while doing stress test:\n\njump label: negative count!\nWARNING: CPU: 3 PID: 38 at kernel/jump_label.c:263 static_key_slow_try_dec+0x9d/0xb0\nCall Trace:\n \n __static_key_slow_dec_cpuslocked+0x16/0x70\n sched_cpu_deactivate+0x26e/0x2a0\n cpuhp_invoke_callback+0x3ad/0x10d0\n cpuhp_thread_fun+0x3f5/0x680\n smpboot_thread_fn+0x56d/0x8d0\n kthread+0x309/0x400\n ret_from_fork+0x41/0x70\n ret_from_fork_asm+0x1b/0x30\n \n\nBecause when cpuset_cpu_inactive() fails in sched_cpu_deactivate(),\nthe cpu offline failed, but sched_smt_present is decremented before\ncalling sched_cpu_deactivate(), it leads to unbalanced dec/inc, so\nfix it by incrementing sched_smt_present in the error path.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44958', 'https://git.kernel.org/linus/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117 (6.11-rc2)', 'https://git.kernel.org/stable/c/2a3548c7ef2e135aee40e7e5e44e7d11b893e7c4', 'https://git.kernel.org/stable/c/2cf7665efe451e48d27953e6b5bc627d518c902b', 'https://git.kernel.org/stable/c/65727331b60197b742089855ac09464c22b96f66', 'https://git.kernel.org/stable/c/d0c87a3c6be10a57aa3463c32c3fc6b2a47c3dab', 'https://git.kernel.org/stable/c/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44958-80e9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44958', 'https://www.cve.org/CVERecord?id=CVE-2024-44958'], 'PublishedDate': '2024-09-04T19:15:30.58Z', 'LastModifiedDate': '2024-10-10T17:56:24.467Z'}, {'VulnerabilityID': 'CVE-2024-44959', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44959', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracefs: Use generic inode RCU for synchronizing freeing', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntracefs: Use generic inode RCU for synchronizing freeing\n\nWith structure layout randomization enabled for 'struct inode' we need to\navoid overlapping any of the RCU-used / initialized-only-once members,\ne.g. i_lru or i_sb_list to not corrupt related list traversals when making\nuse of the rcu_head.\n\nFor an unlucky structure layout of 'struct inode' we may end up with the\nfollowing splat when running the ftrace selftests:\n\n[<...>] list_del corruption, ffff888103ee2cb0->next (tracefs_inode_cache+0x0/0x4e0 [slab object]) is NULL (prev is tracefs_inode_cache+0x78/0x4e0 [slab object])\n[<...>] ------------[ cut here ]------------\n[<...>] kernel BUG at lib/list_debug.c:54!\n[<...>] invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[<...>] CPU: 3 PID: 2550 Comm: mount Tainted: G N 6.8.12-grsec+ #122 ed2f536ca62f28b087b90e3cc906a8d25b3ddc65\n[<...>] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\n[<...>] RIP: 0010:[] __list_del_entry_valid_or_report+0x138/0x3e0\n[<...>] Code: 48 b8 99 fb 65 f2 ff ff ff ff e9 03 5c d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff e9 33 5a d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff <0f> 0b 4c 89 e9 48 89 ea 48 89 ee 48 c7 c7 60 8f dd 89 31 c0 e8 2f\n[<...>] RSP: 0018:fffffe80416afaf0 EFLAGS: 00010283\n[<...>] RAX: 0000000000000098 RBX: ffff888103ee2cb0 RCX: 0000000000000000\n[<...>] RDX: ffffffff84655fe8 RSI: ffffffff89dd8b60 RDI: 0000000000000001\n[<...>] RBP: ffff888103ee2cb0 R08: 0000000000000001 R09: fffffbd0082d5f25\n[<...>] R10: fffffe80416af92f R11: 0000000000000001 R12: fdf99c16731d9b6d\n[<...>] R13: 0000000000000000 R14: ffff88819ad4b8b8 R15: 0000000000000000\n[<...>] RBX: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RDX: __list_del_entry_valid_or_report+0x108/0x3e0\n[<...>] RSI: __func__.47+0x4340/0x4400\n[<...>] RBP: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RSP: process kstack fffffe80416afaf0+0x7af0/0x8000 [mount 2550 2550]\n[<...>] R09: kasan shadow of process kstack fffffe80416af928+0x7928/0x8000 [mount 2550 2550]\n[<...>] R10: process kstack fffffe80416af92f+0x792f/0x8000 [mount 2550 2550]\n[<...>] R14: tracefs_inode_cache+0x78/0x4e0 [slab object]\n[<...>] FS: 00006dcb380c1840(0000) GS:ffff8881e0600000(0000) knlGS:0000000000000000\n[<...>] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[<...>] CR2: 000076ab72b30e84 CR3: 000000000b088004 CR4: 0000000000360ef0 shadow CR4: 0000000000360ef0\n[<...>] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[<...>] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[<...>] ASID: 0003\n[<...>] Stack:\n[<...>] ffffffff818a2315 00000000f5c856ee ffffffff896f1840 ffff888103ee2cb0\n[<...>] ffff88812b6b9750 0000000079d714b6 fffffbfff1e9280b ffffffff8f49405f\n[<...>] 0000000000000001 0000000000000000 ffff888104457280 ffffffff8248b392\n[<...>] Call Trace:\n[<...>] \n[<...>] [] ? lock_release+0x175/0x380 fffffe80416afaf0\n[<...>] [] list_lru_del+0x152/0x740 fffffe80416afb48\n[<...>] [] list_lru_del_obj+0x113/0x280 fffffe80416afb88\n[<...>] [] ? _atomic_dec_and_lock+0x119/0x200 fffffe80416afb90\n[<...>] [] iput_final+0x1c4/0x9a0 fffffe80416afbb8\n[<...>] [] dentry_unlink_inode+0x44b/0xaa0 fffffe80416afbf8\n[<...>] [] __dentry_kill+0x23c/0xf00 fffffe80416afc40\n[<...>] [] ? __this_cpu_preempt_check+0x1f/0xa0 fffffe80416afc48\n[<...>] [] ? shrink_dentry_list+0x1c5/0x760 fffffe80416afc70\n[<...>] [] ? shrink_dentry_list+0x51/0x760 fffffe80416afc78\n[<...>] [] shrink_dentry_list+0x288/0x760 fffffe80416afc80\n[<...>] [] shrink_dcache_sb+0x155/0x420 fffffe80416afcc8\n[<...>] [] ? debug_smp_processor_id+0x23/0xa0 fffffe80416afce0\n[<...>] [] ? do_one_tre\n---truncated---", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44959', 'https://git.kernel.org/linus/0b6743bd60a56a701070b89fb80c327a44b7b3e2 (6.11-rc3)', 'https://git.kernel.org/stable/c/061da60716ce0cde99f62f31937b81e1c03acef6', 'https://git.kernel.org/stable/c/0b6743bd60a56a701070b89fb80c327a44b7b3e2', 'https://git.kernel.org/stable/c/726f4c241e17be75a9cf6870d80cd7479dc89e8f', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44959-61a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44959', 'https://www.cve.org/CVERecord?id=CVE-2024-44959'], 'PublishedDate': '2024-09-04T19:15:30.637Z', 'LastModifiedDate': '2024-10-10T17:54:07.96Z'}, {'VulnerabilityID': 'CVE-2024-44960', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44960', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: gadget: core: Check for unset descriptor', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: core: Check for unset descriptor\n\nMake sure the descriptor has been set before looking at maxpacket.\nThis fixes a null pointer panic in this case.\n\nThis may happen if the gadget doesn't properly set up the endpoint\nfor the current speed, or the gadget descriptors are malformed and\nthe descriptor for the speed/endpoint are not found.\n\nNo current gadget driver is known to have this problem, but this\nmay cause a hard-to-find bug during development of new gadgets.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44960', 'https://git.kernel.org/linus/973a57891608a98e894db2887f278777f564de18 (6.11-rc3)', 'https://git.kernel.org/stable/c/1a9df57d57452b104c46c918569143cf21d7ebf1', 'https://git.kernel.org/stable/c/50c5248b0ea8aae0529fdf28dac42a41312d3b62', 'https://git.kernel.org/stable/c/716cba46f73a92645cf13eded8d257ed48afc2a4', 'https://git.kernel.org/stable/c/7cc9ebcfe58be22f18056ad8bc6272d120bdcb3e', 'https://git.kernel.org/stable/c/973a57891608a98e894db2887f278777f564de18', 'https://git.kernel.org/stable/c/a0362cd6e503278add954123957fd47990e8d9bf', 'https://git.kernel.org/stable/c/ba15815dd24cc5ec0d23e2170dc58c7db1e03b4a', 'https://git.kernel.org/stable/c/df8e734ae5e605348aa0ca2498aedb73e815f244', 'https://linux.oracle.com/cve/CVE-2024-44960.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44960-039b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44960', 'https://www.cve.org/CVERecord?id=CVE-2024-44960'], 'PublishedDate': '2024-09-04T19:15:30.7Z', 'LastModifiedDate': '2024-10-04T16:44:05.497Z'}, {'VulnerabilityID': 'CVE-2024-44961', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44961', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Forward soft recovery errors to userspace', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Forward soft recovery errors to userspace\n\nAs we discussed before[1], soft recovery should be\nforwarded to userspace, or we can get into a really\nbad state where apps will keep submitting hanging\ncommand buffers cascading us to a hard reset.\n\n1: https://lore.kernel.org/all/bf23d5ed-9a6b-43e7-84ee-8cbfd0d60f18@froggi.es/\n(cherry picked from commit 434967aadbbbe3ad9103cc29e9a327de20fdba01)', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44961', 'https://git.kernel.org/linus/829798c789f567ef6ba4b084c15b7b5f3bd98d51 (6.11-rc3)', 'https://git.kernel.org/stable/c/0da0b06165d83a8ecbb6582d9d5a135f9d38a52a', 'https://git.kernel.org/stable/c/829798c789f567ef6ba4b084c15b7b5f3bd98d51', 'https://git.kernel.org/stable/c/c28d207edfc5679585f4e96acb67000076ce90be', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44961-8666@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44961', 'https://www.cve.org/CVERecord?id=CVE-2024-44961'], 'PublishedDate': '2024-09-04T19:15:30.77Z', 'LastModifiedDate': '2024-10-04T16:39:39.3Z'}, {'VulnerabilityID': 'CVE-2024-44962', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44962', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: btnxpuart: Shutdown timer and prevent rearming when driver unloading', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Shutdown timer and prevent rearming when driver unloading\n\nWhen unload the btnxpuart driver, its associated timer will be deleted.\nIf the timer happens to be modified at this moment, it leads to the\nkernel call this timer even after the driver unloaded, resulting in\nkernel panic.\nUse timer_shutdown_sync() instead of del_timer_sync() to prevent rearming.\n\npanic log:\n Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n Modules linked in: algif_hash algif_skcipher af_alg moal(O) mlan(O) crct10dif_ce polyval_ce polyval_generic snd_soc_imx_card snd_soc_fsl_asoc_card snd_soc_imx_audmux mxc_jpeg_encdec v4l2_jpeg snd_soc_wm8962 snd_soc_fsl_micfil snd_soc_fsl_sai flexcan snd_soc_fsl_utils ap130x rpmsg_ctrl imx_pcm_dma can_dev rpmsg_char pwm_fan fuse [last unloaded: btnxpuart]\n CPU: 5 PID: 723 Comm: memtester Tainted: G O 6.6.23-lts-next-06207-g4aef2658ac28 #1\n Hardware name: NXP i.MX95 19X19 board (DT)\n pstate: 20400009 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : 0xffff80007a2cf464\n lr : call_timer_fn.isra.0+0x24/0x80\n...\n Call trace:\n 0xffff80007a2cf464\n __run_timers+0x234/0x280\n run_timer_softirq+0x20/0x40\n __do_softirq+0x100/0x26c\n ____do_softirq+0x10/0x1c\n call_on_irq_stack+0x24/0x4c\n do_softirq_own_stack+0x1c/0x2c\n irq_exit_rcu+0xc0/0xdc\n el0_interrupt+0x54/0xd8\n __el0_irq_handler_common+0x18/0x24\n el0t_64_irq_handler+0x10/0x1c\n el0t_64_irq+0x190/0x194\n Code: ???????? ???????? ???????? ???????? (????????)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Oops: Fatal exception in interrupt\n SMP: stopping secondary CPUs\n Kernel Offset: disabled\n CPU features: 0x0,c0000000,40028143,1000721b\n Memory Limit: none\n ---[ end Kernel panic - not syncing: Oops: Fatal exception in interrupt ]---', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44962', 'https://git.kernel.org/linus/0d0df1e750bac0fdaa77940e711c1625cff08d33 (6.11-rc1)', 'https://git.kernel.org/stable/c/0d0df1e750bac0fdaa77940e711c1625cff08d33', 'https://git.kernel.org/stable/c/28bbb5011a9723700006da67bdb57ab6a914452b', 'https://git.kernel.org/stable/c/4d9adcb94d55e9be8a3e464d9f2ff7d27e2ed016', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44962-c329@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44962', 'https://www.cve.org/CVERecord?id=CVE-2024-44962'], 'PublishedDate': '2024-09-04T19:15:30.827Z', 'LastModifiedDate': '2024-10-04T16:20:34.55Z'}, {'VulnerabilityID': 'CVE-2024-44963', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44963', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: do not BUG_ON() when freeing tree block after error', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not BUG_ON() when freeing tree block after error\n\nWhen freeing a tree block, at btrfs_free_tree_block(), if we fail to\ncreate a delayed reference we don't deal with the error and just do a\nBUG_ON(). The error most likely to happen is -ENOMEM, and we have a\ncomment mentioning that only -ENOMEM can happen, but that is not true,\nbecause in case qgroups are enabled any error returned from\nbtrfs_qgroup_trace_extent_post() (can be -EUCLEAN or anything returned\nfrom btrfs_search_slot() for example) can be propagated back to\nbtrfs_free_tree_block().\n\nSo stop doing a BUG_ON() and return the error to the callers and make\nthem abort the transaction to prevent leaking space. Syzbot was\ntriggering this, likely due to memory allocation failure injection.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44963', 'https://git.kernel.org/linus/bb3868033a4cccff7be57e9145f2117cbdc91c11 (6.11-rc1)', 'https://git.kernel.org/stable/c/98251cd60b4d702a8a81de442ab621e83a3fb24f', 'https://git.kernel.org/stable/c/bb3868033a4cccff7be57e9145f2117cbdc91c11', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44963-2e6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44963', 'https://www.cve.org/CVERecord?id=CVE-2024-44963'], 'PublishedDate': '2024-09-04T19:15:30.883Z', 'LastModifiedDate': '2024-10-04T16:19:20.77Z'}, {'VulnerabilityID': 'CVE-2024-44964', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44964', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: idpf: fix memory leaks and crashes while performing a soft reset', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix memory leaks and crashes while performing a soft reset\n\nThe second tagged commit introduced a UAF, as it removed restoring\nq_vector->vport pointers after reinitializating the structures.\nThis is due to that all queue allocation functions are performed here\nwith the new temporary vport structure and those functions rewrite\nthe backpointers to the vport. Then, this new struct is freed and\nthe pointers start leading to nowhere.\n\nBut generally speaking, the current logic is very fragile. It claims\nto be more reliable when the system is low on memory, but in fact, it\nconsumes two times more memory as at the moment of running this\nfunction, there are two vports allocated with their queues and vectors.\nMoreover, it claims to prevent the driver from running into "bad state",\nbut in fact, any error during the rebuild leaves the old vport in the\npartially allocated state.\nFinally, if the interface is down when the function is called, it always\nallocates a new queue set, but when the user decides to enable the\ninterface later on, vport_open() allocates them once again, IOW there\'s\na clear memory leak here.\n\nJust don\'t allocate a new queue set when performing a reset, that solves\ncrashes and memory leaks. Readd the old queue number and reopen the\ninterface on rollback - that solves limbo states when the device is left\ndisabled and/or without HW queues enabled.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401', 'CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44964', 'https://git.kernel.org/linus/f01032a2ca099ec8d619aaa916c3762aa62495df (6.11-rc3)', 'https://git.kernel.org/stable/c/6b289f8d91537ec1e4f9c7b38b31b90d93b1419b', 'https://git.kernel.org/stable/c/f01032a2ca099ec8d619aaa916c3762aa62495df', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44964-ebb1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44964', 'https://www.cve.org/CVERecord?id=CVE-2024-44964'], 'PublishedDate': '2024-09-04T19:15:30.94Z', 'LastModifiedDate': '2024-09-06T16:36:45.137Z'}, {'VulnerabilityID': 'CVE-2024-44965', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44965', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/mm: Fix pti_clone_pgtable() alignment assumption', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Fix pti_clone_pgtable() alignment assumption\n\nGuenter reported dodgy crashes on an i386-nosmp build using GCC-11\nthat had the form of endless traps until entry stack exhaust and then\n#DF from the stack guard.\n\nIt turned out that pti_clone_pgtable() had alignment assumptions on\nthe start address, notably it hard assumes start is PMD aligned. This\nis true on x86_64, but very much not true on i386.\n\nThese assumptions can cause the end condition to malfunction, leading\nto a 'short' clone. Guess what happens when the user mapping has a\nshort copy of the entry text?\n\nUse the correct increment form for addr to avoid alignment\nassumptions.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44965', 'https://git.kernel.org/linus/41e71dbb0e0a0fe214545fe64af031303a08524c (6.11-rc2)', 'https://git.kernel.org/stable/c/18da1b27ce16a14a9b636af9232acb4fb24f4c9e', 'https://git.kernel.org/stable/c/25a727233a40a9b33370eec9f0cad67d8fd312f8', 'https://git.kernel.org/stable/c/41e71dbb0e0a0fe214545fe64af031303a08524c', 'https://git.kernel.org/stable/c/4d143ae782009b43b4f366402e5c37f59d4e4346', 'https://git.kernel.org/stable/c/5c580c1050bcbc15c3e78090859d798dcf8c9763', 'https://git.kernel.org/stable/c/ca07aab70dd3b5e7fddb62d7a6ecd7a7d6d0b2ed', 'https://git.kernel.org/stable/c/d00c9b4bbc442d99e1dafbdfdab848bc1ead73f6', 'https://git.kernel.org/stable/c/df3eecb5496f87263d171b254ca6e2758ab3c35c', 'https://linux.oracle.com/cve/CVE-2024-44965.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090415-CVE-2024-44965-d41d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44965', 'https://www.cve.org/CVERecord?id=CVE-2024-44965'], 'PublishedDate': '2024-09-04T19:15:30.99Z', 'LastModifiedDate': '2024-10-04T16:17:15.23Z'}, {'VulnerabilityID': 'CVE-2024-44966', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44966', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: binfmt_flat: Fix corruption when not offsetting data start', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_flat: Fix corruption when not offsetting data start\n\nCommit 04d82a6d0881 ("binfmt_flat: allow not offsetting data start")\nintroduced a RISC-V specific variant of the FLAT format which does\nnot allocate any space for the (obsolete) array of shared library\npointers. However, it did not disable the code which initializes the\narray, resulting in the corruption of sizeof(long) bytes before the DATA\nsegment, generally the end of the TEXT segment.\n\nIntroduce MAX_SHARED_LIBS_UPDATE which depends on the state of\nCONFIG_BINFMT_FLAT_NO_DATA_START_OFFSET to guard the initialization of\nthe shared library pointer region so that it will only be initialized\nif space is reserved for it.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44966', 'https://git.kernel.org/linus/3eb3cd5992f7a0c37edc8d05b4c38c98758d8671 (6.11-rc4)', 'https://git.kernel.org/stable/c/3a684499261d0f7ed5ee72793025c88c2276809c', 'https://git.kernel.org/stable/c/3eb3cd5992f7a0c37edc8d05b4c38c98758d8671', 'https://git.kernel.org/stable/c/49df34d2b7da9e57c839555a2f7877291ce45ad1', 'https://git.kernel.org/stable/c/9350ba06ee61db392c486716ac68ecc20e030f7c', 'https://git.kernel.org/stable/c/af65d5383854cc3f172a7d0843b628758bf462c8', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-44966-3aac@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44966', 'https://www.cve.org/CVERecord?id=CVE-2024-44966'], 'PublishedDate': '2024-09-04T19:15:31.06Z', 'LastModifiedDate': '2024-10-04T16:15:30.047Z'}, {'VulnerabilityID': 'CVE-2024-44967', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44967', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/mgag200: Bind I2C lifetime to DRM device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mgag200: Bind I2C lifetime to DRM device\n\nManaged cleanup with devm_add_action_or_reset() will release the I2C\nadapter when the underlying Linux device goes away. But the connector\nstill refers to it, so this cleanup leaves behind a stale pointer\nin struct drm_connector.ddc.\n\nBind the lifetime of the I2C adapter to the connector's lifetime by\nusing DRM's managed release. When the DRM device goes away (after\nthe Linux device) DRM will first clean up the connector and then\nclean up the I2C adapter.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44967', 'https://git.kernel.org/linus/eb1ae34e48a09b7a1179c579aed042b032e408f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/55a6916db77102765b22855d3a0add4751988b7c', 'https://git.kernel.org/stable/c/81d34df843620e902dd04aa9205c875833d61c17', 'https://git.kernel.org/stable/c/9d96b91e03cba9dfcb4ac370c93af4dbc47d5191', 'https://git.kernel.org/stable/c/eb1ae34e48a09b7a1179c579aed042b032e408f4', 'https://lore.kernel.org/linux-cve-announce/2024090453-CVE-2024-44967-dd14@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44967', 'https://www.cve.org/CVERecord?id=CVE-2024-44967'], 'PublishedDate': '2024-09-04T19:15:31.117Z', 'LastModifiedDate': '2024-10-03T18:21:17.23Z'}, {'VulnerabilityID': 'CVE-2024-44969', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44969', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/sclp: Prevent release of buffer in I/O', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/sclp: Prevent release of buffer in I/O\n\nWhen a task waiting for completion of a Store Data operation is\ninterrupted, an attempt is made to halt this operation. If this attempt\nfails due to a hardware or firmware problem, there is a chance that the\nSCLP facility might store data into buffers referenced by the original\noperation at a later time.\n\nHandle this situation by not releasing the referenced data buffers if\nthe halt attempt fails. For current use cases, this might result in a\nleak of few pages of memory in case of a rare hardware/firmware\nmalfunction.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44969', 'https://git.kernel.org/linus/bf365071ea92b9579d5a272679b74052a5643e35 (6.11-rc1)', 'https://git.kernel.org/stable/c/1e8b7fb427af6b2ddd54eff66a6b428a81c96633', 'https://git.kernel.org/stable/c/1ec5ea9e25f582fd6999393e2f2c3bf56f234e05', 'https://git.kernel.org/stable/c/2429ea3b4330e3653b72b210a0d5f2a717359506', 'https://git.kernel.org/stable/c/46f67233b011385d53cf14d272431755de3a7c79', 'https://git.kernel.org/stable/c/7a7e60ed23d471a07dbbe72565d2992ee8244bbe', 'https://git.kernel.org/stable/c/a3e52a4c22c846858a6875e1c280030a3849e148', 'https://git.kernel.org/stable/c/a88a49473c94ccfd8dce1e766aacf3c627278463', 'https://git.kernel.org/stable/c/bf365071ea92b9579d5a272679b74052a5643e35', 'https://linux.oracle.com/cve/CVE-2024-44969.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090456-CVE-2024-44969-48bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44969', 'https://www.cve.org/CVERecord?id=CVE-2024-44969'], 'PublishedDate': '2024-09-04T19:15:31.24Z', 'LastModifiedDate': '2024-10-03T17:38:41.333Z'}, {'VulnerabilityID': 'CVE-2024-44970', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44970', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink\n\nWhen all the strides in a WQE have been consumed, the WQE is unlinked\nfrom the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible\nto receive CQEs with 0 consumed strides for the same WQE even after the\nWQE is fully consumed and unlinked. This triggers an additional unlink\nfor the same wqe which corrupts the linked list.\n\nFix this scenario by accepting 0 sized consumed strides without\nunlinking the WQE again.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44970', 'https://git.kernel.org/linus/fba8334721e266f92079632598e46e5f89082f30 (6.11-rc1)', 'https://git.kernel.org/stable/c/50d8009a0ac02c3311b23a0066511f8337bd88d9', 'https://git.kernel.org/stable/c/650e24748e1e0a7ff91d5c72b72a2f2a452b5b76', 'https://git.kernel.org/stable/c/7b379353e9144e1f7460ff15f39862012c9d0d78', 'https://git.kernel.org/stable/c/fba8334721e266f92079632598e46e5f89082f30', 'https://lore.kernel.org/linux-cve-announce/2024090456-CVE-2024-44970-f687@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44970', 'https://www.cve.org/CVERecord?id=CVE-2024-44970'], 'PublishedDate': '2024-09-04T19:15:31.307Z', 'LastModifiedDate': '2024-10-03T14:22:06.003Z'}, {'VulnerabilityID': 'CVE-2024-44971', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44971', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()\n\nbcm_sf2_mdio_register() calls of_phy_find_device() and then\nphy_device_remove() in a loop to remove existing PHY devices.\nof_phy_find_device() eventually calls bus_find_device(), which calls\nget_device() on the returned struct device * to increment the refcount.\nThe current implementation does not decrement the refcount, which causes\nmemory leak.\n\nThis commit adds the missing phy_device_free() call to decrement the\nrefcount via put_device() to balance the refcount.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44971', 'https://git.kernel.org/linus/e3862093ee93fcfbdadcb7957f5f8974fffa806a (6.11-rc3)', 'https://git.kernel.org/stable/c/7feef10768ea71d468d9bbc1e0d14c461876768c', 'https://git.kernel.org/stable/c/a7d2808d67570e6acae45c2a96e0d59986888e4c', 'https://git.kernel.org/stable/c/b7b8d9f5e679af60c94251fd6728dde34be69a71', 'https://git.kernel.org/stable/c/c05516c072903f6fb9134b8e7e1ad4bffcdc4819', 'https://git.kernel.org/stable/c/e3862093ee93fcfbdadcb7957f5f8974fffa806a', 'https://git.kernel.org/stable/c/f3d5efe18a11f94150fee8b3fda9d62079af640a', 'https://lore.kernel.org/linux-cve-announce/2024090457-CVE-2024-44971-eb75@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44971', 'https://www.cve.org/CVERecord?id=CVE-2024-44971'], 'PublishedDate': '2024-09-04T19:15:31.367Z', 'LastModifiedDate': '2024-09-05T17:54:36.607Z'}, {'VulnerabilityID': 'CVE-2024-44972', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44972', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: do not clear page dirty inside extent_write_locked_range()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not clear page dirty inside extent_write_locked_range()\n\n[BUG]\nFor subpage + zoned case, the following workload can lead to rsv data\nleak at unmount time:\n\n # mkfs.btrfs -f -s 4k $dev\n # mount $dev $mnt\n # fsstress -w -n 8 -d $mnt -s 1709539240\n 0/0: fiemap - no filename\n 0/1: copyrange read - no filename\n 0/2: write - no filename\n 0/3: rename - no source filename\n 0/4: creat f0 x:0 0 0\n 0/4: creat add id=0,parent=-1\n 0/5: writev f0[259 1 0 0 0 0] [778052,113,965] 0\n 0/6: ioctl(FIEMAP) f0[259 1 0 0 224 887097] [1294220,2291618343991484791,0x10000] -1\n 0/7: dwrite - xfsctl(XFS_IOC_DIOINFO) f0[259 1 0 0 224 887097] return 25, fallback to stat()\n 0/7: dwrite f0[259 1 0 0 224 887097] [696320,102400] 0\n # umount $mnt\n\nThe dmesg includes the following rsv leak detection warning (all call\ntrace skipped):\n\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8653 btrfs_destroy_inode+0x1e0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8654 btrfs_destroy_inode+0x1a8/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8660 btrfs_destroy_inode+0x1a0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): last unmount of filesystem 1b4abba9-de34-4f07-9e7f-157cf12a18d6\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info DATA has 268218368 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=204800, pinned=0, reserved=0, may_use=12288, readonly=0 zone_unusable=0\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info METADATA has 267796480 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=131072, pinned=0, reserved=0, may_use=262144, readonly=0 zone_unusable=245760\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n\nAbove $dev is a tcmu-runner emulated zoned HDD, which has a max zone\nappend size of 64K, and the system has 64K page size.\n\n[CAUSE]\nI have added several trace_printk() to show the events (header skipped):\n\n > btrfs_dirty_pages: r/i=5/259 dirty start=774144 len=114688\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=720896 off_in_page=53248 len_in_page=12288\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=786432 off_in_page=0 len_in_page=65536\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=851968 off_in_page=0 len_in_page=36864\n\nThe above lines show our buffered write has dirtied 3 pages of inode\n259 of root 5:\n\n 704K 768K 832K 896K\n I |////I/////////////////I///////////| I\n 756K 868K\n\n |///| is the dirtied range using subpage bitmaps. and 'I' is the page\n boundary.\n\n Meanwhile all three pages (704K, 768K, 832K) have their PageDirty\n flag set.\n\n > btrfs_direct_write: r/i=5/259 start dio filepos=696320 len=102400\n\nThen direct IO writ\n---truncated---", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44972', 'https://git.kernel.org/linus/97713b1a2ced1e4a2a6c40045903797ebd44d7e0 (6.11-rc1)', 'https://git.kernel.org/stable/c/97713b1a2ced1e4a2a6c40045903797ebd44d7e0', 'https://git.kernel.org/stable/c/ba4dedb71356638d8284e34724daca944be70368', 'https://git.kernel.org/stable/c/d3b403209f767e5857c1b9fda66726e6e6ffc99f', 'https://lore.kernel.org/linux-cve-announce/2024090457-CVE-2024-44972-23b5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44972', 'https://www.cve.org/CVERecord?id=CVE-2024-44972'], 'PublishedDate': '2024-09-04T19:15:31.43Z', 'LastModifiedDate': '2024-10-03T16:10:12.077Z'}, {'VulnerabilityID': 'CVE-2024-44973', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44973', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm, slub: do not call do_slab_free for kfence object', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: do not call do_slab_free for kfence object\n\nIn 782f8906f805 the freeing of kfence objects was moved from deep\ninside do_slab_free to the wrapper functions outside. This is a nice\nchange, but unfortunately it missed one spot in __kmem_cache_free_bulk.\n\nThis results in a crash like this:\n\nBUG skbuff_head_cache (Tainted: G S B E ): Padding overwritten. 0xffff88907fea0f00-0xffff88907fea0fff @offset=3840\n\nslab_err (mm/slub.c:1129)\nfree_to_partial_list (mm/slub.c:? mm/slub.c:4036)\nslab_pad_check (mm/slub.c:864 mm/slub.c:1290)\ncheck_slab (mm/slub.c:?)\nfree_to_partial_list (mm/slub.c:3171 mm/slub.c:4036)\nkmem_cache_alloc_bulk (mm/slub.c:? mm/slub.c:4495 mm/slub.c:4586 mm/slub.c:4635)\nnapi_build_skb (net/core/skbuff.c:348 net/core/skbuff.c:527 net/core/skbuff.c:549)\n\nAll the other callers to do_slab_free appear to be ok.\n\nAdd a kfence_free check in __kmem_cache_free_bulk to avoid the crash.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44973', 'https://git.kernel.org/linus/a371d558e6f3aed977a8a7346350557de5d25190 (6.11-rc3)', 'https://git.kernel.org/stable/c/a371d558e6f3aed977a8a7346350557de5d25190', 'https://git.kernel.org/stable/c/b35cd7f1e969aaa63e6716d82480f6b8a3230949', 'https://lore.kernel.org/linux-cve-announce/2024090425-CVE-2024-44973-a92d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44973', 'https://www.cve.org/CVERecord?id=CVE-2024-44973'], 'PublishedDate': '2024-09-04T19:15:31.487Z', 'LastModifiedDate': '2024-10-03T14:23:09.147Z'}, {'VulnerabilityID': 'CVE-2024-44974', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44974', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: avoid possible UaF when selecting endp', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: avoid possible UaF when selecting endp\n\nselect_local_address() and select_signal_address() both select an\nendpoint entry from the list inside an RCU protected section, but return\na reference to it, to be read later on. If the entry is dereferenced\nafter the RCU unlock, reading info could cause a Use-after-Free.\n\nA simple solution is to copy the required info while inside the RCU\nprotected section to avoid any risk of UaF later. The address ID might\nneed to be modified later to handle the ID0 case later, so a copy seems\nOK to deal with.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44974', 'https://git.kernel.org/linus/48e50dcbcbaaf713d82bf2da5c16aeced94ad07d (6.11-rc5)', 'https://git.kernel.org/stable/c/0201d65d9806d287a00e0ba96f0321835631f63f', 'https://git.kernel.org/stable/c/2b4f46f9503633dade75cb796dd1949d0e6581a1', 'https://git.kernel.org/stable/c/48e50dcbcbaaf713d82bf2da5c16aeced94ad07d', 'https://git.kernel.org/stable/c/9a9afbbc3fbfca4975eea4aa5b18556db5a0c0b8', 'https://git.kernel.org/stable/c/ddee5b4b6a1cc03c1e9921cf34382e094c2009f1', 'https://git.kernel.org/stable/c/f2c865e9e3ca44fc06b5f73b29a954775e4dbb38', 'https://lore.kernel.org/linux-cve-announce/2024090440-CVE-2024-44974-dbe8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44974', 'https://www.cve.org/CVERecord?id=CVE-2024-44974'], 'PublishedDate': '2024-09-04T20:15:07.1Z', 'LastModifiedDate': '2024-09-12T12:15:51.397Z'}, {'VulnerabilityID': 'CVE-2024-44975', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44975', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cgroup/cpuset: fix panic caused by partcmd_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: fix panic caused by partcmd_update\n\nWe find a bug as below:\nBUG: unable to handle page fault for address: 00000003\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 3 PID: 358 Comm: bash Tainted: G W I 6.6.0-10893-g60d6\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/4\nRIP: 0010:partition_sched_domains_locked+0x483/0x600\nCode: 01 48 85 d2 74 0d 48 83 05 29 3f f8 03 01 f3 48 0f bc c2 89 c0 48 9\nRSP: 0018:ffffc90000fdbc58 EFLAGS: 00000202\nRAX: 0000000100000003 RBX: ffff888100b3dfa0 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000002fe80\nRBP: ffff888100b3dfb0 R08: 0000000000000001 R09: 0000000000000000\nR10: ffffc90000fdbcb0 R11: 0000000000000004 R12: 0000000000000002\nR13: ffff888100a92b48 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f44a5425740(0000) GS:ffff888237d80000(0000) knlGS:0000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000100030973 CR3: 000000010722c000 CR4: 00000000000006e0\nCall Trace:\n \n ? show_regs+0x8c/0xa0\n ? __die_body+0x23/0xa0\n ? __die+0x3a/0x50\n ? page_fault_oops+0x1d2/0x5c0\n ? partition_sched_domains_locked+0x483/0x600\n ? search_module_extables+0x2a/0xb0\n ? search_exception_tables+0x67/0x90\n ? kernelmode_fixup_or_oops+0x144/0x1b0\n ? __bad_area_nosemaphore+0x211/0x360\n ? up_read+0x3b/0x50\n ? bad_area_nosemaphore+0x1a/0x30\n ? exc_page_fault+0x890/0xd90\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? asm_exc_page_fault+0x26/0x30\n ? partition_sched_domains_locked+0x483/0x600\n ? partition_sched_domains_locked+0xf0/0x600\n rebuild_sched_domains_locked+0x806/0xdc0\n update_partition_sd_lb+0x118/0x130\n cpuset_write_resmask+0xffc/0x1420\n cgroup_file_write+0xb2/0x290\n kernfs_fop_write_iter+0x194/0x290\n new_sync_write+0xeb/0x160\n vfs_write+0x16f/0x1d0\n ksys_write+0x81/0x180\n __x64_sys_write+0x21/0x30\n x64_sys_call+0x2f25/0x4630\n do_syscall_64+0x44/0xb0\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\nRIP: 0033:0x7f44a553c887\n\nIt can be reproduced with cammands:\ncd /sys/fs/cgroup/\nmkdir test\ncd test/\necho +cpuset > ../cgroup.subtree_control\necho root > cpuset.cpus.partition\ncat /sys/fs/cgroup/cpuset.cpus.effective\n0-3\necho 0-3 > cpuset.cpus // taking away all cpus from root\n\nThis issue is caused by the incorrect rebuilding of scheduling domains.\nIn this scenario, test/cpuset.cpus.partition should be an invalid root\nand should not trigger the rebuilding of scheduling domains. When calling\nupdate_parent_effective_cpumask with partcmd_update, if newmask is not\nnull, it should recheck newmask whether there are cpus is available\nfor parect/cs that has tasks.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44975', 'https://git.kernel.org/linus/959ab6350add903e352890af53e86663739fcb9a (6.11-rc5)', 'https://git.kernel.org/stable/c/73d6c6cf8ef6a3c532aa159f5114077746a372d6', 'https://git.kernel.org/stable/c/959ab6350add903e352890af53e86663739fcb9a', 'https://lore.kernel.org/linux-cve-announce/2024090442-CVE-2024-44975-7c21@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44975', 'https://www.cve.org/CVERecord?id=CVE-2024-44975'], 'PublishedDate': '2024-09-04T20:15:07.16Z', 'LastModifiedDate': '2024-10-03T14:32:31.677Z'}, {'VulnerabilityID': 'CVE-2024-44977', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44977', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Validate TA binary size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Validate TA binary size\n\nAdd TA binary size validation to avoid OOB write.\n\n(cherry picked from commit c0a04e3570d72aaf090962156ad085e37c62e442)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44977', 'https://git.kernel.org/linus/c99769bceab4ecb6a067b9af11f9db281eea3e2a (6.11-rc5)', 'https://git.kernel.org/stable/c/50553ea7cbd3344fbf40afb065f6a2d38171c1ad', 'https://git.kernel.org/stable/c/5ab8793b9a6cc059f503cbe6fe596f80765e0f19', 'https://git.kernel.org/stable/c/c99769bceab4ecb6a067b9af11f9db281eea3e2a', 'https://git.kernel.org/stable/c/e562415248f402203e7fb6d8c38c1b32fa99220f', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44977-7f6b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44977', 'https://www.cve.org/CVERecord?id=CVE-2024-44977'], 'PublishedDate': '2024-09-04T20:15:07.29Z', 'LastModifiedDate': '2024-10-10T17:47:59.593Z'}, {'VulnerabilityID': 'CVE-2024-44978', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44978', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Free job before xe_exec_queue_put', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Free job before xe_exec_queue_put\n\nFree job depends on job->vm being valid, the last xe_exec_queue_put can\ndestroy the VM. Prevent UAF by freeing job before xe_exec_queue_put.\n\n(cherry picked from commit 32a42c93b74c8ca6d0915ea3eba21bceff53042f)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44978', 'https://git.kernel.org/linus/9e7f30563677fbeff62d368d5d2a5ac7aaa9746a (6.11-rc5)', 'https://git.kernel.org/stable/c/98aa0330f200b9b8fb9e1298e006eda57a13351c', 'https://git.kernel.org/stable/c/9e7f30563677fbeff62d368d5d2a5ac7aaa9746a', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44978-096b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44978', 'https://www.cve.org/CVERecord?id=CVE-2024-44978'], 'PublishedDate': '2024-09-04T20:15:07.343Z', 'LastModifiedDate': '2024-09-10T16:51:19.813Z'}, {'VulnerabilityID': 'CVE-2024-44979', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44979', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Fix missing workqueue destroy in xe_gt_pagefault', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix missing workqueue destroy in xe_gt_pagefault\n\nOn driver reload we never free up the memory for the pagefault and\naccess counter workqueues. Add those destroy calls here.\n\n(cherry picked from commit 7586fc52b14e0b8edd0d1f8a434e0de2078b7b2b)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44979', 'https://git.kernel.org/linus/a6f78359ac75f24cac3c1bdd753c49c1877bcd82 (6.11-rc5)', 'https://git.kernel.org/stable/c/a6f78359ac75f24cac3c1bdd753c49c1877bcd82', 'https://git.kernel.org/stable/c/b09ef3b762a7fc641fb2f89afd3ebdb65b8ba1b9', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44979-74c3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44979', 'https://www.cve.org/CVERecord?id=CVE-2024-44979'], 'PublishedDate': '2024-09-04T20:15:07.4Z', 'LastModifiedDate': '2024-10-10T17:44:36.417Z'}, {'VulnerabilityID': 'CVE-2024-44980', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44980', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Fix opregion leak', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix opregion leak\n\nBeing part o the display, ideally the setup and cleanup would be done by\ndisplay itself. However this is a bigger refactor that needs to be done\non both i915 and xe. For now, just fix the leak:\n\nunreferenced object 0xffff8881a0300008 (size 192):\n comm "modprobe", pid 4354, jiffies 4295647021\n hex dump (first 32 bytes):\n 00 00 87 27 81 88 ff ff 18 80 9b 00 00 c9 ff ff ...\'............\n 18 81 9b 00 00 c9 ff ff 00 00 00 00 00 00 00 00 ................\n backtrace (crc 99260e31):\n [] kmemleak_alloc+0x4b/0x80\n [] kmalloc_trace_noprof+0x312/0x3d0\n [] intel_opregion_setup+0x89/0x700 [xe]\n [] xe_display_init_noirq+0x2f/0x90 [xe]\n [] xe_device_probe+0x7a3/0xbf0 [xe]\n [] xe_pci_probe+0x333/0x5b0 [xe]\n [] local_pci_probe+0x48/0xb0\n [] pci_device_probe+0xc8/0x280\n [] really_probe+0xf8/0x390\n [] __driver_probe_device+0x8a/0x170\n [] driver_probe_device+0x23/0xb0\n [] __driver_attach+0xc7/0x190\n [] bus_for_each_dev+0x7d/0xd0\n [] driver_attach+0x1e/0x30\n [] bus_add_driver+0x117/0x250\n\n(cherry picked from commit 6f4e43a2f771b737d991142ec4f6d4b7ff31fbb4)', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44980', 'https://git.kernel.org/linus/f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f (6.11-rc5)', 'https://git.kernel.org/stable/c/f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f', 'https://git.kernel.org/stable/c/f7ecdd9853dd9f34e7cdfdadfb70b8f40644ebb4', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44980-d1ba@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44980', 'https://www.cve.org/CVERecord?id=CVE-2024-44980'], 'PublishedDate': '2024-09-04T20:15:07.46Z', 'LastModifiedDate': '2024-10-10T17:42:53.433Z'}, {'VulnerabilityID': 'CVE-2024-44982', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44982', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: cleanup FB if dpu_format_populate_layout fails\n\nIf the dpu_format_populate_layout() fails, then FB is prepared, but not\ncleaned up. This ends up leaking the pin_count on the GEM object and\ncauses a splat during DRM file closure:\n\nmsm_obj->pin_count\nWARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc\n[...]\nCall trace:\n update_lru_locked+0xc4/0xcc\n put_pages+0xac/0x100\n msm_gem_free_object+0x138/0x180\n drm_gem_object_free+0x1c/0x30\n drm_gem_object_handle_put_unlocked+0x108/0x10c\n drm_gem_object_release_handle+0x58/0x70\n idr_for_each+0x68/0xec\n drm_gem_release+0x28/0x40\n drm_file_free+0x174/0x234\n drm_release+0xb0/0x160\n __fput+0xc0/0x2c8\n __fput_sync+0x50/0x5c\n __arm64_sys_close+0x38/0x7c\n invoke_syscall+0x48/0x118\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x4c/0x120\n el0t_64_sync_handler+0x100/0x12c\n el0t_64_sync+0x190/0x194\nirq event stamp: 129818\nhardirqs last enabled at (129817): [] console_unlock+0x118/0x124\nhardirqs last disabled at (129818): [] el1_dbg+0x24/0x8c\nsoftirqs last enabled at (129808): [] handle_softirqs+0x4c8/0x4e8\nsoftirqs last disabled at (129785): [] __do_softirq+0x14/0x20\n\nPatchwork: https://patchwork.freedesktop.org/patch/600714/', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44982', 'https://git.kernel.org/linus/bfa1a6283be390947d3649c482e5167186a37016 (6.11-rc5)', 'https://git.kernel.org/stable/c/02193c70723118889281f75b88722b26b58bf4ae', 'https://git.kernel.org/stable/c/7ecf85542169012765e4c2817cd3be6c2e009962', 'https://git.kernel.org/stable/c/9b8b65211a880af8fe8330a101e1e239a2d4008f', 'https://git.kernel.org/stable/c/a3c5815b07f4ee19d0b7e2ddf91ff9f03ecbf27d', 'https://git.kernel.org/stable/c/bfa1a6283be390947d3649c482e5167186a37016', 'https://lore.kernel.org/linux-cve-announce/2024090444-CVE-2024-44982-dd24@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44982', 'https://www.cve.org/CVERecord?id=CVE-2024-44982'], 'PublishedDate': '2024-09-04T20:15:07.593Z', 'LastModifiedDate': '2024-10-10T17:09:54.35Z'}, {'VulnerabilityID': 'CVE-2024-44983', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44983', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: flowtable: validate vlan header', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: validate vlan header\n\nEnsure there is sufficient room to access the protocol field of the\nVLAN header, validate it once before the flowtable lookup.\n\n=====================================================\nBUG: KMSAN: uninit-value in nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_ingress include/linux/netfilter_netdev.h:34 [inline]\n nf_ingress net/core/dev.c:5440 [inline]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44983', 'https://git.kernel.org/linus/6ea14ccb60c8ab829349979b22b58a941ec4a3ee (6.11-rc5)', 'https://git.kernel.org/stable/c/0279c35d242d037abeb73d60d06a6d1bb7f672d9', 'https://git.kernel.org/stable/c/043a18bb6cf16adaa2f8642acfde6e8956a9caaa', 'https://git.kernel.org/stable/c/6ea14ccb60c8ab829349979b22b58a941ec4a3ee', 'https://git.kernel.org/stable/c/c05155cc455785916164aa5e1b4605a2ae946537', 'https://git.kernel.org/stable/c/d9384ae7aec46036d248d1c2c2757e471ab486c3', 'https://lore.kernel.org/linux-cve-announce/2024090444-CVE-2024-44983-dcdd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44983', 'https://www.cve.org/CVERecord?id=CVE-2024-44983'], 'PublishedDate': '2024-09-04T20:15:07.657Z', 'LastModifiedDate': '2024-09-10T16:57:55.11Z'}, {'VulnerabilityID': 'CVE-2024-44984', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44984', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix double DMA unmapping for XDP_REDIRECT\n\nRemove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT\ncode path. This should have been removed when we let the page pool\nhandle the DMA mapping. This bug causes the warning:\n\nWARNING: CPU: 7 PID: 59 at drivers/iommu/dma-iommu.c:1198 iommu_dma_unmap_page+0xd5/0x100\nCPU: 7 PID: 59 Comm: ksoftirqd/7 Tainted: G W 6.8.0-1010-gcp #11-Ubuntu\nHardware name: Dell Inc. PowerEdge R7525/0PYVT1, BIOS 2.15.2 04/02/2024\nRIP: 0010:iommu_dma_unmap_page+0xd5/0x100\nCode: 89 ee 48 89 df e8 cb f2 69 ff 48 83 c4 08 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 c9 31 f6 31 ff 45 31 c0 e9 ab 17 71 00 <0f> 0b 48 83 c4 08 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 c9\nRSP: 0018:ffffab1fc0597a48 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff99ff838280c8 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffab1fc0597a78 R08: 0000000000000002 R09: ffffab1fc0597c1c\nR10: ffffab1fc0597cd3 R11: ffff99ffe375acd8 R12: 00000000e65b9000\nR13: 0000000000000050 R14: 0000000000001000 R15: 0000000000000002\nFS: 0000000000000000(0000) GS:ffff9a06efb80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000565c34c37210 CR3: 00000005c7e3e000 CR4: 0000000000350ef0\n? show_regs+0x6d/0x80\n? __warn+0x89/0x150\n? iommu_dma_unmap_page+0xd5/0x100\n? report_bug+0x16a/0x190\n? handle_bug+0x51/0xa0\n? exc_invalid_op+0x18/0x80\n? iommu_dma_unmap_page+0xd5/0x100\n? iommu_dma_unmap_page+0x35/0x100\ndma_unmap_page_attrs+0x55/0x220\n? bpf_prog_4d7e87c0d30db711_xdp_dispatcher+0x64/0x9f\nbnxt_rx_xdp+0x237/0x520 [bnxt_en]\nbnxt_rx_pkt+0x640/0xdd0 [bnxt_en]\n__bnxt_poll_work+0x1a1/0x3d0 [bnxt_en]\nbnxt_poll+0xaa/0x1e0 [bnxt_en]\n__napi_poll+0x33/0x1e0\nnet_rx_action+0x18a/0x2f0", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44984', 'https://git.kernel.org/linus/8baeef7616d5194045c5a6b97fd1246b87c55b13 (6.11-rc5)', 'https://git.kernel.org/stable/c/8baeef7616d5194045c5a6b97fd1246b87c55b13', 'https://git.kernel.org/stable/c/95a305ba259b685780ed62ea2295aa2feb2d6c0c', 'https://git.kernel.org/stable/c/fa4e6ae38574d0fc5596272bee64727d8ab7052b', 'https://lore.kernel.org/linux-cve-announce/2024090445-CVE-2024-44984-43ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44984', 'https://www.cve.org/CVERecord?id=CVE-2024-44984'], 'PublishedDate': '2024-09-04T20:15:07.717Z', 'LastModifiedDate': '2024-10-10T16:48:56.167Z'}, {'VulnerabilityID': 'CVE-2024-44985', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44985', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipv6: prevent possible UAF in ip6_xmit()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible UAF in ip6_xmit()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand the associated dst/idev could also have been freed.\n\nWe must use rcu_read_lock() to prevent a possible UAF.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44985', 'https://git.kernel.org/linus/2d5ff7e339d04622d8282661df36151906d0e1c7 (6.11-rc5)', 'https://git.kernel.org/stable/c/124b428fe28064c809e4237b0b38e97200a8a4a8', 'https://git.kernel.org/stable/c/2d5ff7e339d04622d8282661df36151906d0e1c7', 'https://git.kernel.org/stable/c/38a21c026ed2cc7232414cb166efc1923f34af17', 'https://git.kernel.org/stable/c/975f764e96f71616b530e300c1bb2ac0ce0c2596', 'https://git.kernel.org/stable/c/fc88d6c1f2895a5775795d82ec581afdff7661d1', 'https://lore.kernel.org/linux-cve-announce/2024090445-CVE-2024-44985-2dde@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44985', 'https://www.cve.org/CVERecord?id=CVE-2024-44985'], 'PublishedDate': '2024-09-04T20:15:07.777Z', 'LastModifiedDate': '2024-09-05T17:54:11.313Z'}, {'VulnerabilityID': 'CVE-2024-44986', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44986', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipv6: fix possible UAF in ip6_finish_output2()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in ip6_finish_output2()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand associated dst/idev could also have been freed.\n\nWe need to hold rcu_read_lock() to make sure the dst and\nassociated idev are alive.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44986', 'https://git.kernel.org/linus/da273b377ae0d9bd255281ed3c2adb228321687b (6.11-rc5)', 'https://git.kernel.org/stable/c/3574d28caf9a09756ae87ad1ea096c6f47b6101e', 'https://git.kernel.org/stable/c/56efc253196751ece1fc535a5b582be127b0578a', 'https://git.kernel.org/stable/c/6ab6bf731354a6fdbaa617d1ec194960db61cf3b', 'https://git.kernel.org/stable/c/da273b377ae0d9bd255281ed3c2adb228321687b', 'https://git.kernel.org/stable/c/e891b36de161fcd96f12ff83667473e5067b9037', 'https://lore.kernel.org/linux-cve-announce/2024090445-CVE-2024-44986-1197@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44986', 'https://www.cve.org/CVERecord?id=CVE-2024-44986'], 'PublishedDate': '2024-09-04T20:15:07.833Z', 'LastModifiedDate': '2024-09-05T17:54:04.127Z'}, {'VulnerabilityID': 'CVE-2024-44987', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44987', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipv6: prevent UAF in ip6_send_skb()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent UAF in ip6_send_skb()\n\nsyzbot reported an UAF in ip6_send_skb() [1]\n\nAfter ip6_local_out() has returned, we no longer can safely\ndereference rt, unless we hold rcu_read_lock().\n\nA similar issue has been fixed in commit\na688caa34beb ("ipv6: take rcu lock in rawv6_send_hdrinc()")\n\nAnother potential issue in ip6_finish_output2() is handled in a\nseparate patch.\n\n[1]\n BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\nRead of size 8 at addr ffff88806dde4858 by task syz.1.380/6530\n\nCPU: 1 UID: 0 PID: 6530 Comm: syz.1.380 Not tainted 6.11.0-rc3-syzkaller-00306-gdf6cbc62cc9b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\n rawv6_push_pending_frames+0x75c/0x9e0 net/ipv6/raw.c:588\n rawv6_sendmsg+0x19c7/0x23c0 net/ipv6/raw.c:926\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n sock_write_iter+0x2dd/0x400 net/socket.c:1160\n do_iter_readv_writev+0x60a/0x890\n vfs_writev+0x37c/0xbb0 fs/read_write.c:971\n do_writev+0x1b1/0x350 fs/read_write.c:1018\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f936bf79e79\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f936cd7f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000014\nRAX: ffffffffffffffda RBX: 00007f936c115f80 RCX: 00007f936bf79e79\nRDX: 0000000000000001 RSI: 0000000020000040 RDI: 0000000000000004\nRBP: 00007f936bfe7916 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f936c115f80 R15: 00007fff2860a7a8\n \n\nAllocated by task 6530:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:312 [inline]\n __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:338\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3988 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_noprof+0x135/0x2a0 mm/slub.c:4044\n dst_alloc+0x12b/0x190 net/core/dst.c:89\n ip6_blackhole_route+0x59/0x340 net/ipv6/route.c:2670\n make_blackhole net/xfrm/xfrm_policy.c:3120 [inline]\n xfrm_lookup_route+0xd1/0x1c0 net/xfrm/xfrm_policy.c:3313\n ip6_dst_lookup_flow+0x13e/0x180 net/ipv6/ip6_output.c:1257\n rawv6_sendmsg+0x1283/0x23c0 net/ipv6/raw.c:898\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597\n ___sys_sendmsg net/socket.c:2651 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2680\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 45:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2252 [inline]\n slab_free mm/slub.c:4473 [inline]\n kmem_cache_free+0x145/0x350 mm/slub.c:4548\n dst_destroy+0x2ac/0x460 net/core/dst.c:124\n rcu_do_batch kernel/rcu/tree.c:2569 [inline]\n rcu_core+0xafd/0x1830 kernel/rcu/tree.\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44987', 'https://git.kernel.org/linus/faa389b2fbaaec7fd27a390b4896139f9da662e3 (6.11-rc5)', 'https://git.kernel.org/stable/c/24e93695b1239fbe4c31e224372be77f82dab69a', 'https://git.kernel.org/stable/c/571567e0277008459750f0728f246086b2659429', 'https://git.kernel.org/stable/c/9a3e55afa95ed4ac9eda112d4f918af645d72f25', 'https://git.kernel.org/stable/c/af1dde074ee2ed7dd5bdca4e7e8ba17f44e7b011', 'https://git.kernel.org/stable/c/cb5880a0de12c7f618d2bdd84e2d985f1e06ed7e', 'https://git.kernel.org/stable/c/ce2f6cfab2c637d0bd9762104023a15d0ab7c0a8', 'https://git.kernel.org/stable/c/e44bd76dd072756e674f45c5be00153f4ded68b2', 'https://git.kernel.org/stable/c/faa389b2fbaaec7fd27a390b4896139f9da662e3', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44987-f916@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44987', 'https://www.cve.org/CVERecord?id=CVE-2024-44987'], 'PublishedDate': '2024-09-04T20:15:07.89Z', 'LastModifiedDate': '2024-09-05T17:53:54.687Z'}, {'VulnerabilityID': 'CVE-2024-44988', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44988', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: mv88e6xxx: Fix out-of-bound access', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Fix out-of-bound access\n\nIf an ATU violation was caused by a CPU Load operation, the SPID could\nbe larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44988', 'https://git.kernel.org/linus/528876d867a23b5198022baf2e388052ca67c952 (6.11-rc5)', 'https://git.kernel.org/stable/c/050e7274ab2150cd212b2372595720e7b83a15bd', 'https://git.kernel.org/stable/c/18b2e833daf049223ab3c2efdf8cdee08854c484', 'https://git.kernel.org/stable/c/528876d867a23b5198022baf2e388052ca67c952', 'https://git.kernel.org/stable/c/a10d0337115a6d223a1563d853d4455f05d0b2e3', 'https://git.kernel.org/stable/c/d39f5be62f098fe367d672b4dd4bc4b2b80e08e7', 'https://git.kernel.org/stable/c/f7d8c2fabd39250cf2333fbf8eef67e837f90a5d', 'https://git.kernel.org/stable/c/f87ce03c652dba199aef15ac18ade3991db5477e', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44988-516a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44988', 'https://www.cve.org/CVERecord?id=CVE-2024-44988'], 'PublishedDate': '2024-09-04T20:15:07.96Z', 'LastModifiedDate': '2024-10-10T16:44:14.767Z'}, {'VulnerabilityID': 'CVE-2024-44989', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44989', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bonding: fix xfrm real_dev null pointer dereference', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix xfrm real_dev null pointer dereference\n\nWe shouldn't set real_dev to NULL because packets can be in transit and\nxfrm might call xdo_dev_offload_ok() in parallel. All callbacks assume\nreal_dev is set.\n\n Example trace:\n kernel: BUG: unable to handle page fault for address: 0000000000001030\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: #PF: supervisor write access in kernel mode\n kernel: #PF: error_code(0x0002) - not-present page\n kernel: PGD 0 P4D 0\n kernel: Oops: 0002 [#1] PREEMPT SMP\n kernel: CPU: 4 PID: 2237 Comm: ping Not tainted 6.7.7+ #12\n kernel: Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\n kernel: RIP: 0010:nsim_ipsec_offload_ok+0xc/0x20 [netdevsim]\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: Code: e0 0f 0b 48 83 7f 38 00 74 de 0f 0b 48 8b 47 08 48 8b 37 48 8b 78 40 e9 b2 e5 9a d7 66 90 0f 1f 44 00 00 48 8b 86 80 02 00 00 <83> 80 30 10 00 00 01 b8 01 00 00 00 c3 0f 1f 80 00 00 00 00 0f 1f\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: RSP: 0018:ffffabde81553b98 EFLAGS: 00010246\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel:\n kernel: RAX: 0000000000000000 RBX: ffff9eb404e74900 RCX: ffff9eb403d97c60\n kernel: RDX: ffffffffc090de10 RSI: ffff9eb404e74900 RDI: ffff9eb3c5de9e00\n kernel: RBP: ffff9eb3c0a42000 R08: 0000000000000010 R09: 0000000000000014\n kernel: R10: 7974203030303030 R11: 3030303030303030 R12: 0000000000000000\n kernel: R13: ffff9eb3c5de9e00 R14: ffffabde81553cc8 R15: ffff9eb404c53000\n kernel: FS: 00007f2a77a3ad00(0000) GS:ffff9eb43bd00000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 0000000000001030 CR3: 00000001122ab000 CR4: 0000000000350ef0\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: Call Trace:\n kernel: \n kernel: ? __die+0x1f/0x60\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ? page_fault_oops+0x142/0x4c0\n kernel: ? do_user_addr_fault+0x65/0x670\n kernel: ? kvm_read_and_reset_apf_flags+0x3b/0x50\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: ? exc_page_fault+0x7b/0x180\n kernel: ? asm_exc_page_fault+0x22/0x30\n kernel: ? nsim_bpf_uninit+0x50/0x50 [netdevsim]\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ? nsim_ipsec_offload_ok+0xc/0x20 [netdevsim]\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: bond_ipsec_offload_ok+0x7b/0x90 [bonding]\n kernel: xfrm_output+0x61/0x3b0\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ip_push_pending_frames+0x56/0x80", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44989', 'https://git.kernel.org/linus/f8cde9805981c50d0c029063dc7d82821806fc44 (6.11-rc5)', 'https://git.kernel.org/stable/c/21816b696c172c19d53a30d45ee005cce246ed21', 'https://git.kernel.org/stable/c/2f72c6a66bcd7e0187ec085237fee5db27145294', 'https://git.kernel.org/stable/c/4582d4ff413a07d4ed8a4823c652dc5207760548', 'https://git.kernel.org/stable/c/7fa9243391ad2afe798ef4ea2e2851947b95754f', 'https://git.kernel.org/stable/c/89fc1dca79db5c3e7a2d589ecbf8a3661c65f436', 'https://git.kernel.org/stable/c/f8cde9805981c50d0c029063dc7d82821806fc44', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44989-8a2d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44989', 'https://www.cve.org/CVERecord?id=CVE-2024-44989'], 'PublishedDate': '2024-09-04T20:15:08.02Z', 'LastModifiedDate': '2024-09-06T16:31:22.253Z'}, {'VulnerabilityID': 'CVE-2024-44990', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44990', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bonding: fix null pointer deref in bond_ipsec_offload_ok', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix null pointer deref in bond_ipsec_offload_ok\n\nWe must check if there is an active slave before dereferencing the pointer.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44990', 'https://git.kernel.org/linus/95c90e4ad89d493a7a14fa200082e466e2548f9d (6.11-rc5)', 'https://git.kernel.org/stable/c/0707260a18312bbcd2a5668584e3692d0a29e3f6', 'https://git.kernel.org/stable/c/2f5bdd68c1ce64bda6bef4d361a3de23b04ccd59', 'https://git.kernel.org/stable/c/32a0173600c63aadaf2103bf02f074982e8602ab', 'https://git.kernel.org/stable/c/81216b9352be43f8958092d379f6dec85443c309', 'https://git.kernel.org/stable/c/95c90e4ad89d493a7a14fa200082e466e2548f9d', 'https://git.kernel.org/stable/c/b70b0ddfed31fc92c8dc722d0afafc8e14cb550c', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44990-6b62@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44990', 'https://www.cve.org/CVERecord?id=CVE-2024-44990'], 'PublishedDate': '2024-09-04T20:15:08.087Z', 'LastModifiedDate': '2024-09-06T16:31:12.87Z'}, {'VulnerabilityID': 'CVE-2024-44991', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44991', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp: prevent concurrent execution of tcp_sk_exit_batch', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: prevent concurrent execution of tcp_sk_exit_batch\n\nIts possible that two threads call tcp_sk_exit_batch() concurrently,\nonce from the cleanup_net workqueue, once from a task that failed to clone\na new netns. In the latter case, error unwinding calls the exit handlers\nin reverse order for the \'failed\' netns.\n\ntcp_sk_exit_batch() calls tcp_twsk_purge().\nProblem is that since commit b099ce2602d8 ("net: Batch inet_twsk_purge"),\nthis function picks up twsk in any dying netns, not just the one passed\nin via exit_batch list.\n\nThis means that the error unwind of setup_net() can "steal" and destroy\ntimewait sockets belonging to the exiting netns.\n\nThis allows the netns exit worker to proceed to call\n\nWARN_ON_ONCE(!refcount_dec_and_test(&net->ipv4.tcp_death_row.tw_refcount));\n\nwithout the expected 1 -> 0 transition, which then splats.\n\nAt same time, error unwind path that is also running inet_twsk_purge()\nwill splat as well:\n\nWARNING: .. at lib/refcount.c:31 refcount_warn_saturate+0x1ed/0x210\n...\n refcount_dec include/linux/refcount.h:351 [inline]\n inet_twsk_kill+0x758/0x9c0 net/ipv4/inet_timewait_sock.c:70\n inet_twsk_deschedule_put net/ipv4/inet_timewait_sock.c:221\n inet_twsk_purge+0x725/0x890 net/ipv4/inet_timewait_sock.c:304\n tcp_sk_exit_batch+0x1c/0x170 net/ipv4/tcp_ipv4.c:3522\n ops_exit_list+0x128/0x180 net/core/net_namespace.c:178\n setup_net+0x714/0xb40 net/core/net_namespace.c:375\n copy_net_ns+0x2f0/0x670 net/core/net_namespace.c:508\n create_new_namespaces+0x3ea/0xb10 kernel/nsproxy.c:110\n\n... because refcount_dec() of tw_refcount unexpectedly dropped to 0.\n\nThis doesn\'t seem like an actual bug (no tw sockets got lost and I don\'t\nsee a use-after-free) but as erroneous trigger of debug check.\n\nAdd a mutex to force strict ordering: the task that calls tcp_twsk_purge()\nblocks other task from doing final _dec_and_test before mutex-owner has\nremoved all tw sockets of dying netns.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44991', 'https://git.kernel.org/linus/565d121b69980637f040eb4d84289869cdaabedf (6.11-rc5)', 'https://git.kernel.org/stable/c/565d121b69980637f040eb4d84289869cdaabedf', 'https://git.kernel.org/stable/c/99580ae890ec8bd98b21a2a9c6668f8f1555b62e', 'https://git.kernel.org/stable/c/e3d9de3742f4d5c47ae35f888d3023a5b54fcd2f', 'https://git.kernel.org/stable/c/f6fd2dbf584a4047ba88d1369ff91c9851261ec1', 'https://lore.kernel.org/linux-cve-announce/2024090447-CVE-2024-44991-2437@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44991', 'https://www.cve.org/CVERecord?id=CVE-2024-44991'], 'PublishedDate': '2024-09-04T20:15:08.15Z', 'LastModifiedDate': '2024-10-09T14:36:15.79Z'}, {'VulnerabilityID': 'CVE-2024-44993', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44993', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()`', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()`\n\nWhen enabling UBSAN on Raspberry Pi 5, we get the following warning:\n\n[ 387.894977] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/v3d/v3d_sched.c:320:3\n[ 387.903868] index 7 is out of range for type '__u32 [7]'\n[ 387.909692] CPU: 0 PID: 1207 Comm: kworker/u16:2 Tainted: G WC 6.10.3-v8-16k-numa #151\n[ 387.919166] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT)\n[ 387.925961] Workqueue: v3d_csd drm_sched_run_job_work [gpu_sched]\n[ 387.932525] Call trace:\n[ 387.935296] dump_backtrace+0x170/0x1b8\n[ 387.939403] show_stack+0x20/0x38\n[ 387.942907] dump_stack_lvl+0x90/0xd0\n[ 387.946785] dump_stack+0x18/0x28\n[ 387.950301] __ubsan_handle_out_of_bounds+0x98/0xd0\n[ 387.955383] v3d_csd_job_run+0x3a8/0x438 [v3d]\n[ 387.960707] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched]\n[ 387.966862] process_one_work+0x62c/0xb48\n[ 387.971296] worker_thread+0x468/0x5b0\n[ 387.975317] kthread+0x1c4/0x1e0\n[ 387.978818] ret_from_fork+0x10/0x20\n[ 387.983014] ---[ end trace ]---\n\nThis happens because the UAPI provides only seven configuration\nregisters and we are reading the eighth position of this u32 array.\n\nTherefore, fix the out-of-bounds read in `v3d_csd_job_run()` by\naccessing only seven positions on the '__u32 [7]' array. The eighth\nregister exists indeed on V3D 7.1, but it isn't currently used. That\nbeing so, let's guarantee that it remains unused and add a note that it\ncould be set in a future patch.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44993', 'https://git.kernel.org/linus/497d370a644d95a9f04271aa92cb96d32e84c770 (6.11-rc4)', 'https://git.kernel.org/stable/c/497d370a644d95a9f04271aa92cb96d32e84c770', 'https://git.kernel.org/stable/c/d656b82c4b30cf12715e6cd129d3df808fde24a7', 'https://lore.kernel.org/linux-cve-announce/2024090447-CVE-2024-44993-b6db@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44993', 'https://www.cve.org/CVERecord?id=CVE-2024-44993'], 'PublishedDate': '2024-09-04T20:15:08.257Z', 'LastModifiedDate': '2024-09-06T16:28:49.18Z'}, {'VulnerabilityID': 'CVE-2024-44995', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44995', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: hns3: fix a deadlock problem when config TC during resetting', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix a deadlock problem when config TC during resetting\n\nWhen config TC during the reset process, may cause a deadlock, the flow is\nas below:\n pf reset start\n │\n ▼\n ......\nsetup tc │\n │ ▼\n ▼ DOWN: napi_disable()\nnapi_disable()(skip) │\n │ │\n ▼ ▼\n ...... ......\n │ │\n ▼ │\nnapi_enable() │\n ▼\n UINIT: netif_napi_del()\n │\n ▼\n ......\n │\n ▼\n INIT: netif_napi_add()\n │\n ▼\n ...... global reset start\n │ │\n ▼ ▼\n UP: napi_enable()(skip) ......\n │ │\n ▼ ▼\n ...... napi_disable()\n\nIn reset process, the driver will DOWN the port and then UINIT, in this\ncase, the setup tc process will UP the port before UINIT, so cause the\nproblem. Adds a DOWN process in UINIT to fix it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44995', 'https://git.kernel.org/linus/be5e816d00a506719e9dbb1a9c861c5ced30a109 (6.11-rc4)', 'https://git.kernel.org/stable/c/195918217448a6bb7f929d6a2ffffce9f1ece1cc', 'https://git.kernel.org/stable/c/67492d4d105c0a6321b00c393eec96b9a7a97a16', 'https://git.kernel.org/stable/c/6ae2b7d63cd056f363045eb65409143e16f23ae8', 'https://git.kernel.org/stable/c/be5e816d00a506719e9dbb1a9c861c5ced30a109', 'https://git.kernel.org/stable/c/de37408d5c26fc4a296a28a0c96dcb814219bfa1', 'https://git.kernel.org/stable/c/fa1d4de7265c370e673583ac8d1bd17d21826cd9', 'https://git.kernel.org/stable/c/fc250eca15bde34c4c8f806b9d88f55bd56a992c', 'https://lore.kernel.org/linux-cve-announce/2024090448-CVE-2024-44995-16e5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44995', 'https://www.cve.org/CVERecord?id=CVE-2024-44995'], 'PublishedDate': '2024-09-04T20:15:08.353Z', 'LastModifiedDate': '2024-09-15T18:15:34.54Z'}, {'VulnerabilityID': 'CVE-2024-44996', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44996', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: vsock: fix recursive ->recvmsg calls', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: fix recursive ->recvmsg calls\n\nAfter a vsock socket has been added to a BPF sockmap, its prot->recvmsg\nhas been replaced with vsock_bpf_recvmsg(). Thus the following\nrecursiion could happen:\n\nvsock_bpf_recvmsg()\n -> __vsock_recvmsg()\n -> vsock_connectible_recvmsg()\n -> prot->recvmsg()\n -> vsock_bpf_recvmsg() again\n\nWe need to fix it by calling the original ->recvmsg() without any BPF\nsockmap logic in __vsock_recvmsg().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44996', 'https://git.kernel.org/linus/69139d2919dd4aa9a553c8245e7c63e82613e3fc (6.11-rc4)', 'https://git.kernel.org/stable/c/69139d2919dd4aa9a553c8245e7c63e82613e3fc', 'https://git.kernel.org/stable/c/921f1acf0c3cf6b1260ab57a8a6e8b3d5f3023d5', 'https://git.kernel.org/stable/c/b4ee8cf1acc5018ed1369150d7bb3e0d0f79e135', 'https://lore.kernel.org/linux-cve-announce/2024090448-CVE-2024-44996-8b26@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44996', 'https://www.cve.org/CVERecord?id=CVE-2024-44996'], 'PublishedDate': '2024-09-04T20:15:08.413Z', 'LastModifiedDate': '2024-09-16T12:21:47.37Z'}, {'VulnerabilityID': 'CVE-2024-44998', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44998', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: atm: idt77252: prevent use after free in dequeue_rx()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\natm: idt77252: prevent use after free in dequeue_rx()\n\nWe can\'t dereference "skb" after calling vcc->push() because the skb\nis released.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44998', 'https://git.kernel.org/linus/a9a18e8f770c9b0703dab93580d0b02e199a4c79 (6.11-rc4)', 'https://git.kernel.org/stable/c/09e086a5f72ea27c758b3f3b419a69000c32adc1', 'https://git.kernel.org/stable/c/1cece837e387c039225f19028df255df87a97c0d', 'https://git.kernel.org/stable/c/24cf390a5426aac9255205e9533cdd7b4235d518', 'https://git.kernel.org/stable/c/379a6a326514a3e2f71b674091dfb0e0e7522b55', 'https://git.kernel.org/stable/c/628ea82190a678a56d2ec38cda3addf3b3a6248d', 'https://git.kernel.org/stable/c/91b4850e7165a4b7180ef1e227733bcb41ccdf10', 'https://git.kernel.org/stable/c/a9a18e8f770c9b0703dab93580d0b02e199a4c79', 'https://git.kernel.org/stable/c/ef23c18ab88e33ce000d06a5c6aad0620f219bfd', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-44998-6505@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44998', 'https://www.cve.org/CVERecord?id=CVE-2024-44998'], 'PublishedDate': '2024-09-04T20:15:08.52Z', 'LastModifiedDate': '2024-09-06T16:28:16Z'}, {'VulnerabilityID': 'CVE-2024-44999', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44999', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gtp: pull network headers in gtp_dev_xmit()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: pull network headers in gtp_dev_xmit()\n\nsyzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1]\n\nWe must make sure the IPv4 or Ipv6 header is pulled in skb->head\nbefore accessing fields in them.\n\nUse pskb_inet_may_pull() to fix this issue.\n\n[1]\nBUG: KMSAN: uninit-value in ipv6_pdp_find drivers/net/gtp.c:220 [inline]\n BUG: KMSAN: uninit-value in gtp_build_skb_ip6 drivers/net/gtp.c:1229 [inline]\n BUG: KMSAN: uninit-value in gtp_dev_xmit+0x1424/0x2540 drivers/net/gtp.c:1281\n ipv6_pdp_find drivers/net/gtp.c:220 [inline]\n gtp_build_skb_ip6 drivers/net/gtp.c:1229 [inline]\n gtp_dev_xmit+0x1424/0x2540 drivers/net/gtp.c:1281\n __netdev_start_xmit include/linux/netdevice.h:4913 [inline]\n netdev_start_xmit include/linux/netdevice.h:4922 [inline]\n xmit_one net/core/dev.c:3580 [inline]\n dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3596\n __dev_queue_xmit+0x358c/0x5610 net/core/dev.c:4423\n dev_queue_xmit include/linux/netdevice.h:3105 [inline]\n packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3145 [inline]\n packet_sendmsg+0x90e3/0xa3a0 net/packet/af_packet.c:3177\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n __sys_sendto+0x685/0x830 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2212\n x64_sys_call+0x3799/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3994 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4080\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:583\n __alloc_skb+0x363/0x7b0 net/core/skbuff.c:674\n alloc_skb include/linux/skbuff.h:1320 [inline]\n alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6526\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2815\n packet_alloc_skb net/packet/af_packet.c:2994 [inline]\n packet_snd net/packet/af_packet.c:3088 [inline]\n packet_sendmsg+0x749c/0xa3a0 net/packet/af_packet.c:3177\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n __sys_sendto+0x685/0x830 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2212\n x64_sys_call+0x3799/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCPU: 0 UID: 0 PID: 7115 Comm: syz.1.515 Not tainted 6.11.0-rc1-syzkaller-00043-g94ede2a3e913 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44999', 'https://git.kernel.org/linus/3a3be7ff9224f424e485287b54be00d2c6bd9c40 (6.11-rc4)', 'https://git.kernel.org/stable/c/137d565ab89ce3584503b443bc9e00d44f482593', 'https://git.kernel.org/stable/c/1f6b62392453d8f36685d19b761307a8c5617ac1', 'https://git.kernel.org/stable/c/34ba4f29f3d9eb52dee37512059efb2afd7e966f', 'https://git.kernel.org/stable/c/3939d787139e359b77aaf9485d1e145d6713d7b9', 'https://git.kernel.org/stable/c/3a3be7ff9224f424e485287b54be00d2c6bd9c40', 'https://git.kernel.org/stable/c/3d89d0c4a1c6d4d2a755e826351b0a101dbc86f3', 'https://git.kernel.org/stable/c/cbb9a969fc190e85195d1b0f08038e7f6199044e', 'https://git.kernel.org/stable/c/f5dda8db382c5751c4e572afc7c99df7da1f83ca', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-44999-187d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44999', 'https://www.cve.org/CVERecord?id=CVE-2024-44999'], 'PublishedDate': '2024-09-04T20:15:08.59Z', 'LastModifiedDate': '2024-09-06T16:27:51.89Z'}, {'VulnerabilityID': 'CVE-2024-45000', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45000', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fs/netfs/fscache_cookie: add missing "n_accesses" check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/netfs/fscache_cookie: add missing "n_accesses" check\n\nThis fixes a NULL pointer dereference bug due to a data race which\nlooks like this:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000008\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP PTI\n CPU: 33 PID: 16573 Comm: kworker/u97:799 Not tainted 6.8.7-cm4all1-hp+ #43\n Hardware name: HP ProLiant DL380 Gen9/ProLiant DL380 Gen9, BIOS P89 10/17/2018\n Workqueue: events_unbound netfs_rreq_write_to_cache_work\n RIP: 0010:cachefiles_prepare_write+0x30/0xa0\n Code: 57 41 56 45 89 ce 41 55 49 89 cd 41 54 49 89 d4 55 53 48 89 fb 48 83 ec 08 48 8b 47 08 48 83 7f 10 00 48 89 34 24 48 8b 68 20 <48> 8b 45 08 4c 8b 38 74 45 49 8b 7f 50 e8 4e a9 b0 ff 48 8b 73 10\n RSP: 0018:ffffb4e78113bde0 EFLAGS: 00010286\n RAX: ffff976126be6d10 RBX: ffff97615cdb8438 RCX: 0000000000020000\n RDX: ffff97605e6c4c68 RSI: ffff97605e6c4c60 RDI: ffff97615cdb8438\n RBP: 0000000000000000 R08: 0000000000278333 R09: 0000000000000001\n R10: ffff97605e6c4600 R11: 0000000000000001 R12: ffff97605e6c4c68\n R13: 0000000000020000 R14: 0000000000000001 R15: ffff976064fe2c00\n FS: 0000000000000000(0000) GS:ffff9776dfd40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000005942c002 CR4: 00000000001706f0\n Call Trace:\n \n ? __die+0x1f/0x70\n ? page_fault_oops+0x15d/0x440\n ? search_module_extables+0xe/0x40\n ? fixup_exception+0x22/0x2f0\n ? exc_page_fault+0x5f/0x100\n ? asm_exc_page_fault+0x22/0x30\n ? cachefiles_prepare_write+0x30/0xa0\n netfs_rreq_write_to_cache_work+0x135/0x2e0\n process_one_work+0x137/0x2c0\n worker_thread+0x2e9/0x400\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xcc/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x30/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n Modules linked in:\n CR2: 0000000000000008\n ---[ end trace 0000000000000000 ]---\n\nThis happened because fscache_cookie_state_machine() was slow and was\nstill running while another process invoked fscache_unuse_cookie();\nthis led to a fscache_cookie_lru_do_one() call, setting the\nFSCACHE_COOKIE_DO_LRU_DISCARD flag, which was picked up by\nfscache_cookie_state_machine(), withdrawing the cookie via\ncachefiles_withdraw_cookie(), clearing cookie->cache_priv.\n\nAt the same time, yet another process invoked\ncachefiles_prepare_write(), which found a NULL pointer in this code\nline:\n\n struct cachefiles_object *object = cachefiles_cres_object(cres);\n\nThe next line crashes, obviously:\n\n struct cachefiles_cache *cache = object->volume->cache;\n\nDuring cachefiles_prepare_write(), the "n_accesses" counter is\nnon-zero (via fscache_begin_operation()). The cookie must not be\nwithdrawn until it drops to zero.\n\nThe counter is checked by fscache_cookie_state_machine() before\nswitching to FSCACHE_COOKIE_STATE_RELINQUISHING and\nFSCACHE_COOKIE_STATE_WITHDRAWING (in "case\nFSCACHE_COOKIE_STATE_FAILED"), but not for\nFSCACHE_COOKIE_STATE_LRU_DISCARDING ("case\nFSCACHE_COOKIE_STATE_ACTIVE").\n\nThis patch adds the missing check. With a non-zero access counter,\nthe function returns and the next fscache_end_cookie_access() call\nwill queue another fscache_cookie_state_machine() call to handle the\nstill-pending FSCACHE_COOKIE_DO_LRU_DISCARD.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45000', 'https://git.kernel.org/linus/f71aa06398aabc2e3eaac25acdf3d62e0094ba70 (6.11-rc4)', 'https://git.kernel.org/stable/c/0a4d41fa14b2a0efd40e350cfe8ec6a4c998ac1d', 'https://git.kernel.org/stable/c/b8a50877f68efdcc0be3fcc5116e00c31b90e45b', 'https://git.kernel.org/stable/c/dfaa39b05a6cf34a16c525a2759ee6ab26b5fef6', 'https://git.kernel.org/stable/c/f71aa06398aabc2e3eaac25acdf3d62e0094ba70', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-45000-fd6f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45000', 'https://www.cve.org/CVERecord?id=CVE-2024-45000'], 'PublishedDate': '2024-09-04T20:15:08.657Z', 'LastModifiedDate': '2024-09-06T16:27:31.003Z'}, {'VulnerabilityID': 'CVE-2024-45001', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45001', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: mana: Fix RX buf alloc_size alignment and atomic op panic', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix RX buf alloc_size alignment and atomic op panic\n\nThe MANA driver's RX buffer alloc_size is passed into napi_build_skb() to\ncreate SKB. skb_shinfo(skb) is located at the end of skb, and its alignment\nis affected by the alloc_size passed into napi_build_skb(). The size needs\nto be aligned properly for better performance and atomic operations.\nOtherwise, on ARM64 CPU, for certain MTU settings like 4000, atomic\noperations may panic on the skb_shinfo(skb)->dataref due to alignment fault.\n\nTo fix this bug, add proper alignment to the alloc_size calculation.\n\nSample panic info:\n[ 253.298819] Unable to handle kernel paging request at virtual address ffff000129ba5cce\n[ 253.300900] Mem abort info:\n[ 253.301760] ESR = 0x0000000096000021\n[ 253.302825] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 253.304268] SET = 0, FnV = 0\n[ 253.305172] EA = 0, S1PTW = 0\n[ 253.306103] FSC = 0x21: alignment fault\nCall trace:\n __skb_clone+0xfc/0x198\n skb_clone+0x78/0xe0\n raw6_local_deliver+0xfc/0x228\n ip6_protocol_deliver_rcu+0x80/0x500\n ip6_input_finish+0x48/0x80\n ip6_input+0x48/0xc0\n ip6_sublist_rcv_finish+0x50/0x78\n ip6_sublist_rcv+0x1cc/0x2b8\n ipv6_list_rcv+0x100/0x150\n __netif_receive_skb_list_core+0x180/0x220\n netif_receive_skb_list_internal+0x198/0x2a8\n __napi_poll+0x138/0x250\n net_rx_action+0x148/0x330\n handle_softirqs+0x12c/0x3a0", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45001', 'https://git.kernel.org/linus/32316f676b4ee87c0404d333d248ccf777f739bc (6.11-rc4)', 'https://git.kernel.org/stable/c/32316f676b4ee87c0404d333d248ccf777f739bc', 'https://git.kernel.org/stable/c/65f20b174ec0172f2d6bcfd8533ab9c9e7e347fa', 'https://git.kernel.org/stable/c/e6bea6a45f8a401f3d5a430bc81814f0cc8848cf', 'https://lore.kernel.org/linux-cve-announce/2024090450-CVE-2024-45001-50df@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45001', 'https://ubuntu.com/security/notices/USN-7074-1', 'https://ubuntu.com/security/notices/USN-7076-1', 'https://www.cve.org/CVERecord?id=CVE-2024-45001'], 'PublishedDate': '2024-09-04T20:15:08.71Z', 'LastModifiedDate': '2024-10-09T14:49:39.953Z'}, {'VulnerabilityID': 'CVE-2024-45002', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45002', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: rtla/osnoise: Prevent NULL dereference in error handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrtla/osnoise: Prevent NULL dereference in error handling\n\nIf the "tool->data" allocation fails then there is no need to call\nosnoise_free_top() and, in fact, doing so will lead to a NULL dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45002', 'https://git.kernel.org/linus/90574d2a675947858b47008df8d07f75ea50d0d0 (6.11-rc4)', 'https://git.kernel.org/stable/c/753f1745146e03abd17eec8eee95faffc96d743d', 'https://git.kernel.org/stable/c/90574d2a675947858b47008df8d07f75ea50d0d0', 'https://git.kernel.org/stable/c/abdb9ddaaab476e62805e36cce7b4ef8413ffd01', 'https://git.kernel.org/stable/c/fc575212c6b75d538e1a0a74f4c7e2ac73bc46ac', 'https://lore.kernel.org/linux-cve-announce/2024090450-CVE-2024-45002-c292@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45002', 'https://www.cve.org/CVERecord?id=CVE-2024-45002'], 'PublishedDate': '2024-09-04T20:15:08.763Z', 'LastModifiedDate': '2024-09-06T16:27:13.727Z'}, {'VulnerabilityID': 'CVE-2024-45003', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45003', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: vfs: Don't evict inode under the inode lru traversing context", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nvfs: Don't evict inode under the inode lru traversing context\n\nThe inode reclaiming process(See function prune_icache_sb) collects all\nreclaimable inodes and mark them with I_FREEING flag at first, at that\ntime, other processes will be stuck if they try getting these inodes\n(See function find_inode_fast), then the reclaiming process destroy the\ninodes by function dispose_list(). Some filesystems(eg. ext4 with\nea_inode feature, ubifs with xattr) may do inode lookup in the inode\nevicting callback function, if the inode lookup is operated under the\ninode lru traversing context, deadlock problems may happen.\n\nCase 1: In function ext4_evict_inode(), the ea inode lookup could happen\n if ea_inode feature is enabled, the lookup process will be stuck\n\tunder the evicting context like this:\n\n 1. File A has inode i_reg and an ea inode i_ea\n 2. getfattr(A, xattr_buf) // i_ea is added into lru // lru->i_ea\n 3. Then, following three processes running like this:\n\n PA PB\n echo 2 > /proc/sys/vm/drop_caches\n shrink_slab\n prune_dcache_sb\n // i_reg is added into lru, lru->i_ea->i_reg\n prune_icache_sb\n list_lru_walk_one\n inode_lru_isolate\n i_ea->i_state |= I_FREEING // set inode state\n inode_lru_isolate\n __iget(i_reg)\n spin_unlock(&i_reg->i_lock)\n spin_unlock(lru_lock)\n rm file A\n i_reg->nlink = 0\n iput(i_reg) // i_reg->nlink is 0, do evict\n ext4_evict_inode\n ext4_xattr_delete_inode\n ext4_xattr_inode_dec_ref_all\n ext4_xattr_inode_iget\n ext4_iget(i_ea->i_ino)\n iget_locked\n find_inode_fast\n __wait_on_freeing_inode(i_ea) ----? AA deadlock\n dispose_list // cannot be executed by prune_icache_sb\n wake_up_bit(&i_ea->i_state)\n\nCase 2: In deleted inode writing function ubifs_jnl_write_inode(), file\n deleting process holds BASEHD's wbuf->io_mutex while getting the\n\txattr inode, which could race with inode reclaiming process(The\n reclaiming process could try locking BASEHD's wbuf->io_mutex in\n\tinode evicting function), then an ABBA deadlock problem would\n\thappen as following:\n\n 1. File A has inode ia and a xattr(with inode ixa), regular file B has\n inode ib and a xattr.\n 2. getfattr(A, xattr_buf) // ixa is added into lru // lru->ixa\n 3. Then, following three processes running like this:\n\n PA PB PC\n echo 2 > /proc/sys/vm/drop_caches\n shrink_slab\n prune_dcache_sb\n // ib and ia are added into lru, lru->ixa->ib->ia\n prune_icache_sb\n list_lru_walk_one\n inode_lru_isolate\n ixa->i_state |= I_FREEING // set inode state\n inode_lru_isolate\n __iget(ib)\n spin_unlock(&ib->i_lock)\n spin_unlock(lru_lock)\n rm file B\n ib->nlink = 0\n rm file A\n iput(ia)\n ubifs_evict_inode(ia)\n ubifs_jnl_delete_inode(ia)\n ubifs_jnl_write_inode(ia)\n make_reservation(BASEHD) // Lock wbuf->io_mutex\n ubifs_iget(ixa->i_ino)\n iget_locked\n find_inode_fast\n __wait_on_freeing_inode(ixa)\n | iput(ib) // ib->nlink is 0, do evict\n | ubifs_evict_inode\n | ubifs_jnl_delete_inode(ib)\n ? ubifs_jnl_write_inode\n ABBA deadlock ?-----make_reservation(BASEHD)\n dispose_list // cannot be executed by prune_icache_sb\n wake_up_bit(&ixa->i_state)\n\nFix the possible deadlock by using new inode state flag I_LRU_ISOLATING\nto pin the inode in memory while inode_lru_isolate(\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45003', 'https://git.kernel.org/linus/2a0629834cd82f05d424bbc193374f9a43d1f87d (6.11-rc4)', 'https://git.kernel.org/stable/c/03880af02a78bc9a98b5a581f529cf709c88a9b8', 'https://git.kernel.org/stable/c/2a0629834cd82f05d424bbc193374f9a43d1f87d', 'https://git.kernel.org/stable/c/3525ad25240dfdd8c78f3470911ed10aa727aa72', 'https://git.kernel.org/stable/c/437741eba63bf4e437e2beb5583f8633556a2b98', 'https://git.kernel.org/stable/c/9063ab49c11e9518a3f2352434bb276cc8134c5f', 'https://git.kernel.org/stable/c/b9bda5f6012dd00372f3a06a82ed8971a4c57c32', 'https://git.kernel.org/stable/c/cda54ec82c0f9d05393242b20b13f69b083f7e88', 'https://lore.kernel.org/linux-cve-announce/2024090450-CVE-2024-45003-3bc2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45003', 'https://www.cve.org/CVERecord?id=CVE-2024-45003'], 'PublishedDate': '2024-09-04T20:15:08.823Z', 'LastModifiedDate': '2024-10-09T15:07:31.027Z'}, {'VulnerabilityID': 'CVE-2024-45005', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45005', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: KVM: s390: fix validity interception issue when gisa is switched off', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: fix validity interception issue when gisa is switched off\n\nWe might run into a SIE validity if gisa has been disabled either via using\nkernel parameter "kvm.use_gisa=0" or by setting the related sysfs\nattribute to N (echo N >/sys/module/kvm/parameters/use_gisa).\n\nThe validity is caused by an invalid value in the SIE control block\'s\ngisa designation. That happens because we pass the uninitialized gisa\norigin to virt_to_phys() before writing it to the gisa designation.\n\nTo fix this we return 0 in kvm_s390_get_gisa_desc() if the origin is 0.\nkvm_s390_get_gisa_desc() is used to determine which gisa designation to\nset in the SIE control block. A value of 0 in the gisa designation disables\ngisa usage.\n\nThe issue surfaces in the host kernel with the following kernel message as\nsoon a new kvm guest start is attemted.\n\nkvm: unhandled validity intercept 0x1011\nWARNING: CPU: 0 PID: 781237 at arch/s390/kvm/intercept.c:101 kvm_handle_sie_intercept+0x42e/0x4d0 [kvm]\nModules linked in: vhost_net tap tun xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT xt_tcpudp nft_compat x_tables nf_nat_tftp nf_conntrack_tftp vfio_pci_core irqbypass vhost_vsock vmw_vsock_virtio_transport_common vsock vhost vhost_iotlb kvm nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables sunrpc mlx5_ib ib_uverbs ib_core mlx5_core uvdevice s390_trng eadm_sch vfio_ccw zcrypt_cex4 mdev vfio_iommu_type1 vfio sch_fq_codel drm i2c_core loop drm_panel_orientation_quirks configfs nfnetlink lcs ctcm fsm dm_service_time ghash_s390 prng chacha_s390 libchacha aes_s390 des_s390 libdes sha3_512_s390 sha3_256_s390 sha512_s390 sha256_s390 sha1_s390 sha_common dm_mirror dm_region_hash dm_log zfcp scsi_transport_fc scsi_dh_rdac scsi_dh_emc scsi_dh_alua pkey zcrypt dm_multipath rng_core autofs4 [last unloaded: vfio_pci]\nCPU: 0 PID: 781237 Comm: CPU 0/KVM Not tainted 6.10.0-08682-gcad9f11498ea #6\nHardware name: IBM 3931 A01 701 (LPAR)\nKrnl PSW : 0704c00180000000 000003d93deb0122 (kvm_handle_sie_intercept+0x432/0x4d0 [kvm])\n R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:0 PM:0 RI:0 EA:3\nKrnl GPRS: 000003d900000027 000003d900000023 0000000000000028 000002cd00000000\n 000002d063a00900 00000359c6daf708 00000000000bebb5 0000000000001eff\n 000002cfd82e9000 000002cfd80bc000 0000000000001011 000003d93deda412\n 000003ff8962df98 000003d93de77ce0 000003d93deb011e 00000359c6daf960\nKrnl Code: 000003d93deb0112: c020fffe7259\tlarl\t%r2,000003d93de7e5c4\n 000003d93deb0118: c0e53fa8beac\tbrasl\t%r14,000003d9bd3c7e70\n #000003d93deb011e: af000000\t\tmc\t0,0\n >000003d93deb0122: a728ffea\t\tlhi\t%r2,-22\n 000003d93deb0126: a7f4fe24\t\tbrc\t15,000003d93deafd6e\n 000003d93deb012a: 9101f0b0\t\ttm\t176(%r15),1\n 000003d93deb012e: a774fe48\t\tbrc\t7,000003d93deafdbe\n 000003d93deb0132: 40a0f0ae\t\tsth\t%r10,174(%r15)\nCall Trace:\n [<000003d93deb0122>] kvm_handle_sie_intercept+0x432/0x4d0 [kvm]\n([<000003d93deb011e>] kvm_handle_sie_intercept+0x42e/0x4d0 [kvm])\n [<000003d93deacc10>] vcpu_post_run+0x1d0/0x3b0 [kvm]\n [<000003d93deaceda>] __vcpu_run+0xea/0x2d0 [kvm]\n [<000003d93dead9da>] kvm_arch_vcpu_ioctl_run+0x16a/0x430 [kvm]\n [<000003d93de93ee0>] kvm_vcpu_ioctl+0x190/0x7c0 [kvm]\n [<000003d9bd728b4e>] vfs_ioctl+0x2e/0x70\n [<000003d9bd72a092>] __s390x_sys_ioctl+0xc2/0xd0\n [<000003d9be0e9222>] __do_syscall+0x1f2/0x2e0\n [<000003d9be0f9a90>] system_call+0x70/0x98\nLast Breaking-Event-Address:\n [<000003d9bd3c7f58>] __warn_printk+0xe8/0xf0', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45005', 'https://git.kernel.org/linus/5a44bb061d04b0306f2aa8add761d86d152b9377 (6.11-rc4)', 'https://git.kernel.org/stable/c/027ac3c5092561bccce09b314a73a1c167117ef6', 'https://git.kernel.org/stable/c/051c0a558154174cfcea301a386e4c91ade83ce1', 'https://git.kernel.org/stable/c/5a44bb061d04b0306f2aa8add761d86d152b9377', 'https://lore.kernel.org/linux-cve-announce/2024090451-CVE-2024-45005-2297@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45005', 'https://www.cve.org/CVERecord?id=CVE-2024-45005'], 'PublishedDate': '2024-09-04T20:15:08.94Z', 'LastModifiedDate': '2024-10-09T15:30:03.767Z'}, {'VulnerabilityID': 'CVE-2024-45006', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45006', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: Fix Panther point NULL pointer deref at full-speed re-enumeration\n\nre-enumerating full-speed devices after a failed address device command\ncan trigger a NULL pointer dereference.\n\nFull-speed devices may need to reconfigure the endpoint 0 Max Packet Size\nvalue during enumeration. Usb core calls usb_ep0_reinit() in this case,\nwhich ends up calling xhci_configure_endpoint().\n\nOn Panther point xHC the xhci_configure_endpoint() function will\nadditionally check and reserve bandwidth in software. Other hosts do\nthis in hardware\n\nIf xHC address device command fails then a new xhci_virt_device structure\nis allocated as part of re-enabling the slot, but the bandwidth table\npointers are not set up properly here.\nThis triggers the NULL pointer dereference the next time usb_ep0_reinit()\nis called and xhci_configure_endpoint() tries to check and reserve\nbandwidth\n\n[46710.713538] usb 3-1: new full-speed USB device number 5 using xhci_hcd\n[46710.713699] usb 3-1: Device not responding to setup address.\n[46710.917684] usb 3-1: Device not responding to setup address.\n[46711.125536] usb 3-1: device not accepting address 5, error -71\n[46711.125594] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[46711.125600] #PF: supervisor read access in kernel mode\n[46711.125603] #PF: error_code(0x0000) - not-present page\n[46711.125606] PGD 0 P4D 0\n[46711.125610] Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n[46711.125615] CPU: 1 PID: 25760 Comm: kworker/1:2 Not tainted 6.10.3_2 #1\n[46711.125620] Hardware name: Gigabyte Technology Co., Ltd.\n[46711.125623] Workqueue: usb_hub_wq hub_event [usbcore]\n[46711.125668] RIP: 0010:xhci_reserve_bandwidth (drivers/usb/host/xhci.c\n\nFix this by making sure bandwidth table pointers are set up correctly\nafter a failed address device command, and additionally by avoiding\nchecking for bandwidth in cases like this where no actual endpoints are\nadded or removed, i.e. only context for default control endpoint 0 is\nevaluated.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45006', 'https://git.kernel.org/linus/af8e119f52e9c13e556be9e03f27957554a84656 (6.11-rc4)', 'https://git.kernel.org/stable/c/0f0654318e25b2c185e245ba4a591e42fabb5e59', 'https://git.kernel.org/stable/c/365ef7c4277fdd781a695c3553fa157d622d805d', 'https://git.kernel.org/stable/c/5ad898ae82412f8a689d59829804bff2999dd0ea', 'https://git.kernel.org/stable/c/6b99de301d78e1f5249e57ef2c32e1dec3df2bb1', 'https://git.kernel.org/stable/c/8fb9d412ebe2f245f13481e4624b40e651570cbd', 'https://git.kernel.org/stable/c/a57b0ebabe6862dce0a2e0f13e17941ad72fc56b', 'https://git.kernel.org/stable/c/af8e119f52e9c13e556be9e03f27957554a84656', 'https://git.kernel.org/stable/c/ef0a0e616b2789bb804a0ce5e161db03170a85b6', 'https://lore.kernel.org/linux-cve-announce/2024090451-CVE-2024-45006-6642@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45006', 'https://www.cve.org/CVERecord?id=CVE-2024-45006'], 'PublishedDate': '2024-09-04T20:15:08.997Z', 'LastModifiedDate': '2024-09-06T16:26:52.64Z'}, {'VulnerabilityID': 'CVE-2024-45007', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45007', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: char: xillybus: Don't destroy workqueue from work item running on it", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Don't destroy workqueue from work item running on it\n\nTriggered by a kref decrement, destroy_workqueue() may be called from\nwithin a work item for destroying its own workqueue. This illegal\nsituation is averted by adding a module-global workqueue for exclusive\nuse of the offending work item. Other work items continue to be queued\non per-device workqueues to ensure performance.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45007', 'https://git.kernel.org/linus/ccbde4b128ef9c73d14d0d7817d68ef795f6d131 (6.11-rc4)', 'https://git.kernel.org/stable/c/409b495f8e3300d5fba08bc817fa8825dae48cc9', 'https://git.kernel.org/stable/c/5d3567caff2a1d678aa40cc74a54e1318941fad3', 'https://git.kernel.org/stable/c/a7ad105b12256ec7fb6d6d1a0e2e60f00b7da157', 'https://git.kernel.org/stable/c/aa1a19724fa2c31e97a9be48baedd4692b265157', 'https://git.kernel.org/stable/c/ccbde4b128ef9c73d14d0d7817d68ef795f6d131', 'https://lore.kernel.org/linux-cve-announce/2024090452-CVE-2024-45007-74c8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45007', 'https://www.cve.org/CVERecord?id=CVE-2024-45007'], 'PublishedDate': '2024-09-04T20:15:09.053Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-45008', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Input: MT - limit max slots', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: MT - limit max slots\n\nsyzbot is reporting too large allocation at input_mt_init_slots(), for\nnum_slots is supplied from userspace using ioctl(UI_DEV_CREATE).\n\nSince nobody knows possible max slots, this patch chose 1024.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45008', 'https://git.kernel.org/linus/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb (6.11-rc2)', 'https://git.kernel.org/stable/c/05dd9aabd04f9b5eb04dab9bb83d8c3e982d7549', 'https://git.kernel.org/stable/c/2829c80614890624456337e47320289112785f3e', 'https://git.kernel.org/stable/c/87f610a1a7fbdb1f2e3d90b54c955bd3b8a0c322', 'https://git.kernel.org/stable/c/8f04edd554d191834e9e1349ef030318ea6b11ba', 'https://git.kernel.org/stable/c/94736334b8a25e4fae8daa6934e54a31f099be43', 'https://git.kernel.org/stable/c/95f73d01f547dfc67fda3022c51e377a0454b505', 'https://git.kernel.org/stable/c/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb', 'https://git.kernel.org/stable/c/cd19f1799c32ba7b874474b1b968815ce5364f73', 'https://lore.kernel.org/linux-cve-announce/2024090452-CVE-2024-45008-1d89@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45008', 'https://www.cve.org/CVERecord?id=CVE-2024-45008'], 'PublishedDate': '2024-09-04T20:15:09.107Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-45009', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45009', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: only decrement add_addr_accepted for MPJ req', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: only decrement add_addr_accepted for MPJ req\n\nAdding the following warning ...\n\n WARN_ON_ONCE(msk->pm.add_addr_accepted == 0)\n\n... before decrementing the add_addr_accepted counter helped to find a\nbug when running the "remove single subflow" subtest from the\nmptcp_join.sh selftest.\n\nRemoving a \'subflow\' endpoint will first trigger a RM_ADDR, then the\nsubflow closure. Before this patch, and upon the reception of the\nRM_ADDR, the other peer will then try to decrement this\nadd_addr_accepted. That\'s not correct because the attached subflows have\nnot been created upon the reception of an ADD_ADDR.\n\nA way to solve that is to decrement the counter only if the attached\nsubflow was an MP_JOIN to a remote id that was not 0, and initiated by\nthe host receiving the RM_ADDR.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45009', 'https://git.kernel.org/linus/1c1f721375989579e46741f59523e39ec9b2a9bd (6.11-rc5)', 'https://git.kernel.org/stable/c/1c1f721375989579e46741f59523e39ec9b2a9bd', 'https://git.kernel.org/stable/c/2060f1efab370b496c4903b840844ecaff324c3c', 'https://git.kernel.org/stable/c/35b31f5549ede4070566b949781e83495906b43d', 'https://git.kernel.org/stable/c/85b866e4c4e63a1d7afb58f1e24273caad03d0b7', 'https://git.kernel.org/stable/c/d20bf2c96d7ffd171299b32f562f70e5bf5dc608', 'https://lore.kernel.org/linux-cve-announce/2024091104-CVE-2024-45009-24ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45009', 'https://www.cve.org/CVERecord?id=CVE-2024-45009'], 'PublishedDate': '2024-09-11T16:15:06.427Z', 'LastModifiedDate': '2024-09-13T16:36:57.233Z'}, {'VulnerabilityID': 'CVE-2024-45010', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45010', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: mptcp: pm: only mark 'subflow' endp as available", 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: only mark \'subflow\' endp as available\n\nAdding the following warning ...\n\n WARN_ON_ONCE(msk->pm.local_addr_used == 0)\n\n... before decrementing the local_addr_used counter helped to find a bug\nwhen running the "remove single address" subtest from the mptcp_join.sh\nselftests.\n\nRemoving a \'signal\' endpoint will trigger the removal of all subflows\nlinked to this endpoint via mptcp_pm_nl_rm_addr_or_subflow() with\nrm_type == MPTCP_MIB_RMSUBFLOW. This will decrement the local_addr_used\ncounter, which is wrong in this case because this counter is linked to\n\'subflow\' endpoints, and here it is a \'signal\' endpoint that is being\nremoved.\n\nNow, the counter is decremented, only if the ID is being used outside\nof mptcp_pm_nl_rm_addr_or_subflow(), only for \'subflow\' endpoints, and\nif the ID is not 0 -- local_addr_used is not taking into account these\nones. This marking of the ID as being available, and the decrement is\ndone no matter if a subflow using this ID is currently available,\nbecause the subflow could have been closed before.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45010', 'https://git.kernel.org/linus/322ea3778965da72862cca2a0c50253aacf65fe6 (6.11-rc5)', 'https://git.kernel.org/stable/c/322ea3778965da72862cca2a0c50253aacf65fe6', 'https://git.kernel.org/stable/c/43cf912b0b0fc7b4fd12cbc735d1f5afb8e1322d', 'https://git.kernel.org/stable/c/7fdc870d08960961408a44c569f20f50940e7d4f', 'https://git.kernel.org/stable/c/9849cfc67383ceb167155186f8f8fe8a896b60b3', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45010-33ee@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45010', 'https://www.cve.org/CVERecord?id=CVE-2024-45010'], 'PublishedDate': '2024-09-11T16:15:06.483Z', 'LastModifiedDate': '2024-09-13T16:35:05.843Z'}, {'VulnerabilityID': 'CVE-2024-45011', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45011', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: char: xillybus: Check USB endpoints when probing device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Check USB endpoints when probing device\n\nEnsure, as the driver probes the device, that all endpoints that the\ndriver may attempt to access exist and are of the correct type.\n\nAll XillyUSB devices must have a Bulk IN and Bulk OUT endpoint at\naddress 1. This is verified in xillyusb_setup_base_eps().\n\nOn top of that, a XillyUSB device may have additional Bulk OUT\nendpoints. The information about these endpoints' addresses is deduced\nfrom a data structure (the IDT) that the driver fetches from the device\nwhile probing it. These endpoints are checked in setup_channels().\n\nA XillyUSB device never has more than one IN endpoint, as all data\ntowards the host is multiplexed in this single Bulk IN endpoint. This is\nwhy setup_channels() only checks OUT endpoints.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45011', 'https://git.kernel.org/linus/2374bf7558de915edc6ec8cb10ec3291dfab9594 (6.11-rc4)', 'https://git.kernel.org/stable/c/1371d32b95972d39c1e6e4bae8b6d0df1b573731', 'https://git.kernel.org/stable/c/2374bf7558de915edc6ec8cb10ec3291dfab9594', 'https://git.kernel.org/stable/c/25ee8b2908200fc862c0434e5ad483817d50ceda', 'https://git.kernel.org/stable/c/4267131278f5cc98f8db31d035d64bdbbfe18658', 'https://git.kernel.org/stable/c/5cff754692ad45d5086b75fef8cc3a99c30a1005', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45011-e729@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45011', 'https://www.cve.org/CVERecord?id=CVE-2024-45011'], 'PublishedDate': '2024-09-11T16:15:06.55Z', 'LastModifiedDate': '2024-09-13T16:36:55.757Z'}, {'VulnerabilityID': 'CVE-2024-45012', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45012', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nouveau/firmware: use dma non-coherent allocator', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/firmware: use dma non-coherent allocator\n\nCurrently, enabling SG_DEBUG in the kernel will cause nouveau to hit a\nBUG() on startup, when the iommu is enabled:\n\nkernel BUG at include/linux/scatterlist.h:187!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 7 PID: 930 Comm: (udev-worker) Not tainted 6.9.0-rc3Lyude-Test+ #30\nHardware name: MSI MS-7A39/A320M GAMING PRO (MS-7A39), BIOS 1.I0 01/22/2019\nRIP: 0010:sg_init_one+0x85/0xa0\nCode: 69 88 32 01 83 e1 03 f6 c3 03 75 20 a8 01 75 1e 48 09 cb 41 89 54\n24 08 49 89 1c 24 41 89 6c 24 0c 5b 5d 41 5c e9 7b b9 88 00 <0f> 0b 0f 0b\n0f 0b 48 8b 05 5e 46 9a 01 eb b2 66 66 2e 0f 1f 84 00\nRSP: 0018:ffffa776017bf6a0 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffffa77600d87000 RCX: 000000000000002b\nRDX: 0000000000000001 RSI: 0000000000000000 RDI: ffffa77680d87000\nRBP: 000000000000e000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffff98f4c46aa508 R11: 0000000000000000 R12: ffff98f4c46aa508\nR13: ffff98f4c46aa008 R14: ffffa77600d4a000 R15: ffffa77600d4a018\nFS: 00007feeb5aae980(0000) GS:ffff98f5c4dc0000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f22cb9a4520 CR3: 00000001043ba000 CR4: 00000000003506f0\nCall Trace:\n \n ? die+0x36/0x90\n ? do_trap+0xdd/0x100\n ? sg_init_one+0x85/0xa0\n ? do_error_trap+0x65/0x80\n ? sg_init_one+0x85/0xa0\n ? exc_invalid_op+0x50/0x70\n ? sg_init_one+0x85/0xa0\n ? asm_exc_invalid_op+0x1a/0x20\n ? sg_init_one+0x85/0xa0\n nvkm_firmware_ctor+0x14a/0x250 [nouveau]\n nvkm_falcon_fw_ctor+0x42/0x70 [nouveau]\n ga102_gsp_booter_ctor+0xb4/0x1a0 [nouveau]\n r535_gsp_oneinit+0xb3/0x15f0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? nvkm_udevice_new+0x95/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? ktime_get+0x47/0xb0\n\nFix this by using the non-coherent allocator instead, I think there\nmight be a better answer to this, but it involve ripping up some of\nAPIs using sg lists.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45012', 'https://git.kernel.org/linus/9b340aeb26d50e9a9ec99599e2a39b035fac978e (6.11-rc5)', 'https://git.kernel.org/stable/c/57ca481fca97ca4553e8c85d6a94baf4cb40c40e', 'https://git.kernel.org/stable/c/9b340aeb26d50e9a9ec99599e2a39b035fac978e', 'https://git.kernel.org/stable/c/cc29c5546c6a373648363ac49781f1d74b530707', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45012-9234@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45012', 'https://www.cve.org/CVERecord?id=CVE-2024-45012'], 'PublishedDate': '2024-09-11T16:15:06.607Z', 'LastModifiedDate': '2024-09-13T16:35:35.787Z'}, {'VulnerabilityID': 'CVE-2024-45013', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: move stopping keep-alive into nvme_uninit_ctrl()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: move stopping keep-alive into nvme_uninit_ctrl()\n\nCommit 4733b65d82bd ("nvme: start keep-alive after admin queue setup")\nmoves starting keep-alive from nvme_start_ctrl() into\nnvme_init_ctrl_finish(), but don\'t move stopping keep-alive into\nnvme_uninit_ctrl(), so keep-alive work can be started and keep pending\nafter failing to start controller, finally use-after-free is triggered if\nnvme host driver is unloaded.\n\nThis patch fixes kernel panic when running nvme/004 in case that connection\nfailure is triggered, by moving stopping keep-alive into nvme_uninit_ctrl().\n\nThis way is reasonable because keep-alive is now started in\nnvme_init_ctrl_finish().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45013', 'https://git.kernel.org/linus/a54a93d0e3599b05856971734e15418ac551a14c (6.11-rc5)', 'https://git.kernel.org/stable/c/4101af98ab573554c4225e328d506fec2a74bc54', 'https://git.kernel.org/stable/c/a54a93d0e3599b05856971734e15418ac551a14c', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45013-8efe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45013', 'https://www.cve.org/CVERecord?id=CVE-2024-45013'], 'PublishedDate': '2024-09-11T16:15:06.663Z', 'LastModifiedDate': '2024-09-13T16:35:42.49Z'}, {'VulnerabilityID': 'CVE-2024-45015', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45015', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()\n\nFor cases where the crtc's connectors_changed was set without enable/active\ngetting toggled , there is an atomic_enable() call followed by an\natomic_disable() but without an atomic_mode_set().\n\nThis results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in\nthe atomic_enable() as the dpu_encoder's connector was cleared in the\natomic_disable() but not re-assigned as there was no atomic_mode_set() call.\n\nFix the NULL ptr access by moving the assignment for atomic_enable() and also\nuse drm_atomic_get_new_connector_for_encoder() to get the connector from\nthe atomic_state.\n\nPatchwork: https://patchwork.freedesktop.org/patch/606729/", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45015', 'https://git.kernel.org/linus/aedf02e46eb549dac8db4821a6b9f0c6bf6e3990 (6.11-rc5)', 'https://git.kernel.org/stable/c/3bacf814b6a61cc683c68465f175ebd938f09c52', 'https://git.kernel.org/stable/c/3fb61718bcbe309279205d1cc275a6435611dc77', 'https://git.kernel.org/stable/c/aedf02e46eb549dac8db4821a6b9f0c6bf6e3990', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45015-c139@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45015', 'https://www.cve.org/CVERecord?id=CVE-2024-45015'], 'PublishedDate': '2024-09-11T16:15:06.763Z', 'LastModifiedDate': '2024-09-13T16:35:58.617Z'}, {'VulnerabilityID': 'CVE-2024-45016', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1017.18~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45016', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netem: fix return value if duplicate enqueue fails', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetem: fix return value if duplicate enqueue fails\n\nThere is a bug in netem_enqueue() introduced by\ncommit 5845f706388a ("net: netem: fix skb length BUG_ON in __skb_to_sgvec")\nthat can lead to a use-after-free.\n\nThis commit made netem_enqueue() always return NET_XMIT_SUCCESS\nwhen a packet is duplicated, which can cause the parent qdisc\'s q.qlen\nto be mistakenly incremented. When this happens qlen_notify() may be\nskipped on the parent during destruction, leaving a dangling pointer\nfor some classful qdiscs like DRR.\n\nThere are two ways for the bug happen:\n\n- If the duplicated packet is dropped by rootq->enqueue() and then\n the original packet is also dropped.\n- If rootq->enqueue() sends the duplicated packet to a different qdisc\n and the original packet is dropped.\n\nIn both cases NET_XMIT_SUCCESS is returned even though no packets\nare enqueued at the netem qdisc.\n\nThe fix is to defer the enqueue of the duplicate packet until after\nthe original packet has been guaranteed to return NET_XMIT_SUCCESS.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45016', 'https://git.kernel.org/linus/c07ff8592d57ed258afee5a5e04991a48dbaf382 (6.11-rc5)', 'https://git.kernel.org/stable/c/0486d31dd8198e22b63a4730244b38fffce6d469', 'https://git.kernel.org/stable/c/52d99a69f3d556c6426048c9d481b912205919d8', 'https://git.kernel.org/stable/c/577d6c0619467fe90f7e8e57e45cb5bd9d936014', 'https://git.kernel.org/stable/c/759e3e8c4a6a6b4e52ebc4547123a457f0ce90d4', 'https://git.kernel.org/stable/c/c07ff8592d57ed258afee5a5e04991a48dbaf382', 'https://git.kernel.org/stable/c/c414000da1c2ea1ba9a5e5bb1a4ba774e51e202d', 'https://git.kernel.org/stable/c/e5bb2988a310667abed66c7d3ffa28880cf0f883', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45016-fd5a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45016', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://ubuntu.com/security/notices/USN-7071-1', 'https://ubuntu.com/security/notices/USN-7072-1', 'https://ubuntu.com/security/notices/USN-7073-1', 'https://ubuntu.com/security/notices/USN-7073-2', 'https://ubuntu.com/security/notices/USN-7074-1', 'https://ubuntu.com/security/notices/USN-7076-1', 'https://www.cve.org/CVERecord?id=CVE-2024-45016'], 'PublishedDate': '2024-09-11T16:15:06.817Z', 'LastModifiedDate': '2024-09-13T16:36:06.773Z'}, {'VulnerabilityID': 'CVE-2024-45017', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45017', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix IPsec RoCE MPV trace call', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix IPsec RoCE MPV trace call\n\nPrevent the call trace below from happening, by not allowing IPsec\ncreation over a slave, if master device doesn't support IPsec.\n\nWARNING: CPU: 44 PID: 16136 at kernel/locking/rwsem.c:240 down_read+0x75/0x94\nModules linked in: esp4_offload esp4 act_mirred act_vlan cls_flower sch_ingress mlx5_vdpa vringh vhost_iotlb vdpa mst_pciconf(OE) nfsv3 nfs_acl nfs lockd grace fscache netfs xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_reject_ipv4 nft_compat nft_counter nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill cuse fuse rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi rdma_cm ib_ipoib iw_cm ib_cm ipmi_ssif intel_rapl_msr intel_rapl_common amd64_edac edac_mce_amd kvm_amd kvm irqbypass crct10dif_pclmul crc32_pclmul mlx5_ib ghash_clmulni_intel sha1_ssse3 dell_smbios ib_uverbs aesni_intel crypto_simd dcdbas wmi_bmof dell_wmi_descriptor cryptd pcspkr ib_core acpi_ipmi sp5100_tco ccp i2c_piix4 ipmi_si ptdma k10temp ipmi_devintf ipmi_msghandler acpi_power_meter acpi_cpufreq ext4 mbcache jbd2 sd_mod t10_pi sg mgag200 drm_kms_helper syscopyarea sysfillrect mlx5_core sysimgblt fb_sys_fops cec\n ahci libahci mlxfw drm pci_hyperv_intf libata tg3 sha256_ssse3 tls megaraid_sas i2c_algo_bit psample wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: mst_pci]\nCPU: 44 PID: 16136 Comm: kworker/44:3 Kdump: loaded Tainted: GOE 5.15.0-20240509.el8uek.uek7_u3_update_v6.6_ipsec_bf.x86_64 #2\nHardware name: Dell Inc. PowerEdge R7525/074H08, BIOS 2.0.3 01/15/2021\nWorkqueue: events xfrm_state_gc_task\nRIP: 0010:down_read+0x75/0x94\nCode: 00 48 8b 45 08 65 48 8b 14 25 80 fc 01 00 83 e0 02 48 09 d0 48 83 c8 01 48 89 45 08 5d 31 c0 89 c2 89 c6 89 c7 e9 cb 88 3b 00 <0f> 0b 48 8b 45 08 a8 01 74 b2 a8 02 75 ae 48 89 c2 48 83 ca 02 f0\nRSP: 0018:ffffb26387773da8 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffffa08b658af900 RCX: 0000000000000001\nRDX: 0000000000000000 RSI: ff886bc5e1366f2f RDI: 0000000000000000\nRBP: ffffa08b658af940 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffa0a9bfb31540\nR13: ffffa0a9bfb37900 R14: 0000000000000000 R15: ffffa0a9bfb37905\nFS: 0000000000000000(0000) GS:ffffa0a9bfb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055a45ed814e8 CR3: 000000109038a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? show_trace_log_lvl+0x1d6/0x2f9\n ? show_trace_log_lvl+0x1d6/0x2f9\n ? mlx5_devcom_for_each_peer_begin+0x29/0x60 [mlx5_core]\n ? down_read+0x75/0x94\n ? __warn+0x80/0x113\n ? down_read+0x75/0x94\n ? report_bug+0xa4/0x11d\n ? handle_bug+0x35/0x8b\n ? exc_invalid_op+0x14/0x75\n ? asm_exc_invalid_op+0x16/0x1b\n ? down_read+0x75/0x94\n ? down_read+0xe/0x94\n mlx5_devcom_for_each_peer_begin+0x29/0x60 [mlx5_core]\n mlx5_ipsec_fs_roce_tx_destroy+0xb1/0x130 [mlx5_core]\n tx_destroy+0x1b/0xc0 [mlx5_core]\n tx_ft_put+0x53/0xc0 [mlx5_core]\n mlx5e_xfrm_free_state+0x45/0x90 [mlx5_core]\n ___xfrm_state_destroy+0x10f/0x1a2\n xfrm_state_gc_task+0x81/0xa9\n process_one_work+0x1f1/0x3c6\n worker_thread+0x53/0x3e4\n ? process_one_work.cold+0x46/0x3c\n kthread+0x127/0x144\n ? set_kthread_struct+0x60/0x52\n ret_from_fork+0x22/0x2d\n \n---[ end trace 5ef7896144d398e1 ]---", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45017', 'https://git.kernel.org/linus/607e1df7bd47fe91cab85a97f57870a26d066137 (6.11-rc5)', 'https://git.kernel.org/stable/c/2ae52a65a850ded75a94e8d7ec1e09737f4c6509', 'https://git.kernel.org/stable/c/607e1df7bd47fe91cab85a97f57870a26d066137', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45017-ee3e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45017', 'https://www.cve.org/CVERecord?id=CVE-2024-45017'], 'PublishedDate': '2024-09-11T16:15:06.877Z', 'LastModifiedDate': '2024-09-13T16:36:13.19Z'}, {'VulnerabilityID': 'CVE-2024-45018', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45018', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: flowtable: initialise extack before use', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: initialise extack before use\n\nFix missing initialisation of extack in flow offload.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45018', 'https://git.kernel.org/linus/e9767137308daf906496613fd879808a07f006a2 (6.11-rc4)', 'https://git.kernel.org/stable/c/119be227bc04f5035efa64cb823b8a5ca5e2d1c1', 'https://git.kernel.org/stable/c/356beb911b63a8cff34cb57f755c2a2d2ee9dec7', 'https://git.kernel.org/stable/c/7eafeec6be68ebd6140a830ce9ae68ad5b67ec78', 'https://git.kernel.org/stable/c/c7b760499f7791352b49b11667ed04b23d7f5b0f', 'https://git.kernel.org/stable/c/e5ceff2196dc633c995afb080f6f44a72cff6e1d', 'https://git.kernel.org/stable/c/e9767137308daf906496613fd879808a07f006a2', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45018-7e30@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45018', 'https://www.cve.org/CVERecord?id=CVE-2024-45018'], 'PublishedDate': '2024-09-11T16:15:06.933Z', 'LastModifiedDate': '2024-09-13T16:36:24.397Z'}, {'VulnerabilityID': 'CVE-2024-45019', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45019', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Take state lock during tx timeout reporter', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Take state lock during tx timeout reporter\n\nmlx5e_safe_reopen_channels() requires the state lock taken. The\nreferenced changed in the Fixes tag removed the lock to fix another\nissue. This patch adds it back but at a later point (when calling\nmlx5e_safe_reopen_channels()) to avoid the deadlock referenced in the\nFixes tag.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45019', 'https://git.kernel.org/linus/e6b5afd30b99b43682a7764e1a74a42fe4d5f4b3 (6.11-rc4)', 'https://git.kernel.org/stable/c/03d3734bd692affe4d0e9c9d638f491aaf37411b', 'https://git.kernel.org/stable/c/8e57e66ecbdd2fddc9fbf3e984b1c523b70e9809', 'https://git.kernel.org/stable/c/b3b9a87adee97854bcd71057901d46943076267e', 'https://git.kernel.org/stable/c/e6b5afd30b99b43682a7764e1a74a42fe4d5f4b3', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45019-5f8b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45019', 'https://www.cve.org/CVERecord?id=CVE-2024-45019'], 'PublishedDate': '2024-09-11T16:15:06.99Z', 'LastModifiedDate': '2024-09-13T16:36:19.36Z'}, {'VulnerabilityID': 'CVE-2024-45020', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45020', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix a kernel verifier crash in stacksafe()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a kernel verifier crash in stacksafe()\n\nDaniel Hodges reported a kernel verifier crash when playing with sched-ext.\nFurther investigation shows that the crash is due to invalid memory access\nin stacksafe(). More specifically, it is the following code:\n\n if (exact != NOT_EXACT &&\n old->stack[spi].slot_type[i % BPF_REG_SIZE] !=\n cur->stack[spi].slot_type[i % BPF_REG_SIZE])\n return false;\n\nThe 'i' iterates old->allocated_stack.\nIf cur->allocated_stack < old->allocated_stack the out-of-bound\naccess will happen.\n\nTo fix the issue add 'i >= cur->allocated_stack' check such that if\nthe condition is true, stacksafe() should fail. Otherwise,\ncur->stack[spi].slot_type[i % BPF_REG_SIZE] memory access is legal.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45020', 'https://git.kernel.org/linus/bed2eb964c70b780fb55925892a74f26cb590b25 (6.11-rc4)', 'https://git.kernel.org/stable/c/6e3987ac310c74bb4dd6a2fa8e46702fe505fb2b', 'https://git.kernel.org/stable/c/7cad3174cc79519bf5f6c4441780264416822c08', 'https://git.kernel.org/stable/c/bed2eb964c70b780fb55925892a74f26cb590b25', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45020-afcc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45020', 'https://www.cve.org/CVERecord?id=CVE-2024-45020'], 'PublishedDate': '2024-09-11T16:15:07.05Z', 'LastModifiedDate': '2024-09-13T16:36:52.29Z'}, {'VulnerabilityID': 'CVE-2024-45021', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45021', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg_write_event_control(): fix a user-triggerable oops', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg_write_event_control(): fix a user-triggerable oops\n\nwe are *not* guaranteed that anything past the terminating NUL\nis mapped (let alone initialized with anything sane).', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45021', 'https://git.kernel.org/linus/046667c4d3196938e992fba0dfcde570aa85cd0e (6.11-rc4)', 'https://git.kernel.org/stable/c/046667c4d3196938e992fba0dfcde570aa85cd0e', 'https://git.kernel.org/stable/c/0fbe2a72e853a1052abe9bc2b7df8ddb102da227', 'https://git.kernel.org/stable/c/1b37ec85ad95b612307627758c6018cd9d92cca8', 'https://git.kernel.org/stable/c/21b578f1d599edb87462f11113c5b0fc7a04ac61', 'https://git.kernel.org/stable/c/43768fa80fd192558737e24ed6548f74554611d7', 'https://git.kernel.org/stable/c/ad149f5585345e383baa65f1539d816cd715fd3b', 'https://git.kernel.org/stable/c/f1aa7c509aa766080db7ab3aec2e31b1df09e57c', 'https://git.kernel.org/stable/c/fa5bfdf6cb5846a00e712d630a43e3cf55ccb411', 'https://lore.kernel.org/linux-cve-announce/2024091109-CVE-2024-45021-68c4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45021', 'https://www.cve.org/CVERecord?id=CVE-2024-45021'], 'PublishedDate': '2024-09-11T16:15:07.103Z', 'LastModifiedDate': '2024-09-13T16:36:31.583Z'}, {'VulnerabilityID': 'CVE-2024-45022', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45022', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0\n\nThe __vmap_pages_range_noflush() assumes its argument pages** contains\npages with the same page shift. However, since commit e9c3cda4d86e ("mm,\nvmalloc: fix high order __GFP_NOFAIL allocations"), if gfp_flags includes\n__GFP_NOFAIL with high order in vm_area_alloc_pages() and page allocation\nfailed for high order, the pages** may contain two different page shifts\n(high order and order-0). This could lead __vmap_pages_range_noflush() to\nperform incorrect mappings, potentially resulting in memory corruption.\n\nUsers might encounter this as follows (vmap_allow_huge = true, 2M is for\nPMD_SIZE):\n\nkvmalloc(2M, __GFP_NOFAIL|GFP_X)\n __vmalloc_node_range_noprof(vm_flags=VM_ALLOW_HUGE_VMAP)\n vm_area_alloc_pages(order=9) ---> order-9 allocation failed and fallback to order-0\n vmap_pages_range()\n vmap_pages_range_noflush()\n __vmap_pages_range_noflush(page_shift = 21) ----> wrong mapping happens\n\nWe can remove the fallback code because if a high-order allocation fails,\n__vmalloc_node_range_noprof() will retry with order-0. Therefore, it is\nunnecessary to fallback to order-0 here. Therefore, fix this by removing\nthe fallback code.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45022', 'https://git.kernel.org/linus/61ebe5a747da649057c37be1c37eb934b4af79ca (6.11-rc4)', 'https://git.kernel.org/stable/c/61ebe5a747da649057c37be1c37eb934b4af79ca', 'https://git.kernel.org/stable/c/c91618816f4d21fc574d7577a37722adcd4075b2', 'https://git.kernel.org/stable/c/de7bad86345c43cd040ed43e20d9fad78a3ee59f', 'https://git.kernel.org/stable/c/fd1ffbb50ef4da5e1378a46616b6d7407dc795da', 'https://lore.kernel.org/linux-cve-announce/2024091109-CVE-2024-45022-08f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45022', 'https://www.cve.org/CVERecord?id=CVE-2024-45022'], 'PublishedDate': '2024-09-11T16:15:07.163Z', 'LastModifiedDate': '2024-09-13T16:36:39.043Z'}, {'VulnerabilityID': 'CVE-2024-45025', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45025', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE\n\ncopy_fd_bitmaps(new, old, count) is expected to copy the first\ncount/BITS_PER_LONG bits from old->full_fds_bits[] and fill\nthe rest with zeroes. What it does is copying enough words\n(BITS_TO_LONGS(count/BITS_PER_LONG)), then memsets the rest.\nThat works fine, *if* all bits past the cutoff point are\nclear. Otherwise we are risking garbage from the last word\nwe'd copied.\n\nFor most of the callers that is true - expand_fdtable() has\ncount equal to old->max_fds, so there's no open descriptors\npast count, let alone fully occupied words in ->open_fds[],\nwhich is what bits in ->full_fds_bits[] correspond to.\n\nThe other caller (dup_fd()) passes sane_fdtable_size(old_fdt, max_fds),\nwhich is the smallest multiple of BITS_PER_LONG that covers all\nopened descriptors below max_fds. In the common case (copying on\nfork()) max_fds is ~0U, so all opened descriptors will be below\nit and we are fine, by the same reasons why the call in expand_fdtable()\nis safe.\n\nUnfortunately, there is a case where max_fds is less than that\nand where we might, indeed, end up with junk in ->full_fds_bits[] -\nclose_range(from, to, CLOSE_RANGE_UNSHARE) with\n\t* descriptor table being currently shared\n\t* 'to' being above the current capacity of descriptor table\n\t* 'from' being just under some chunk of opened descriptors.\nIn that case we end up with observably wrong behaviour - e.g. spawn\na child with CLONE_FILES, get all descriptors in range 0..127 open,\nthen close_range(64, ~0U, CLOSE_RANGE_UNSHARE) and watch dup(0) ending\nup with descriptor #128, despite #64 being observably not open.\n\nThe minimally invasive fix would be to deal with that in dup_fd().\nIf this proves to add measurable overhead, we can go that way, but\nlet's try to fix copy_fd_bitmaps() first.\n\n* new helper: bitmap_copy_and_expand(to, from, bits_to_copy, size).\n* make copy_fd_bitmaps() take the bitmap size in words, rather than\nbits; it's 'count' argument is always a multiple of BITS_PER_LONG,\nso we are not losing any information, and that way we can use the\nsame helper for all three bitmaps - compiler will see that count\nis a multiple of BITS_PER_LONG for the large ones, so it'll generate\nplain memcpy()+memset().\n\nReproducer added to tools/testing/selftests/core/close_range_test.c", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45025', 'https://git.kernel.org/linus/9a2fa1472083580b6c66bdaf291f591e1170123a (6.11-rc4)', 'https://git.kernel.org/stable/c/5053581fe5dfb09b58c65dd8462bf5dea71f41ff', 'https://git.kernel.org/stable/c/8cad3b2b3ab81ca55f37405ffd1315bcc2948058', 'https://git.kernel.org/stable/c/9a2fa1472083580b6c66bdaf291f591e1170123a', 'https://git.kernel.org/stable/c/c69d18f0ac7060de724511537810f10f29a27958', 'https://git.kernel.org/stable/c/dd72ae8b0fce9c0bbe9582b9b50820f0407f8d8a', 'https://git.kernel.org/stable/c/e807487a1d5fd5d941f26578ae826ca815dbfcd6', 'https://git.kernel.org/stable/c/ee501f827f3db02d4e599afbbc1a7f8b792d05d7', 'https://git.kernel.org/stable/c/fe5bf14881701119aeeda7cf685f3c226c7380df', 'https://lore.kernel.org/linux-cve-announce/2024091109-CVE-2024-45025-94f6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45025', 'https://www.cve.org/CVERecord?id=CVE-2024-45025'], 'PublishedDate': '2024-09-11T16:15:07.44Z', 'LastModifiedDate': '2024-09-13T16:30:07.073Z'}, {'VulnerabilityID': 'CVE-2024-45026', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45026', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/dasd: fix error recovery leading to data corruption on ESE devices', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix error recovery leading to data corruption on ESE devices\n\nExtent Space Efficient (ESE) or thin provisioned volumes need to be\nformatted on demand during usual IO processing.\n\nThe dasd_ese_needs_format function checks for error codes that signal\nthe non existence of a proper track format.\n\nThe check for incorrect length is to imprecise since other error cases\nleading to transport of insufficient data also have this flag set.\nThis might lead to data corruption in certain error cases for example\nduring a storage server warmstart.\n\nFix by removing the check for incorrect length and replacing by\nexplicitly checking for invalid track format in transport mode.\n\nAlso remove the check for file protected since this is not a valid\nESE handling case.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45026', 'https://git.kernel.org/linus/7db4042336580dfd75cb5faa82c12cd51098c90b (6.11-rc4)', 'https://git.kernel.org/stable/c/0a228896a1b3654cd461ff654f6a64e97a9c3246', 'https://git.kernel.org/stable/c/19f60a55b2fda49bc4f6134a5f6356ef62ee69d8', 'https://git.kernel.org/stable/c/5d4a304338daf83ace2887aaacafd66fe99ed5cc', 'https://git.kernel.org/stable/c/7db4042336580dfd75cb5faa82c12cd51098c90b', 'https://git.kernel.org/stable/c/93a7e2856951680cd7fe6ebd705ac10c8a8a5efd', 'https://git.kernel.org/stable/c/a665e3b7ac7d5cdc26e00e3d0fc8fd490e00316a', 'https://git.kernel.org/stable/c/e245a18281c252c8dbc467492e09bb5d4b012118', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45026-eaa8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45026', 'https://www.cve.org/CVERecord?id=CVE-2024-45026'], 'PublishedDate': '2024-09-11T16:15:07.507Z', 'LastModifiedDate': '2024-09-13T16:29:55.927Z'}, {'VulnerabilityID': 'CVE-2024-45027', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45027', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup()\n\nIf xhci_mem_init() fails, it calls into xhci_mem_cleanup() to mop\nup the damage. If it fails early enough, before xhci->interrupters\nis allocated but after xhci->max_interrupters has been set, which\nhappens in most (all?) cases, things get uglier, as xhci_mem_cleanup()\nunconditionally derefences xhci->interrupters. With prejudice.\n\nGate the interrupt freeing loop with a check on xhci->interrupters\nbeing non-NULL.\n\nFound while debugging a DMA allocation issue that led the XHCI driver\non this exact path.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45027', 'https://git.kernel.org/linus/dcdb52d948f3a17ccd3fce757d9bd981d7c32039 (6.11-rc4)', 'https://git.kernel.org/stable/c/770cacc75b0091ece17349195d72133912c1ca7c', 'https://git.kernel.org/stable/c/dcdb52d948f3a17ccd3fce757d9bd981d7c32039', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45027-95b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45027', 'https://www.cve.org/CVERecord?id=CVE-2024-45027'], 'PublishedDate': '2024-09-11T16:15:07.57Z', 'LastModifiedDate': '2024-09-13T16:29:44.213Z'}, {'VulnerabilityID': 'CVE-2024-45028', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45028', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mmc: mmc_test: Fix NULL dereference on allocation failure', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmc_test: Fix NULL dereference on allocation failure\n\nIf the "test->highmem = alloc_pages()" allocation fails then calling\n__free_pages(test->highmem) will result in a NULL dereference. Also\nchange the error code to -ENOMEM instead of returning success.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45028', 'https://git.kernel.org/linus/a1e627af32ed60713941cbfc8075d44cad07f6dd (6.11-rc5)', 'https://git.kernel.org/stable/c/2b507b03991f44dfb202fc2a82c9874d1b1f0c06', 'https://git.kernel.org/stable/c/3b4e76ceae5b5a46c968bd952f551ce173809f63', 'https://git.kernel.org/stable/c/9b9ba386d7bfdbc38445932c90fa9444c0524bea', 'https://git.kernel.org/stable/c/a1e627af32ed60713941cbfc8075d44cad07f6dd', 'https://git.kernel.org/stable/c/cac2815f49d343b2f0acc4973d2c14918ac3ab0c', 'https://git.kernel.org/stable/c/e40515582141a9e7c84b269be699c05236a499a6', 'https://git.kernel.org/stable/c/e97be13a9f51284da450dd2a592e3fa87b49cdc9', 'https://git.kernel.org/stable/c/ecb15b8ca12c0cbdab81e307e9795214d8b90890', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45028-34f7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45028', 'https://www.cve.org/CVERecord?id=CVE-2024-45028'], 'PublishedDate': '2024-09-11T16:15:07.647Z', 'LastModifiedDate': '2024-09-13T16:29:35.877Z'}, {'VulnerabilityID': 'CVE-2024-45029', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45029', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: i2c: tegra: Do not mark ACPI devices as irq safe', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: tegra: Do not mark ACPI devices as irq safe\n\nOn ACPI machines, the tegra i2c module encounters an issue due to a\nmutex being called inside a spinlock. This leads to the following bug:\n\n\tBUG: sleeping function called from invalid context at kernel/locking/mutex.c:585\n\t...\n\n\tCall trace:\n\t__might_sleep\n\t__mutex_lock_common\n\tmutex_lock_nested\n\tacpi_subsys_runtime_resume\n\trpm_resume\n\ttegra_i2c_xfer\n\nThe problem arises because during __pm_runtime_resume(), the spinlock\n&dev->power.lock is acquired before rpm_resume() is called. Later,\nrpm_resume() invokes acpi_subsys_runtime_resume(), which relies on\nmutexes, triggering the error.\n\nTo address this issue, devices on ACPI are now marked as not IRQ-safe,\nconsidering the dependency of acpi_subsys_runtime_resume() on mutexes.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45029', 'https://git.kernel.org/linus/14d069d92951a3e150c0a81f2ca3b93e54da913b (6.11-rc4)', 'https://git.kernel.org/stable/c/14d069d92951a3e150c0a81f2ca3b93e54da913b', 'https://git.kernel.org/stable/c/2853e1376d8161b04c9ff18ba82b43f08a049905', 'https://git.kernel.org/stable/c/6861faf4232e4b78878f2de1ed3ee324ddae2287', 'https://git.kernel.org/stable/c/a89aef1e6cc43fa019a58080ed05c839e6c77876', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45029-662e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45029', 'https://www.cve.org/CVERecord?id=CVE-2024-45029'], 'PublishedDate': '2024-09-11T16:15:07.717Z', 'LastModifiedDate': '2024-09-13T16:29:29.74Z'}, {'VulnerabilityID': 'CVE-2024-45030', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45030', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: igb: cope with large MAX_SKB_FRAGS', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nigb: cope with large MAX_SKB_FRAGS\n\nSabrina reports that the igb driver does not cope well with large\nMAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload\ncorruption on TX.\n\nAn easy reproducer is to run ssh to connect to the machine. With\nMAX_SKB_FRAGS=17 it works, with MAX_SKB_FRAGS=45 it fails. This has\nbeen reported originally in\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2265320\n\nThe root cause of the issue is that the driver does not take into\naccount properly the (possibly large) shared info size when selecting\nthe ring layout, and will try to fit two packets inside the same 4K\npage even when the 1st fraglist will trump over the 2nd head.\n\nAddress the issue by checking if 2K buffers are insufficient.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45030', 'https://git.kernel.org/linus/8aba27c4a5020abdf60149239198297f88338a8d (6.11-rc5)', 'https://git.kernel.org/stable/c/8aba27c4a5020abdf60149239198297f88338a8d', 'https://git.kernel.org/stable/c/8ea80ff5d8298356d28077bc30913ed37df65109', 'https://git.kernel.org/stable/c/b52bd8bcb9e8ff250c79b44f9af8b15cae8911ab', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45030-c2eb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45030', 'https://www.cve.org/CVERecord?id=CVE-2024-45030'], 'PublishedDate': '2024-09-11T16:15:07.77Z', 'LastModifiedDate': '2024-09-13T16:29:23.557Z'}, {'VulnerabilityID': 'CVE-2024-46672', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46672', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion\n\nwpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA flush in the\ndriver for SAE/OWE offload cases") SSID based PMKSA del commands.\nbrcmfmac is not prepared and tries to dereference the NULL bssid and\npmkid pointers in cfg80211_pmksa. PMKID_V3 operations support SSID based\nupdates so copy the SSID.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46672', 'https://git.kernel.org/linus/2ad4e1ada8eebafa2d75a4b75eeeca882de6ada1 (6.11-rc4)', 'https://git.kernel.org/stable/c/1f566eb912d192c83475a919331aea59619e1197', 'https://git.kernel.org/stable/c/2ad4e1ada8eebafa2d75a4b75eeeca882de6ada1', 'https://git.kernel.org/stable/c/4291f94f8c6b01505132c22ee27b59ed27c3584f', 'https://lore.kernel.org/linux-cve-announce/2024091111-CVE-2024-46672-7542@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46672', 'https://www.cve.org/CVERecord?id=CVE-2024-46672'], 'PublishedDate': '2024-09-11T16:15:07.84Z', 'LastModifiedDate': '2024-09-13T16:29:17.123Z'}, {'VulnerabilityID': 'CVE-2024-46673', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46673', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: aacraid: Fix double-free on probe failure', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: aacraid: Fix double-free on probe failure\n\naac_probe_one() calls hardware-specific init functions through the\naac_driver_ident::init pointer, all of which eventually call down to\naac_init_adapter().\n\nIf aac_init_adapter() fails after allocating memory for aac_dev::queues,\nit frees the memory but does not clear that member.\n\nAfter the hardware-specific init function returns an error,\naac_probe_one() goes down an error path that frees the memory pointed to\nby aac_dev::queues, resulting.in a double-free.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46673', 'https://git.kernel.org/linus/919ddf8336f0b84c0453bac583808c9f165a85c2 (6.11-rc6)', 'https://git.kernel.org/stable/c/4b540ec7c0045c2d01c4e479f34bbc8f147afa4c', 'https://git.kernel.org/stable/c/564e1986b00c5f05d75342f8407f75f0a17b94df', 'https://git.kernel.org/stable/c/60962c3d8e18e5d8dfa16df788974dd7f35bd87a', 'https://git.kernel.org/stable/c/85449b28ff6a89c4513115e43ddcad949b5890c9', 'https://git.kernel.org/stable/c/8a3995a3ffeca280a961b59f5c99843d81b15929', 'https://git.kernel.org/stable/c/919ddf8336f0b84c0453bac583808c9f165a85c2', 'https://git.kernel.org/stable/c/9e96dea7eff6f2bbcd0b42a098012fc66af9eb69', 'https://git.kernel.org/stable/c/d237c7d06ffddcdb5d36948c527dc01284388218', 'https://lore.kernel.org/linux-cve-announce/2024091333-CVE-2024-46673-c49c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46673', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-46673'], 'PublishedDate': '2024-09-13T06:15:11.917Z', 'LastModifiedDate': '2024-09-13T16:51:39.117Z'}, {'VulnerabilityID': 'CVE-2024-46675', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46675', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: dwc3: core: Prevent USB core invalid event buffer address access', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: core: Prevent USB core invalid event buffer address access\n\nThis commit addresses an issue where the USB core could access an\ninvalid event buffer address during runtime suspend, potentially causing\nSMMU faults and other memory issues in Exynos platforms. The problem\narises from the following sequence.\n 1. In dwc3_gadget_suspend, there is a chance of a timeout when\n moving the USB core to the halt state after clearing the\n run/stop bit by software.\n 2. In dwc3_core_exit, the event buffer is cleared regardless of\n the USB core's status, which may lead to an SMMU faults and\n other memory issues. if the USB core tries to access the event\n buffer address.\n\nTo prevent this hardware quirk on Exynos platforms, this commit ensures\nthat the event buffer address is not cleared by software when the USB\ncore is active during runtime suspend by checking its status before\nclearing the buffer address.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46675', 'https://git.kernel.org/linus/14e497183df28c006603cc67fd3797a537eef7b9 (6.11-rc6)', 'https://git.kernel.org/stable/c/111277b881def3153335acfe0d1f43e6cd83ac93', 'https://git.kernel.org/stable/c/14e497183df28c006603cc67fd3797a537eef7b9', 'https://git.kernel.org/stable/c/2189fd13c577d7881f94affc09c950a795064c4b', 'https://git.kernel.org/stable/c/7bb11a75dd4d3612378b90e2a4aa49bdccea28ab', 'https://git.kernel.org/stable/c/b72da4d89b97da71e056cc4d1429b2bc426a9c2f', 'https://git.kernel.org/stable/c/d2afc2bffec77316b90d530b07695e3f534df914', 'https://git.kernel.org/stable/c/e23f6ad8d110bf632f7471482e10b43dc174fb72', 'https://git.kernel.org/stable/c/eca3f543f817da87c00d1a5697b473efb548204f', 'https://lore.kernel.org/linux-cve-announce/2024091335-CVE-2024-46675-ba70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46675', 'https://www.cve.org/CVERecord?id=CVE-2024-46675'], 'PublishedDate': '2024-09-13T06:15:12.117Z', 'LastModifiedDate': '2024-09-20T17:18:48.753Z'}, {'VulnerabilityID': 'CVE-2024-46676', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46676', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfc: pn533: Add poll mod list filling check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: Add poll mod list filling check\n\nIn case of im_protocols value is 1 and tm_protocols value is 0 this\ncombination successfully passes the check\n\'if (!im_protocols && !tm_protocols)\' in the nfc_start_poll().\nBut then after pn533_poll_create_mod_list() call in pn533_start_poll()\npoll mod list will remain empty and dev->poll_mod_count will remain 0\nwhich lead to division by zero.\n\nNormally no im protocol has value 1 in the mask, so this combination is\nnot expected by driver. But these protocol values actually come from\nuserspace via Netlink interface (NFC_CMD_START_POLL operation). So a\nbroken or malicious program may pass a message containing a "bad"\ncombination of protocol parameter values so that dev->poll_mod_count\nis not incremented inside pn533_poll_create_mod_list(), thus leading\nto division by zero.\nCall trace looks like:\nnfc_genl_start_poll()\n nfc_start_poll()\n ->start_poll()\n pn533_start_poll()\n\nAdd poll mod list filling check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46676', 'https://git.kernel.org/linus/febccb39255f9df35527b88c953b2e0deae50e53 (6.11-rc6)', 'https://git.kernel.org/stable/c/56ad559cf6d87f250a8d203b555dfc3716afa946', 'https://git.kernel.org/stable/c/64513d0e546a1f19e390f7e5eba3872bfcbdacf5', 'https://git.kernel.org/stable/c/7535db0624a2dede374c42040808ad9a9101d723', 'https://git.kernel.org/stable/c/7ecd3dd4f8eecd3309432156ccfe24768e009ec4', 'https://git.kernel.org/stable/c/8ddaea033de051ed61b39f6b69ad54a411172b33', 'https://git.kernel.org/stable/c/c5e05237444f32f6cfe5d907603a232c77a08b31', 'https://git.kernel.org/stable/c/febccb39255f9df35527b88c953b2e0deae50e53', 'https://lore.kernel.org/linux-cve-announce/2024091335-CVE-2024-46676-0b05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46676', 'https://www.cve.org/CVERecord?id=CVE-2024-46676'], 'PublishedDate': '2024-09-13T06:15:12.223Z', 'LastModifiedDate': '2024-09-23T14:42:38.23Z'}, {'VulnerabilityID': 'CVE-2024-46677', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46677', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gtp: fix a potential NULL pointer dereference', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix a potential NULL pointer dereference\n\nWhen sockfd_lookup() fails, gtp_encap_enable_socket() returns a\nNULL pointer, but its callers only check for error pointers thus miss\nthe NULL pointer case.\n\nFix it by returning an error pointer with the error code carried from\nsockfd_lookup().\n\n(I found this bug during code inspection.)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46677', 'https://git.kernel.org/linus/defd8b3c37b0f9cb3e0f60f47d3d78d459d57fda (6.11-rc6)', 'https://git.kernel.org/stable/c/28c67f0f84f889fe9f4cbda8354132b20dc9212d', 'https://git.kernel.org/stable/c/4643b91691e969b1b9ad54bf552d7a990cfa3b87', 'https://git.kernel.org/stable/c/612edd35f2a3910ab1f61c1f2338889d4ba99fa2', 'https://git.kernel.org/stable/c/620fe9809752fae91b4190e897b81ed9976dfb39', 'https://git.kernel.org/stable/c/8bbb9e4e0e66a39282e582d0440724055404b38c', 'https://git.kernel.org/stable/c/bdd99e5f0ad5fa727b16f2101fe880aa2bff2f8e', 'https://git.kernel.org/stable/c/defd8b3c37b0f9cb3e0f60f47d3d78d459d57fda', 'https://git.kernel.org/stable/c/e8b9930b0eb045d19e883c65ff9676fc89320c70', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46677-b53c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46677', 'https://www.cve.org/CVERecord?id=CVE-2024-46677'], 'PublishedDate': '2024-09-13T06:15:12.36Z', 'LastModifiedDate': '2024-09-13T16:51:53.69Z'}, {'VulnerabilityID': 'CVE-2024-46678', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46678', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bonding: change ipsec_lock from spin lock to mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: change ipsec_lock from spin lock to mutex\n\nIn the cited commit, bond->ipsec_lock is added to protect ipsec_list,\nhence xdo_dev_state_add and xdo_dev_state_delete are called inside\nthis lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep,\n"scheduling while atomic" will be triggered when changing bond\'s\nactive slave.\n\n[ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200\n[ 101.055726] Modules linked in:\n[ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1\n[ 101.058760] Hardware name:\n[ 101.059434] Call Trace:\n[ 101.059436] \n[ 101.060873] dump_stack_lvl+0x51/0x60\n[ 101.061275] __schedule_bug+0x4e/0x60\n[ 101.061682] __schedule+0x612/0x7c0\n[ 101.062078] ? __mod_timer+0x25c/0x370\n[ 101.062486] schedule+0x25/0xd0\n[ 101.062845] schedule_timeout+0x77/0xf0\n[ 101.063265] ? asm_common_interrupt+0x22/0x40\n[ 101.063724] ? __bpf_trace_itimer_state+0x10/0x10\n[ 101.064215] __wait_for_common+0x87/0x190\n[ 101.064648] ? usleep_range_state+0x90/0x90\n[ 101.065091] cmd_exec+0x437/0xb20 [mlx5_core]\n[ 101.065569] mlx5_cmd_do+0x1e/0x40 [mlx5_core]\n[ 101.066051] mlx5_cmd_exec+0x18/0x30 [mlx5_core]\n[ 101.066552] mlx5_crypto_create_dek_key+0xea/0x120 [mlx5_core]\n[ 101.067163] ? bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[ 101.067738] ? kmalloc_trace+0x4d/0x350\n[ 101.068156] mlx5_ipsec_create_sa_ctx+0x33/0x100 [mlx5_core]\n[ 101.068747] mlx5e_xfrm_add_state+0x47b/0xaa0 [mlx5_core]\n[ 101.069312] bond_change_active_slave+0x392/0x900 [bonding]\n[ 101.069868] bond_option_active_slave_set+0x1c2/0x240 [bonding]\n[ 101.070454] __bond_opt_set+0xa6/0x430 [bonding]\n[ 101.070935] __bond_opt_set_notify+0x2f/0x90 [bonding]\n[ 101.071453] bond_opt_tryset_rtnl+0x72/0xb0 [bonding]\n[ 101.071965] bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[ 101.072567] kernfs_fop_write_iter+0x10c/0x1a0\n[ 101.073033] vfs_write+0x2d8/0x400\n[ 101.073416] ? alloc_fd+0x48/0x180\n[ 101.073798] ksys_write+0x5f/0xe0\n[ 101.074175] do_syscall_64+0x52/0x110\n[ 101.074576] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nAs bond_ipsec_add_sa_all and bond_ipsec_del_sa_all are only called\nfrom bond_change_active_slave, which requires holding the RTNL lock.\nAnd bond_ipsec_add_sa and bond_ipsec_del_sa are xfrm state\nxdo_dev_state_add and xdo_dev_state_delete APIs, which are in user\ncontext. So ipsec_lock doesn\'t have to be spin lock, change it to\nmutex, and thus the above issue can be resolved.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46678', 'https://git.kernel.org/linus/2aeeef906d5a526dc60cf4af92eda69836c39b1f (6.11-rc6)', 'https://git.kernel.org/stable/c/2aeeef906d5a526dc60cf4af92eda69836c39b1f', 'https://git.kernel.org/stable/c/56354b0a2c24a7828eeed7de4b4dc9652d9affa3', 'https://git.kernel.org/stable/c/6b598069164ac1bb60996d6ff94e7f9169dbd2d3', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46678-ca65@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46678', 'https://www.cve.org/CVERecord?id=CVE-2024-46678'], 'PublishedDate': '2024-09-13T06:15:12.45Z', 'LastModifiedDate': '2024-09-23T14:44:12.88Z'}, {'VulnerabilityID': 'CVE-2024-46679', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46679', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ethtool: check device is present when getting link settings', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: check device is present when getting link settings\n\nA sysfs reader can race with a device reset or removal, attempting to\nread device state when the device is not actually present. eg:\n\n [exception RIP: qed_get_current_link+17]\n #8 [ffffb9e4f2907c48] qede_get_link_ksettings at ffffffffc07a994a [qede]\n #9 [ffffb9e4f2907cd8] __rh_call_get_link_ksettings at ffffffff992b01a3\n #10 [ffffb9e4f2907d38] __ethtool_get_link_ksettings at ffffffff992b04e4\n #11 [ffffb9e4f2907d90] duplex_show at ffffffff99260300\n #12 [ffffb9e4f2907e38] dev_attr_show at ffffffff9905a01c\n #13 [ffffb9e4f2907e50] sysfs_kf_seq_show at ffffffff98e0145b\n #14 [ffffb9e4f2907e68] seq_read at ffffffff98d902e3\n #15 [ffffb9e4f2907ec8] vfs_read at ffffffff98d657d1\n #16 [ffffb9e4f2907f00] ksys_read at ffffffff98d65c3f\n #17 [ffffb9e4f2907f38] do_syscall_64 at ffffffff98a052fb\n\n crash> struct net_device.state ffff9a9d21336000\n state = 5,\n\nstate 5 is __LINK_STATE_START (0b1) and __LINK_STATE_NOCARRIER (0b100).\nThe device is not present, note lack of __LINK_STATE_PRESENT (0b10).\n\nThis is the same sort of panic as observed in commit 4224cfd7fb65\n("net-sysfs: add check for netdevice being present to speed_show").\n\nThere are many other callers of __ethtool_get_link_ksettings() which\ndon\'t have a device presence check.\n\nMove this check into ethtool to protect all callers.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46679', 'https://git.kernel.org/linus/a699781c79ecf6cfe67fb00a0331b4088c7c8466 (6.11-rc6)', 'https://git.kernel.org/stable/c/1d6d9b5b1b95bfeccb84386a51b7e6c510ec13b2', 'https://git.kernel.org/stable/c/7a8d98b6d6484d3ad358510366022da080c37cbc', 'https://git.kernel.org/stable/c/842a40c7273ba1c1cb30dda50405b328de1d860e', 'https://git.kernel.org/stable/c/94ab317024ba373d37340893d1c0358638935fbb', 'https://git.kernel.org/stable/c/9bba5955eed160102114d4cc00c3d399be9bdae4', 'https://git.kernel.org/stable/c/a699781c79ecf6cfe67fb00a0331b4088c7c8466', 'https://git.kernel.org/stable/c/ec7b4f7f644018ac293cb1b02528a40a32917e62', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46679-3527@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46679', 'https://www.cve.org/CVERecord?id=CVE-2024-46679'], 'PublishedDate': '2024-09-13T06:15:12.53Z', 'LastModifiedDate': '2024-09-23T14:47:23.287Z'}, {'VulnerabilityID': 'CVE-2024-46680', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46680', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: btnxpuart: Fix random crash seen while removing driver', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix random crash seen while removing driver\n\nThis fixes the random kernel crash seen while removing the driver, when\nrunning the load/unload test over multiple iterations.\n\n1) modprobe btnxpuart\n2) hciconfig hci0 reset\n3) hciconfig (check hci0 interface up with valid BD address)\n4) modprobe -r btnxpuart\nRepeat steps 1 to 4\n\nThe ps_wakeup() call in btnxpuart_close() schedules the psdata->work(),\nwhich gets scheduled after module is removed, causing a kernel crash.\n\nThis hidden issue got highlighted after enabling Power Save by default\nin 4183a7be7700 (Bluetooth: btnxpuart: Enable Power Save feature on\nstartup)\n\nThe new ps_cleanup() deasserts UART break immediately while closing\nserdev device, cancels any scheduled ps_work and destroys the ps_lock\nmutex.\n\n[ 85.884604] Unable to handle kernel paging request at virtual address ffffd4a61638f258\n[ 85.884624] Mem abort info:\n[ 85.884625] ESR = 0x0000000086000007\n[ 85.884628] EC = 0x21: IABT (current EL), IL = 32 bits\n[ 85.884633] SET = 0, FnV = 0\n[ 85.884636] EA = 0, S1PTW = 0\n[ 85.884638] FSC = 0x07: level 3 translation fault\n[ 85.884642] swapper pgtable: 4k pages, 48-bit VAs, pgdp=0000000041dd0000\n[ 85.884646] [ffffd4a61638f258] pgd=1000000095fff003, p4d=1000000095fff003, pud=100000004823d003, pmd=100000004823e003, pte=0000000000000000\n[ 85.884662] Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n[ 85.890932] Modules linked in: algif_hash algif_skcipher af_alg overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_spdif snd_soc_fsl_micfil snd_soc_fsl_sai snd_soc_fsl_utils gpio_ir_recv rc_core fuse [last unloaded: btnxpuart(O)]\n[ 85.927297] CPU: 1 PID: 67 Comm: kworker/1:3 Tainted: G O 6.1.36+g937b1be4345a #1\n[ 85.936176] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 85.936182] Workqueue: events 0xffffd4a61638f380\n[ 85.936198] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 85.952817] pc : 0xffffd4a61638f258\n[ 85.952823] lr : 0xffffd4a61638f258\n[ 85.952827] sp : ffff8000084fbd70\n[ 85.952829] x29: ffff8000084fbd70 x28: 0000000000000000 x27: 0000000000000000\n[ 85.963112] x26: ffffd4a69133f000 x25: ffff4bf1c8540990 x24: ffff4bf215b87305\n[ 85.963119] x23: ffff4bf215b87300 x22: ffff4bf1c85409d0 x21: ffff4bf1c8540970\n[ 85.977382] x20: 0000000000000000 x19: ffff4bf1c8540880 x18: 0000000000000000\n[ 85.977391] x17: 0000000000000000 x16: 0000000000000133 x15: 0000ffffe2217090\n[ 85.977399] x14: 0000000000000001 x13: 0000000000000133 x12: 0000000000000139\n[ 85.977407] x11: 0000000000000001 x10: 0000000000000a60 x9 : ffff8000084fbc50\n[ 85.977417] x8 : ffff4bf215b7d000 x7 : ffff4bf215b83b40 x6 : 00000000000003e8\n[ 85.977424] x5 : 00000000410fd030 x4 : 0000000000000000 x3 : 0000000000000000\n[ 85.977432] x2 : 0000000000000000 x1 : ffff4bf1c4265880 x0 : 0000000000000000\n[ 85.977443] Call trace:\n[ 85.977446] 0xffffd4a61638f258\n[ 85.977451] 0xffffd4a61638f3e8\n[ 85.977455] process_one_work+0x1d4/0x330\n[ 85.977464] worker_thread+0x6c/0x430\n[ 85.977471] kthread+0x108/0x10c\n[ 85.977476] ret_from_fork+0x10/0x20\n[ 85.977488] Code: bad PC value\n[ 85.977491] ---[ end trace 0000000000000000 ]---\n\nPreset since v6.9.11', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46680', 'https://git.kernel.org/linus/35237475384ab3622f63c3c09bdf6af6dacfe9c3 (6.11-rc6)', 'https://git.kernel.org/stable/c/29a1d9971e38f92c84b363ff50379dd434ddfe1c', 'https://git.kernel.org/stable/c/35237475384ab3622f63c3c09bdf6af6dacfe9c3', 'https://git.kernel.org/stable/c/662a55986b88807da4d112d838c8aaa05810e938', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46680-f40d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46680', 'https://www.cve.org/CVERecord?id=CVE-2024-46680'], 'PublishedDate': '2024-09-13T06:15:12.617Z', 'LastModifiedDate': '2024-09-23T14:45:10.233Z'}, {'VulnerabilityID': 'CVE-2024-46681', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46681', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pktgen: use cpus_read_lock() in pg_net_init()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npktgen: use cpus_read_lock() in pg_net_init()\n\nI have seen the WARN_ON(smp_processor_id() != cpu) firing\nin pktgen_thread_worker() during tests.\n\nWe must use cpus_read_lock()/cpus_read_unlock()\naround the for_each_online_cpu(cpu) loop.\n\nWhile we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46681', 'https://git.kernel.org/linus/979b581e4c69257acab1af415ddad6b2d78a2fa5 (6.11-rc6)', 'https://git.kernel.org/stable/c/5f5f7366dda8ae870e8305d6e7b3c0c2686cd2cf', 'https://git.kernel.org/stable/c/979b581e4c69257acab1af415ddad6b2d78a2fa5', 'https://lore.kernel.org/linux-cve-announce/2024091337-CVE-2024-46681-6086@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46681', 'https://www.cve.org/CVERecord?id=CVE-2024-46681'], 'PublishedDate': '2024-09-13T06:15:12.71Z', 'LastModifiedDate': '2024-09-19T18:10:49.623Z'}, {'VulnerabilityID': 'CVE-2024-46683', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46683', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: prevent UAF around preempt fence', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: prevent UAF around preempt fence\n\nThe fence lock is part of the queue, therefore in the current design\nanything locking the fence should then also hold a ref to the queue to\nprevent the queue from being freed.\n\nHowever, currently it looks like we signal the fence and then drop the\nqueue ref, but if something is waiting on the fence, the waiter is\nkicked to wake up at some later point, where upon waking up it first\ngrabs the lock before checking the fence state. But if we have already\ndropped the queue ref, then the lock might already be freed as part of\nthe queue, leading to uaf.\n\nTo prevent this, move the fence lock into the fence itself so we don't\nrun into lifetime issues. Alternative might be to have device level\nlock, or only release the queue in the fence release callback, however\nthat might require pushing to another worker to avoid locking issues.\n\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2454\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2342\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2020\n(cherry picked from commit 7116c35aacedc38be6d15bd21b2fc936eed0008b)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46683', 'https://git.kernel.org/linus/730b72480e29f63fd644f5fa57c9d46109428953 (6.11-rc5)', 'https://git.kernel.org/stable/c/10081b0b0ed201f53e24bd92deb2e0f3c3e713d4', 'https://git.kernel.org/stable/c/730b72480e29f63fd644f5fa57c9d46109428953', 'https://lore.kernel.org/linux-cve-announce/2024091337-CVE-2024-46683-e513@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46683', 'https://www.cve.org/CVERecord?id=CVE-2024-46683'], 'PublishedDate': '2024-09-13T06:15:12.993Z', 'LastModifiedDate': '2024-09-13T16:52:14.373Z'}, {'VulnerabilityID': 'CVE-2024-46685', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46685', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pinctrl: single: fix potential NULL dereference in pcs_get_function()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: single: fix potential NULL dereference in pcs_get_function()\n\npinmux_generic_get_function() can return NULL and the pointer 'function'\nwas dereferenced without checking against NULL. Add checking of pointer\n'function' in pcs_get_function().\n\nFound by code review.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46685', 'https://git.kernel.org/linus/1c38a62f15e595346a1106025722869e87ffe044 (6.11-rc6)', 'https://git.kernel.org/stable/c/0a2bab5ed161318f57134716accba0a30f3af191', 'https://git.kernel.org/stable/c/1c38a62f15e595346a1106025722869e87ffe044', 'https://git.kernel.org/stable/c/292151af6add3e5ab11b2e9916cffa5f52859a1f', 'https://git.kernel.org/stable/c/2cea369a5c2e85ab14ae716da1d1cc6d25c85e11', 'https://git.kernel.org/stable/c/4e9436375fcc9bd2a60ee96aba6ed53f7a377d10', 'https://git.kernel.org/stable/c/4ed45fe99ec9e3c9478bd634624cd05a57d002f7', 'https://git.kernel.org/stable/c/6341c2856785dca7006820b127278058a180c075', 'https://git.kernel.org/stable/c/8f0bd526921b6867c2f10a83cd4fd14139adcd92', 'https://lore.kernel.org/linux-cve-announce/2024091338-CVE-2024-46685-6606@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46685', 'https://www.cve.org/CVERecord?id=CVE-2024-46685'], 'PublishedDate': '2024-09-13T06:15:13.2Z', 'LastModifiedDate': '2024-09-14T16:00:55.547Z'}, {'VulnerabilityID': 'CVE-2024-46686', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46686', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: avoid dereferencing rdata=NULL in smb2_new_read_req()\n\nThis happens when called from SMB2_read() while using rdma\nand reaching the rdma_readwrite_threshold.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46686', 'https://git.kernel.org/linus/c724b2ab6a46435b4e7d58ad2fbbdb7a318823cf (6.11-rc6)', 'https://git.kernel.org/stable/c/6df57c63c200cd05e085c3b695128260e21959b7', 'https://git.kernel.org/stable/c/a01859dd6aebf826576513850a3b05992809e9d2', 'https://git.kernel.org/stable/c/b902fb78ab21299e4dd1775e7e8d251d5c0735bc', 'https://git.kernel.org/stable/c/c724b2ab6a46435b4e7d58ad2fbbdb7a318823cf', 'https://lore.kernel.org/linux-cve-announce/2024091338-CVE-2024-46686-5b18@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46686', 'https://www.cve.org/CVERecord?id=CVE-2024-46686'], 'PublishedDate': '2024-09-13T06:15:13.28Z', 'LastModifiedDate': '2024-09-14T16:16:33.087Z'}, {'VulnerabilityID': 'CVE-2024-46687', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46687', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()\n\n[BUG]\nThere is an internal report that KASAN is reporting use-after-free, with\nthe following backtrace:\n\n BUG: KASAN: slab-use-after-free in btrfs_check_read_bio+0xa68/0xb70 [btrfs]\n Read of size 4 at addr ffff8881117cec28 by task kworker/u16:2/45\n CPU: 1 UID: 0 PID: 45 Comm: kworker/u16:2 Not tainted 6.11.0-rc2-next-20240805-default+ #76\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\n Workqueue: btrfs-endio btrfs_end_bio_work [btrfs]\n Call Trace:\n dump_stack_lvl+0x61/0x80\n print_address_description.constprop.0+0x5e/0x2f0\n print_report+0x118/0x216\n kasan_report+0x11d/0x1f0\n btrfs_check_read_bio+0xa68/0xb70 [btrfs]\n process_one_work+0xce0/0x12a0\n worker_thread+0x717/0x1250\n kthread+0x2e3/0x3c0\n ret_from_fork+0x2d/0x70\n ret_from_fork_asm+0x11/0x20\n\n Allocated by task 20917:\n kasan_save_stack+0x37/0x60\n kasan_save_track+0x10/0x30\n __kasan_slab_alloc+0x7d/0x80\n kmem_cache_alloc_noprof+0x16e/0x3e0\n mempool_alloc_noprof+0x12e/0x310\n bio_alloc_bioset+0x3f0/0x7a0\n btrfs_bio_alloc+0x2e/0x50 [btrfs]\n submit_extent_page+0x4d1/0xdb0 [btrfs]\n btrfs_do_readpage+0x8b4/0x12a0 [btrfs]\n btrfs_readahead+0x29a/0x430 [btrfs]\n read_pages+0x1a7/0xc60\n page_cache_ra_unbounded+0x2ad/0x560\n filemap_get_pages+0x629/0xa20\n filemap_read+0x335/0xbf0\n vfs_read+0x790/0xcb0\n ksys_read+0xfd/0x1d0\n do_syscall_64+0x6d/0x140\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n Freed by task 20917:\n kasan_save_stack+0x37/0x60\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x37/0x50\n __kasan_slab_free+0x4b/0x60\n kmem_cache_free+0x214/0x5d0\n bio_free+0xed/0x180\n end_bbio_data_read+0x1cc/0x580 [btrfs]\n btrfs_submit_chunk+0x98d/0x1880 [btrfs]\n btrfs_submit_bio+0x33/0x70 [btrfs]\n submit_one_bio+0xd4/0x130 [btrfs]\n submit_extent_page+0x3ea/0xdb0 [btrfs]\n btrfs_do_readpage+0x8b4/0x12a0 [btrfs]\n btrfs_readahead+0x29a/0x430 [btrfs]\n read_pages+0x1a7/0xc60\n page_cache_ra_unbounded+0x2ad/0x560\n filemap_get_pages+0x629/0xa20\n filemap_read+0x335/0xbf0\n vfs_read+0x790/0xcb0\n ksys_read+0xfd/0x1d0\n do_syscall_64+0x6d/0x140\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n[CAUSE]\nAlthough I cannot reproduce the error, the report itself is good enough\nto pin down the cause.\n\nThe call trace is the regular endio workqueue context, but the\nfree-by-task trace is showing that during btrfs_submit_chunk() we\nalready hit a critical error, and is calling btrfs_bio_end_io() to error\nout. And the original endio function called bio_put() to free the whole\nbio.\n\nThis means a double freeing thus causing use-after-free, e.g.:\n\n1. Enter btrfs_submit_bio() with a read bio\n The read bio length is 128K, crossing two 64K stripes.\n\n2. The first run of btrfs_submit_chunk()\n\n2.1 Call btrfs_map_block(), which returns 64K\n2.2 Call btrfs_split_bio()\n Now there are two bios, one referring to the first 64K, the other\n referring to the second 64K.\n2.3 The first half is submitted.\n\n3. The second run of btrfs_submit_chunk()\n\n3.1 Call btrfs_map_block(), which by somehow failed\n Now we call btrfs_bio_end_io() to handle the error\n\n3.2 btrfs_bio_end_io() calls the original endio function\n Which is end_bbio_data_read(), and it calls bio_put() for the\n original bio.\n\n Now the original bio is freed.\n\n4. The submitted first 64K bio finished\n Now we call into btrfs_check_read_bio() and tries to advance the bio\n iter.\n But since the original bio (thus its iter) is already freed, we\n trigger the above use-after free.\n\n And even if the memory is not poisoned/corrupted, we will later call\n the original endio function, causing a double freeing.\n\n[FIX]\nInstead of calling btrfs_bio_end_io(), call btrfs_orig_bbio_end_io(),\nwhich has the extra check on split bios and do the pr\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415', 'CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46687', 'https://git.kernel.org/linus/10d9d8c3512f16cad47b2ff81ec6fc4b27d8ee10 (6.11-rc6)', 'https://git.kernel.org/stable/c/10d9d8c3512f16cad47b2ff81ec6fc4b27d8ee10', 'https://git.kernel.org/stable/c/4a3b9e1a8e6cd1a8d427a905e159de58d38941cc', 'https://git.kernel.org/stable/c/51722b99f41f5e722ffa10b8f61e802a0e70b331', 'https://lore.kernel.org/linux-cve-announce/2024091338-CVE-2024-46687-5668@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46687', 'https://www.cve.org/CVERecord?id=CVE-2024-46687'], 'PublishedDate': '2024-09-13T06:15:13.377Z', 'LastModifiedDate': '2024-09-14T16:17:33.073Z'}, {'VulnerabilityID': 'CVE-2024-46689', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46689', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: cmd-db: Map shared memory as WC, not WB\n\nLinux does not write into cmd-db region. This region of memory is write\nprotected by XPU. XPU may sometime falsely detect clean cache eviction\nas "write" into the write protected region leading to secure interrupt\nwhich causes an endless loop somewhere in Trust Zone.\n\nThe only reason it is working right now is because Qualcomm Hypervisor\nmaps the same region as Non-Cacheable memory in Stage 2 translation\ntables. The issue manifests if we want to use another hypervisor (like\nXen or KVM), which does not know anything about those specific mappings.\n\nChanging the mapping of cmd-db memory from MEMREMAP_WB to MEMREMAP_WT/WC\nremoves dependency on correct mappings in Stage 2 tables. This patch\nfixes the issue by updating the mapping to MEMREMAP_WC.\n\nI tested this on SA8155P with Xen.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46689', 'https://git.kernel.org/linus/f9bb896eab221618927ae6a2f1d566567999839d (6.11-rc6)', 'https://git.kernel.org/stable/c/0ee9594c974368a17e85a431e9fe1c14fb65c278', 'https://git.kernel.org/stable/c/62c2d63605ca25b5db78a347ed303c0a0a77d5b4', 'https://git.kernel.org/stable/c/d9d48d70e922b272875cda60d2ada89291c840cf', 'https://git.kernel.org/stable/c/eaff392c1e34fb77cc61505a31b0191e5e46e271', 'https://git.kernel.org/stable/c/ef80520be0ff78ae5ed44cb6eee1525e65bebe70', 'https://git.kernel.org/stable/c/f5a5a5a0e95f36e2792d48e6e4b64e665eb01374', 'https://git.kernel.org/stable/c/f9bb896eab221618927ae6a2f1d566567999839d', 'https://lore.kernel.org/linux-cve-announce/2024091339-CVE-2024-46689-4c19@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46689', 'https://www.cve.org/CVERecord?id=CVE-2024-46689'], 'PublishedDate': '2024-09-13T06:15:13.653Z', 'LastModifiedDate': '2024-09-20T15:52:23.727Z'}, {'VulnerabilityID': 'CVE-2024-46691', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46691', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: typec: ucsi: Move unregister out of atomic section', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Move unregister out of atomic section\n\nCommit \'9329933699b3 ("soc: qcom: pmic_glink: Make client-lock\nnon-sleeping")\' moved the pmic_glink client list under a spinlock, as it\nis accessed by the rpmsg/glink callback, which in turn is invoked from\nIRQ context.\n\nThis means that ucsi_unregister() is now called from atomic context,\nwhich isn\'t feasible as it\'s expecting a sleepable context. An effort is\nunder way to get GLINK to invoke its callbacks in a sleepable context,\nbut until then lets schedule the unregistration.\n\nA side effect of this is that ucsi_unregister() can now happen\nafter the remote processor, and thereby the communication link with it, is\ngone. pmic_glink_send() is amended with a check to avoid the resulting NULL\npointer dereference.\nThis does however result in the user being informed about this error by\nthe following entry in the kernel log:\n\n ucsi_glink.pmic_glink_ucsi pmic_glink.ucsi.0: failed to send UCSI write request: -5', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46691', 'https://git.kernel.org/linus/11bb2ffb679399f99041540cf662409905179e3a (6.11-rc6)', 'https://git.kernel.org/stable/c/095b0001aefddcd9361097c971b7debc84e72714', 'https://git.kernel.org/stable/c/11bb2ffb679399f99041540cf662409905179e3a', 'https://lore.kernel.org/linux-cve-announce/2024091339-CVE-2024-46691-93e1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46691', 'https://www.cve.org/CVERecord?id=CVE-2024-46691'], 'PublishedDate': '2024-09-13T06:15:13.96Z', 'LastModifiedDate': '2024-09-13T16:52:21.057Z'}, {'VulnerabilityID': 'CVE-2024-46692', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46692', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: firmware: qcom: scm: Mark get_wq_ctx() as atomic call', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: scm: Mark get_wq_ctx() as atomic call\n\nCurrently get_wq_ctx() is wrongly configured as a standard call. When two\nSMC calls are in sleep and one SMC wakes up, it calls get_wq_ctx() to\nresume the corresponding sleeping thread. But if get_wq_ctx() is\ninterrupted, goes to sleep and another SMC call is waiting to be allocated\na waitq context, it leads to a deadlock.\n\nTo avoid this get_wq_ctx() must be an atomic call and can't be a standard\nSMC call. Hence mark get_wq_ctx() as a fast call.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46692', 'https://git.kernel.org/linus/9960085a3a82c58d3323c1c20b991db6045063b0 (6.11-rc6)', 'https://git.kernel.org/stable/c/9960085a3a82c58d3323c1c20b991db6045063b0', 'https://git.kernel.org/stable/c/cdf7efe4b02aa93813db0bf1ca596ad298ab6b06', 'https://git.kernel.org/stable/c/e40115c33c0d79c940545b6b12112aace7acd9f5', 'https://lore.kernel.org/linux-cve-announce/2024091339-CVE-2024-46692-f287@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46692', 'https://www.cve.org/CVERecord?id=CVE-2024-46692'], 'PublishedDate': '2024-09-13T06:15:14.047Z', 'LastModifiedDate': '2024-09-13T16:52:31.627Z'}, {'VulnerabilityID': 'CVE-2024-46693', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46693', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: pmic_glink: Fix race during initialization', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pmic_glink: Fix race during initialization\n\nAs pointed out by Stephen Boyd it is possible that during initialization\nof the pmic_glink child drivers, the protection-domain notifiers fires,\nand the associated work is scheduled, before the client registration\nreturns and as a result the local "client" pointer has been initialized.\n\nThe outcome of this is a NULL pointer dereference as the "client"\npointer is blindly dereferenced.\n\nTimeline provided by Stephen:\n CPU0 CPU1\n ---- ----\n ucsi->client = NULL;\n devm_pmic_glink_register_client()\n client->pdr_notify(client->priv, pg->client_state)\n pmic_glink_ucsi_pdr_notify()\n schedule_work(&ucsi->register_work)\n \n pmic_glink_ucsi_register()\n ucsi_register()\n pmic_glink_ucsi_read_version()\n pmic_glink_ucsi_read()\n pmic_glink_ucsi_read()\n pmic_glink_send(ucsi->client)\n \n ucsi->client = client // Too late!\n\nThis code is identical across the altmode, battery manager and usci\nchild drivers.\n\nResolve this by splitting the allocation of the "client" object and the\nregistration thereof into two operations.\n\nThis only happens if the protection domain registry is populated at the\ntime of registration, which by the introduction of commit \'1ebcde047c54\n("soc: qcom: add pd-mapper implementation")\' became much more likely.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46693', 'https://git.kernel.org/linus/3568affcddd68743e25aa3ec1647d9b82797757b (6.11-rc6)', 'https://git.kernel.org/stable/c/1efdbf5323c9360e05066049b97414405e94e087', 'https://git.kernel.org/stable/c/3568affcddd68743e25aa3ec1647d9b82797757b', 'https://git.kernel.org/stable/c/943b0e7cc646a624bb20a68080f8f1a4a55df41c', 'https://lore.kernel.org/linux-cve-announce/2024091340-CVE-2024-46693-cbe3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46693', 'https://www.cve.org/CVERecord?id=CVE-2024-46693'], 'PublishedDate': '2024-09-13T06:15:14.14Z', 'LastModifiedDate': '2024-09-13T16:52:41.27Z'}, {'VulnerabilityID': 'CVE-2024-46694', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46694', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: avoid using null object of framebuffer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: avoid using null object of framebuffer\n\nInstead of using state->fb->obj[0] directly, get object from framebuffer\nby calling drm_gem_fb_get_obj() and return error code when object is\nnull to avoid using null object of framebuffer.\n\n(cherry picked from commit 73dd0ad9e5dad53766ea3e631303430116f834b3)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46694', 'https://git.kernel.org/linus/3b9a33235c773c7a3768060cf1d2cf8a9153bc37 (6.11-rc6)', 'https://git.kernel.org/stable/c/093ee72ed35c2338c87c26b6ba6f0b7789c9e14e', 'https://git.kernel.org/stable/c/3b9a33235c773c7a3768060cf1d2cf8a9153bc37', 'https://git.kernel.org/stable/c/49e1b214f3239b78967c6ddb8f8ec47ae047b051', 'https://git.kernel.org/stable/c/f6f5e39a3fe7cbdba190f42b28b40bdff03c8cf0', 'https://lore.kernel.org/linux-cve-announce/2024091340-CVE-2024-46694-0706@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46694', 'https://www.cve.org/CVERecord?id=CVE-2024-46694'], 'PublishedDate': '2024-09-13T06:15:14.24Z', 'LastModifiedDate': '2024-09-19T18:16:22.247Z'}, {'VulnerabilityID': 'CVE-2024-46695', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46695', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: selinux,smack: don't bypass permissions check in inode_setsecctx hook', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux,smack: don't bypass permissions check in inode_setsecctx hook\n\nMarek Gresko reports that the root user on an NFS client is able to\nchange the security labels on files on an NFS filesystem that is\nexported with root squashing enabled.\n\nThe end of the kerneldoc comment for __vfs_setxattr_noperm() states:\n\n * This function requires the caller to lock the inode's i_mutex before it\n * is executed. It also assumes that the caller will make the appropriate\n * permission checks.\n\nnfsd_setattr() does do permissions checking via fh_verify() and\nnfsd_permission(), but those don't do all the same permissions checks\nthat are done by security_inode_setxattr() and its related LSM hooks do.\n\nSince nfsd_setattr() is the only consumer of security_inode_setsecctx(),\nsimplest solution appears to be to replace the call to\n__vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This\nfixes the above issue and has the added benefit of causing nfsd to\nrecall conflicting delegations on a file when a client tries to change\nits security label.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-276'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46695', 'https://git.kernel.org/linus/76a0e79bc84f466999fa501fce5bf7a07641b8a7 (6.11-rc6)', 'https://git.kernel.org/stable/c/2dbc4b7bac60b02cc6e70d05bf6a7dfd551f9dda', 'https://git.kernel.org/stable/c/459584258d47ec3cc6245a82e8a49c9d08eb8b57', 'https://git.kernel.org/stable/c/76a0e79bc84f466999fa501fce5bf7a07641b8a7', 'https://git.kernel.org/stable/c/eebec98791d0137e455cc006411bb92a54250924', 'https://git.kernel.org/stable/c/f71ec019257ba4f7ab198bd948c5902a207bad96', 'https://git.kernel.org/stable/c/fe0cd53791119f6287b6532af8ce41576d664930', 'https://lore.kernel.org/linux-cve-announce/2024091340-CVE-2024-46695-affc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46695', 'https://www.cve.org/CVERecord?id=CVE-2024-46695'], 'PublishedDate': '2024-09-13T06:15:14.32Z', 'LastModifiedDate': '2024-10-17T14:15:07.517Z'}, {'VulnerabilityID': 'CVE-2024-46697', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46697', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfsd: ensure that nfsd4_fattr_args.context is zeroed out', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: ensure that nfsd4_fattr_args.context is zeroed out\n\nIf nfsd4_encode_fattr4 ends up doing a "goto out" before we get to\nchecking for the security label, then args.context will be set to\nuninitialized junk on the stack, which we\'ll then try to free.\nInitialize it early.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46697', 'https://git.kernel.org/linus/f58bab6fd4063913bd8321e99874b8239e9ba726 (6.11-rc6)', 'https://git.kernel.org/stable/c/dd65b324174a64558a16ebbf4c3266e5701185d0', 'https://git.kernel.org/stable/c/f58bab6fd4063913bd8321e99874b8239e9ba726', 'https://lore.kernel.org/linux-cve-announce/2024091341-CVE-2024-46697-d166@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46697', 'https://www.cve.org/CVERecord?id=CVE-2024-46697'], 'PublishedDate': '2024-09-13T06:15:14.5Z', 'LastModifiedDate': '2024-09-19T17:53:43.173Z'}, {'VulnerabilityID': 'CVE-2024-46698', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46698', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: video/aperture: optionally match the device in sysfb_disable()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvideo/aperture: optionally match the device in sysfb_disable()\n\nIn aperture_remove_conflicting_pci_devices(), we currently only\ncall sysfb_disable() on vga class devices. This leads to the\nfollowing problem when the pimary device is not VGA compatible:\n\n1. A PCI device with a non-VGA class is the boot display\n2. That device is probed first and it is not a VGA device so\n sysfb_disable() is not called, but the device resources\n are freed by aperture_detach_platform_device()\n3. Non-primary GPU has a VGA class and it ends up calling sysfb_disable()\n4. NULL pointer dereference via sysfb_disable() since the resources\n have already been freed by aperture_detach_platform_device() when\n it was called by the other device.\n\nFix this by passing a device pointer to sysfb_disable() and checking\nthe device to determine if we should execute it or not.\n\nv2: Fix build when CONFIG_SCREEN_INFO is not set\nv3: Move device check into the mutex\n Drop primary variable in aperture_remove_conflicting_pci_devices()\n Drop __init on pci sysfb_pci_dev_is_enabled()', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46698', 'https://git.kernel.org/linus/b49420d6a1aeb399e5b107fc6eb8584d0860fbd7 (6.11-rc6)', 'https://git.kernel.org/stable/c/17e78f43de0c6da34204cc858b4cc05671ea9acf', 'https://git.kernel.org/stable/c/b49420d6a1aeb399e5b107fc6eb8584d0860fbd7', 'https://lore.kernel.org/linux-cve-announce/2024091341-CVE-2024-46698-357c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46698', 'https://www.cve.org/CVERecord?id=CVE-2024-46698'], 'PublishedDate': '2024-09-13T06:15:14.563Z', 'LastModifiedDate': '2024-09-13T16:53:03Z'}, {'VulnerabilityID': 'CVE-2024-46701', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46701', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: libfs: fix infinite directory reads for offset dir', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibfs: fix infinite directory reads for offset dir\n\nAfter we switch tmpfs dir operations from simple_dir_operations to\nsimple_offset_dir_operations, every rename happened will fill new dentry\nto dest dir\'s maple tree(&SHMEM_I(inode)->dir_offsets->mt) with a free\nkey starting with octx->newx_offset, and then set newx_offset equals to\nfree key + 1. This will lead to infinite readdir combine with rename\nhappened at the same time, which fail generic/736 in xfstests(detail show\nas below).\n\n1. create 5000 files(1 2 3...) under one dir\n2. call readdir(man 3 readdir) once, and get one entry\n3. rename(entry, "TEMPFILE"), then rename("TEMPFILE", entry)\n4. loop 2~3, until readdir return nothing or we loop too many\n times(tmpfs break test with the second condition)\n\nWe choose the same logic what commit 9b378f6ad48cf ("btrfs: fix infinite\ndirectory reads") to fix it, record the last_index when we open dir, and\ndo not emit the entry which index >= last_index. The file->private_data\nnow used in offset dir can use directly to do this, and we also update\nthe last_index when we llseek the dir file.\n\n[brauner: only update last_index after seek when offset is zero like Jan suggested]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46701', 'https://git.kernel.org/linus/64a7ce76fb901bf9f9c36cf5d681328fc0fd4b5a (6.11-rc4)', 'https://git.kernel.org/stable/c/308b4fc2403b335894592ee9dc212a5e58bb309f', 'https://git.kernel.org/stable/c/64a7ce76fb901bf9f9c36cf5d681328fc0fd4b5a', 'https://lore.kernel.org/linux-cve-announce/2024091326-CVE-2024-46701-ad65@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46701', 'https://www.cve.org/CVERecord?id=CVE-2024-46701'], 'PublishedDate': '2024-09-13T07:15:05.127Z', 'LastModifiedDate': '2024-09-19T13:40:27.817Z'}, {'VulnerabilityID': 'CVE-2024-46702', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46702', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: thunderbolt: Mark XDomain as unplugged when router is removed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Mark XDomain as unplugged when router is removed\n\nI noticed that when we do discrete host router NVM upgrade and it gets\nhot-removed from the PCIe side as a result of NVM firmware authentication,\nif there is another host connected with enabled paths we hang in tearing\nthem down. This is due to fact that the Thunderbolt networking driver\nalso tries to cleanup the paths and ends up blocking in\ntb_disconnect_xdomain_paths() waiting for the domain lock.\n\nHowever, at this point we already cleaned the paths in tb_stop() so\nthere is really no need for tb_disconnect_xdomain_paths() to do that\nanymore. Furthermore it already checks if the XDomain is unplugged and\nbails out early so take advantage of that and mark the XDomain as\nunplugged when we remove the parent router.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46702', 'https://git.kernel.org/linus/e2006140ad2e01a02ed0aff49cc2ae3ceeb11f8d (6.11-rc4)', 'https://git.kernel.org/stable/c/18b3ad2a3cc877dd4b16f48d84aa27b78d53bf1d', 'https://git.kernel.org/stable/c/23ce6ba3b95488a2b9e9f6d43b340da0c15395dc', 'https://git.kernel.org/stable/c/747bc154577de6e6af4bc99abfa859b8419bb4d8', 'https://git.kernel.org/stable/c/7ca24cf9163c112bb6b580c6fb57c04a1f8b76e1', 'https://git.kernel.org/stable/c/80ac8d194831eca0c2f4fd862f7925532fda320c', 'https://git.kernel.org/stable/c/e2006140ad2e01a02ed0aff49cc2ae3ceeb11f8d', 'https://lore.kernel.org/linux-cve-announce/2024091329-CVE-2024-46702-9b8e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46702', 'https://www.cve.org/CVERecord?id=CVE-2024-46702'], 'PublishedDate': '2024-09-13T07:15:05.217Z', 'LastModifiedDate': '2024-09-19T13:35:58.637Z'}, {'VulnerabilityID': 'CVE-2024-46703', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46703', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "serial: 8250_omap: Set the console genpd always on if no console suspend"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "serial: 8250_omap: Set the console genpd always on if no console suspend"\n\nThis reverts commit 68e6939ea9ec3d6579eadeab16060339cdeaf940.\n\nKevin reported that this causes a crash during suspend on platforms that\ndont use PM domains.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46703', 'https://git.kernel.org/linus/0863bffda1131fd2fa9c05b653ad9ee3d8db127e (6.11-rc4)', 'https://git.kernel.org/stable/c/0863bffda1131fd2fa9c05b653ad9ee3d8db127e', 'https://git.kernel.org/stable/c/321aecb079e9ca8b1af90778068a6fb40f2bf22d', 'https://lore.kernel.org/linux-cve-announce/2024091329-CVE-2024-46703-1f29@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46703', 'https://www.cve.org/CVERecord?id=CVE-2024-46703'], 'PublishedDate': '2024-09-13T07:15:05.317Z', 'LastModifiedDate': '2024-09-19T13:33:57.563Z'}, {'VulnerabilityID': 'CVE-2024-46705', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46705', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: reset mmio mappings with devm', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: reset mmio mappings with devm\n\nSet our various mmio mappings to NULL. This should make it easier to\ncatch something rogue trying to mess with mmio after device removal. For\nexample, we might unmap everything and then start hitting some mmio\naddress which has already been unmamped by us and then remapped by\nsomething else, causing all kinds of carnage.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46705', 'https://git.kernel.org/linus/c7117419784f612d59ee565145f722e8b5541fe6 (6.11-rc1)', 'https://git.kernel.org/stable/c/b1c9fbed3884d3883021d699c7cdf5253a65543a', 'https://git.kernel.org/stable/c/c7117419784f612d59ee565145f722e8b5541fe6', 'https://lore.kernel.org/linux-cve-announce/2024091330-CVE-2024-46705-b9c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46705', 'https://www.cve.org/CVERecord?id=CVE-2024-46705'], 'PublishedDate': '2024-09-13T07:15:05.477Z', 'LastModifiedDate': '2024-09-19T13:30:44.133Z'}, {'VulnerabilityID': 'CVE-2024-46706', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46706', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tty: serial: fsl_lpuart: mark last busy before uart_add_one_port', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: fsl_lpuart: mark last busy before uart_add_one_port\n\nWith "earlycon initcall_debug=1 loglevel=8" in bootargs, kernel\nsometimes boot hang. It is because normal console still is not ready,\nbut runtime suspend is called, so early console putchar will hang\nin waiting TRDE set in UARTSTAT.\n\nThe lpuart driver has auto suspend delay set to 3000ms, but during\nuart_add_one_port, a child device serial ctrl will added and probed with\nits pm runtime enabled(see serial_ctrl.c).\nThe runtime suspend call path is:\ndevice_add\n |-> bus_probe_device\n |->device_initial_probe\n\t |->__device_attach\n |-> pm_runtime_get_sync(dev->parent);\n\t\t\t |-> pm_request_idle(dev);\n\t\t\t |-> pm_runtime_put(dev->parent);\n\nSo in the end, before normal console ready, the lpuart get runtime\nsuspended. And earlycon putchar will hang.\n\nTo address the issue, mark last busy just after pm_runtime_enable,\nthree seconds is long enough to switch from bootconsole to normal\nconsole.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46706', 'https://git.kernel.org/linus/dc98d76a15bc29a9a4e76f2f65f39f3e590fb15c (6.11-rc4)', 'https://git.kernel.org/stable/c/3ecf625d4acb71d726bc0b49403cf68388b3d58d', 'https://git.kernel.org/stable/c/8eb92cfca6c2c5a15ab1773f3d18ab8d8f7dbb68', 'https://git.kernel.org/stable/c/dc98d76a15bc29a9a4e76f2f65f39f3e590fb15c', 'https://lore.kernel.org/linux-cve-announce/2024091330-CVE-2024-46706-ea07@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46706', 'https://www.cve.org/CVERecord?id=CVE-2024-46706'], 'PublishedDate': '2024-09-13T07:15:05.56Z', 'LastModifiedDate': '2024-09-19T17:51:07.67Z'}, {'VulnerabilityID': 'CVE-2024-46707', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46707', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3\n\nOn a system with a GICv3, if a guest hasn't been configured with\nGICv3 and that the host is not capable of GICv2 emulation,\na write to any of the ICC_*SGI*_EL1 registers is trapped to EL2.\n\nWe therefore try to emulate the SGI access, only to hit a NULL\npointer as no private interrupt is allocated (no GIC, remember?).\n\nThe obvious fix is to give the guest what it deserves, in the\nshape of a UNDEF exception.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46707', 'https://git.kernel.org/linus/3e6245ebe7ef341639e9a7e402b3ade8ad45a19f (6.11-rc5)', 'https://git.kernel.org/stable/c/15818af2f7aa55eff375333cb7689df15d3f24ef', 'https://git.kernel.org/stable/c/2073132f6ed3079369e857a8deb33d11bdd983bc', 'https://git.kernel.org/stable/c/3e6245ebe7ef341639e9a7e402b3ade8ad45a19f', 'https://git.kernel.org/stable/c/94d4fbad01b19ec5eab3d6b50aaec4f9db8b2d8d', 'https://git.kernel.org/stable/c/96b076e8ee5bc3a1126848c8add0f74bd30dc9d1', 'https://git.kernel.org/stable/c/9d7629bec5c3f80bd0e3bf8103c06a2f7046bd92', 'https://lore.kernel.org/linux-cve-announce/2024091330-CVE-2024-46707-9e4f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46707', 'https://www.cve.org/CVERecord?id=CVE-2024-46707'], 'PublishedDate': '2024-09-13T07:15:05.643Z', 'LastModifiedDate': '2024-09-19T13:29:46.757Z'}, {'VulnerabilityID': 'CVE-2024-46708', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46708', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pinctrl: qcom: x1e80100: Fix special pin offsets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: qcom: x1e80100: Fix special pin offsets\n\nRemove the erroneus 0x100000 offset to prevent the boards from crashing\non pin state setting, as well as for the intended state changes to take\neffect.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46708', 'https://git.kernel.org/linus/d3692d95cc4d88114b070ee63cffc976f00f207f (6.11-rc6)', 'https://git.kernel.org/stable/c/0197bf772f657fbdea5e9bdec5eea6e67d82cbde', 'https://git.kernel.org/stable/c/d3692d95cc4d88114b070ee63cffc976f00f207f', 'https://lore.kernel.org/linux-cve-announce/2024091347-CVE-2024-46708-95c1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46708', 'https://www.cve.org/CVERecord?id=CVE-2024-46708'], 'PublishedDate': '2024-09-13T07:15:05.717Z', 'LastModifiedDate': '2024-09-19T13:28:49.483Z'}, {'VulnerabilityID': 'CVE-2024-46709', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46709', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Fix prime with external buffers', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix prime with external buffers\n\nMake sure that for external buffers mapping goes through the dma_buf\ninterface instead of trying to access pages directly.\n\nExternal buffers might not provide direct access to readable/writable\npages so to make sure the bo's created from external dma_bufs can be\nread dma_buf interface has to be used.\n\nFixes crashes in IGT's kms_prime with vgem. Regular desktop usage won't\ntrigger this due to the fact that virtual machines will not have\nmultiple GPUs but it enables better test coverage in IGT.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46709', 'https://git.kernel.org/linus/50f1199250912568606b3778dc56646c10cb7b04 (6.11-rc6)', 'https://git.kernel.org/stable/c/50f1199250912568606b3778dc56646c10cb7b04', 'https://git.kernel.org/stable/c/5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854', 'https://git.kernel.org/stable/c/9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4', 'https://lore.kernel.org/linux-cve-announce/2024091347-CVE-2024-46709-2465@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46709', 'https://www.cve.org/CVERecord?id=CVE-2024-46709'], 'PublishedDate': '2024-09-13T07:15:05.793Z', 'LastModifiedDate': '2024-09-19T13:26:24.14Z'}, {'VulnerabilityID': 'CVE-2024-46710', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46710', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Prevent unmapping active read buffers', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Prevent unmapping active read buffers\n\nThe kms paths keep a persistent map active to read and compare the cursor\nbuffer. These maps can race with each other in simple scenario where:\na) buffer "a" mapped for update\nb) buffer "a" mapped for compare\nc) do the compare\nd) unmap "a" for compare\ne) update the cursor\nf) unmap "a" for update\nAt step "e" the buffer has been unmapped and the read contents is bogus.\n\nPrevent unmapping of active read buffers by simply keeping a count of\nhow many paths have currently active maps and unmap only when the count\nreaches 0.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46710', 'https://git.kernel.org/linus/aba07b9a0587f50e5d3346eaa19019cf3f86c0ea (6.11-rc6)', 'https://git.kernel.org/stable/c/0851b1ec650adadcaa23ec96daad95a55bf966f0', 'https://git.kernel.org/stable/c/58a3714db4d9dcaeb9fc4905141e17b9f536c0a5', 'https://git.kernel.org/stable/c/aba07b9a0587f50e5d3346eaa19019cf3f86c0ea', 'https://git.kernel.org/stable/c/d5228d158e4c0b1663b3983044913c15c3d0135e', 'https://lore.kernel.org/linux-cve-announce/2024091347-CVE-2024-46710-cd88@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46710', 'https://www.cve.org/CVERecord?id=CVE-2024-46710'], 'PublishedDate': '2024-09-13T07:15:05.88Z', 'LastModifiedDate': '2024-10-17T14:15:07.63Z'}, {'VulnerabilityID': 'CVE-2024-46711', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46711', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: fix ID 0 endp usage after multiple re-creations', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix ID 0 endp usage after multiple re-creations\n\n\'local_addr_used\' and \'add_addr_accepted\' are decremented for addresses\nnot related to the initial subflow (ID0), because the source and\ndestination addresses of the initial subflows are known from the\nbeginning: they don\'t count as "additional local address being used" or\n"ADD_ADDR being accepted".\n\nIt is then required not to increment them when the entrypoint used by\nthe initial subflow is removed and re-added during a connection. Without\nthis modification, this entrypoint cannot be removed and re-added more\nthan once.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46711', 'https://git.kernel.org/linus/9366922adc6a71378ca01f898c41be295309f044 (6.11-rc6)', 'https://git.kernel.org/stable/c/119806ae4e46cf239db8e6ad92bc2fd3daae86dc', 'https://git.kernel.org/stable/c/53e2173172d26c0617b29dd83618b71664bed1fb', 'https://git.kernel.org/stable/c/9366922adc6a71378ca01f898c41be295309f044', 'https://git.kernel.org/stable/c/c9c744666f7308a4daba520191e29d395260bcfe', 'https://lore.kernel.org/linux-cve-announce/2024091348-CVE-2024-46711-ab95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46711', 'https://www.cve.org/CVERecord?id=CVE-2024-46711'], 'PublishedDate': '2024-09-13T07:15:05.953Z', 'LastModifiedDate': '2024-09-19T13:12:30.39Z'}, {'VulnerabilityID': 'CVE-2024-46713', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46713', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf/aux: Fix AUX buffer serialization', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf/aux: Fix AUX buffer serialization\n\nOle reported that event->mmap_mutex is strictly insufficient to\nserialize the AUX buffer, add a per RB mutex to fully serialize it.\n\nNote that in the lock order comment the perf_event::mmap_mutex order\nwas already wrong, that is, it nesting under mmap_lock is not new with\nthis patch.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46713', 'https://git.kernel.org/linus/2ab9d830262c132ab5db2f571003d80850d56b2a (6.11-rc7)', 'https://git.kernel.org/stable/c/2ab9d830262c132ab5db2f571003d80850d56b2a', 'https://git.kernel.org/stable/c/52d13d224fdf1299c8b642807fa1ea14d693f5ff', 'https://git.kernel.org/stable/c/7882923f1cb88dc1a17f2bf0c81b1fc80d44db82', 'https://git.kernel.org/stable/c/9dc7ad2b67772cfb94ceb3b0c9c4023c2463215d', 'https://git.kernel.org/stable/c/b9b6882e243b653d379abbeaa64a500182aba370', 'https://git.kernel.org/stable/c/c4b69bee3f4ef76809288fe6827bc14d4ae788ef', 'https://lore.kernel.org/linux-cve-announce/2024091316-CVE-2024-46713-5e49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46713', 'https://www.cve.org/CVERecord?id=CVE-2024-46713'], 'PublishedDate': '2024-09-13T15:15:15.01Z', 'LastModifiedDate': '2024-09-13T16:37:22.997Z'}, {'VulnerabilityID': 'CVE-2024-46714', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46714', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip wbscl_set_scaler_filter if filter is null', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip wbscl_set_scaler_filter if filter is null\n\nCallers can pass null in filter (i.e. from returned from the function\nwbscl_get_filter_coeffs_16p) and a null check is added to ensure that is\nnot the case.\n\nThis fixes 4 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46714', 'https://git.kernel.org/linus/c4d31653c03b90e51515b1380115d1aedad925dd (6.11-rc1)', 'https://git.kernel.org/stable/c/0364f1f17a86d89dc39040beea4f099e60189f1b', 'https://git.kernel.org/stable/c/1726914cb17cedab233820d26b86764dc08857b4', 'https://git.kernel.org/stable/c/54834585e91cab13e9f82d3a811deb212a4df786', 'https://git.kernel.org/stable/c/6d94c05a13fadd80c3e732f14c83b2632ebfaa50', 'https://git.kernel.org/stable/c/c083c8be6bdd046049884bec076660d4ec9a19ca', 'https://git.kernel.org/stable/c/c4d31653c03b90e51515b1380115d1aedad925dd', 'https://git.kernel.org/stable/c/e3a95f29647ae45d1ec9541cd7df64f40bf2120a', 'https://lore.kernel.org/linux-cve-announce/2024091831-CVE-2024-46714-73de@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46714', 'https://www.cve.org/CVERecord?id=CVE-2024-46714'], 'PublishedDate': '2024-09-18T07:15:03.06Z', 'LastModifiedDate': '2024-09-30T12:50:27.723Z'}, {'VulnerabilityID': 'CVE-2024-46715', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46715', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: driver: iio: add missing checks on iio_info's callback access', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver: iio: add missing checks on iio_info's callback access\n\nSome callbacks from iio_info structure are accessed without any check, so\nif a driver doesn't implement them trying to access the corresponding\nsysfs entries produce a kernel oops such as:\n\n[ 2203.527791] Unable to handle kernel NULL pointer dereference at virtual address 00000000 when execute\n[...]\n[ 2203.783416] Call trace:\n[ 2203.783429] iio_read_channel_info_avail from dev_attr_show+0x18/0x48\n[ 2203.789807] dev_attr_show from sysfs_kf_seq_show+0x90/0x120\n[ 2203.794181] sysfs_kf_seq_show from seq_read_iter+0xd0/0x4e4\n[ 2203.798555] seq_read_iter from vfs_read+0x238/0x2a0\n[ 2203.802236] vfs_read from ksys_read+0xa4/0xd4\n[ 2203.805385] ksys_read from ret_fast_syscall+0x0/0x54\n[ 2203.809135] Exception stack(0xe0badfa8 to 0xe0badff0)\n[ 2203.812880] dfa0: 00000003 b6f10f80 00000003 b6eab000 00020000 00000000\n[ 2203.819746] dfc0: 00000003 b6f10f80 7ff00000 00000003 00000003 00000000 00020000 00000000\n[ 2203.826619] dfe0: b6e1bc88 bed80958 b6e1bc94 b6e1bcb0\n[ 2203.830363] Code: bad PC value\n[ 2203.832695] ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46715', 'https://git.kernel.org/linus/c4ec8dedca961db056ec85cb7ca8c9f7e2e92252 (6.11-rc1)', 'https://git.kernel.org/stable/c/0cc7e0ee31e5c44904e98e2229d591e093282a70', 'https://git.kernel.org/stable/c/72f022ebb9deac28663fa4c04ba315ed5d6654d1', 'https://git.kernel.org/stable/c/c4ec8dedca961db056ec85cb7ca8c9f7e2e92252', 'https://git.kernel.org/stable/c/dc537a72f64890d883d24ae4ac58733fc5bc523d', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46715-7e7b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46715', 'https://www.cve.org/CVERecord?id=CVE-2024-46715'], 'PublishedDate': '2024-09-18T07:15:03.13Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46716', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor\n\nRemove list_del call in msgdma_chan_desc_cleanup, this should be the role\nof msgdma_free_descriptor. In consequence replace list_add_tail with\nlist_move_tail in msgdma_free_descriptor.\n\nThis fixes the path:\n msgdma_free_chan_resources -> msgdma_free_descriptors ->\n msgdma_free_desc_list -> msgdma_free_descriptor\n\nwhich does not correctly free the descriptors as first nodes were not\nremoved from the list.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46716', 'https://git.kernel.org/linus/54e4ada1a4206f878e345ae01cf37347d803d1b1 (6.11-rc1)', 'https://git.kernel.org/stable/c/20bf2920a869f9dbda0ef8c94c87d1901a64a716', 'https://git.kernel.org/stable/c/54e4ada1a4206f878e345ae01cf37347d803d1b1', 'https://git.kernel.org/stable/c/a3480e59fdbe5585d2d1eff0bed7671583acf725', 'https://git.kernel.org/stable/c/db67686676c7becc1910bf1d6d51505876821863', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46716-f63f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46716', 'https://www.cve.org/CVERecord?id=CVE-2024-46716'], 'PublishedDate': '2024-09-18T07:15:03.183Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46717', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46717', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: SHAMPO, Fix incorrect page release', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix incorrect page release\n\nUnder the following conditions:\n1) No skb created yet\n2) header_size == 0 (no SHAMPO header)\n3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PAGE == 0 (this is the\n last page fragment of a SHAMPO header page)\n\na new skb is formed with a page that is NOT a SHAMPO header page (it\nis a regular data page). Further down in the same function\n(mlx5e_handle_rx_cqe_mpwrq_shampo()), a SHAMPO header page from\nheader_index is released. This is wrong and it leads to SHAMPO header\npages being released more than once.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46717', 'https://git.kernel.org/linus/70bd03b89f20b9bbe51a7f73c4950565a17a45f7 (6.11-rc1)', 'https://git.kernel.org/stable/c/03924d117625ecb10ee3c9b65930bcb2c37ae629', 'https://git.kernel.org/stable/c/70bd03b89f20b9bbe51a7f73c4950565a17a45f7', 'https://git.kernel.org/stable/c/ae9018e3f61ba5cc1f08a6e51d3c0bef0a79f3ab', 'https://git.kernel.org/stable/c/c909ab41df2b09cde919801c7a7b6bb2cc37ea22', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46717-2f30@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46717', 'https://www.cve.org/CVERecord?id=CVE-2024-46717'], 'PublishedDate': '2024-09-18T07:15:03.237Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46718', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46718', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Don't overmap identity VRAM mapping', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Don't overmap identity VRAM mapping\n\nOvermapping the identity VRAM mapping is triggering hardware bugs on\ncertain platforms. Use 2M pages for the last unaligned (to 1G) VRAM\nchunk.\n\nv2:\n - Always use 2M pages for last chunk (Fei Yang)\n - break loop when 2M pages are used\n - Add assert for usable_size being 2M aligned\nv3:\n - Fix checkpatch", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46718', 'https://git.kernel.org/linus/6d3581edffea0b3a64b0d3094d3f09222e0024f7 (6.11-rc1)', 'https://git.kernel.org/stable/c/6d3581edffea0b3a64b0d3094d3f09222e0024f7', 'https://git.kernel.org/stable/c/bb706e92c87beb9f2543faa1705ccc330b9e7c65', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46718-c5c7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46718', 'https://www.cve.org/CVERecord?id=CVE-2024-46718'], 'PublishedDate': '2024-09-18T07:15:03.303Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46719', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46719', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: typec: ucsi: Fix null pointer dereference in trace', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix null pointer dereference in trace\n\nucsi_register_altmode checks IS_ERR for the alt pointer and treats\nNULL as valid. When CONFIG_TYPEC_DP_ALTMODE is not enabled,\nucsi_register_displayport returns NULL which causes a NULL pointer\ndereference in trace. Rather than return NULL, call\ntypec_port_register_altmode to register DisplayPort alternate mode\nas a non-controllable mode when CONFIG_TYPEC_DP_ALTMODE is not enabled.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46719', 'https://git.kernel.org/linus/99516f76db48e1a9d54cdfed63c1babcee4e71a5 (6.11-rc1)', 'https://git.kernel.org/stable/c/3aa56313b0de06ce1911950b2cc0c269614a87a9', 'https://git.kernel.org/stable/c/3b9f2d9301ae67070fe77a0c06758722fd7172b7', 'https://git.kernel.org/stable/c/7e64cabe81c303bdf6fd26b6a09a3289b33bc870', 'https://git.kernel.org/stable/c/8095bf0579ed4906a33f7bec675bfb29b6b16a3b', 'https://git.kernel.org/stable/c/99331fe68a8eaa4097143a33fb0c12d5e5e8e830', 'https://git.kernel.org/stable/c/99516f76db48e1a9d54cdfed63c1babcee4e71a5', 'https://git.kernel.org/stable/c/b4243c05d7e3db0bdbf9124e6fa59b4ca7c807ae', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46719-4a53@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46719', 'https://www.cve.org/CVERecord?id=CVE-2024-46719'], 'PublishedDate': '2024-09-18T07:15:03.357Z', 'LastModifiedDate': '2024-09-20T18:21:49.963Z'}, {'VulnerabilityID': 'CVE-2024-46720', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46720', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix dereference after null check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix dereference after null check\n\ncheck the pointer hive before use.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46720', 'https://git.kernel.org/linus/b1f7810b05d1950350ac2e06992982974343e441 (6.11-rc1)', 'https://git.kernel.org/stable/c/00b9594d6310eb33e14d3f07b54866499efe0d50', 'https://git.kernel.org/stable/c/0aad97bf6d0bc7a34a19f266b0b9fb2861efe64c', 'https://git.kernel.org/stable/c/1b73ea3d97cc23f9b16d10021782b48397d2b517', 'https://git.kernel.org/stable/c/b1f7810b05d1950350ac2e06992982974343e441', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46720-a598@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46720', 'https://www.cve.org/CVERecord?id=CVE-2024-46720'], 'PublishedDate': '2024-09-18T07:15:03.42Z', 'LastModifiedDate': '2024-09-20T18:22:04.693Z'}, {'VulnerabilityID': 'CVE-2024-46721', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46721', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: apparmor: fix possible NULL pointer dereference', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix possible NULL pointer dereference\n\nprofile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made\nfrom __create_missing_ancestors(..) and 'ent->old' is NULL in\naa_replace_profiles(..).\nIn that case, it must return an error code and the code, -ENOENT represents\nits state that the path of its parent is not existed yet.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000030\nPGD 0 P4D 0\nPREEMPT SMP PTI\nCPU: 4 PID: 3362 Comm: apparmor_parser Not tainted 6.8.0-24-generic #24\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\nRIP: 0010:aafs_create.constprop.0+0x7f/0x130\nCode: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae\nRSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 00000000000041ed RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc9000b2c7cd8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffffff82baac10\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007be9f22cf740(0000) GS:ffff88817bc00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000030 CR3: 0000000134b08000 CR4: 00000000000006f0\nCall Trace:\n \n ? show_regs+0x6d/0x80\n ? __die+0x24/0x80\n ? page_fault_oops+0x99/0x1b0\n ? kernelmode_fixup_or_oops+0xb2/0x140\n ? __bad_area_nosemaphore+0x1a5/0x2c0\n ? find_vma+0x34/0x60\n ? bad_area_nosemaphore+0x16/0x30\n ? do_user_addr_fault+0x2a2/0x6b0\n ? exc_page_fault+0x83/0x1b0\n ? asm_exc_page_fault+0x27/0x30\n ? aafs_create.constprop.0+0x7f/0x130\n ? aafs_create.constprop.0+0x51/0x130\n __aafs_profile_mkdir+0x3d6/0x480\n aa_replace_profiles+0x83f/0x1270\n policy_update+0xe3/0x180\n profile_load+0xbc/0x150\n ? rw_verify_area+0x47/0x140\n vfs_write+0x100/0x480\n ? __x64_sys_openat+0x55/0xa0\n ? syscall_exit_to_user_mode+0x86/0x260\n ksys_write+0x73/0x100\n __x64_sys_write+0x19/0x30\n x64_sys_call+0x7e/0x25c0\n do_syscall_64+0x7f/0x180\n entry_SYSCALL_64_after_hwframe+0x78/0x80\nRIP: 0033:0x7be9f211c574\nCode: c7 00 16 00 00 00 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 80 3d d5 ea 0e 00 00 74 13 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 54 c3 0f 1f 00 55 48 89 e5 48 83 ec 20 48 89\nRSP: 002b:00007ffd26f2b8c8 EFLAGS: 00000202 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00005d504415e200 RCX: 00007be9f211c574\nRDX: 0000000000001fc1 RSI: 00005d504418bc80 RDI: 0000000000000004\nRBP: 0000000000001fc1 R08: 0000000000001fc1 R09: 0000000080000000\nR10: 0000000000000000 R11: 0000000000000202 R12: 00005d504418bc80\nR13: 0000000000000004 R14: 00007ffd26f2b9b0 R15: 00007ffd26f2ba30\n \nModules linked in: snd_seq_dummy snd_hrtimer qrtr snd_hda_codec_generic snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_seq_midi snd_seq_midi_event snd_rawmidi snd_seq snd_seq_device i2c_i801 snd_timer i2c_smbus qxl snd soundcore drm_ttm_helper lpc_ich ttm joydev input_leds serio_raw mac_hid binfmt_misc msr parport_pc ppdev lp parport efi_pstore nfnetlink dmi_sysfs qemu_fw_cfg ip_tables x_tables autofs4 hid_generic usbhid hid ahci libahci psmouse virtio_rng xhci_pci xhci_pci_renesas\nCR2: 0000000000000030\n---[ end trace 0000000000000000 ]---\nRIP: 0010:aafs_create.constprop.0+0x7f/0x130\nCode: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae\nRSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 00000000000041ed RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc9000b2c7cd8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46721', 'https://git.kernel.org/linus/3dd384108d53834002be5630132ad5c3f32166ad (6.11-rc1)', 'https://git.kernel.org/stable/c/09b2d107fe63e55b6ae643f9f26bf8eb14a261d9', 'https://git.kernel.org/stable/c/3dd384108d53834002be5630132ad5c3f32166ad', 'https://git.kernel.org/stable/c/52338a3aa772762b8392ce7cac106c1099aeab85', 'https://git.kernel.org/stable/c/59f742e55a469ef36c5c1533b6095a103b61eda8', 'https://git.kernel.org/stable/c/730ee2686af0d55372e97a2695005ff142702363', 'https://git.kernel.org/stable/c/8d9da10a392a32368392f7a16775e1f36e2a5346', 'https://git.kernel.org/stable/c/c49bbe69ee152bd9c1c1f314c0f582e76c578f64', 'https://git.kernel.org/stable/c/e3c7d23f7a5c0b11ba0093cea32261ab8098b94e', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46721-9aa7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46721', 'https://www.cve.org/CVERecord?id=CVE-2024-46721'], 'PublishedDate': '2024-09-18T07:15:03.48Z', 'LastModifiedDate': '2024-09-20T18:22:46.637Z'}, {'VulnerabilityID': 'CVE-2024-46722', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46722', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix mc_data out-of-bounds read warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix mc_data out-of-bounds read warning\n\nClear warning that read mc_data[i-1] may out-of-bounds.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46722', 'https://git.kernel.org/linus/51dfc0a4d609fe700750a62f41447f01b8c9ea50 (6.11-rc1)', 'https://git.kernel.org/stable/c/2097edede72ec5bb3869cf0205337d392fb2a553', 'https://git.kernel.org/stable/c/310b9d8363b88e818afec97ca7652bd7fe3d0650', 'https://git.kernel.org/stable/c/345bd3ad387f9e121aaad9c95957b80895e2f2ec', 'https://git.kernel.org/stable/c/51dfc0a4d609fe700750a62f41447f01b8c9ea50', 'https://git.kernel.org/stable/c/578ae965e8b90cd09edeb0252b50fa0503ea35c5', 'https://git.kernel.org/stable/c/5fa4df25ecfc7b6c9006f5b871c46cfe25ea8826', 'https://git.kernel.org/stable/c/b862a0bc5356197ed159fed7b1c647e77bc9f653', 'https://git.kernel.org/stable/c/d0a43bf367ed640e527e8ef3d53aac1e71f80114', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46722-34b3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46722', 'https://www.cve.org/CVERecord?id=CVE-2024-46722'], 'PublishedDate': '2024-09-18T07:15:03.547Z', 'LastModifiedDate': '2024-09-20T18:23:11.93Z'}, {'VulnerabilityID': 'CVE-2024-46723', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46723', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix ucode out-of-bounds read warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix ucode out-of-bounds read warning\n\nClear warning that read ucode[] may out-of-bounds.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46723', 'https://git.kernel.org/linus/8944acd0f9db33e17f387fdc75d33bb473d7936f (6.11-rc1)', 'https://git.kernel.org/stable/c/0bef65e069d84d1cd77ce757aea0e437b8e2bd33', 'https://git.kernel.org/stable/c/23fefef859c6057e6770584242bdd938254f8ddd', 'https://git.kernel.org/stable/c/5f09fa5e0ad45fbca71933a0e024ca52da47d59b', 'https://git.kernel.org/stable/c/82ac8f1d02886b5d8aeb9e058989d3bd6fc581e2', 'https://git.kernel.org/stable/c/8944acd0f9db33e17f387fdc75d33bb473d7936f', 'https://git.kernel.org/stable/c/8981927ebc6c12fa76b30c4178acb462bab15f54', 'https://git.kernel.org/stable/c/e789e05388854a5436b2b5d8695fdb864c9bcc27', 'https://git.kernel.org/stable/c/f2b7a9f3839e92f43559b2795b34640ca8cf839f', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46723-6726@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46723', 'https://www.cve.org/CVERecord?id=CVE-2024-46723'], 'PublishedDate': '2024-09-18T07:15:03.61Z', 'LastModifiedDate': '2024-09-20T18:30:30.117Z'}, {'VulnerabilityID': 'CVE-2024-46724', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46724', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number\n\nCheck the fb_channel_number range to avoid the array out-of-bounds\nread error', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46724', 'https://git.kernel.org/linus/d768394fa99467bcf2703bde74ddc96eeb0b71fa (6.11-rc1)', 'https://git.kernel.org/stable/c/32915dc909ff502823babfe07d5416c5b6e8a8b1', 'https://git.kernel.org/stable/c/45f7b02afc464c208e8f56bcbc672ef5c364c815', 'https://git.kernel.org/stable/c/725b728cc0c8c5fafdfb51cb0937870d33a40fa4', 'https://git.kernel.org/stable/c/d768394fa99467bcf2703bde74ddc96eeb0b71fa', 'https://git.kernel.org/stable/c/db7a86676fd624768a5d907faf34ad7bb4ff25f4', 'https://git.kernel.org/stable/c/f9267972490f9fcffe146e79828e97acc0da588c', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46724-02f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46724', 'https://www.cve.org/CVERecord?id=CVE-2024-46724'], 'PublishedDate': '2024-09-18T07:15:03.673Z', 'LastModifiedDate': '2024-09-20T18:30:58.98Z'}, {'VulnerabilityID': 'CVE-2024-46725', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46725', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix out-of-bounds write warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix out-of-bounds write warning\n\nCheck the ring type value to fix the out-of-bounds\nwrite warning', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46725', 'https://git.kernel.org/linus/be1684930f5262a622d40ce7a6f1423530d87f89 (6.11-rc1)', 'https://git.kernel.org/stable/c/130bee397b9cd52006145c87a456fd8719390cb5', 'https://git.kernel.org/stable/c/919f9bf9997b8dcdc132485ea96121e7d15555f9', 'https://git.kernel.org/stable/c/a60d1f7ff62e453dde2d3b4907e178954d199844', 'https://git.kernel.org/stable/c/be1684930f5262a622d40ce7a6f1423530d87f89', 'https://git.kernel.org/stable/c/c253b87c7c37ec40a2e0c84e4a6b636ba5cd66b2', 'https://git.kernel.org/stable/c/cf2db220b38301b6486a0f11da24a0f317de558c', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46725-af49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46725', 'https://www.cve.org/CVERecord?id=CVE-2024-46725'], 'PublishedDate': '2024-09-18T07:15:03.733Z', 'LastModifiedDate': '2024-09-20T18:40:42.753Z'}, {'VulnerabilityID': 'CVE-2024-46726', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46726', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Ensure index calculation will not overflow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Ensure index calculation will not overflow\n\n[WHY & HOW]\nMake sure vmid0p72_idx, vnom0p8_idx and vmax0p9_idx calculation will\nnever overflow and exceess array size.\n\nThis fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46726', 'https://git.kernel.org/linus/8e2734bf444767fed787305ccdcb36a2be5301a2 (6.11-rc1)', 'https://git.kernel.org/stable/c/3dc6bb57dab36b38b7374af0ac916174c146b6ed', 'https://git.kernel.org/stable/c/733ae185502d30bbe79575167b6178cfb6c5d6bd', 'https://git.kernel.org/stable/c/8e2734bf444767fed787305ccdcb36a2be5301a2', 'https://git.kernel.org/stable/c/d705b5869f6b1b46ad5ceb1bd2a08c04f7e5003b', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46726-587e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46726', 'https://www.cve.org/CVERecord?id=CVE-2024-46726'], 'PublishedDate': '2024-09-18T07:15:03.787Z', 'LastModifiedDate': '2024-09-20T18:36:27.07Z'}, {'VulnerabilityID': 'CVE-2024-46727', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46727', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update\n\n[Why]\nCoverity reports NULL_RETURN warning.\n\n[How]\nAdd otg_master NULL check.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46727', 'https://git.kernel.org/linus/871cd9d881fa791d3f82885000713de07041c0ae (6.11-rc1)', 'https://git.kernel.org/stable/c/871cd9d881fa791d3f82885000713de07041c0ae', 'https://git.kernel.org/stable/c/aad4d3d3d3b6a362bf5db11e1f28c4a60620900d', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46727-2565@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46727', 'https://www.cve.org/CVERecord?id=CVE-2024-46727'], 'PublishedDate': '2024-09-18T07:15:03.84Z', 'LastModifiedDate': '2024-09-30T12:49:43.097Z'}, {'VulnerabilityID': 'CVE-2024-46728', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46728', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check index for aux_rd_interval before using', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check index for aux_rd_interval before using\n\naux_rd_interval has size of 7 and should be checked.\n\nThis fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46728', 'https://git.kernel.org/linus/9ba2ea6337b4f159aecb177555a6a81da92d302e (6.11-rc1)', 'https://git.kernel.org/stable/c/48e0b68e2360b16edf2a0bae05c0051c00fbb48a', 'https://git.kernel.org/stable/c/6c588e9350dd7a9fb97a56fe74852c9ecc44450c', 'https://git.kernel.org/stable/c/9ba2ea6337b4f159aecb177555a6a81da92d302e', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46728-edfe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46728', 'https://www.cve.org/CVERecord?id=CVE-2024-46728'], 'PublishedDate': '2024-09-18T07:15:03.893Z', 'LastModifiedDate': '2024-09-26T13:31:34.347Z'}, {'VulnerabilityID': 'CVE-2024-46729', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46729', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix incorrect size calculation for loop', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix incorrect size calculation for loop\n\n[WHY]\nfe_clk_en has size of 5 but sizeof(fe_clk_en) has byte size 20 which is\nlager than the array size.\n\n[HOW]\nDivide byte size 20 by its element size.\n\nThis fixes 2 OVERRUN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46729', 'https://git.kernel.org/linus/3941a3aa4b653b69876d894d08f3fff1cc965267 (6.11-rc1)', 'https://git.kernel.org/stable/c/3941a3aa4b653b69876d894d08f3fff1cc965267', 'https://git.kernel.org/stable/c/712be65b3b372a82bff0865b9c090147764bf1c4', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46729-158c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46729', 'https://www.cve.org/CVERecord?id=CVE-2024-46729'], 'PublishedDate': '2024-09-18T07:15:03.95Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46730', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46730', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Ensure array index tg_inst won't be -1', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Ensure array index tg_inst won't be -1\n\n[WHY & HOW]\ntg_inst will be a negative if timing_generator_count equals 0, which\nshould be checked before used.\n\nThis fixes 2 OVERRUN issues reported by Coverity.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46730', 'https://git.kernel.org/linus/687fe329f18ab0ab0496b20ed2cb003d4879d931 (6.11-rc1)', 'https://git.kernel.org/stable/c/687fe329f18ab0ab0496b20ed2cb003d4879d931', 'https://git.kernel.org/stable/c/a64284b9e1999ad5580debced4bc6d6adb28aad4', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46730-b69e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46730', 'https://www.cve.org/CVERecord?id=CVE-2024-46730'], 'PublishedDate': '2024-09-18T07:15:04.003Z', 'LastModifiedDate': '2024-09-30T12:49:00.333Z'}, {'VulnerabilityID': 'CVE-2024-46731', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46731', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: fix the Out-of-bounds read warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: fix the Out-of-bounds read warning\n\nusing index i - 1U may beyond element index\nfor mc_data[] when i = 0.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46731', 'https://git.kernel.org/linus/12c6967428a099bbba9dfd247bb4322a984fcc0b (6.11-rc1)', 'https://git.kernel.org/stable/c/12c6967428a099bbba9dfd247bb4322a984fcc0b', 'https://git.kernel.org/stable/c/20c6373a6be93039f9d66029bb1e21038a060be1', 'https://git.kernel.org/stable/c/3317966efcdc5101e93db21514b68917e7eb34ea', 'https://git.kernel.org/stable/c/38e32a0d837443c91c4b615a067b976cfb925376', 'https://git.kernel.org/stable/c/d83fb9f9f63e9a120bf405b078f829f0b2e58934', 'https://git.kernel.org/stable/c/f1e261ced9bcad772a45a2fcdf413c3490e87299', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46731-0e54@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46731', 'https://www.cve.org/CVERecord?id=CVE-2024-46731'], 'PublishedDate': '2024-09-18T07:15:04.057Z', 'LastModifiedDate': '2024-09-26T13:29:19.877Z'}, {'VulnerabilityID': 'CVE-2024-46732', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46732', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Assign linear_pitch_alignment even for VM', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Assign linear_pitch_alignment even for VM\n\n[Description]\nAssign linear_pitch_alignment so we don't cause a divide by 0\nerror in VM environments", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46732', 'https://git.kernel.org/linus/984debc133efa05e62f5aa1a7a1dd8ca0ef041f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/4bd7710f2fecfc5fb2dda1ca2adc69db8a66b8b6', 'https://git.kernel.org/stable/c/984debc133efa05e62f5aa1a7a1dd8ca0ef041f4', 'https://git.kernel.org/stable/c/c44b568931d23aed9d37ecbb31fb5fbdd198bf7b', 'https://git.kernel.org/stable/c/d219f902b16d42f0cb8c499ea8f31cf3c0f36349', 'https://git.kernel.org/stable/c/d2fe7ac613a1ea8c346c9f5c89dc6ecc27232997', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46732-49a9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46732', 'https://www.cve.org/CVERecord?id=CVE-2024-46732'], 'PublishedDate': '2024-09-18T07:15:04.117Z', 'LastModifiedDate': '2024-09-26T13:28:07.157Z'}, {'VulnerabilityID': 'CVE-2024-46733', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46733', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix qgroup reserve leaks in cow_file_range', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix qgroup reserve leaks in cow_file_range\n\nIn the buffered write path, the dirty page owns the qgroup reserve until\nit creates an ordered_extent.\n\nTherefore, any errors that occur before the ordered_extent is created\nmust free that reservation, or else the space is leaked. The fstest\ngeneric/475 exercises various IO error paths, and is able to trigger\nerrors in cow_file_range where we fail to get to allocating the ordered\nextent. Note that because we *do* clear delalloc, we are likely to\nremove the inode from the delalloc list, so the inodes/pages to not have\ninvalidate/launder called on them in the commit abort path.\n\nThis results in failures at the unmount stage of the test that look like:\n\n BTRFS: error (device dm-8 state EA) in cleanup_transaction:2018: errno=-5 IO failure\n BTRFS: error (device dm-8 state EA) in btrfs_replace_file_extents:2416: errno=-5 IO failure\n BTRFS warning (device dm-8 state EA): qgroup 0/5 has unreleased space, type 0 rsv 28672\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 22588 at fs/btrfs/disk-io.c:4333 close_ctree+0x222/0x4d0 [btrfs]\n Modules linked in: btrfs blake2b_generic libcrc32c xor zstd_compress raid6_pq\n CPU: 3 PID: 22588 Comm: umount Kdump: loaded Tainted: G W 6.10.0-rc7-gab56fde445b8 #21\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n RIP: 0010:close_ctree+0x222/0x4d0 [btrfs]\n RSP: 0018:ffffb4465283be00 EFLAGS: 00010202\n RAX: 0000000000000001 RBX: ffffa1a1818e1000 RCX: 0000000000000001\n RDX: 0000000000000000 RSI: ffffb4465283bbe0 RDI: ffffa1a19374fcb8\n RBP: ffffa1a1818e13c0 R08: 0000000100028b16 R09: 0000000000000000\n R10: 0000000000000003 R11: 0000000000000003 R12: ffffa1a18ad7972c\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n FS: 00007f9168312b80(0000) GS:ffffa1a4afcc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f91683c9140 CR3: 000000010acaa000 CR4: 00000000000006f0\n Call Trace:\n \n ? close_ctree+0x222/0x4d0 [btrfs]\n ? __warn.cold+0x8e/0xea\n ? close_ctree+0x222/0x4d0 [btrfs]\n ? report_bug+0xff/0x140\n ? handle_bug+0x3b/0x70\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? close_ctree+0x222/0x4d0 [btrfs]\n generic_shutdown_super+0x70/0x160\n kill_anon_super+0x11/0x40\n btrfs_kill_super+0x11/0x20 [btrfs]\n deactivate_locked_super+0x2e/0xa0\n cleanup_mnt+0xb5/0x150\n task_work_run+0x57/0x80\n syscall_exit_to_user_mode+0x121/0x130\n do_syscall_64+0xab/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n RIP: 0033:0x7f916847a887\n ---[ end trace 0000000000000000 ]---\n BTRFS error (device dm-8 state EA): qgroup reserved space leaked\n\nCases 2 and 3 in the out_reserve path both pertain to this type of leak\nand must free the reserved qgroup data. Because it is already an error\npath, I opted not to handle the possible errors in\nbtrfs_free_qgroup_data.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46733', 'https://git.kernel.org/linus/30479f31d44d47ed00ae0c7453d9b253537005b2 (6.11-rc3)', 'https://git.kernel.org/stable/c/30479f31d44d47ed00ae0c7453d9b253537005b2', 'https://git.kernel.org/stable/c/e42ef22bc10f0309c0c65d8d6ca8b4127a674b7f', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46733-77eb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46733', 'https://www.cve.org/CVERecord?id=CVE-2024-46733'], 'PublishedDate': '2024-09-18T07:15:04.17Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46735', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46735', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery()\n\nWhen two UBLK_CMD_START_USER_RECOVERY commands are submitted, the\nfirst one sets 'ubq->ubq_daemon' to NULL, and the second one triggers\nWARN in ublk_queue_reinit() and subsequently a NULL pointer dereference\nissue.\n\nFix it by adding the check in ublk_ctrl_start_recovery() and return\nimmediately in case of zero 'ub->nr_queues_ready'.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n RIP: 0010:ublk_ctrl_start_recovery.constprop.0+0x82/0x180\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x75/0x170\n ? exc_page_fault+0x64/0x140\n ? asm_exc_page_fault+0x22/0x30\n ? ublk_ctrl_start_recovery.constprop.0+0x82/0x180\n ublk_ctrl_uring_cmd+0x4f7/0x6c0\n ? pick_next_task_idle+0x26/0x40\n io_uring_cmd+0x9a/0x1b0\n io_issue_sqe+0x193/0x3f0\n io_wq_submit_work+0x9b/0x390\n io_worker_handle_work+0x165/0x360\n io_wq_worker+0xcb/0x2f0\n ? finish_task_switch.isra.0+0x203/0x290\n ? finish_task_switch.isra.0+0x203/0x290\n ? __pfx_io_wq_worker+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_io_wq_worker+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46735', 'https://git.kernel.org/linus/e58f5142f88320a5b1449f96a146f2f24615c5c7 (6.11-rc7)', 'https://git.kernel.org/stable/c/136a29d8112df4ea0a57f9602ddf3579e04089dc', 'https://git.kernel.org/stable/c/7c890ef60bf417d3fe5c6f7a9f6cef0e1d77f74f', 'https://git.kernel.org/stable/c/ca249435893dda766f3845c15ca77ca5672022d8', 'https://git.kernel.org/stable/c/e58f5142f88320a5b1449f96a146f2f24615c5c7', 'https://lore.kernel.org/linux-cve-announce/2024091832-CVE-2024-46735-fbce@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46735', 'https://www.cve.org/CVERecord?id=CVE-2024-46735'], 'PublishedDate': '2024-09-18T08:15:03.057Z', 'LastModifiedDate': '2024-09-20T18:35:53.967Z'}, {'VulnerabilityID': 'CVE-2024-46737', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46737', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvmet-tcp: fix kernel crash if commands allocation fails', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: fix kernel crash if commands allocation fails\n\nIf the commands allocation fails in nvmet_tcp_alloc_cmds()\nthe kernel crashes in nvmet_tcp_release_queue_work() because of\na NULL pointer dereference.\n\n nvmet: failed to install queue 0 cntlid 1 ret 6\n Unable to handle kernel NULL pointer dereference at\n virtual address 0000000000000008\n\nFix the bug by setting queue->nr_cmds to zero in case\nnvmet_tcp_alloc_cmd() fails.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46737', 'https://git.kernel.org/linus/5572a55a6f830ee3f3a994b6b962a5c327d28cb3 (6.11-rc7)', 'https://git.kernel.org/stable/c/03e1fd0327fa5e2174567f5fe9290fe21d21b8f4', 'https://git.kernel.org/stable/c/489f2913a63f528cfe3f21722583fb981967ecda', 'https://git.kernel.org/stable/c/50632b877ce55356f5d276b9add289b1e7ddc683', 'https://git.kernel.org/stable/c/5572a55a6f830ee3f3a994b6b962a5c327d28cb3', 'https://git.kernel.org/stable/c/6c04d1e3ab22cc5394ef656429638a5947f87244', 'https://git.kernel.org/stable/c/7957c731fc2b23312f8935812dee5a0b14b04e2d', 'https://git.kernel.org/stable/c/91dad30c5607e62864f888e735d0965567827bdf', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46737-d36f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46737', 'https://www.cve.org/CVERecord?id=CVE-2024-46737'], 'PublishedDate': '2024-09-18T08:15:03.167Z', 'LastModifiedDate': '2024-09-20T18:35:34.7Z'}, {'VulnerabilityID': 'CVE-2024-46738', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46738', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: VMCI: Fix use-after-free when removing resource in vmci_resource_remove()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: Fix use-after-free when removing resource in vmci_resource_remove()\n\nWhen removing a resource from vmci_resource_table in\nvmci_resource_remove(), the search is performed using the resource\nhandle by comparing context and resource fields.\n\nIt is possible though to create two resources with different types\nbut same handle (same context and resource fields).\n\nWhen trying to remove one of the resources, vmci_resource_remove()\nmay not remove the intended one, but the object will still be freed\nas in the case of the datagram type in vmci_datagram_destroy_handle().\nvmci_resource_table will still hold a pointer to this freed resource\nleading to a use-after-free vulnerability.\n\nBUG: KASAN: use-after-free in vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]\nBUG: KASAN: use-after-free in vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147\nRead of size 4 at addr ffff88801c16d800 by task syz-executor197/1592\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x82/0xa9 lib/dump_stack.c:106\n print_address_description.constprop.0+0x21/0x366 mm/kasan/report.c:239\n __kasan_report.cold+0x7f/0x132 mm/kasan/report.c:425\n kasan_report+0x38/0x51 mm/kasan/report.c:442\n vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]\n vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147\n vmci_qp_broker_detach+0x89a/0x11b9 drivers/misc/vmw_vmci/vmci_queue_pair.c:2182\n ctx_free_ctx+0x473/0xbe1 drivers/misc/vmw_vmci/vmci_context.c:444\n kref_put include/linux/kref.h:65 [inline]\n vmci_ctx_put drivers/misc/vmw_vmci/vmci_context.c:497 [inline]\n vmci_ctx_destroy+0x170/0x1d6 drivers/misc/vmw_vmci/vmci_context.c:195\n vmci_host_close+0x125/0x1ac drivers/misc/vmw_vmci/vmci_host.c:143\n __fput+0x261/0xa34 fs/file_table.c:282\n task_work_run+0xf0/0x194 kernel/task_work.c:164\n tracehook_notify_resume include/linux/tracehook.h:189 [inline]\n exit_to_user_mode_loop+0x184/0x189 kernel/entry/common.c:187\n exit_to_user_mode_prepare+0x11b/0x123 kernel/entry/common.c:220\n __syscall_exit_to_user_mode_work kernel/entry/common.c:302 [inline]\n syscall_exit_to_user_mode+0x18/0x42 kernel/entry/common.c:313\n do_syscall_64+0x41/0x85 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x6e/0x0\n\nThis change ensures the type is also checked when removing\nthe resource from vmci_resource_table in vmci_resource_remove().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46738', 'https://git.kernel.org/linus/48b9a8dabcc3cf5f961b2ebcd8933bf9204babb7 (6.11-rc7)', 'https://git.kernel.org/stable/c/00fe5292f081f8d773e572df8e03bf6e1855fe49', 'https://git.kernel.org/stable/c/39e7e593418ccdbd151f2925fa6be1a616d16c96', 'https://git.kernel.org/stable/c/48b9a8dabcc3cf5f961b2ebcd8933bf9204babb7', 'https://git.kernel.org/stable/c/6c563a29857aa8053b67ee141191f69757f27f6e', 'https://git.kernel.org/stable/c/b243d52b5f6f59f9d39e69b191fb3d58b94a43b1', 'https://git.kernel.org/stable/c/b9efdf333174468651be40390cbc79c9f55d9cce', 'https://git.kernel.org/stable/c/ef5f4d0c5ee22d4f873116fec844ff6edaf3fa7d', 'https://git.kernel.org/stable/c/f6365931bf7c07b2b397dbb06a4f6573cc9fae73', 'https://linux.oracle.com/cve/CVE-2024-46738.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46738-d871@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46738', 'https://www.cve.org/CVERecord?id=CVE-2024-46738'], 'PublishedDate': '2024-09-18T08:15:03.233Z', 'LastModifiedDate': '2024-09-20T18:35:04.373Z'}, {'VulnerabilityID': 'CVE-2024-46739', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46739', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind\n\nFor primary VM Bus channels, primary_channel pointer is always NULL. This\npointer is valid only for the secondary channels. Also, rescind callback\nis meant for primary channels only.\n\nFix NULL pointer dereference by retrieving the device_obj from the parent\nfor the primary channel.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46739', 'https://git.kernel.org/linus/fb1adbd7e50f3d2de56d0a2bb0700e2e819a329e (6.11-rc7)', 'https://git.kernel.org/stable/c/1d8e020e51ab07e40f9dd00b52f1da7d96fec04c', 'https://git.kernel.org/stable/c/2be373469be1774bbe03b0fa7e2854e65005b1cc', 'https://git.kernel.org/stable/c/3005091cd537ef8cdb7530dcb2ecfba8d2ef475c', 'https://git.kernel.org/stable/c/3d414b64ecf6fd717d7510ffb893c6f23acbf50e', 'https://git.kernel.org/stable/c/928e399e84f4e80307dce44e89415115c473275b', 'https://git.kernel.org/stable/c/de6946be9c8bc7d2279123433495af7c21011b99', 'https://git.kernel.org/stable/c/f38f46da80a2ab7d1b2f8fcb444c916034a2dac4', 'https://git.kernel.org/stable/c/fb1adbd7e50f3d2de56d0a2bb0700e2e819a329e', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46739-0aa7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46739', 'https://www.cve.org/CVERecord?id=CVE-2024-46739'], 'PublishedDate': '2024-09-18T08:15:03.293Z', 'LastModifiedDate': '2024-09-20T18:34:29.957Z'}, {'VulnerabilityID': 'CVE-2024-46740', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46740', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: binder: fix UAF caused by offsets overwrite', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF caused by offsets overwrite\n\nBinder objects are processed and copied individually into the target\nbuffer during transactions. Any raw data in-between these objects is\ncopied as well. However, this raw data copy lacks an out-of-bounds\ncheck. If the raw data exceeds the data section size then the copy\noverwrites the offsets section. This eventually triggers an error that\nattempts to unwind the processed objects. However, at this point the\noffsets used to index these objects are now corrupted.\n\nUnwinding with corrupted offsets can result in decrements of arbitrary\nnodes and lead to their premature release. Other users of such nodes are\nleft with a dangling pointer triggering a use-after-free. This issue is\nmade evident by the following KASAN report (trimmed):\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c\n Write of size 4 at addr ffff47fc91598f04 by task binder-util/743\n\n CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n _raw_spin_lock+0xe4/0x19c\n binder_free_buf+0x128/0x434\n binder_thread_write+0x8a4/0x3260\n binder_ioctl+0x18f0/0x258c\n [...]\n\n Allocated by task 743:\n __kmalloc_cache_noprof+0x110/0x270\n binder_new_node+0x50/0x700\n binder_transaction+0x413c/0x6da8\n binder_thread_write+0x978/0x3260\n binder_ioctl+0x18f0/0x258c\n [...]\n\n Freed by task 745:\n kfree+0xbc/0x208\n binder_thread_read+0x1c5c/0x37d4\n binder_ioctl+0x16d8/0x258c\n [...]\n ==================================================================\n\nTo avoid this issue, let's check that the raw data copy is within the\nboundaries of the data section.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46740', 'https://git.kernel.org/linus/4df153652cc46545722879415937582028c18af5 (6.11-rc7)', 'https://git.kernel.org/stable/c/109e845c1184c9f786d41516348ba3efd9112792', 'https://git.kernel.org/stable/c/1f33d9f1d9ac3f0129f8508925000900c2fe5bb0', 'https://git.kernel.org/stable/c/3a8154bb4ab4a01390a3abf1e6afac296e037da4', 'https://git.kernel.org/stable/c/4df153652cc46545722879415937582028c18af5', 'https://git.kernel.org/stable/c/4f79e0b80dc69bd5eaaed70f0df1b558728b4e59', 'https://git.kernel.org/stable/c/5a32bfd23022ffa7e152f273fa3fa29befb7d929', 'https://git.kernel.org/stable/c/eef79854a04feac5b861f94d7b19cbbe79874117', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46740-e05a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46740', 'https://www.cve.org/CVERecord?id=CVE-2024-46740'], 'PublishedDate': '2024-09-18T08:15:03.377Z', 'LastModifiedDate': '2024-09-20T18:34:08.163Z'}, {'VulnerabilityID': 'CVE-2024-46741', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46741', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: misc: fastrpc: Fix double free of 'buf' in error path', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Fix double free of 'buf' in error path\n\nsmatch warning:\ndrivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf'\n\nIn fastrpc_req_mmap() error path, the fastrpc buffer is freed in\nfastrpc_req_munmap_impl() if unmap is successful.\n\nBut in the end, there is an unconditional call to fastrpc_buf_free().\nSo the above case triggers the double free of fastrpc buf.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46741', 'https://git.kernel.org/linus/e8c276d4dc0e19ee48385f74426aebc855b49aaf (6.11-rc7)', 'https://git.kernel.org/stable/c/bfc1704d909dc9911a558b1a5833d3d61a43a1f2', 'https://git.kernel.org/stable/c/e8c276d4dc0e19ee48385f74426aebc855b49aaf', 'https://git.kernel.org/stable/c/f77dc8a75859e559f3238a6d906206259227985e', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46741-4ce7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46741', 'https://www.cve.org/CVERecord?id=CVE-2024-46741'], 'PublishedDate': '2024-09-18T08:15:03.43Z', 'LastModifiedDate': '2024-09-20T18:33:27.96Z'}, {'VulnerabilityID': 'CVE-2024-46742', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46742', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: smb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open()\n\nnull-ptr-deref will occur when (req_op_level == SMB2_OPLOCK_LEVEL_LEASE)\nand parse_lease_state() return NULL.\n\nFix this by check if 'lease_ctx_info' is NULL.\n\nAdditionally, remove the redundant parentheses in\nparse_durable_handle_context().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46742', 'https://git.kernel.org/linus/4e8771a3666c8f216eefd6bd2fd50121c6c437db (6.11-rc5)', 'https://git.kernel.org/stable/c/07f384c5be1f8633b13f0a22616e227570450bc6', 'https://git.kernel.org/stable/c/3b692794b81f2ecad69a4adbba687f3836824ada', 'https://git.kernel.org/stable/c/4e8771a3666c8f216eefd6bd2fd50121c6c437db', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46742-223b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46742', 'https://www.cve.org/CVERecord?id=CVE-2024-46742'], 'PublishedDate': '2024-09-18T08:15:03.48Z', 'LastModifiedDate': '2024-09-20T18:32:34.303Z'}, {'VulnerabilityID': 'CVE-2024-46743', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46743', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: of/irq: Prevent device address out-of-bounds read in interrupt map walk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nof/irq: Prevent device address out-of-bounds read in interrupt map walk\n\nWhen of_irq_parse_raw() is invoked with a device address smaller than\nthe interrupt parent node (from #address-cells property), KASAN detects\nthe following out-of-bounds read when populating the initial match table\n(dyndbg="func of_irq_parse_* +p"):\n\n OF: of_irq_parse_one: dev=/soc@0/picasso/watchdog, index=0\n OF: parent=/soc@0/pci@878000000000/gpio0@17,0, intsize=2\n OF: intspec=4\n OF: of_irq_parse_raw: ipar=/soc@0/pci@878000000000/gpio0@17,0, size=2\n OF: -> addrsize=3\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in of_irq_parse_raw+0x2b8/0x8d0\n Read of size 4 at addr ffffff81beca5608 by task bash/764\n\n CPU: 1 PID: 764 Comm: bash Tainted: G O 6.1.67-484c613561-nokia_sm_arm64 #1\n Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2023.01-12.24.03-dirty 01/01/2023\n Call trace:\n dump_backtrace+0xdc/0x130\n show_stack+0x1c/0x30\n dump_stack_lvl+0x6c/0x84\n print_report+0x150/0x448\n kasan_report+0x98/0x140\n __asan_load4+0x78/0xa0\n of_irq_parse_raw+0x2b8/0x8d0\n of_irq_parse_one+0x24c/0x270\n parse_interrupts+0xc0/0x120\n of_fwnode_add_links+0x100/0x2d0\n fw_devlink_parse_fwtree+0x64/0xc0\n device_add+0xb38/0xc30\n of_device_add+0x64/0x90\n of_platform_device_create_pdata+0xd0/0x170\n of_platform_bus_create+0x244/0x600\n of_platform_notify+0x1b0/0x254\n blocking_notifier_call_chain+0x9c/0xd0\n __of_changeset_entry_notify+0x1b8/0x230\n __of_changeset_apply_notify+0x54/0xe4\n of_overlay_fdt_apply+0xc04/0xd94\n ...\n\n The buggy address belongs to the object at ffffff81beca5600\n which belongs to the cache kmalloc-128 of size 128\n The buggy address is located 8 bytes inside of\n 128-byte region [ffffff81beca5600, ffffff81beca5680)\n\n The buggy address belongs to the physical page:\n page:00000000230d3d03 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1beca4\n head:00000000230d3d03 order:1 compound_mapcount:0 compound_pincount:0\n flags: 0x8000000000010200(slab|head|zone=2)\n raw: 8000000000010200 0000000000000000 dead000000000122 ffffff810000c300\n raw: 0000000000000000 0000000000200020 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffffff81beca5500: 04 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffffff81beca5580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n >ffffff81beca5600: 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffffff81beca5680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffffff81beca5700: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc\n ==================================================================\n OF: -> got it !\n\nPrevent the out-of-bounds read by copying the device address into a\nbuffer of sufficient size.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46743', 'https://git.kernel.org/linus/b739dffa5d570b411d4bdf4bb9b8dfd6b7d72305 (6.11-rc4)', 'https://git.kernel.org/stable/c/7ead730af11ee7da107f16fc77995613c58d292d', 'https://git.kernel.org/stable/c/8ff351ea12e918db1373b915c4c268815929cbe5', 'https://git.kernel.org/stable/c/9d1e9f0876b03d74d44513a0ed3ed15ef8f2fed5', 'https://git.kernel.org/stable/c/b739dffa5d570b411d4bdf4bb9b8dfd6b7d72305', 'https://git.kernel.org/stable/c/baaf26723beab3a04da578d3008be3544f83758f', 'https://git.kernel.org/stable/c/bf68acd840b6a5bfd3777e0d5aaa204db6b461a9', 'https://git.kernel.org/stable/c/d2a79494d8a5262949736fb2c3ac44d20a51b0d8', 'https://git.kernel.org/stable/c/defcaa426ba0bc89ffdafb799d2e50b52f74ffc4', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46743-f386@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46743', 'https://www.cve.org/CVERecord?id=CVE-2024-46743'], 'PublishedDate': '2024-09-18T08:15:03.54Z', 'LastModifiedDate': '2024-09-20T18:32:11.827Z'}, {'VulnerabilityID': 'CVE-2024-46744', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46744', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Squashfs: sanity check symbolic link size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: sanity check symbolic link size\n\nSyzkiller reports a "KMSAN: uninit-value in pick_link" bug.\n\nThis is caused by an uninitialised page, which is ultimately caused\nby a corrupted symbolic link size read from disk.\n\nThe reason why the corrupted symlink size causes an uninitialised\npage is due to the following sequence of events:\n\n1. squashfs_read_inode() is called to read the symbolic\n link from disk. This assigns the corrupted value\n 3875536935 to inode->i_size.\n\n2. Later squashfs_symlink_read_folio() is called, which assigns\n this corrupted value to the length variable, which being a\n signed int, overflows producing a negative number.\n\n3. The following loop that fills in the page contents checks that\n the copied bytes is less than length, which being negative means\n the loop is skipped, producing an uninitialised page.\n\nThis patch adds a sanity check which checks that the symbolic\nlink size is not larger than expected.\n\n--\n\nV2: fix spelling mistake.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-59'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46744', 'https://git.kernel.org/linus/810ee43d9cd245d138a2733d87a24858a23f577d (6.11-rc4)', 'https://git.kernel.org/stable/c/087f25b2d36adae19951114ffcbb7106ed405ebb', 'https://git.kernel.org/stable/c/1b9451ba6f21478a75288ea3e3fca4be35e2a438', 'https://git.kernel.org/stable/c/5c8906de98d0d7ad42ff3edf2cb6cd7e0ea658c4', 'https://git.kernel.org/stable/c/810ee43d9cd245d138a2733d87a24858a23f577d', 'https://git.kernel.org/stable/c/c3af7e460a526007e4bed1ce3623274a1a6afe5e', 'https://git.kernel.org/stable/c/ef4e249971eb77ec33d74c5c3de1e2576faf6c90', 'https://git.kernel.org/stable/c/f82cb7f24032ed023fc67d26ea9bf322d8431a90', 'https://git.kernel.org/stable/c/fac5e82ab1334fc8ed6ff7183702df634bd1d93d', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46744-451f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46744', 'https://www.cve.org/CVERecord?id=CVE-2024-46744'], 'PublishedDate': '2024-09-18T08:15:03.603Z', 'LastModifiedDate': '2024-09-30T13:36:19.557Z'}, {'VulnerabilityID': 'CVE-2024-46745', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46745', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Input: uinput - reject requests with unreasonable number of slots', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: uinput - reject requests with unreasonable number of slots\n\n\nWhen exercising uinput interface syzkaller may try setting up device\nwith a really large number of slots, which causes memory allocation\nfailure in input_mt_init_slots(). While this allocation failure is\nhandled properly and request is rejected, it results in syzkaller\nreports. Additionally, such request may put undue burden on the\nsystem which will try to free a lot of memory for a bogus request.\n\nFix it by limiting allowed number of slots to 100. This can easily\nbe extended if we see devices that can track more than 100 contacts.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46745', 'https://git.kernel.org/linus/206f533a0a7c683982af473079c4111f4a0f9f5e (6.11-rc5)', 'https://git.kernel.org/stable/c/206f533a0a7c683982af473079c4111f4a0f9f5e', 'https://git.kernel.org/stable/c/51fa08edd80003db700bdaa099385c5900d27f4b', 'https://git.kernel.org/stable/c/597ff930296c4c8fc6b6a536884d4f1a7187ec70', 'https://git.kernel.org/stable/c/61df76619e270a46fd427fbdeb670ad491c42de2', 'https://git.kernel.org/stable/c/9719687398dea8a6a12a10321a54dd75eec7ab2d', 'https://git.kernel.org/stable/c/9c6d189f0c1c59ba9a32326ec82a0b367a3cd47b', 'https://git.kernel.org/stable/c/a4858b00a1ec57043697fb935565fe267f161833', 'https://git.kernel.org/stable/c/d76fc0f0b18d49b7e721c9e4975ef4bffde2f3e7', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46745-7b05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46745', 'https://www.cve.org/CVERecord?id=CVE-2024-46745'], 'PublishedDate': '2024-09-18T08:15:03.667Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46746', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46746', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: HID: amd_sfh: free driver_data after destroying hid device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: amd_sfh: free driver_data after destroying hid device\n\nHID driver callbacks aren't called anymore once hid_destroy_device() has\nbeen called. Hence, hid driver_data should be freed only after the\nhid_destroy_device() function returned as driver_data is used in several\ncallbacks.\n\nI observed a crash with kernel 6.10.0 on my T14s Gen 3, after enabling\nKASAN to debug memory allocation, I got this output:\n\n [ 13.050438] ==================================================================\n [ 13.054060] BUG: KASAN: slab-use-after-free in amd_sfh_get_report+0x3ec/0x530 [amd_sfh]\n [ 13.054809] psmouse serio1: trackpoint: Synaptics TrackPoint firmware: 0x02, buttons: 3/3\n [ 13.056432] Read of size 8 at addr ffff88813152f408 by task (udev-worker)/479\n\n [ 13.060970] CPU: 5 PID: 479 Comm: (udev-worker) Not tainted 6.10.0-arch1-2 #1 893bb55d7f0073f25c46adbb49eb3785fefd74b0\n [ 13.063978] Hardware name: LENOVO 21CQCTO1WW/21CQCTO1WW, BIOS R22ET70W (1.40 ) 03/21/2024\n [ 13.067860] Call Trace:\n [ 13.069383] input: TPPS/2 Synaptics TrackPoint as /devices/platform/i8042/serio1/input/input8\n [ 13.071486] \n [ 13.071492] dump_stack_lvl+0x5d/0x80\n [ 13.074870] snd_hda_intel 0000:33:00.6: enabling device (0000 -> 0002)\n [ 13.078296] ? amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.082199] print_report+0x174/0x505\n [ 13.085776] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n [ 13.089367] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.093255] ? amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.097464] kasan_report+0xc8/0x150\n [ 13.101461] ? amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.105802] amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.110303] amdtp_hid_request+0xb8/0x110 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.114879] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.119450] sensor_hub_get_feature+0x1d3/0x540 [hid_sensor_hub 3f13be3016ff415bea03008d45d99da837ee3082]\n [ 13.124097] hid_sensor_parse_common_attributes+0x4d0/0xad0 [hid_sensor_iio_common c3a5cbe93969c28b122609768bbe23efe52eb8f5]\n [ 13.127404] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.131925] ? __pfx_hid_sensor_parse_common_attributes+0x10/0x10 [hid_sensor_iio_common c3a5cbe93969c28b122609768bbe23efe52eb8f5]\n [ 13.136455] ? _raw_spin_lock_irqsave+0x96/0xf0\n [ 13.140197] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n [ 13.143602] ? devm_iio_device_alloc+0x34/0x50 [industrialio 3d261d5e5765625d2b052be40e526d62b1d2123b]\n [ 13.147234] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.150446] ? __devm_add_action+0x167/0x1d0\n [ 13.155061] hid_gyro_3d_probe+0x120/0x7f0 [hid_sensor_gyro_3d 63da36a143b775846ab2dbb86c343b401b5e3172]\n [ 13.158581] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.161814] platform_probe+0xa2/0x150\n [ 13.165029] really_probe+0x1e3/0x8a0\n [ 13.168243] __driver_probe_device+0x18c/0x370\n [ 13.171500] driver_probe_device+0x4a/0x120\n [ 13.175000] __driver_attach+0x190/0x4a0\n [ 13.178521] ? __pfx___driver_attach+0x10/0x10\n [ 13.181771] bus_for_each_dev+0x106/0x180\n [ 13.185033] ? __pfx__raw_spin_lock+0x10/0x10\n [ 13.188229] ? __pfx_bus_for_each_dev+0x10/0x10\n [ 13.191446] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.194382] bus_add_driver+0x29e/0x4d0\n [ 13.197328] driver_register+0x1a5/0x360\n [ 13.200283] ? __pfx_hid_gyro_3d_platform_driver_init+0x10/0x10 [hid_sensor_gyro_3d 63da36a143b775846ab2dbb86c343b401b5e3172]\n [ 13.203362] do_one_initcall+0xa7/0x380\n [ 13.206432] ? __pfx_do_one_initcall+0x10/0x10\n [ 13.210175] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.213211] ? kasan_unpoison+0x44/0x70\n [ 13.216688] do_init_module+0x238/0x750\n [ 13.2196\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46746', 'https://git.kernel.org/linus/97155021ae17b86985121b33cf8098bcde00d497 (6.11-rc5)', 'https://git.kernel.org/stable/c/60dc4ee0428d70bcbb41436b6729d29f1cbdfb89', 'https://git.kernel.org/stable/c/775125c7fe38533aaa4b20769f5b5e62cc1170a0', 'https://git.kernel.org/stable/c/86b4f5cf91ca03c08e3822ac89476a677a780bcc', 'https://git.kernel.org/stable/c/97155021ae17b86985121b33cf8098bcde00d497', 'https://git.kernel.org/stable/c/adb3e3c1ddb5a23b8b7122ef1913f528d728937c', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46746-eb7f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46746', 'https://www.cve.org/CVERecord?id=CVE-2024-46746'], 'PublishedDate': '2024-09-18T08:15:03.73Z', 'LastModifiedDate': '2024-09-26T12:47:53.267Z'}, {'VulnerabilityID': 'CVE-2024-46747', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46747', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup\n\nreport_fixup for the Cougar 500k Gaming Keyboard was not verifying\nthat the report descriptor size was correct before accessing it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46747', 'https://git.kernel.org/linus/a6e9c391d45b5865b61e569146304cff72821a5d (6.11-rc5)', 'https://git.kernel.org/stable/c/30e9ce7cd5591be639b53595c95812f1a2afdfdc', 'https://git.kernel.org/stable/c/34185de73d74fdc90e8651cfc472bfea6073a13f', 'https://git.kernel.org/stable/c/48b2108efa205f4579052c27fba2b22cc6ad8aa0', 'https://git.kernel.org/stable/c/890dde6001b651be79819ef7a3f8c71fc8f9cabf', 'https://git.kernel.org/stable/c/a6e9c391d45b5865b61e569146304cff72821a5d', 'https://git.kernel.org/stable/c/e239e44dcd419b13cf840e2a3a833204e4329714', 'https://git.kernel.org/stable/c/e4a602a45aecd6a98b4b37482f5c9f8f67a32ddd', 'https://git.kernel.org/stable/c/fac3cb3c6428afe2207593a183b5bc4742529dfd', 'https://lore.kernel.org/linux-cve-announce/2024091837-CVE-2024-46747-f489@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46747', 'https://www.cve.org/CVERecord?id=CVE-2024-46747'], 'PublishedDate': '2024-09-18T08:15:03.79Z', 'LastModifiedDate': '2024-09-20T18:31:19.19Z'}, {'VulnerabilityID': 'CVE-2024-46748', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46748', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cachefiles: Set the max subreq size for cache writes to MAX_RW_COUNT', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Set the max subreq size for cache writes to MAX_RW_COUNT\n\nSet the maximum size of a subrequest that writes to cachefiles to be\nMAX_RW_COUNT so that we don't overrun the maximum write we can make to the\nbacking filesystem.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46748', 'https://git.kernel.org/linus/51d37982bbac3ea0ca21b2797a9cb0044272b3aa (6.11-rc1)', 'https://git.kernel.org/stable/c/51d37982bbac3ea0ca21b2797a9cb0044272b3aa', 'https://git.kernel.org/stable/c/cec226f9b1fd6cf55bc157873aec61b523083e96', 'https://lore.kernel.org/linux-cve-announce/2024091837-CVE-2024-46748-03e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46748', 'https://www.cve.org/CVERecord?id=CVE-2024-46748'], 'PublishedDate': '2024-09-18T08:15:03.847Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46749', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46749', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: btnxpuart: Fix Null pointer dereference in btnxpuart_flush()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix Null pointer dereference in btnxpuart_flush()\n\nThis adds a check before freeing the rx->skb in flush and close\nfunctions to handle the kernel crash seen while removing driver after FW\ndownload fails or before FW download completes.\n\ndmesg log:\n[ 54.634586] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000080\n[ 54.643398] Mem abort info:\n[ 54.646204] ESR = 0x0000000096000004\n[ 54.649964] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 54.655286] SET = 0, FnV = 0\n[ 54.658348] EA = 0, S1PTW = 0\n[ 54.661498] FSC = 0x04: level 0 translation fault\n[ 54.666391] Data abort info:\n[ 54.669273] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 54.674768] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 54.674771] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 54.674775] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000048860000\n[ 54.674780] [0000000000000080] pgd=0000000000000000, p4d=0000000000000000\n[ 54.703880] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 54.710152] Modules linked in: btnxpuart(-) overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_micfil snd_soc_fsl_spdif snd_soc_fsl_sai snd_soc_fsl_utils imx_pcm_dma gpio_ir_recv rc_core sch_fq_codel fuse\n[ 54.744357] CPU: 3 PID: 72 Comm: kworker/u9:0 Not tainted 6.6.3-otbr-g128004619037 #2\n[ 54.744364] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 54.744368] Workqueue: hci0 hci_power_on\n[ 54.757244] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 54.757249] pc : kfree_skb_reason+0x18/0xb0\n[ 54.772299] lr : btnxpuart_flush+0x40/0x58 [btnxpuart]\n[ 54.782921] sp : ffff8000805ebca0\n[ 54.782923] x29: ffff8000805ebca0 x28: ffffa5c6cf1869c0 x27: ffffa5c6cf186000\n[ 54.782931] x26: ffff377b84852400 x25: ffff377b848523c0 x24: ffff377b845e7230\n[ 54.782938] x23: ffffa5c6ce8dbe08 x22: ffffa5c6ceb65410 x21: 00000000ffffff92\n[ 54.782945] x20: ffffa5c6ce8dbe98 x19: ffffffffffffffac x18: ffffffffffffffff\n[ 54.807651] x17: 0000000000000000 x16: ffffa5c6ce2824ec x15: ffff8001005eb857\n[ 54.821917] x14: 0000000000000000 x13: ffffa5c6cf1a02e0 x12: 0000000000000642\n[ 54.821924] x11: 0000000000000040 x10: ffffa5c6cf19d690 x9 : ffffa5c6cf19d688\n[ 54.821931] x8 : ffff377b86000028 x7 : 0000000000000000 x6 : 0000000000000000\n[ 54.821938] x5 : ffff377b86000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 54.843331] x2 : 0000000000000000 x1 : 0000000000000002 x0 : ffffffffffffffac\n[ 54.857599] Call trace:\n[ 54.857601] kfree_skb_reason+0x18/0xb0\n[ 54.863878] btnxpuart_flush+0x40/0x58 [btnxpuart]\n[ 54.863888] hci_dev_open_sync+0x3a8/0xa04\n[ 54.872773] hci_power_on+0x54/0x2e4\n[ 54.881832] process_one_work+0x138/0x260\n[ 54.881842] worker_thread+0x32c/0x438\n[ 54.881847] kthread+0x118/0x11c\n[ 54.881853] ret_from_fork+0x10/0x20\n[ 54.896406] Code: a9be7bfd 910003fd f9000bf3 aa0003f3 (b940d400)\n[ 54.896410] ---[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46749', 'https://git.kernel.org/linus/c68bbf5e334b35b36ac5b9f0419f1f93f796bad1 (6.11-rc1)', 'https://git.kernel.org/stable/c/013dae4735d2010544d1f2121bdeb8e6c9ea171e', 'https://git.kernel.org/stable/c/056e0cd381d59a9124b7c43dd715e15f56a11635', 'https://git.kernel.org/stable/c/c68bbf5e334b35b36ac5b9f0419f1f93f796bad1', 'https://lore.kernel.org/linux-cve-announce/2024091838-CVE-2024-46749-fc9c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46749', 'https://www.cve.org/CVERecord?id=CVE-2024-46749'], 'PublishedDate': '2024-09-18T08:15:03.893Z', 'LastModifiedDate': '2024-09-20T18:45:43.483Z'}, {'VulnerabilityID': 'CVE-2024-46750', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46750', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: Add missing bridge lock to pci_bus_lock()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Add missing bridge lock to pci_bus_lock()\n\nOne of the true positives that the cfg_access_lock lockdep effort\nidentified is this sequence:\n\n WARNING: CPU: 14 PID: 1 at drivers/pci/pci.c:4886 pci_bridge_secondary_bus_reset+0x5d/0x70\n RIP: 0010:pci_bridge_secondary_bus_reset+0x5d/0x70\n Call Trace:\n \n ? __warn+0x8c/0x190\n ? pci_bridge_secondary_bus_reset+0x5d/0x70\n ? report_bug+0x1f8/0x200\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? pci_bridge_secondary_bus_reset+0x5d/0x70\n pci_reset_bus+0x1d8/0x270\n vmd_probe+0x778/0xa10\n pci_device_probe+0x95/0x120\n\nWhere pci_reset_bus() users are triggering unlocked secondary bus resets.\nIronically pci_bus_reset(), several calls down from pci_reset_bus(), uses\npci_bus_lock() before issuing the reset which locks everything *but* the\nbridge itself.\n\nFor the same motivation as adding:\n\n bridge = pci_upstream_bridge(dev);\n if (bridge)\n pci_dev_lock(bridge);\n\nto pci_reset_function() for the "bus" and "cxl_bus" reset cases, add\npci_dev_lock() for @bus->self to pci_bus_lock().\n\n[bhelgaas: squash in recursive locking deadlock fix from Keith Busch:\nhttps://lore.kernel.org/r/20240711193650.701834-1-kbusch@meta.com]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46750', 'https://git.kernel.org/linus/a4e772898f8bf2e7e1cf661a12c60a5612c4afab (6.11-rc1)', 'https://git.kernel.org/stable/c/04e85a3285b0e5c5af6fd2c0fd6e95ffecc01945', 'https://git.kernel.org/stable/c/0790b89c7e911003b8c50ae50e3ac7645de1fae9', 'https://git.kernel.org/stable/c/7253b4fed46471cc247c6cacefac890a8472c083', 'https://git.kernel.org/stable/c/78c6e39fef5c428960aff742149bba302dd46f5a', 'https://git.kernel.org/stable/c/81c68e218ab883dfa368460a59b674084c0240da', 'https://git.kernel.org/stable/c/a4e772898f8bf2e7e1cf661a12c60a5612c4afab', 'https://git.kernel.org/stable/c/df77a678c33871a6e4ac5b54a71662f1d702335b', 'https://git.kernel.org/stable/c/e2355d513b89a2cb511b4ded0deb426cdb01acd0', 'https://lore.kernel.org/linux-cve-announce/2024091838-CVE-2024-46750-3be1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46750', 'https://www.cve.org/CVERecord?id=CVE-2024-46750'], 'PublishedDate': '2024-09-18T08:15:03.947Z', 'LastModifiedDate': '2024-09-30T13:27:45.787Z'}, {'VulnerabilityID': 'CVE-2024-46751', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46751', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()\n\nInstead of doing a BUG_ON() handle the error by returning -EUCLEAN,\naborting the transaction and logging an error message.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46751', 'https://git.kernel.org/linus/28cb13f29faf6290597b24b728dc3100c019356f (6.11-rc1)', 'https://git.kernel.org/stable/c/28cb13f29faf6290597b24b728dc3100c019356f', 'https://git.kernel.org/stable/c/ef9a8b73c8b60b27d9db4787e624a3438ffe8428', 'https://lore.kernel.org/linux-cve-announce/2024091838-CVE-2024-46751-17f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46751', 'https://www.cve.org/CVERecord?id=CVE-2024-46751'], 'PublishedDate': '2024-09-18T08:15:04.01Z', 'LastModifiedDate': '2024-09-30T12:45:56.957Z'}, {'VulnerabilityID': 'CVE-2024-46752', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46752', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: replace BUG_ON() with error handling at update_ref_for_cow()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: replace BUG_ON() with error handling at update_ref_for_cow()\n\nInstead of a BUG_ON() just return an error, log an error message and\nabort the transaction in case we find an extent buffer belonging to the\nrelocation tree that doesn't have the full backref flag set. This is\nunexpected and should never happen (save for bugs or a potential bad\nmemory).", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46752', 'https://git.kernel.org/linus/b56329a782314fde5b61058e2a25097af7ccb675 (6.11-rc1)', 'https://git.kernel.org/stable/c/0fbac73a97286a7ec72229cb9b42d760a2c717ac', 'https://git.kernel.org/stable/c/41a0f85e268d72fe04f731b8ceea4748c2d65491', 'https://git.kernel.org/stable/c/b50857b96429a09fd3beed9f7f21b7bb7c433688', 'https://git.kernel.org/stable/c/b56329a782314fde5b61058e2a25097af7ccb675', 'https://git.kernel.org/stable/c/f895db00c65e5d77c437cce946da9ec29dcdf563', 'https://lore.kernel.org/linux-cve-announce/2024091839-CVE-2024-46752-49e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46752', 'https://www.cve.org/CVERecord?id=CVE-2024-46752'], 'PublishedDate': '2024-09-18T08:15:04.057Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46753', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46753', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: handle errors from btrfs_dec_ref() properly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: handle errors from btrfs_dec_ref() properly\n\nIn walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is\nincorrect, we have proper error handling here, return the error.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46753', 'https://git.kernel.org/linus/5eb178f373b4f16f3b42d55ff88fc94dd95b93b1 (6.11-rc1)', 'https://git.kernel.org/stable/c/5eb178f373b4f16f3b42d55ff88fc94dd95b93b1', 'https://git.kernel.org/stable/c/a7f16a7a709845855cb5a0e080a52bda5873f9de', 'https://lore.kernel.org/linux-cve-announce/2024091839-CVE-2024-46753-5ec2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46753', 'https://www.cve.org/CVERecord?id=CVE-2024-46753'], 'PublishedDate': '2024-09-18T08:15:04.107Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46754', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46754', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Remove tst_run from lwt_seg6local_prog_ops.', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Remove tst_run from lwt_seg6local_prog_ops.\n\nThe syzbot reported that the lwt_seg6 related BPF ops can be invoked\nvia bpf_test_run() without without entering input_action_end_bpf()\nfirst.\n\nMartin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL\nprobably didn\'t work since it was introduced in commit 04d4b274e2a\n("ipv6: sr: Add seg6local action End.BPF"). The reason is that the\nper-CPU variable seg6_bpf_srh_states::srh is never assigned in the self\ntest case but each BPF function expects it.\n\nRemove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46754', 'https://git.kernel.org/linus/c13fda93aca118b8e5cd202e339046728ee7dddb (6.11-rc1)', 'https://git.kernel.org/stable/c/9cd15511de7c619bbd0f54bb3f28e6e720ded5d6', 'https://git.kernel.org/stable/c/c13fda93aca118b8e5cd202e339046728ee7dddb', 'https://lore.kernel.org/linux-cve-announce/2024091840-CVE-2024-46754-7f04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46754', 'https://www.cve.org/CVERecord?id=CVE-2024-46754'], 'PublishedDate': '2024-09-18T08:15:04.153Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46755', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46755', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()\n\nmwifiex_get_priv_by_id() returns the priv pointer corresponding to\nthe bss_num and bss_type, but without checking if the priv is actually\ncurrently in use.\nUnused priv pointers do not have a wiphy attached to them which can\nlead to NULL pointer dereferences further down the callstack. Fix\nthis by returning only used priv pointers which have priv->bss_mode\nset to something else than NL80211_IFTYPE_UNSPECIFIED.\n\nSaid NULL pointer dereference happened when an Accesspoint was started\nwith wpa_supplicant -i mlan0 with this config:\n\nnetwork={\n ssid="somessid"\n mode=2\n frequency=2412\n key_mgmt=WPA-PSK WPA-PSK-SHA256\n proto=RSN\n group=CCMP\n pairwise=CCMP\n psk="12345678"\n}\n\nWhen waiting for the AP to be established, interrupting wpa_supplicant\nwith and starting it again this happens:\n\n| Unable to handle kernel NULL pointer dereference at virtual address 0000000000000140\n| Mem abort info:\n| ESR = 0x0000000096000004\n| EC = 0x25: DABT (current EL), IL = 32 bits\n| SET = 0, FnV = 0\n| EA = 0, S1PTW = 0\n| FSC = 0x04: level 0 translation fault\n| Data abort info:\n| ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n| CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n| GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n| user pgtable: 4k pages, 48-bit VAs, pgdp=0000000046d96000\n| [0000000000000140] pgd=0000000000000000, p4d=0000000000000000\n| Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n| Modules linked in: caam_jr caamhash_desc spidev caamalg_desc crypto_engine authenc libdes mwifiex_sdio\n+mwifiex crct10dif_ce cdc_acm onboard_usb_hub fsl_imx8_ddr_perf imx8m_ddrc rtc_ds1307 lm75 rtc_snvs\n+imx_sdma caam imx8mm_thermal spi_imx error imx_cpufreq_dt fuse ip_tables x_tables ipv6\n| CPU: 0 PID: 8 Comm: kworker/0:1 Not tainted 6.9.0-00007-g937242013fce-dirty #18\n| Hardware name: somemachine (DT)\n| Workqueue: events sdio_irq_work\n| pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n| pc : mwifiex_get_cfp+0xd8/0x15c [mwifiex]\n| lr : mwifiex_get_cfp+0x34/0x15c [mwifiex]\n| sp : ffff8000818b3a70\n| x29: ffff8000818b3a70 x28: ffff000006bfd8a5 x27: 0000000000000004\n| x26: 000000000000002c x25: 0000000000001511 x24: 0000000002e86bc9\n| x23: ffff000006bfd996 x22: 0000000000000004 x21: ffff000007bec000\n| x20: 000000000000002c x19: 0000000000000000 x18: 0000000000000000\n| x17: 000000040044ffff x16: 00500072b5503510 x15: ccc283740681e517\n| x14: 0201000101006d15 x13: 0000000002e8ff43 x12: 002c01000000ffb1\n| x11: 0100000000000000 x10: 02e8ff43002c0100 x9 : 0000ffb100100157\n| x8 : ffff000003d20000 x7 : 00000000000002f1 x6 : 00000000ffffe124\n| x5 : 0000000000000001 x4 : 0000000000000003 x3 : 0000000000000000\n| x2 : 0000000000000000 x1 : 0001000000011001 x0 : 0000000000000000\n| Call trace:\n| mwifiex_get_cfp+0xd8/0x15c [mwifiex]\n| mwifiex_parse_single_response_buf+0x1d0/0x504 [mwifiex]\n| mwifiex_handle_event_ext_scan_report+0x19c/0x2f8 [mwifiex]\n| mwifiex_process_sta_event+0x298/0xf0c [mwifiex]\n| mwifiex_process_event+0x110/0x238 [mwifiex]\n| mwifiex_main_process+0x428/0xa44 [mwifiex]\n| mwifiex_sdio_interrupt+0x64/0x12c [mwifiex_sdio]\n| process_sdio_pending_irqs+0x64/0x1b8\n| sdio_irq_work+0x4c/0x7c\n| process_one_work+0x148/0x2a0\n| worker_thread+0x2fc/0x40c\n| kthread+0x110/0x114\n| ret_from_fork+0x10/0x20\n| Code: a94153f3 a8c37bfd d50323bf d65f03c0 (f940a000)\n| ---[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46755', 'https://git.kernel.org/linus/c145eea2f75ff7949392aebecf7ef0a81c1f6c14 (6.11-rc1)', 'https://git.kernel.org/stable/c/1a05d8d02cfa3540ea5dbd6b39446bd3f515521f', 'https://git.kernel.org/stable/c/9813770f25855b866b8ead8155b8806b2db70f6d', 'https://git.kernel.org/stable/c/a12cf97cbefa139ef8d95081f2ea047cbbd74b7a', 'https://git.kernel.org/stable/c/c145eea2f75ff7949392aebecf7ef0a81c1f6c14', 'https://git.kernel.org/stable/c/c16916dd6c16fa7e13ca3923eb6b9f50d848ad03', 'https://git.kernel.org/stable/c/c2618dcb26c7211342b54520b5b148c0d3471c8a', 'https://git.kernel.org/stable/c/cb67b2e51b75f1a17bee7599c8161b96e1808a70', 'https://git.kernel.org/stable/c/d834433ff313838a259bb6607055ece87b895b66', 'https://lore.kernel.org/linux-cve-announce/2024091840-CVE-2024-46755-1f46@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46755', 'https://www.cve.org/CVERecord?id=CVE-2024-46755'], 'PublishedDate': '2024-09-18T08:15:04.203Z', 'LastModifiedDate': '2024-09-26T13:25:54.593Z'}, {'VulnerabilityID': 'CVE-2024-46756', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46756', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (w83627ehf) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83627ehf) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46756', 'https://git.kernel.org/linus/5c1de37969b7bc0abcb20b86e91e70caebbd4f89 (6.11-rc1)', 'https://git.kernel.org/stable/c/26825b62bd1bd3e53b4f44e0745cb516d5186343', 'https://git.kernel.org/stable/c/56cfdeb2c77291f0b5e4592731adfb6ca8fc7c24', 'https://git.kernel.org/stable/c/5c1de37969b7bc0abcb20b86e91e70caebbd4f89', 'https://git.kernel.org/stable/c/77ab0fd231c4ca873ec6908e761970360acc6df2', 'https://git.kernel.org/stable/c/8fecb75bff1b7d87a071c32a37aa0700f2be379d', 'https://git.kernel.org/stable/c/93cf73a7bfdce683bde3a7bb65f270d3bd24497b', 'https://git.kernel.org/stable/c/cc4be794c8d8c253770103e097ab9dbdb5f99ae1', 'https://git.kernel.org/stable/c/d92f0baf99a7e327dcceab37cce57c38aab1f691', 'https://lore.kernel.org/linux-cve-announce/2024091840-CVE-2024-46756-2ca6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46756', 'https://www.cve.org/CVERecord?id=CVE-2024-46756'], 'PublishedDate': '2024-09-18T08:15:04.26Z', 'LastModifiedDate': '2024-09-23T16:29:45.077Z'}, {'VulnerabilityID': 'CVE-2024-46757', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46757', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (nct6775-core) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46757', 'https://git.kernel.org/linus/0403e10bf0824bf0ec2bb135d4cf1c0cc3bf4bf0 (6.11-rc1)', 'https://git.kernel.org/stable/c/02bb3b4c7d5695ff4be01e0f55676bba49df435e', 'https://git.kernel.org/stable/c/0403e10bf0824bf0ec2bb135d4cf1c0cc3bf4bf0', 'https://git.kernel.org/stable/c/0c23e18cef20b989a9fd7cb0a745e1259b969159', 'https://git.kernel.org/stable/c/298a55f11edd811f2189b74eb8f53dee34d4f14c', 'https://git.kernel.org/stable/c/2f695544084a559f181cafdfd3f864c5ff9dd1db', 'https://git.kernel.org/stable/c/8a1e958e26640ce015abdbb75c8896301b9bf398', 'https://git.kernel.org/stable/c/996221b030995cc5f5baa4a642201d64b62a17cd', 'https://git.kernel.org/stable/c/d6035c55fa9afefc23f85f57eff1d4a1d82c5b10', 'https://lore.kernel.org/linux-cve-announce/2024091841-CVE-2024-46757-4fbb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46757', 'https://www.cve.org/CVERecord?id=CVE-2024-46757'], 'PublishedDate': '2024-09-18T08:15:04.313Z', 'LastModifiedDate': '2024-09-23T16:29:51.65Z'}, {'VulnerabilityID': 'CVE-2024-46758', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46758', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (lm95234) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm95234) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46758', 'https://git.kernel.org/linus/af64e3e1537896337405f880c1e9ac1f8c0c6198 (6.11-rc1)', 'https://git.kernel.org/stable/c/0fc27747633aa419f9af40e7bdfa00d2ec94ea81', 'https://git.kernel.org/stable/c/16f42953231be1e7be77bc24005270d9e0d9d2ee', 'https://git.kernel.org/stable/c/438453dfbbdcf4be26891492644aa3ecbb42c336', 'https://git.kernel.org/stable/c/46e4fd338d5bdbaf60e41cda625b24949d2af201', 'https://git.kernel.org/stable/c/59c1fb9874a01c9abc49a0a32f192a7e7b4e2650', 'https://git.kernel.org/stable/c/93f0f5721d0cca45dac50af1ae6f9a9826c699fd', 'https://git.kernel.org/stable/c/af64e3e1537896337405f880c1e9ac1f8c0c6198', 'https://git.kernel.org/stable/c/da765bebd90e1b92bdbc3c6a27a3f3cc81529ab6', 'https://lore.kernel.org/linux-cve-announce/2024091841-CVE-2024-46758-6154@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46758', 'https://www.cve.org/CVERecord?id=CVE-2024-46758'], 'PublishedDate': '2024-09-18T08:15:04.367Z', 'LastModifiedDate': '2024-09-23T16:29:24.767Z'}, {'VulnerabilityID': 'CVE-2024-46759', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46759', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (adc128d818) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adc128d818) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46759', 'https://git.kernel.org/linus/8cad724c8537fe3e0da8004646abc00290adae40 (6.11-rc1)', 'https://git.kernel.org/stable/c/019ef2d396363ecddc46e826153a842f8603799b', 'https://git.kernel.org/stable/c/05419d0056dcf7088687e561bb583cc06deba777', 'https://git.kernel.org/stable/c/2a3add62f183459a057336381ef3a896da01ce38', 'https://git.kernel.org/stable/c/6891b11a0c6227ca7ed15786928a07b1c0e4d4af', 'https://git.kernel.org/stable/c/7645d783df23878342d5d8d22030c3861d2d5426', 'https://git.kernel.org/stable/c/8cad724c8537fe3e0da8004646abc00290adae40', 'https://git.kernel.org/stable/c/b0bdb43852bf7f55ba02f0cbf00b4ea7ca897bff', 'https://git.kernel.org/stable/c/f7f5101af5b47a331cdbfa42ba64c507b47dd1fe', 'https://lore.kernel.org/linux-cve-announce/2024091841-CVE-2024-46759-9b86@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46759', 'https://www.cve.org/CVERecord?id=CVE-2024-46759'], 'PublishedDate': '2024-09-18T08:15:04.413Z', 'LastModifiedDate': '2024-09-23T16:28:53.257Z'}, {'VulnerabilityID': 'CVE-2024-46760', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46760', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw88: usb: schedule rx work after everything is set up', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: usb: schedule rx work after everything is set up\n\nRight now it's possible to hit NULL pointer dereference in\nrtw_rx_fill_rx_status on hw object and/or its fields because\ninitialization routine can start getting USB replies before\nrtw_dev is fully setup.\n\nThe stack trace looks like this:\n\nrtw_rx_fill_rx_status\nrtw8821c_query_rx_desc\nrtw_usb_rx_handler\n...\nqueue_work\nrtw_usb_read_port_complete\n...\nusb_submit_urb\nrtw_usb_rx_resubmit\nrtw_usb_init_rx\nrtw_usb_probe\n\nSo while we do the async stuff rtw_usb_probe continues and calls\nrtw_register_hw, which does all kinds of initialization (e.g.\nvia ieee80211_register_hw) that rtw_rx_fill_rx_status relies on.\n\nFix this by moving the first usb_submit_urb after everything\nis set up.\n\nFor me, this bug manifested as:\n[ 8.893177] rtw_8821cu 1-1:1.2: band wrong, packet dropped\n[ 8.910904] rtw_8821cu 1-1:1.2: hw->conf.chandef.chan NULL in rtw_rx_fill_rx_status\nbecause I'm using Larry's backport of rtw88 driver with the NULL\nchecks in rtw_rx_fill_rx_status.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46760', 'https://git.kernel.org/linus/adc539784c98a7cc602cbf557debfc2e7b9be8b3 (6.11-rc1)', 'https://git.kernel.org/stable/c/25eaef533bf3ccc6fee5067aac16f41f280e343e', 'https://git.kernel.org/stable/c/adc539784c98a7cc602cbf557debfc2e7b9be8b3', 'https://git.kernel.org/stable/c/c83d464b82a8ad62ec9077637f75d73fe955635a', 'https://lore.kernel.org/linux-cve-announce/2024091842-CVE-2024-46760-1eb3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46760', 'https://www.cve.org/CVERecord?id=CVE-2024-46760'], 'PublishedDate': '2024-09-18T08:15:04.47Z', 'LastModifiedDate': '2024-09-23T16:18:28.87Z'}, {'VulnerabilityID': 'CVE-2024-46761', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46761', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npci/hotplug/pnv_php: Fix hotplug driver crash on Powernv\n\nThe hotplug driver for powerpc (pci/hotplug/pnv_php.c) causes a kernel\ncrash when we try to hot-unplug/disable the PCIe switch/bridge from\nthe PHB.\n\nThe crash occurs because although the MSI data structure has been\nreleased during disable/hot-unplug path and it has been assigned\nwith NULL, still during unregistration the code was again trying to\nexplicitly disable the MSI which causes the NULL pointer dereference and\nkernel crash.\n\nThe patch fixes the check during unregistration path to prevent invoking\npci_disable_msi/msix() since its data structure is already freed.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46761', 'https://git.kernel.org/linus/335e35b748527f0c06ded9eebb65387f60647fda (6.11-rc1)', 'https://git.kernel.org/stable/c/335e35b748527f0c06ded9eebb65387f60647fda', 'https://git.kernel.org/stable/c/438d522227374042b5c8798f8ce83bbe479dca4d', 'https://git.kernel.org/stable/c/4eb4085c1346d19d4a05c55246eb93e74e671048', 'https://git.kernel.org/stable/c/b82d4d5c736f4fd2ed224c35f554f50d1953d21e', 'https://git.kernel.org/stable/c/bc1faed19db95abf0933b104910a3fb01b138f59', 'https://git.kernel.org/stable/c/bfc44075b19740d372f989f21dd03168bfda0689', 'https://git.kernel.org/stable/c/c0d8094dc740cfacf3775bbc6a1c4720459e8de4', 'https://git.kernel.org/stable/c/c4c681999d385e28f84808bbf3a85ea8e982da55', 'https://lore.kernel.org/linux-cve-announce/2024091842-CVE-2024-46761-289f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46761', 'https://www.cve.org/CVERecord?id=CVE-2024-46761'], 'PublishedDate': '2024-09-18T08:15:04.517Z', 'LastModifiedDate': '2024-09-23T16:06:58.397Z'}, {'VulnerabilityID': 'CVE-2024-46762', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46762', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xen: privcmd: Fix possible access to a freed kirqfd instance', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Fix possible access to a freed kirqfd instance\n\nNothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and\nprivcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd\ncreated and added to the irqfds_list by privcmd_irqfd_assign() may get\nremoved by another thread executing privcmd_irqfd_deassign(), while the\nformer is still using it after dropping the locks.\n\nThis can lead to a situation where an already freed kirqfd instance may\nbe accessed and cause kernel oops.\n\nUse SRCU locking to prevent the same, as is done for the KVM\nimplementation for irqfds.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46762', 'https://git.kernel.org/linus/611ff1b1ae989a7bcce3e2a8e132ee30e968c557 (6.11-rc1)', 'https://git.kernel.org/stable/c/112fd2f02b308564724b8e81006c254d20945c4b', 'https://git.kernel.org/stable/c/611ff1b1ae989a7bcce3e2a8e132ee30e968c557', 'https://git.kernel.org/stable/c/e997b357b13a7d95de31681fc54fcc34235fa527', 'https://lore.kernel.org/linux-cve-announce/2024091843-CVE-2024-46762-6512@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46762', 'https://www.cve.org/CVERecord?id=CVE-2024-46762'], 'PublishedDate': '2024-09-18T08:15:04.57Z', 'LastModifiedDate': '2024-09-23T16:12:34.42Z'}, {'VulnerabilityID': 'CVE-2024-46763', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46763', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fou: Fix null-ptr-deref in GRO.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix null-ptr-deref in GRO.\n\nWe observed a null-ptr-deref in fou_gro_receive() while shutting down\na host. [0]\n\nThe NULL pointer is sk->sk_user_data, and the offset 8 is of protocol\nin struct fou.\n\nWhen fou_release() is called due to netns dismantle or explicit tunnel\nteardown, udp_tunnel_sock_release() sets NULL to sk->sk_user_data.\nThen, the tunnel socket is destroyed after a single RCU grace period.\n\nSo, in-flight udp4_gro_receive() could find the socket and execute the\nFOU GRO handler, where sk->sk_user_data could be NULL.\n\nLet's use rcu_dereference_sk_user_data() in fou_from_sock() and add NULL\nchecks in FOU GRO handlers.\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 80000001032f4067 P4D 80000001032f4067 PUD 103240067 PMD 0\nSMP PTI\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.216-204.855.amzn2.x86_64 #1\nHardware name: Amazon EC2 c5.large/, BIOS 1.0 10/16/2017\nRIP: 0010:fou_gro_receive (net/ipv4/fou.c:233) [fou]\nCode: 41 5f c3 cc cc cc cc e8 e7 2e 69 f4 0f 1f 80 00 00 00 00 0f 1f 44 00 00 49 89 f8 41 54 48 89 f7 48 89 d6 49 8b 80 88 02 00 00 <0f> b6 48 08 0f b7 42 4a 66 25 fd fd 80 cc 02 66 89 42 4a 0f b6 42\nRSP: 0018:ffffa330c0003d08 EFLAGS: 00010297\nRAX: 0000000000000000 RBX: ffff93d9e3a6b900 RCX: 0000000000000010\nRDX: ffff93d9e3a6b900 RSI: ffff93d9e3a6b900 RDI: ffff93dac2e24d08\nRBP: ffff93d9e3a6b900 R08: ffff93dacbce6400 R09: 0000000000000002\nR10: 0000000000000000 R11: ffffffffb5f369b0 R12: ffff93dacbce6400\nR13: ffff93dac2e24d08 R14: 0000000000000000 R15: ffffffffb4edd1c0\nFS: 0000000000000000(0000) GS:ffff93daee800000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000102140001 CR4: 00000000007706f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? no_context (arch/x86/mm/fault.c:752)\n ? exc_page_fault (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 arch/x86/mm/fault.c:1435 arch/x86/mm/fault.c:1483)\n ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:571)\n ? fou_gro_receive (net/ipv4/fou.c:233) [fou]\n udp_gro_receive (include/linux/netdevice.h:2552 net/ipv4/udp_offload.c:559)\n udp4_gro_receive (net/ipv4/udp_offload.c:604)\n inet_gro_receive (net/ipv4/af_inet.c:1549 (discriminator 7))\n dev_gro_receive (net/core/dev.c:6035 (discriminator 4))\n napi_gro_receive (net/core/dev.c:6170)\n ena_clean_rx_irq (drivers/amazon/net/ena/ena_netdev.c:1558) [ena]\n ena_io_poll (drivers/amazon/net/ena/ena_netdev.c:1742) [ena]\n napi_poll (net/core/dev.c:6847)\n net_rx_action (net/core/dev.c:6917)\n __do_softirq (arch/x86/include/asm/jump_label.h:25 include/linux/jump_label.h:200 include/trace/events/irq.h:142 kernel/softirq.c:299)\n asm_call_irq_on_stack (arch/x86/entry/entry_64.S:809)\n\n do_softirq_own_stack (arch/x86/include/asm/irq_stack.h:27 arch/x86/include/asm/irq_stack.h:77 arch/x86/kernel/irq_64.c:77)\n irq_exit_rcu (kernel/softirq.c:393 kernel/softirq.c:423 kernel/softirq.c:435)\n common_interrupt (arch/x86/kernel/irq.c:239)\n asm_common_interrupt (arch/x86/include/asm/idtentry.h:626)\nRIP: 0010:acpi_idle_do_entry (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 drivers/acpi/processor_idle.c:114 drivers/acpi/processor_idle.c:575)\nCode: 8b 15 d1 3c c4 02 ed c3 cc cc cc cc 65 48 8b 04 25 40 ef 01 00 48 8b 00 a8 08 75 eb 0f 1f 44 00 00 0f 00 2d d5 09 55 00 fb f4 c3 cc cc cc cc e9 be fc ff ff 66 66 2e 0f 1f 84 00 00 00 00 00\nRSP: 0018:ffffffffb5603e58 EFLAGS: 00000246\nRAX: 0000000000004000 RBX: ffff93dac0929c00 RCX: ffff93daee833900\nRDX: ffff93daee800000 RSI: ffff93d\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46763', 'https://git.kernel.org/linus/7e4196935069947d8b70b09c1660b67b067e75cb (6.11-rc7)', 'https://git.kernel.org/stable/c/1df42be305fe478ded1ee0c1d775f4ece713483b', 'https://git.kernel.org/stable/c/231c235d2f7a66f018f172e26ffd47c363f244ef', 'https://git.kernel.org/stable/c/4494bccb52ffda22ce5a1163a776d970e6229e08', 'https://git.kernel.org/stable/c/7e4196935069947d8b70b09c1660b67b067e75cb', 'https://git.kernel.org/stable/c/c46cd6aaca81040deaea3500ba75126963294bd9', 'https://git.kernel.org/stable/c/d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3', 'https://lore.kernel.org/linux-cve-announce/2024091843-CVE-2024-46763-a580@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46763', 'https://www.cve.org/CVERecord?id=CVE-2024-46763'], 'PublishedDate': '2024-09-18T08:15:04.613Z', 'LastModifiedDate': '2024-09-23T16:14:18.297Z'}, {'VulnerabilityID': 'CVE-2024-46765', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46765', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: protect XDP configuration with a mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: protect XDP configuration with a mutex\n\nThe main threat to data consistency in ice_xdp() is a possible asynchronous\nPF reset. It can be triggered by a user or by TX timeout handler.\n\nXDP setup and PF reset code access the same resources in the following\nsections:\n* ice_vsi_close() in ice_prepare_for_reset() - already rtnl-locked\n* ice_vsi_rebuild() for the PF VSI - not protected\n* ice_vsi_open() - already rtnl-locked\n\nWith an unfortunate timing, such accesses can result in a crash such as the\none below:\n\n[ +1.999878] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 14\n[ +2.002992] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 18\n[Mar15 18:17] ice 0000:b1:00.0 ens801f0np0: NETDEV WATCHDOG: CPU: 38: transmit queue 14 timed out 80692736 ms\n[ +0.000093] ice 0000:b1:00.0 ens801f0np0: tx_timeout: VSI_num: 6, Q 14, NTC: 0x0, HW_HEAD: 0x0, NTU: 0x0, INT: 0x4000001\n[ +0.000012] ice 0000:b1:00.0 ens801f0np0: tx_timeout recovery level 1, txqueue 14\n[ +0.394718] ice 0000:b1:00.0: PTP reset successful\n[ +0.006184] BUG: kernel NULL pointer dereference, address: 0000000000000098\n[ +0.000045] #PF: supervisor read access in kernel mode\n[ +0.000023] #PF: error_code(0x0000) - not-present page\n[ +0.000023] PGD 0 P4D 0\n[ +0.000018] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ +0.000023] CPU: 38 PID: 7540 Comm: kworker/38:1 Not tainted 6.8.0-rc7 #1\n[ +0.000031] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000036] Workqueue: ice ice_service_task [ice]\n[ +0.000183] RIP: 0010:ice_clean_tx_ring+0xa/0xd0 [ice]\n[...]\n[ +0.000013] Call Trace:\n[ +0.000016] \n[ +0.000014] ? __die+0x1f/0x70\n[ +0.000029] ? page_fault_oops+0x171/0x4f0\n[ +0.000029] ? schedule+0x3b/0xd0\n[ +0.000027] ? exc_page_fault+0x7b/0x180\n[ +0.000022] ? asm_exc_page_fault+0x22/0x30\n[ +0.000031] ? ice_clean_tx_ring+0xa/0xd0 [ice]\n[ +0.000194] ice_free_tx_ring+0xe/0x60 [ice]\n[ +0.000186] ice_destroy_xdp_rings+0x157/0x310 [ice]\n[ +0.000151] ice_vsi_decfg+0x53/0xe0 [ice]\n[ +0.000180] ice_vsi_rebuild+0x239/0x540 [ice]\n[ +0.000186] ice_vsi_rebuild_by_type+0x76/0x180 [ice]\n[ +0.000145] ice_rebuild+0x18c/0x840 [ice]\n[ +0.000145] ? delay_tsc+0x4a/0xc0\n[ +0.000022] ? delay_tsc+0x92/0xc0\n[ +0.000020] ice_do_reset+0x140/0x180 [ice]\n[ +0.000886] ice_service_task+0x404/0x1030 [ice]\n[ +0.000824] process_one_work+0x171/0x340\n[ +0.000685] worker_thread+0x277/0x3a0\n[ +0.000675] ? preempt_count_add+0x6a/0xa0\n[ +0.000677] ? _raw_spin_lock_irqsave+0x23/0x50\n[ +0.000679] ? __pfx_worker_thread+0x10/0x10\n[ +0.000653] kthread+0xf0/0x120\n[ +0.000635] ? __pfx_kthread+0x10/0x10\n[ +0.000616] ret_from_fork+0x2d/0x50\n[ +0.000612] ? __pfx_kthread+0x10/0x10\n[ +0.000604] ret_from_fork_asm+0x1b/0x30\n[ +0.000604] \n\nThe previous way of handling this through returning -EBUSY is not viable,\nparticularly when destroying AF_XDP socket, because the kernel proceeds\nwith removal anyway.\n\nThere is plenty of code between those calls and there is no need to create\na large critical section that covers all of them, same as there is no need\nto protect ice_vsi_rebuild() with rtnl_lock().\n\nAdd xdp_state_lock mutex to protect ice_vsi_rebuild() and ice_xdp().\n\nLeaving unprotected sections in between would result in two states that\nhave to be considered:\n1. when the VSI is closed, but not yet rebuild\n2. when VSI is already rebuild, but not yet open\n\nThe latter case is actually already handled through !netif_running() case,\nwe just need to adjust flag checking a little. The former one is not as\ntrivial, because between ice_vsi_close() and ice_vsi_rebuild(), a lot of\nhardware interaction happens, this can make adding/deleting rings exit\nwith an error. Luckily, VSI rebuild is pending and can apply new\nconfiguration for us in a managed fashion.\n\nTherefore, add an additional VSI state flag ICE_VSI_REBUILD_PENDING to\nindicate that ice_x\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46765', 'https://git.kernel.org/linus/2504b8405768a57a71e660dbfd5abd59f679a03f (6.11-rc7)', 'https://git.kernel.org/stable/c/2504b8405768a57a71e660dbfd5abd59f679a03f', 'https://git.kernel.org/stable/c/2f057db2fb29bc209c103050647562e60554d3d3', 'https://git.kernel.org/stable/c/391f7dae3d836891fc6cfbde38add2d0e10c6b7f', 'https://lore.kernel.org/linux-cve-announce/2024091844-CVE-2024-46765-1b8f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46765', 'https://www.cve.org/CVERecord?id=CVE-2024-46765'], 'PublishedDate': '2024-09-18T08:15:04.71Z', 'LastModifiedDate': '2024-09-26T13:24:29.697Z'}, {'VulnerabilityID': 'CVE-2024-46766', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46766', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: move netif_queue_set_napi to rtnl-protected sections', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: move netif_queue_set_napi to rtnl-protected sections\n\nCurrently, netif_queue_set_napi() is called from ice_vsi_rebuild() that is\nnot rtnl-locked when called from the reset. This creates the need to take\nthe rtnl_lock just for a single function and complicates the\nsynchronization with .ndo_bpf. At the same time, there no actual need to\nfill napi-to-queue information at this exact point.\n\nFill napi-to-queue information when opening the VSI and clear it when the\nVSI is being closed. Those routines are already rtnl-locked.\n\nAlso, rewrite napi-to-queue assignment in a way that prevents inclusion of\nXDP queues, as this leads to out-of-bounds writes, such as one below.\n\n[ +0.000004] BUG: KASAN: slab-out-of-bounds in netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000012] Write of size 8 at addr ffff889881727c80 by task bash/7047\n[ +0.000006] CPU: 24 PID: 7047 Comm: bash Not tainted 6.10.0-rc2+ #2\n[ +0.000004] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000003] Call Trace:\n[ +0.000003] \n[ +0.000002] dump_stack_lvl+0x60/0x80\n[ +0.000007] print_report+0xce/0x630\n[ +0.000007] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n[ +0.000007] ? __virt_addr_valid+0x1c9/0x2c0\n[ +0.000005] ? netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000003] kasan_report+0xe9/0x120\n[ +0.000004] ? netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000004] netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000005] ice_vsi_close+0x161/0x670 [ice]\n[ +0.000114] ice_dis_vsi+0x22f/0x270 [ice]\n[ +0.000095] ice_pf_dis_all_vsi.constprop.0+0xae/0x1c0 [ice]\n[ +0.000086] ice_prepare_for_reset+0x299/0x750 [ice]\n[ +0.000087] pci_dev_save_and_disable+0x82/0xd0\n[ +0.000006] pci_reset_function+0x12d/0x230\n[ +0.000004] reset_store+0xa0/0x100\n[ +0.000006] ? __pfx_reset_store+0x10/0x10\n[ +0.000002] ? __pfx_mutex_lock+0x10/0x10\n[ +0.000004] ? __check_object_size+0x4c1/0x640\n[ +0.000007] kernfs_fop_write_iter+0x30b/0x4a0\n[ +0.000006] vfs_write+0x5d6/0xdf0\n[ +0.000005] ? fd_install+0x180/0x350\n[ +0.000005] ? __pfx_vfs_write+0x10/0xA10\n[ +0.000004] ? do_fcntl+0x52c/0xcd0\n[ +0.000004] ? kasan_save_track+0x13/0x60\n[ +0.000003] ? kasan_save_free_info+0x37/0x60\n[ +0.000006] ksys_write+0xfa/0x1d0\n[ +0.000003] ? __pfx_ksys_write+0x10/0x10\n[ +0.000002] ? __x64_sys_fcntl+0x121/0x180\n[ +0.000004] ? _raw_spin_lock+0x87/0xe0\n[ +0.000005] do_syscall_64+0x80/0x170\n[ +0.000007] ? _raw_spin_lock+0x87/0xe0\n[ +0.000004] ? __pfx__raw_spin_lock+0x10/0x10\n[ +0.000003] ? file_close_fd_locked+0x167/0x230\n[ +0.000005] ? syscall_exit_to_user_mode+0x7d/0x220\n[ +0.000005] ? do_syscall_64+0x8c/0x170\n[ +0.000004] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? fput+0x1a/0x2c0\n[ +0.000004] ? filp_close+0x19/0x30\n[ +0.000004] ? do_dup2+0x25a/0x4c0\n[ +0.000004] ? __x64_sys_dup2+0x6e/0x2e0\n[ +0.000002] ? syscall_exit_to_user_mode+0x7d/0x220\n[ +0.000004] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? __count_memcg_events+0x113/0x380\n[ +0.000005] ? handle_mm_fault+0x136/0x820\n[ +0.000005] ? do_user_addr_fault+0x444/0xa80\n[ +0.000004] ? clear_bhb_loop+0x25/0x80\n[ +0.000004] ? clear_bhb_loop+0x25/0x80\n[ +0.000002] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ +0.000005] RIP: 0033:0x7f2033593154', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46766', 'https://git.kernel.org/linus/2a5dc090b92cfa5270e20056074241c6db5c9cdd (6.11-rc7)', 'https://git.kernel.org/stable/c/2285c2faef19ee08a6bd6754f4c3ec07dceb2889', 'https://git.kernel.org/stable/c/2a5dc090b92cfa5270e20056074241c6db5c9cdd', 'https://lore.kernel.org/linux-cve-announce/2024091844-CVE-2024-46766-417c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46766', 'https://www.cve.org/CVERecord?id=CVE-2024-46766'], 'PublishedDate': '2024-09-18T08:15:04.76Z', 'LastModifiedDate': '2024-09-23T16:15:23.823Z'}, {'VulnerabilityID': 'CVE-2024-46767', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46767', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: phy: Fix missing of_node_put() for leds', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: Fix missing of_node_put() for leds\n\nThe call of of_get_child_by_name() will cause refcount incremented\nfor leds, if it succeeds, it should call of_node_put() to decrease\nit, fix it.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46767', 'https://git.kernel.org/linus/2560db6ede1aaf162a73b2df43e0b6c5ed8819f7 (6.11-rc7)', 'https://git.kernel.org/stable/c/2560db6ede1aaf162a73b2df43e0b6c5ed8819f7', 'https://git.kernel.org/stable/c/26928c8f00f6bb0e194f3957fe51c69d36838eb2', 'https://git.kernel.org/stable/c/d9c8dbbc236cdc6231ee91cdede2fc97b430cfff', 'https://lore.kernel.org/linux-cve-announce/2024091844-CVE-2024-46767-31a2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46767', 'https://www.cve.org/CVERecord?id=CVE-2024-46767'], 'PublishedDate': '2024-09-18T08:15:04.81Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46768', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46768', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (hp-wmi-sensors) Check if WMI event data exists', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Check if WMI event data exists\n\nThe BIOS can choose to return no event data in response to a\nWMI event, so the ACPI object passed to the WMI notify handler\ncan be NULL.\n\nCheck for such a situation and ignore the event in such a case.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46768', 'https://git.kernel.org/linus/a54da9df75cd1b4b5028f6c60f9a211532680585 (6.11-rc7)', 'https://git.kernel.org/stable/c/217539e994e53206bbf3fb330261cc78c480d311', 'https://git.kernel.org/stable/c/4b19c83ba108aa66226da5b79810e4d19e005f12', 'https://git.kernel.org/stable/c/a54da9df75cd1b4b5028f6c60f9a211532680585', 'https://lore.kernel.org/linux-cve-announce/2024091845-CVE-2024-46768-b0bb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46768', 'https://www.cve.org/CVERecord?id=CVE-2024-46768'], 'PublishedDate': '2024-09-18T08:15:04.853Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46770', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46770', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Add netif_device_attach/detach into PF reset flow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add netif_device_attach/detach into PF reset flow\n\nEthtool callbacks can be executed while reset is in progress and try to\naccess deleted resources, e.g. getting coalesce settings can result in a\nNULL pointer dereference seen below.\n\nReproduction steps:\nOnce the driver is fully initialized, trigger reset:\n\t# echo 1 > /sys/class/net//device/reset\nwhen reset is in progress try to get coalesce settings using ethtool:\n\t# ethtool -c \n\nBUG: kernel NULL pointer dereference, address: 0000000000000020\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] PREEMPT SMP PTI\nCPU: 11 PID: 19713 Comm: ethtool Tainted: G S 6.10.0-rc7+ #7\nRIP: 0010:ice_get_q_coalesce+0x2e/0xa0 [ice]\nRSP: 0018:ffffbab1e9bcf6a8 EFLAGS: 00010206\nRAX: 000000000000000c RBX: ffff94512305b028 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffff9451c3f2e588 RDI: ffff9451c3f2e588\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffff9451c3f2e580 R11: 000000000000001f R12: ffff945121fa9000\nR13: ffffbab1e9bcf760 R14: 0000000000000013 R15: ffffffff9e65dd40\nFS: 00007faee5fbe740(0000) GS:ffff94546fd80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000020 CR3: 0000000106c2e005 CR4: 00000000001706f0\nCall Trace:\n\nice_get_coalesce+0x17/0x30 [ice]\ncoalesce_prepare_data+0x61/0x80\nethnl_default_doit+0xde/0x340\ngenl_family_rcv_msg_doit+0xf2/0x150\ngenl_rcv_msg+0x1b3/0x2c0\nnetlink_rcv_skb+0x5b/0x110\ngenl_rcv+0x28/0x40\nnetlink_unicast+0x19c/0x290\nnetlink_sendmsg+0x222/0x490\n__sys_sendto+0x1df/0x1f0\n__x64_sys_sendto+0x24/0x30\ndo_syscall_64+0x82/0x160\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7faee60d8e27\n\nCalling netif_device_detach() before reset makes the net core not call\nthe driver when ethtool command is issued, the attempt to execute an\nethtool command during reset will result in the following message:\n\n netlink error: No such device\n\ninstead of NULL pointer dereference. Once reset is done and\nice_rebuild() is executing, the netif_device_attach() is called to allow\nfor ethtool operations to occur again in a safe manner.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46770', 'https://git.kernel.org/linus/d11a67634227f9f9da51938af085fb41a733848f (6.11-rc7)', 'https://git.kernel.org/stable/c/36486c9e8e01b84faaee47203eac0b7e9cc7fa4a', 'https://git.kernel.org/stable/c/9e3ffb839249eca113062587659224f856fe14e5', 'https://git.kernel.org/stable/c/d11a67634227f9f9da51938af085fb41a733848f', 'https://git.kernel.org/stable/c/efe8effe138044a4747d1112ebb8c454d1663723', 'https://lore.kernel.org/linux-cve-announce/2024091845-CVE-2024-46770-3a5d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46770', 'https://www.cve.org/CVERecord?id=CVE-2024-46770'], 'PublishedDate': '2024-09-18T08:15:04.957Z', 'LastModifiedDate': '2024-09-23T16:13:25.563Z'}, {'VulnerabilityID': 'CVE-2024-46771', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46771', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: can: bcm: Remove proc entry when dev is unregistered.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: Remove proc entry when dev is unregistered.\n\nsyzkaller reported a warning in bcm_connect() below. [0]\n\nThe repro calls connect() to vxcan1, removes vxcan1, and calls\nconnect() with ifindex == 0.\n\nCalling connect() for a BCM socket allocates a proc entry.\nThen, bcm_sk(sk)->bound is set to 1 to prevent further connect().\n\nHowever, removing the bound device resets bcm_sk(sk)->bound to 0\nin bcm_notify().\n\nThe 2nd connect() tries to allocate a proc entry with the same\nname and sets NULL to bcm_sk(sk)->bcm_proc_read, leaking the\noriginal proc entry.\n\nSince the proc entry is available only for connect()ed sockets,\nlet's clean up the entry when the bound netdev is unregistered.\n\n[0]:\nproc_dir_entry 'can-bcm/2456' already registered\nWARNING: CPU: 1 PID: 394 at fs/proc/generic.c:376 proc_register+0x645/0x8f0 fs/proc/generic.c:375\nModules linked in:\nCPU: 1 PID: 394 Comm: syz-executor403 Not tainted 6.10.0-rc7-g852e42cc2dd4\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nRIP: 0010:proc_register+0x645/0x8f0 fs/proc/generic.c:375\nCode: 00 00 00 00 00 48 85 ed 0f 85 97 02 00 00 4d 85 f6 0f 85 9f 02 00 00 48 c7 c7 9b cb cf 87 48 89 de 4c 89 fa e8 1c 6f eb fe 90 <0f> 0b 90 90 48 c7 c7 98 37 99 89 e8 cb 7e 22 05 bb 00 00 00 10 48\nRSP: 0018:ffa0000000cd7c30 EFLAGS: 00010246\nRAX: 9e129be1950f0200 RBX: ff1100011b51582c RCX: ff1100011857cd80\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000002\nRBP: 0000000000000000 R08: ffd400000000000f R09: ff1100013e78cac0\nR10: ffac800000cd7980 R11: ff1100013e12b1f0 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000000 R15: ff1100011a99a2ec\nFS: 00007fbd7086f740(0000) GS:ff1100013fd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000200071c0 CR3: 0000000118556004 CR4: 0000000000771ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n proc_create_net_single+0x144/0x210 fs/proc/proc_net.c:220\n bcm_connect+0x472/0x840 net/can/bcm.c:1673\n __sys_connect_file net/socket.c:2049 [inline]\n __sys_connect+0x5d2/0x690 net/socket.c:2066\n __do_sys_connect net/socket.c:2076 [inline]\n __se_sys_connect net/socket.c:2073 [inline]\n __x64_sys_connect+0x8f/0x100 net/socket.c:2073\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd9/0x1c0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7fbd708b0e5d\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 9f 1b 00 f7 d8 64 89 01 48\nRSP: 002b:00007fff8cd33f08 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fbd708b0e5d\nRDX: 0000000000000010 RSI: 0000000020000040 RDI: 0000000000000003\nRBP: 0000000000000000 R08: 0000000000000040 R09: 0000000000000040\nR10: 0000000000000040 R11: 0000000000000246 R12: 00007fff8cd34098\nR13: 0000000000401280 R14: 0000000000406de8 R15: 00007fbd70ab9000\n \nremove_proc_entry: removing non-empty directory 'net/can-bcm', leaking at least '2456'", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46771', 'https://git.kernel.org/linus/76fe372ccb81b0c89b6cd2fec26e2f38c958be85 (6.11-rc7)', 'https://git.kernel.org/stable/c/10bfacbd5e8d821011d857bee73310457c9c989a', 'https://git.kernel.org/stable/c/33ed4ba73caae39f34ab874ba79138badc2c65dd', 'https://git.kernel.org/stable/c/3b39dc2901aa7a679a5ca981a3de9f8d5658afe8', 'https://git.kernel.org/stable/c/4377b79323df62eb5d310354f19b4d130ff58d50', 'https://git.kernel.org/stable/c/5c680022c4e28ba18ea500f3e29f0428271afa92', 'https://git.kernel.org/stable/c/76fe372ccb81b0c89b6cd2fec26e2f38c958be85', 'https://git.kernel.org/stable/c/abb0a615569ec008e8a93d9f3ab2d5b418ea94d4', 'https://git.kernel.org/stable/c/aec92dbebdbec7567d9f56d7c9296a572b8fd849', 'https://lore.kernel.org/linux-cve-announce/2024091846-CVE-2024-46771-913d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46771', 'https://www.cve.org/CVERecord?id=CVE-2024-46771'], 'PublishedDate': '2024-09-18T08:15:05.01Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46772', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46772', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check denominator crb_pipes before used', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check denominator crb_pipes before used\n\n[WHAT & HOW]\nA denominator cannot be 0, and is checked before used.\n\nThis fixes 2 DIVIDE_BY_ZERO issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46772', 'https://git.kernel.org/linus/ea79068d4073bf303f8203f2625af7d9185a1bc6 (6.11-rc1)', 'https://git.kernel.org/stable/c/ea79068d4073bf303f8203f2625af7d9185a1bc6', 'https://git.kernel.org/stable/c/ede06d23392529b039cf7ac11b5875b047900f1c', 'https://lore.kernel.org/linux-cve-announce/2024091846-CVE-2024-46772-4ad6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46772', 'https://www.cve.org/CVERecord?id=CVE-2024-46772'], 'PublishedDate': '2024-09-18T08:15:05.073Z', 'LastModifiedDate': '2024-09-23T16:52:17.577Z'}, {'VulnerabilityID': 'CVE-2024-46773', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46773', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check denominator pbn_div before used', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check denominator pbn_div before used\n\n[WHAT & HOW]\nA denominator cannot be 0, and is checked before used.\n\nThis fixes 1 DIVIDE_BY_ZERO issue reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46773', 'https://git.kernel.org/linus/116a678f3a9abc24f5c9d2525b7393d18d9eb58e (6.11-rc1)', 'https://git.kernel.org/stable/c/116a678f3a9abc24f5c9d2525b7393d18d9eb58e', 'https://git.kernel.org/stable/c/11f997143c67680d6e40a13363618380cd57a414', 'https://git.kernel.org/stable/c/20e7164c52d9bfbb9d9862b833fa989624a61345', 'https://git.kernel.org/stable/c/dfafee0a7b51c7c9612edd2d991401294964d02f', 'https://lore.kernel.org/linux-cve-announce/2024091847-CVE-2024-46773-5781@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46773', 'https://www.cve.org/CVERecord?id=CVE-2024-46773'], 'PublishedDate': '2024-09-18T08:15:05.123Z', 'LastModifiedDate': '2024-09-23T16:51:59.983Z'}, {'VulnerabilityID': 'CVE-2024-46774', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46774', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()\n\nSmatch warns:\n\n arch/powerpc/kernel/rtas.c:1932 __do_sys_rtas() warn: potential\n spectre issue 'args.args' [r] (local cap)\n\nThe 'nargs' and 'nret' locals come directly from a user-supplied\nbuffer and are used as indexes into a small stack-based array and as\ninputs to copy_to_user() after they are subject to bounds checks.\n\nUse array_index_nospec() after the bounds checks to clamp these values\nfor speculative execution.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46774', 'https://git.kernel.org/linus/0974d03eb479384466d828d65637814bee6b26d7 (6.11-rc1)', 'https://git.kernel.org/stable/c/0974d03eb479384466d828d65637814bee6b26d7', 'https://git.kernel.org/stable/c/68d8156480940b79227d58865ec5d2947b9384a8', 'https://lore.kernel.org/linux-cve-announce/2024091847-CVE-2024-46774-48d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46774', 'https://www.cve.org/CVERecord?id=CVE-2024-46774'], 'PublishedDate': '2024-09-18T08:15:05.18Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46775', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46775', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Validate function returns', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate function returns\n\n[WHAT & HOW]\nFunction return values must be checked before data can be used\nin subsequent functions.\n\nThis fixes 4 CHECKED_RETURN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46775', 'https://git.kernel.org/linus/673f816b9e1e92d1f70e1bf5f21b531e0ff9ad6c (6.11-rc1)', 'https://git.kernel.org/stable/c/5639a3048c7079803256374204ad55ec52cd0b49', 'https://git.kernel.org/stable/c/673f816b9e1e92d1f70e1bf5f21b531e0ff9ad6c', 'https://lore.kernel.org/linux-cve-announce/2024091847-CVE-2024-46775-aecc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46775', 'https://www.cve.org/CVERecord?id=CVE-2024-46775'], 'PublishedDate': '2024-09-18T08:15:05.24Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46776', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46776', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Run DC_LOG_DC after checking link->link_enc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Run DC_LOG_DC after checking link->link_enc\n\n[WHAT]\nThe DC_LOG_DC should be run after link->link_enc is checked, not before.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46776', 'https://git.kernel.org/linus/3a82f62b0d9d7687eac47603bb6cd14a50fa718b (6.11-rc1)', 'https://git.kernel.org/stable/c/3a82f62b0d9d7687eac47603bb6cd14a50fa718b', 'https://git.kernel.org/stable/c/874e3bb302f97b94ac548959ec4f925b8e7b45e2', 'https://git.kernel.org/stable/c/adc74d25cdbba978afbb57caec23bbcd0329f7b8', 'https://lore.kernel.org/linux-cve-announce/2024091848-CVE-2024-46776-7a95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46776', 'https://www.cve.org/CVERecord?id=CVE-2024-46776'], 'PublishedDate': '2024-09-18T08:15:05.287Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46777', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46777', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Avoid excessive partition lengths', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid excessive partition lengths\n\nAvoid mounting filesystems where the partition would overflow the\n32-bits used for block number. Also refuse to mount filesystems where\nthe partition length is so large we cannot safely index bits in a\nblock bitmap.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46777', 'https://git.kernel.org/linus/ebbe26fd54a9621994bc16b14f2ba8f84c089693 (6.11-rc1)', 'https://git.kernel.org/stable/c/0173999123082280cf904bd640015951f194a294', 'https://git.kernel.org/stable/c/1497a4484cdb2cf6c37960d788fb6ba67567bdb7', 'https://git.kernel.org/stable/c/2ddf831451357c6da4b64645eb797c93c1c054d1', 'https://git.kernel.org/stable/c/551966371e17912564bc387fbeb2ac13077c3db1', 'https://git.kernel.org/stable/c/925fd8ee80d5348a5e965548e5484d164d19221d', 'https://git.kernel.org/stable/c/a56330761950cb83de1dfb348479f20c56c95f90', 'https://git.kernel.org/stable/c/c0c23130d38e8bc28e9ef581443de9b1fc749966', 'https://git.kernel.org/stable/c/ebbe26fd54a9621994bc16b14f2ba8f84c089693', 'https://lore.kernel.org/linux-cve-announce/2024091848-CVE-2024-46777-6114@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46777', 'https://www.cve.org/CVERecord?id=CVE-2024-46777'], 'PublishedDate': '2024-09-18T08:15:05.33Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46778', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46778', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check UnboundedRequestEnabled's value', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check UnboundedRequestEnabled's value\n\nCalculateSwathAndDETConfiguration_params_st's UnboundedRequestEnabled\nis a pointer (i.e. dml_bool_t *UnboundedRequestEnabled), and thus\nif (p->UnboundedRequestEnabled) checks its address, not bool value.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46778', 'https://git.kernel.org/linus/a7b38c7852093385d0605aa3c8a2efd6edd1edfd (6.11-rc1)', 'https://git.kernel.org/stable/c/4e2b49a85e7974d21364798c5d4aa8070aa864d9', 'https://git.kernel.org/stable/c/a7b38c7852093385d0605aa3c8a2efd6edd1edfd', 'https://lore.kernel.org/linux-cve-announce/2024091848-CVE-2024-46778-ded6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46778', 'https://www.cve.org/CVERecord?id=CVE-2024-46778'], 'PublishedDate': '2024-09-18T08:15:05.38Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46779', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46779', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/imagination: Free pvr_vm_gpuva after unlink', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Free pvr_vm_gpuva after unlink\n\nThis caused a measurable memory leak. Although the individual\nallocations are small, the leaks occurs in a high-usage codepath\n(remapping or unmapping device memory) so they add up quickly.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46779', 'https://git.kernel.org/linus/3f6b2f60b4631cd0c368da6a1587ab55a696164d (6.11-rc7)', 'https://git.kernel.org/stable/c/1cc695be8920df234f83270d789078cb2d3bc564', 'https://git.kernel.org/stable/c/3f6b2f60b4631cd0c368da6a1587ab55a696164d', 'https://lore.kernel.org/linux-cve-announce/2024091849-CVE-2024-46779-3186@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46779', 'https://www.cve.org/CVERecord?id=CVE-2024-46779'], 'PublishedDate': '2024-09-18T08:15:05.43Z', 'LastModifiedDate': '2024-09-23T16:37:51.473Z'}, {'VulnerabilityID': 'CVE-2024-46780', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46780', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: protect references to superblock parameters exposed in sysfs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect references to superblock parameters exposed in sysfs\n\nThe superblock buffers of nilfs2 can not only be overwritten at runtime\nfor modifications/repairs, but they are also regularly swapped, replaced\nduring resizing, and even abandoned when degrading to one side due to\nbacking device issues. So, accessing them requires mutual exclusion using\nthe reader/writer semaphore "nilfs->ns_sem".\n\nSome sysfs attribute show methods read this superblock buffer without the\nnecessary mutual exclusion, which can cause problems with pointer\ndereferencing and memory access, so fix it.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46780', 'https://git.kernel.org/linus/683408258917541bdb294cd717c210a04381931e (6.11-rc7)', 'https://git.kernel.org/stable/c/157c0d94b4c40887329418c70ef4edd1a8d6b4ed', 'https://git.kernel.org/stable/c/19cfeba0e4b8eda51484fcf8cf7d150418e1d880', 'https://git.kernel.org/stable/c/683408258917541bdb294cd717c210a04381931e', 'https://git.kernel.org/stable/c/8c6e43b3d5f109cf9c61bc188fcc8175404e924f', 'https://git.kernel.org/stable/c/962562d4c70c5cdeb4e955d63ff2017c4eca1aad', 'https://git.kernel.org/stable/c/b14e7260bb691d7f563f61da07d61e3c8b59a614', 'https://git.kernel.org/stable/c/b90beafac05931cbfcb6b1bd4f67c1923f47040e', 'https://git.kernel.org/stable/c/ba97ba173f9625d5f34a986088979eae8b80d38e', 'https://lore.kernel.org/linux-cve-announce/2024091849-CVE-2024-46780-9155@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46780', 'https://www.cve.org/CVERecord?id=CVE-2024-46780'], 'PublishedDate': '2024-09-18T08:15:05.473Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46781', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46781', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: fix missing cleanup on rollforward recovery error', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix missing cleanup on rollforward recovery error\n\nIn an error injection test of a routine for mount-time recovery, KASAN\nfound a use-after-free bug.\n\nIt turned out that if data recovery was performed using partial logs\ncreated by dsync writes, but an error occurred before starting the log\nwriter to create a recovered checkpoint, the inodes whose data had been\nrecovered were left in the ns_dirty_files list of the nilfs object and\nwere not freed.\n\nFix this issue by cleaning up inodes that have read the recovery data if\nthe recovery routine fails midway before the log writer starts.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46781', 'https://git.kernel.org/linus/5787fcaab9eb5930f5378d6a1dd03d916d146622 (6.11-rc7)', 'https://git.kernel.org/stable/c/07e4dc2fe000ab008bcfe90be4324ef56b5b4355', 'https://git.kernel.org/stable/c/1cf1f7e8cd47244fa947d357ef1f642d91e219a3', 'https://git.kernel.org/stable/c/35a9a7a7d94662146396199b0cfd95f9517cdd14', 'https://git.kernel.org/stable/c/5787fcaab9eb5930f5378d6a1dd03d916d146622', 'https://git.kernel.org/stable/c/8e2d1e9d93c4ec51354229361ac3373058529ec4', 'https://git.kernel.org/stable/c/9d8c3a585d564d776ee60d4aabec59b404be7403', 'https://git.kernel.org/stable/c/ca92c4bff2833cb30d493b935168d6cccd5c805d', 'https://git.kernel.org/stable/c/da02f9eb333333b2e4f25d2a14967cff785ac82e', 'https://lore.kernel.org/linux-cve-announce/2024091850-CVE-2024-46781-377e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46781', 'https://www.cve.org/CVERecord?id=CVE-2024-46781'], 'PublishedDate': '2024-09-18T08:15:05.527Z', 'LastModifiedDate': '2024-09-23T16:37:07.117Z'}, {'VulnerabilityID': 'CVE-2024-46782', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46782', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ila: call nf_unregister_net_hooks() sooner', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nila: call nf_unregister_net_hooks() sooner\n\nsyzbot found an use-after-free Read in ila_nf_input [1]\n\nIssue here is that ila_xlat_exit_net() frees the rhashtable,\nthen call nf_unregister_net_hooks().\n\nIt should be done in the reverse way, with a synchronize_rcu().\n\nThis is a good match for a pre_exit() method.\n\n[1]\n BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline]\n BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672\nRead of size 4 at addr ffff888064620008 by task ksoftirqd/0/16\n\nCPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n __rhashtable_lookup include/linux/rhashtable.h:604 [inline]\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672\n ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:132 [inline]\n ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]\n ila_nf_input+0x1fe/0x3c0 net/ipv6/ila/ila_xlat.c:190\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626\n nf_hook include/linux/netfilter.h:269 [inline]\n NF_HOOK+0x29e/0x450 include/linux/netfilter.h:312\n __netif_receive_skb_one_core net/core/dev.c:5661 [inline]\n __netif_receive_skb+0x1ea/0x650 net/core/dev.c:5775\n process_backlog+0x662/0x15b0 net/core/dev.c:6108\n __napi_poll+0xcb/0x490 net/core/dev.c:6772\n napi_poll net/core/dev.c:6841 [inline]\n net_rx_action+0x89b/0x1240 net/core/dev.c:6963\n handle_softirqs+0x2c4/0x970 kernel/softirq.c:554\n run_ksoftirqd+0xca/0x130 kernel/softirq.c:928\n smpboot_thread_fn+0x544/0xa30 kernel/smpboot.c:164\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x64620\nflags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)\npage_type: 0xbfffffff(buddy)\nraw: 00fff00000000000 ffffea0000959608 ffffea00019d9408 0000000000000000\nraw: 0000000000000000 0000000000000003 00000000bfffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as freed\npage last allocated via order 3, migratetype Unmovable, gfp_mask 0x52dc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_ZERO), pid 5242, tgid 5242 (syz-executor), ts 73611328570, free_ts 618981657187\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x1f3/0x230 mm/page_alloc.c:1493\n prep_new_page mm/page_alloc.c:1501 [inline]\n get_page_from_freelist+0x2e4c/0x2f10 mm/page_alloc.c:3439\n __alloc_pages_noprof+0x256/0x6c0 mm/page_alloc.c:4695\n __alloc_pages_node_noprof include/linux/gfp.h:269 [inline]\n alloc_pages_node_noprof include/linux/gfp.h:296 [inline]\n ___kmalloc_large_node+0x8b/0x1d0 mm/slub.c:4103\n __kmalloc_large_node_noprof+0x1a/0x80 mm/slub.c:4130\n __do_kmalloc_node mm/slub.c:4146 [inline]\n __kmalloc_node_noprof+0x2d2/0x440 mm/slub.c:4164\n __kvmalloc_node_noprof+0x72/0x190 mm/util.c:650\n bucket_table_alloc lib/rhashtable.c:186 [inline]\n rhashtable_init_noprof+0x534/0xa60 lib/rhashtable.c:1071\n ila_xlat_init_net+0xa0/0x110 net/ipv6/ila/ila_xlat.c:613\n ops_ini\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46782', 'https://git.kernel.org/linus/031ae72825cef43e4650140b800ad58bf7a6a466 (6.11-rc7)', 'https://git.kernel.org/stable/c/031ae72825cef43e4650140b800ad58bf7a6a466', 'https://git.kernel.org/stable/c/18a5a16940464b301ea91bf5da3a324aedb347b2', 'https://git.kernel.org/stable/c/43d34110882b97ba1ec66cc8234b18983efb9abf', 'https://git.kernel.org/stable/c/47abd8adddbc0aecb8f231269ef659148d5dabe4', 'https://git.kernel.org/stable/c/925c18a7cff93d8a4320d652351294ff7d0ac93c', 'https://git.kernel.org/stable/c/93ee345ba349922834e6a9d1dadabaedcc12dce6', 'https://git.kernel.org/stable/c/bda4d84ac0d5421b346faee720011f58bdb99673', 'https://git.kernel.org/stable/c/dcaf4e2216824839d26727a15b638c6a677bd9fc', 'https://lore.kernel.org/linux-cve-announce/2024091850-CVE-2024-46782-00ff@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46782', 'https://www.cve.org/CVERecord?id=CVE-2024-46782'], 'PublishedDate': '2024-09-18T08:15:05.577Z', 'LastModifiedDate': '2024-09-23T16:32:04.373Z'}, {'VulnerabilityID': 'CVE-2024-46783', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46783', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp_bpf: fix return value of tcp_bpf_sendmsg()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_bpf: fix return value of tcp_bpf_sendmsg()\n\nWhen we cork messages in psock->cork, the last message triggers the\nflushing will result in sending a sk_msg larger than the current\nmessage size. In this case, in tcp_bpf_send_verdict(), 'copied' becomes\nnegative at least in the following case:\n\n468 case __SK_DROP:\n469 default:\n470 sk_msg_free_partial(sk, msg, tosend);\n471 sk_msg_apply_bytes(psock, tosend);\n472 *copied -= (tosend + delta); // <==== HERE\n473 return -EACCES;\n\nTherefore, it could lead to the following BUG with a proper value of\n'copied' (thanks to syzbot). We should not use negative 'copied' as a\nreturn value here.\n\n ------------[ cut here ]------------\n kernel BUG at net/socket.c:733!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 0 UID: 0 PID: 3265 Comm: syz-executor510 Not tainted 6.11.0-rc3-syzkaller-00060-gd07b43284ab3 #0\n Hardware name: linux,dummy-virt (DT)\n pstate: 61400009 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n pc : sock_sendmsg_nosec net/socket.c:733 [inline]\n pc : sock_sendmsg_nosec net/socket.c:728 [inline]\n pc : __sock_sendmsg+0x5c/0x60 net/socket.c:745\n lr : sock_sendmsg_nosec net/socket.c:730 [inline]\n lr : __sock_sendmsg+0x54/0x60 net/socket.c:745\n sp : ffff800088ea3b30\n x29: ffff800088ea3b30 x28: fbf00000062bc900 x27: 0000000000000000\n x26: ffff800088ea3bc0 x25: ffff800088ea3bc0 x24: 0000000000000000\n x23: f9f00000048dc000 x22: 0000000000000000 x21: ffff800088ea3d90\n x20: f9f00000048dc000 x19: ffff800088ea3d90 x18: 0000000000000001\n x17: 0000000000000000 x16: 0000000000000000 x15: 000000002002ffaf\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: ffff8000815849c0 x9 : ffff8000815b49c0\n x8 : 0000000000000000 x7 : 000000000000003f x6 : 0000000000000000\n x5 : 00000000000007e0 x4 : fff07ffffd239000 x3 : fbf00000062bc900\n x2 : 0000000000000000 x1 : 0000000000000000 x0 : 00000000fffffdef\n Call trace:\n sock_sendmsg_nosec net/socket.c:733 [inline]\n __sock_sendmsg+0x5c/0x60 net/socket.c:745\n ____sys_sendmsg+0x274/0x2ac net/socket.c:2597\n ___sys_sendmsg+0xac/0x100 net/socket.c:2651\n __sys_sendmsg+0x84/0xe0 net/socket.c:2680\n __do_sys_sendmsg net/socket.c:2689 [inline]\n __se_sys_sendmsg net/socket.c:2687 [inline]\n __arm64_sys_sendmsg+0x24/0x30 net/socket.c:2687\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x48/0x110 arch/arm64/kernel/syscall.c:49\n el0_svc_common.constprop.0+0x40/0xe0 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x1c/0x28 arch/arm64/kernel/syscall.c:151\n el0_svc+0x34/0xec arch/arm64/kernel/entry-common.c:712\n el0t_64_sync_handler+0x100/0x12c arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x19c/0x1a0 arch/arm64/kernel/entry.S:598\n Code: f9404463 d63f0060 3108441f 54fffe81 (d4210000)\n ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46783', 'https://git.kernel.org/linus/fe1910f9337bd46a9343967b547ccab26b4b2c6e (6.11-rc7)', 'https://git.kernel.org/stable/c/126d72b726c4cf1119f3a7fe413a78d341c3fea9', 'https://git.kernel.org/stable/c/3efe53eb221a38e207c1e3f81c51e4ca057d50c2', 'https://git.kernel.org/stable/c/6f9fdf5806cced888c43512bccbdf7fefd50f510', 'https://git.kernel.org/stable/c/78bb38d9c5a311c5f8bdef7c9557d7d81ca30e4a', 'https://git.kernel.org/stable/c/810a4e7d92dea4074cb04c25758320909d752193', 'https://git.kernel.org/stable/c/c8219a27fa43a2cbf99f5176f6dddfe73e7a24ae', 'https://git.kernel.org/stable/c/fe1910f9337bd46a9343967b547ccab26b4b2c6e', 'https://lore.kernel.org/linux-cve-announce/2024091850-CVE-2024-46783-edcb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46783', 'https://www.cve.org/CVERecord?id=CVE-2024-46783'], 'PublishedDate': '2024-09-18T08:15:05.63Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46784', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46784', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup\n\nCurrently napi_disable() gets called during rxq and txq cleanup,\neven before napi is enabled and hrtimer is initialized. It causes\nkernel panic.\n\n? page_fault_oops+0x136/0x2b0\n ? page_counter_cancel+0x2e/0x80\n ? do_user_addr_fault+0x2f2/0x640\n ? refill_obj_stock+0xc4/0x110\n ? exc_page_fault+0x71/0x160\n ? asm_exc_page_fault+0x27/0x30\n ? __mmdrop+0x10/0x180\n ? __mmdrop+0xec/0x180\n ? hrtimer_active+0xd/0x50\n hrtimer_try_to_cancel+0x2c/0xf0\n hrtimer_cancel+0x15/0x30\n napi_disable+0x65/0x90\n mana_destroy_rxq+0x4c/0x2f0\n mana_create_rxq.isra.0+0x56c/0x6d0\n ? mana_uncfg_vport+0x50/0x50\n mana_alloc_queues+0x21b/0x320\n ? skb_dequeue+0x5f/0x80", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46784', 'https://git.kernel.org/linus/b6ecc662037694488bfff7c9fd21c405df8411f2 (6.11-rc7)', 'https://git.kernel.org/stable/c/4982a47154f0b50de81ee0a0b169a3fc74120a65', 'https://git.kernel.org/stable/c/9178eb8ebcd887ab75e54ac40d538e54bb9c7788', 'https://git.kernel.org/stable/c/9e0bff4900b5d412a9bafe4baeaa6facd34f671c', 'https://git.kernel.org/stable/c/b6ecc662037694488bfff7c9fd21c405df8411f2', 'https://lore.kernel.org/linux-cve-announce/2024091851-CVE-2024-46784-4773@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46784', 'https://www.cve.org/CVERecord?id=CVE-2024-46784'], 'PublishedDate': '2024-09-18T08:15:05.683Z', 'LastModifiedDate': '2024-09-26T13:21:30.657Z'}, {'VulnerabilityID': 'CVE-2024-46785', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46785', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: eventfs: Use list_del_rcu() for SRCU protected list variable', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Use list_del_rcu() for SRCU protected list variable\n\nChi Zhiling reported:\n\n We found a null pointer accessing in tracefs[1], the reason is that the\n variable \'ei_child\' is set to LIST_POISON1, that means the list was\n removed in eventfs_remove_rec. so when access the ei_child->is_freed, the\n panic triggered.\n\n by the way, the following script can reproduce this panic\n\n loop1 (){\n while true\n do\n echo "p:kp submit_bio" > /sys/kernel/debug/tracing/kprobe_events\n echo "" > /sys/kernel/debug/tracing/kprobe_events\n done\n }\n loop2 (){\n while true\n do\n tree /sys/kernel/debug/tracing/events/kprobes/\n done\n }\n loop1 &\n loop2\n\n [1]:\n [ 1147.959632][T17331] Unable to handle kernel paging request at virtual address dead000000000150\n [ 1147.968239][T17331] Mem abort info:\n [ 1147.971739][T17331] ESR = 0x0000000096000004\n [ 1147.976172][T17331] EC = 0x25: DABT (current EL), IL = 32 bits\n [ 1147.982171][T17331] SET = 0, FnV = 0\n [ 1147.985906][T17331] EA = 0, S1PTW = 0\n [ 1147.989734][T17331] FSC = 0x04: level 0 translation fault\n [ 1147.995292][T17331] Data abort info:\n [ 1147.998858][T17331] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n [ 1148.005023][T17331] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n [ 1148.010759][T17331] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n [ 1148.016752][T17331] [dead000000000150] address between user and kernel address ranges\n [ 1148.024571][T17331] Internal error: Oops: 0000000096000004 [#1] SMP\n [ 1148.030825][T17331] Modules linked in: team_mode_loadbalance team nlmon act_gact cls_flower sch_ingress bonding tls macvlan dummy ib_core bridge stp llc veth amdgpu amdxcp mfd_core gpu_sched drm_exec drm_buddy radeon crct10dif_ce video drm_suballoc_helper ghash_ce drm_ttm_helper sha2_ce ttm sha256_arm64 i2c_algo_bit sha1_ce sbsa_gwdt cp210x drm_display_helper cec sr_mod cdrom drm_kms_helper binfmt_misc sg loop fuse drm dm_mod nfnetlink ip_tables autofs4 [last unloaded: tls]\n [ 1148.072808][T17331] CPU: 3 PID: 17331 Comm: ls Tainted: G W ------- ---- 6.6.43 #2\n [ 1148.081751][T17331] Source Version: 21b3b386e948bedd29369af66f3e98ab01b1c650\n [ 1148.088783][T17331] Hardware name: Greatwall GW-001M1A-FTF/GW-001M1A-FTF, BIOS KunLun BIOS V4.0 07/16/2020\n [ 1148.098419][T17331] pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 1148.106060][T17331] pc : eventfs_iterate+0x2c0/0x398\n [ 1148.111017][T17331] lr : eventfs_iterate+0x2fc/0x398\n [ 1148.115969][T17331] sp : ffff80008d56bbd0\n [ 1148.119964][T17331] x29: ffff80008d56bbf0 x28: ffff001ff5be2600 x27: 0000000000000000\n [ 1148.127781][T17331] x26: ffff001ff52ca4e0 x25: 0000000000009977 x24: dead000000000100\n [ 1148.135598][T17331] x23: 0000000000000000 x22: 000000000000000b x21: ffff800082645f10\n [ 1148.143415][T17331] x20: ffff001fddf87c70 x19: ffff80008d56bc90 x18: 0000000000000000\n [ 1148.151231][T17331] x17: 0000000000000000 x16: 0000000000000000 x15: ffff001ff52ca4e0\n [ 1148.159048][T17331] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 1148.166864][T17331] x11: 0000000000000000 x10: 0000000000000000 x9 : ffff8000804391d0\n [ 1148.174680][T17331] x8 : 0000000180000000 x7 : 0000000000000018 x6 : 0000aaab04b92862\n [ 1148.182498][T17331] x5 : 0000aaab04b92862 x4 : 0000000080000000 x3 : 0000000000000068\n [ 1148.190314][T17331] x2 : 000000000000000f x1 : 0000000000007ea8 x0 : 0000000000000001\n [ 1148.198131][T17331] Call trace:\n [ 1148.201259][T17331] eventfs_iterate+0x2c0/0x398\n [ 1148.205864][T17331] iterate_dir+0x98/0x188\n [ 1148.210036][T17331] __arm64_sys_getdents64+0x78/0x160\n [ 1148.215161][T17331] invoke_syscall+0x78/0x108\n [ 1148.219593][T17331] el0_svc_common.constprop.0+0x48/0xf0\n [ 1148.224977][T17331] do_el0_svc+0x24/0x38\n [ 1148.228974][T17331] el0_svc+0x40/0x168\n [ 1148.232798][T17\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46785', 'https://git.kernel.org/linus/d2603279c7d645bf0d11fa253b23f1ab48fc8d3c (6.11-rc7)', 'https://git.kernel.org/stable/c/05e08297c3c298d8ec28e5a5adb55840312dd87e', 'https://git.kernel.org/stable/c/d2603279c7d645bf0d11fa253b23f1ab48fc8d3c', 'https://git.kernel.org/stable/c/f579d17a86448779f9642ad8baca6e3036a8e2d6', 'https://lore.kernel.org/linux-cve-announce/2024091851-CVE-2024-46785-5351@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46785', 'https://www.cve.org/CVERecord?id=CVE-2024-46785'], 'PublishedDate': '2024-09-18T08:15:05.73Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46786', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46786', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF\n\nThe fscache_cookie_lru_timer is initialized when the fscache module\nis inserted, but is not deleted when the fscache module is removed.\nIf timer_reduce() is called before removing the fscache module,\nthe fscache_cookie_lru_timer will be added to the timer list of\nthe current cpu. Afterwards, a use-after-free will be triggered\nin the softIRQ after removing the fscache module, as follows:\n\n==================================================================\nBUG: unable to handle page fault for address: fffffbfff803c9e9\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 21ffea067 P4D 21ffea067 PUD 21ffe6067 PMD 110a7c067 PTE 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 1 UID: 0 PID: 0 Comm: swapper/1 Tainted: G W 6.11.0-rc3 #855\nTainted: [W]=WARN\nRIP: 0010:__run_timer_base.part.0+0x254/0x8a0\nCall Trace:\n \n tmigr_handle_remote_up+0x627/0x810\n __walk_groups.isra.0+0x47/0x140\n tmigr_handle_remote+0x1fa/0x2f0\n handle_softirqs+0x180/0x590\n irq_exit_rcu+0x84/0xb0\n sysvec_apic_timer_interrupt+0x6e/0x90\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20\nRIP: 0010:default_idle+0xf/0x20\n default_idle_call+0x38/0x60\n do_idle+0x2b5/0x300\n cpu_startup_entry+0x54/0x60\n start_secondary+0x20d/0x280\n common_startup_64+0x13e/0x148\n \nModules linked in: [last unloaded: netfs]\n==================================================================\n\nTherefore delete fscache_cookie_lru_timer when removing the fscahe module.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46786', 'https://git.kernel.org/linus/72a6e22c604c95ddb3b10b5d3bb85b6ff4dbc34f (6.11-rc7)', 'https://git.kernel.org/stable/c/0a11262549ac2ac6fb98c7cd40a67136817e5a52', 'https://git.kernel.org/stable/c/72a6e22c604c95ddb3b10b5d3bb85b6ff4dbc34f', 'https://git.kernel.org/stable/c/e0d724932ad12e3528f4ce97fc0f6078d0cce4bc', 'https://lore.kernel.org/linux-cve-announce/2024091851-CVE-2024-46786-a167@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46786', 'https://www.cve.org/CVERecord?id=CVE-2024-46786'], 'PublishedDate': '2024-09-18T08:15:05.783Z', 'LastModifiedDate': '2024-09-26T12:48:37.447Z'}, {'VulnerabilityID': 'CVE-2024-46787', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46787', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: userfaultfd: fix checks for huge PMDs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: fix checks for huge PMDs\n\nPatch series "userfaultfd: fix races around pmd_trans_huge() check", v2.\n\nThe pmd_trans_huge() code in mfill_atomic() is wrong in three different\nways depending on kernel version:\n\n1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit\n the right two race windows) - I\'ve tested this in a kernel build with\n some extra mdelay() calls. See the commit message for a description\n of the race scenario.\n On older kernels (before 6.5), I think the same bug can even\n theoretically lead to accessing transhuge page contents as a page table\n if you hit the right 5 narrow race windows (I haven\'t tested this case).\n2. As pointed out by Qi Zheng, pmd_trans_huge() is not sufficient for\n detecting PMDs that don\'t point to page tables.\n On older kernels (before 6.5), you\'d just have to win a single fairly\n wide race to hit this.\n I\'ve tested this on 6.1 stable by racing migration (with a mdelay()\n patched into try_to_migrate()) against UFFDIO_ZEROPAGE - on my x86\n VM, that causes a kernel oops in ptlock_ptr().\n3. On newer kernels (>=6.5), for shmem mappings, khugepaged is allowed\n to yank page tables out from under us (though I haven\'t tested that),\n so I think the BUG_ON() checks in mfill_atomic() are just wrong.\n\nI decided to write two separate fixes for these (one fix for bugs 1+2, one\nfix for bug 3), so that the first fix can be backported to kernels\naffected by bugs 1+2.\n\n\nThis patch (of 2):\n\nThis fixes two issues.\n\nI discovered that the following race can occur:\n\n mfill_atomic other thread\n ============ ============\n \n pmdp_get_lockless() [reads none pmd]\n \n \n \n __pte_alloc [no-op]\n \n \n BUG_ON(pmd_none(*dst_pmd))\n\nI have experimentally verified this in a kernel with extra mdelay() calls;\nthe BUG_ON(pmd_none(*dst_pmd)) triggers.\n\nOn kernels newer than commit 0d940a9b270b ("mm/pgtable: allow\npte_offset_map[_lock]() to fail"), this can\'t lead to anything worse than\na BUG_ON(), since the page table access helpers are actually designed to\ndeal with page tables concurrently disappearing; but on older kernels\n(<=6.4), I think we could probably theoretically race past the two\nBUG_ON() checks and end up treating a hugepage as a page table.\n\nThe second issue is that, as Qi Zheng pointed out, there are other types\nof huge PMDs that pmd_trans_huge() can\'t catch: devmap PMDs and swap PMDs\n(in particular, migration PMDs).\n\nOn <=6.4, this is worse than the first issue: If mfill_atomic() runs on a\nPMD that contains a migration entry (which just requires winning a single,\nfairly wide race), it will pass the PMD to pte_offset_map_lock(), which\nassumes that the PMD points to a page table.\n\nBreakage follows: First, the kernel tries to take the PTE lock (which will\ncrash or maybe worse if there is no "struct page" for the address bits in\nthe migration entry PMD - I think at least on X86 there usually is no\ncorresponding "struct page" thanks to the PTE inversion mitigation, amd64\nlooks different).\n\nIf that didn\'t crash, the kernel would next try to write a PTE into what\nit wrongly thinks is a page table.\n\nAs part of fixing these issues, get rid of the check for pmd_trans_huge()\nbefore __pte_alloc() - that\'s redundant, we\'re going to have to check for\nthat after the __pte_alloc() anyway.\n\nBackport note: pmdp_get_lockless() is pmd_read_atomic() in older kernels.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46787', 'https://git.kernel.org/linus/71c186efc1b2cf1aeabfeff3b9bd5ac4c5ac14d8 (6.11-rc7)', 'https://git.kernel.org/stable/c/3c6b4bcf37845c9359aed926324bed66bdd2448d', 'https://git.kernel.org/stable/c/71c186efc1b2cf1aeabfeff3b9bd5ac4c5ac14d8', 'https://git.kernel.org/stable/c/98cc18b1b71e23fe81a5194ed432b20c2d81a01a', 'https://lore.kernel.org/linux-cve-announce/2024091852-CVE-2024-46787-8b6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46787', 'https://www.cve.org/CVERecord?id=CVE-2024-46787'], 'PublishedDate': '2024-09-18T08:15:05.833Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46788', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46788', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing/osnoise: Use a cpumask to know what threads are kthreads', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Use a cpumask to know what threads are kthreads\n\nThe start_kthread() and stop_thread() code was not always called with the\ninterface_lock held. This means that the kthread variable could be\nunexpectedly changed causing the kthread_stop() to be called on it when it\nshould not have been, leading to:\n\n while true; do\n rtla timerlat top -u -q & PID=$!;\n sleep 5;\n kill -INT $PID;\n sleep 0.001;\n kill -TERM $PID;\n wait $PID;\n done\n\nCausing the following OOPS:\n\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n CPU: 5 UID: 0 PID: 885 Comm: timerlatu/5 Not tainted 6.11.0-rc4-test-00002-gbc754cc76d1b-dirty #125 a533010b71dab205ad2f507188ce8c82203b0254\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n RIP: 0010:hrtimer_active+0x58/0x300\n Code: 48 c1 ee 03 41 54 48 01 d1 48 01 d6 55 53 48 83 ec 20 80 39 00 0f 85 30 02 00 00 49 8b 6f 30 4c 8d 75 10 4c 89 f0 48 c1 e8 03 <0f> b6 3c 10 4c 89 f0 83 e0 07 83 c0 03 40 38 f8 7c 09 40 84 ff 0f\n RSP: 0018:ffff88811d97f940 EFLAGS: 00010202\n RAX: 0000000000000002 RBX: ffff88823c6b5b28 RCX: ffffed10478d6b6b\n RDX: dffffc0000000000 RSI: ffffed10478d6b6c RDI: ffff88823c6b5b28\n RBP: 0000000000000000 R08: ffff88823c6b5b58 R09: ffff88823c6b5b60\n R10: ffff88811d97f957 R11: 0000000000000010 R12: 00000000000a801d\n R13: ffff88810d8b35d8 R14: 0000000000000010 R15: ffff88823c6b5b28\n FS: 0000000000000000(0000) GS:ffff88823c680000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000561858ad7258 CR3: 000000007729e001 CR4: 0000000000170ef0\n Call Trace:\n \n ? die_addr+0x40/0xa0\n ? exc_general_protection+0x154/0x230\n ? asm_exc_general_protection+0x26/0x30\n ? hrtimer_active+0x58/0x300\n ? __pfx_mutex_lock+0x10/0x10\n ? __pfx_locks_remove_file+0x10/0x10\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x8e/0x1f0\n ? security_file_release+0x43/0x80\n __fput+0x372/0xb10\n task_work_run+0x11e/0x1f0\n ? _raw_spin_lock+0x85/0xe0\n ? __pfx_task_work_run+0x10/0x10\n ? poison_slab_object+0x109/0x170\n ? do_exit+0x7a0/0x24b0\n do_exit+0x7bd/0x24b0\n ? __pfx_migrate_enable+0x10/0x10\n ? __pfx_do_exit+0x10/0x10\n ? __pfx_read_tsc+0x10/0x10\n ? ktime_get+0x64/0x140\n ? _raw_spin_lock_irq+0x86/0xe0\n do_group_exit+0xb0/0x220\n get_signal+0x17ba/0x1b50\n ? vfs_read+0x179/0xa40\n ? timerlat_fd_read+0x30b/0x9d0\n ? __pfx_get_signal+0x10/0x10\n ? __pfx_timerlat_fd_read+0x10/0x10\n arch_do_signal_or_restart+0x8c/0x570\n ? __pfx_arch_do_signal_or_restart+0x10/0x10\n ? vfs_read+0x179/0xa40\n ? ksys_read+0xfe/0x1d0\n ? __pfx_ksys_read+0x10/0x10\n syscall_exit_to_user_mode+0xbc/0x130\n do_syscall_64+0x74/0x110\n ? __pfx___rseq_handle_notify_resume+0x10/0x10\n ? __pfx_ksys_read+0x10/0x10\n ? fpregs_restore_userregs+0xdb/0x1e0\n ? fpregs_restore_userregs+0xdb/0x1e0\n ? syscall_exit_to_user_mode+0x116/0x130\n ? do_syscall_64+0x74/0x110\n ? do_syscall_64+0x74/0x110\n ? do_syscall_64+0x74/0x110\n entry_SYSCALL_64_after_hwframe+0x71/0x79\n RIP: 0033:0x7ff0070eca9c\n Code: Unable to access opcode bytes at 0x7ff0070eca72.\n RSP: 002b:00007ff006dff8c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n RAX: 0000000000000000 RBX: 0000000000000005 RCX: 00007ff0070eca9c\n RDX: 0000000000000400 RSI: 00007ff006dff9a0 RDI: 0000000000000003\n RBP: 00007ff006dffde0 R08: 0000000000000000 R09: 00007ff000000ba0\n R10: 00007ff007004b08 R11: 0000000000000246 R12: 0000000000000003\n R13: 00007ff006dff9a0 R14: 0000000000000007 R15: 0000000000000008\n \n Modules linked in: snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hwdep snd_hda_core\n ---[ end trace 0000000000000000 ]---\n\nThis is because it would mistakenly call kthread_stop() on a user space\nthread making it "exit" before it actually exits.\n\nSince kthread\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46788', 'https://git.kernel.org/linus/177e1cc2f41235c145041eed03ef5bab18f32328 (6.11-rc7)', 'https://git.kernel.org/stable/c/177e1cc2f41235c145041eed03ef5bab18f32328', 'https://git.kernel.org/stable/c/27282d2505b402f39371fd60d19d95c01a4b6776', 'https://git.kernel.org/stable/c/7a5f01828edf152c144d27cf63de446fdf2dc222', 'https://lore.kernel.org/linux-cve-announce/2024091852-CVE-2024-46788-1fbc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46788', 'https://www.cve.org/CVERecord?id=CVE-2024-46788'], 'PublishedDate': '2024-09-18T08:15:05.893Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46791', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46791', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: can: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open\n\nThe mcp251x_hw_wake() function is called with the mpc_lock mutex held and\ndisables the interrupt handler so that no interrupts can be processed while\nwaking the device. If an interrupt has already occurred then waiting for\nthe interrupt handler to complete will deadlock because it will be trying\nto acquire the same mutex.\n\nCPU0 CPU1\n---- ----\nmcp251x_open()\n mutex_lock(&priv->mcp_lock)\n request_threaded_irq()\n \n mcp251x_can_ist()\n mutex_lock(&priv->mcp_lock)\n mcp251x_hw_wake()\n disable_irq() <-- deadlock\n\nUse disable_irq_nosync() instead because the interrupt handler does\neverything while holding the mutex so it doesn't matter if it's still\nrunning.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46791', 'https://git.kernel.org/linus/7dd9c26bd6cf679bcfdef01a8659791aa6487a29 (6.11-rc7)', 'https://git.kernel.org/stable/c/3a49b6b1caf5cefc05264d29079d52c99cb188e0', 'https://git.kernel.org/stable/c/513c8fc189b52f7922e36bdca58997482b198f0e', 'https://git.kernel.org/stable/c/7dd9c26bd6cf679bcfdef01a8659791aa6487a29', 'https://git.kernel.org/stable/c/8fecde9c3f9a4b97b68bb97c9f47e5b662586ba7', 'https://git.kernel.org/stable/c/e554113a1cd2a9cfc6c7af7bdea2141c5757e188', 'https://git.kernel.org/stable/c/f7ab9e14b23a3eac6714bdc4dba244d8aa1ef646', 'https://lore.kernel.org/linux-cve-announce/2024091853-CVE-2024-46791-af66@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46791', 'https://www.cve.org/CVERecord?id=CVE-2024-46791'], 'PublishedDate': '2024-09-18T08:15:06.067Z', 'LastModifiedDate': '2024-09-20T18:21:19.457Z'}, {'VulnerabilityID': 'CVE-2024-46792', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46792', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv: misaligned: Restrict user access to kernel memory', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: misaligned: Restrict user access to kernel memory\n\nraw_copy_{to,from}_user() do not call access_ok(), so this code allowed\nuserspace to access any virtual memory address.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46792', 'https://git.kernel.org/linus/b686ecdeacf6658e1348c1a32a08e2e72f7c0f00 (6.11-rc7)', 'https://git.kernel.org/stable/c/a3b6ff6c896aee5ef9b581e40d0045ff04fcbc8c', 'https://git.kernel.org/stable/c/b686ecdeacf6658e1348c1a32a08e2e72f7c0f00', 'https://lore.kernel.org/linux-cve-announce/2024091854-CVE-2024-46792-7745@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46792', 'https://www.cve.org/CVERecord?id=CVE-2024-46792'], 'PublishedDate': '2024-09-18T08:15:06.123Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46793', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46793', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: Intel: Boards: Fix NULL pointer deref in BYT/CHT boards harder', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: Boards: Fix NULL pointer deref in BYT/CHT boards harder\n\nSince commit 13f58267cda3 ("ASoC: soc.h: don\'t create dummy Component\nvia COMP_DUMMY()") dummy codecs declared like this:\n\nSND_SOC_DAILINK_DEF(dummy,\n DAILINK_COMP_ARRAY(COMP_DUMMY()));\n\nexpand to:\n\nstatic struct snd_soc_dai_link_component dummy[] = {\n};\n\nWhich means that dummy is a zero sized array and thus dais[i].codecs should\nnot be dereferenced *at all* since it points to the address of the next\nvariable stored in the data section as the "dummy" variable has an address\nbut no size, so even dereferencing dais[0] is already an out of bounds\narray reference.\n\nWhich means that the if (dais[i].codecs->name) check added in\ncommit 7d99a70b6595 ("ASoC: Intel: Boards: Fix NULL pointer deref\nin BYT/CHT boards") relies on that the part of the next variable which\nthe name member maps to just happens to be NULL.\n\nWhich apparently so far it usually is, except when it isn\'t\nand then it results in crashes like this one:\n\n[ 28.795659] BUG: unable to handle page fault for address: 0000000000030011\n...\n[ 28.795780] Call Trace:\n[ 28.795787] \n...\n[ 28.795862] ? strcmp+0x18/0x40\n[ 28.795872] 0xffffffffc150c605\n[ 28.795887] platform_probe+0x40/0xa0\n...\n[ 28.795979] ? __pfx_init_module+0x10/0x10 [snd_soc_sst_bytcr_wm5102]\n\nReally fix things this time around by checking dais.num_codecs != 0.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46793', 'https://git.kernel.org/linus/0cc65482f5b03ac2b1c240bc34665e43ea2d71bb (6.11-rc7)', 'https://git.kernel.org/stable/c/0cc65482f5b03ac2b1c240bc34665e43ea2d71bb', 'https://git.kernel.org/stable/c/85cda5b040bda9c577b34eb72d5b2e5b7e31985c', 'https://lore.kernel.org/linux-cve-announce/2024091854-CVE-2024-46793-268d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46793', 'https://www.cve.org/CVERecord?id=CVE-2024-46793'], 'PublishedDate': '2024-09-18T08:15:06.177Z', 'LastModifiedDate': '2024-09-24T16:00:17.977Z'}, {'VulnerabilityID': 'CVE-2024-46794', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46794', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/tdx: Fix data leak in mmio_read()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Fix data leak in mmio_read()\n\nThe mmio_read() function makes a TDVMCALL to retrieve MMIO data for an\naddress from the VMM.\n\nSean noticed that mmio_read() unintentionally exposes the value of an\ninitialized variable (val) on the stack to the VMM.\n\nThis variable is only needed as an output value. It did not need to be\npassed to the VMM in the first place.\n\nDo not send the original value of *val to the VMM.\n\n[ dhansen: clarify what 'val' is used for. ]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46794', 'https://git.kernel.org/linus/b6fb565a2d15277896583d471b21bc14a0c99661 (6.11-rc7)', 'https://git.kernel.org/stable/c/26c6af49d26ffc377e392e30d4086db19eed0ef7', 'https://git.kernel.org/stable/c/b55ce742afcb8e8189d82f2f1e635ba1b5a461fa', 'https://git.kernel.org/stable/c/b6fb565a2d15277896583d471b21bc14a0c99661', 'https://git.kernel.org/stable/c/ef00818c50cf55a3a56bd9a9fae867c92dfb84e7', 'https://lore.kernel.org/linux-cve-announce/2024091854-CVE-2024-46794-9f64@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46794', 'https://www.cve.org/CVERecord?id=CVE-2024-46794'], 'PublishedDate': '2024-09-18T08:15:06.23Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46795', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46795', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ksmbd: unset the binding mark of a reused connection', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: unset the binding mark of a reused connection\n\nSteve French reported null pointer dereference error from sha256 lib.\ncifs.ko can send session setup requests on reused connection.\nIf reused connection is used for binding session, conn->binding can\nstill remain true and generate_preauth_hash() will not set\nsess->Preauth_HashValue and it will be NULL.\nIt is used as a material to create an encryption key in\nksmbd_gen_smb311_encryptionkey. ->Preauth_HashValue cause null pointer\ndereference error from crypto_shash_update().\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n#PF: supervisor read access in kernel mode\n#PF: error_code(0x0000) - not-present page\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 8 PID: 429254 Comm: kworker/8:39\nHardware name: LENOVO 20MAS08500/20MAS08500, BIOS N2CET69W (1.52 )\nWorkqueue: ksmbd-io handle_ksmbd_work [ksmbd]\nRIP: 0010:lib_sha256_base_do_update.isra.0+0x11e/0x1d0 [sha256_ssse3]\n\n? show_regs+0x6d/0x80\n? __die+0x24/0x80\n? page_fault_oops+0x99/0x1b0\n? do_user_addr_fault+0x2ee/0x6b0\n? exc_page_fault+0x83/0x1b0\n? asm_exc_page_fault+0x27/0x30\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n? lib_sha256_base_do_update.isra.0+0x11e/0x1d0 [sha256_ssse3]\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n_sha256_update+0x77/0xa0 [sha256_ssse3]\nsha256_avx2_update+0x15/0x30 [sha256_ssse3]\ncrypto_shash_update+0x1e/0x40\nhmac_update+0x12/0x20\ncrypto_shash_update+0x1e/0x40\ngenerate_key+0x234/0x380 [ksmbd]\ngenerate_smb3encryptionkey+0x40/0x1c0 [ksmbd]\nksmbd_gen_smb311_encryptionkey+0x72/0xa0 [ksmbd]\nntlm_authenticate.isra.0+0x423/0x5d0 [ksmbd]\nsmb2_sess_setup+0x952/0xaa0 [ksmbd]\n__process_request+0xa3/0x1d0 [ksmbd]\n__handle_ksmbd_work+0x1c4/0x2f0 [ksmbd]\nhandle_ksmbd_work+0x2d/0xa0 [ksmbd]\nprocess_one_work+0x16c/0x350\nworker_thread+0x306/0x440\n? __pfx_worker_thread+0x10/0x10\nkthread+0xef/0x120\n? __pfx_kthread+0x10/0x10\nret_from_fork+0x44/0x70\n? __pfx_kthread+0x10/0x10\nret_from_fork_asm+0x1b/0x30\n', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46795', 'https://git.kernel.org/linus/78c5a6f1f630172b19af4912e755e1da93ef0ab5 (6.11-rc7)', 'https://git.kernel.org/stable/c/41bc256da7e47b679df87c7fc7a5b393052b9cce', 'https://git.kernel.org/stable/c/4c8496f44f5bb5c06cdef5eb130ab259643392a1', 'https://git.kernel.org/stable/c/78c5a6f1f630172b19af4912e755e1da93ef0ab5', 'https://git.kernel.org/stable/c/93d54a4b59c4b3d803d20aa645ab5ca71f3b3b02', 'https://git.kernel.org/stable/c/9914f1bd61d5e838bb1ab15a71076d37a6db65d1', 'https://lore.kernel.org/linux-cve-announce/2024091855-CVE-2024-46795-9908@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46795', 'https://www.cve.org/CVERecord?id=CVE-2024-46795'], 'PublishedDate': '2024-09-18T08:15:06.28Z', 'LastModifiedDate': '2024-09-20T18:21:04.067Z'}, {'VulnerabilityID': 'CVE-2024-46797', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46797', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/qspinlock: Fix deadlock in MCS queue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/qspinlock: Fix deadlock in MCS queue\n\nIf an interrupt occurs in queued_spin_lock_slowpath() after we increment\nqnodesp->count and before node->lock is initialized, another CPU might\nsee stale lock values in get_tail_qnode(). If the stale lock value happens\nto match the lock on that CPU, then we write to the "next" pointer of\nthe wrong qnode. This causes a deadlock as the former CPU, once it becomes\nthe head of the MCS queue, will spin indefinitely until it\'s "next" pointer\nis set by its successor in the queue.\n\nRunning stress-ng on a 16 core (16EC/16VP) shared LPAR, results in\noccasional lockups similar to the following:\n\n $ stress-ng --all 128 --vm-bytes 80% --aggressive \\\n --maximize --oomable --verify --syslog \\\n --metrics --times --timeout 5m\n\n watchdog: CPU 15 Hard LOCKUP\n ......\n NIP [c0000000000b78f4] queued_spin_lock_slowpath+0x1184/0x1490\n LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90\n Call Trace:\n 0xc000002cfffa3bf0 (unreliable)\n _raw_spin_lock+0x6c/0x90\n raw_spin_rq_lock_nested.part.135+0x4c/0xd0\n sched_ttwu_pending+0x60/0x1f0\n __flush_smp_call_function_queue+0x1dc/0x670\n smp_ipi_demux_relaxed+0xa4/0x100\n xive_muxed_ipi_action+0x20/0x40\n __handle_irq_event_percpu+0x80/0x240\n handle_irq_event_percpu+0x2c/0x80\n handle_percpu_irq+0x84/0xd0\n generic_handle_irq+0x54/0x80\n __do_irq+0xac/0x210\n __do_IRQ+0x74/0xd0\n 0x0\n do_IRQ+0x8c/0x170\n hardware_interrupt_common_virt+0x29c/0x2a0\n --- interrupt: 500 at queued_spin_lock_slowpath+0x4b8/0x1490\n ......\n NIP [c0000000000b6c28] queued_spin_lock_slowpath+0x4b8/0x1490\n LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90\n --- interrupt: 500\n 0xc0000029c1a41d00 (unreliable)\n _raw_spin_lock+0x6c/0x90\n futex_wake+0x100/0x260\n do_futex+0x21c/0x2a0\n sys_futex+0x98/0x270\n system_call_exception+0x14c/0x2f0\n system_call_vectored_common+0x15c/0x2ec\n\nThe following code flow illustrates how the deadlock occurs.\nFor the sake of brevity, assume that both locks (A and B) are\ncontended and we call the queued_spin_lock_slowpath() function.\n\n CPU0 CPU1\n ---- ----\n spin_lock_irqsave(A) |\n spin_unlock_irqrestore(A) |\n spin_lock(B) |\n | |\n ▼ |\n id = qnodesp->count++; |\n (Note that nodes[0].lock == A) |\n | |\n ▼ |\n Interrupt |\n (happens before "nodes[0].lock = B") |\n | |\n ▼ |\n spin_lock_irqsave(A) |\n | |\n ▼ |\n id = qnodesp->count++ |\n nodes[1].lock = A |\n | |\n ▼ |\n Tail of MCS queue |\n | spin_lock_irqsave(A)\n ▼ |\n Head of MCS queue ▼\n | CPU0 is previous tail\n ▼ |\n Spin indefinitely ▼\n (until "nodes[1].next != NULL") prev = get_tail_qnode(A, CPU0)\n |\n ▼\n prev == &qnodes[CPU0].nodes[0]\n (as qnodes\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46797', 'https://git.kernel.org/linus/734ad0af3609464f8f93e00b6c0de1e112f44559 (6.11-rc7)', 'https://git.kernel.org/stable/c/734ad0af3609464f8f93e00b6c0de1e112f44559', 'https://git.kernel.org/stable/c/d84ab6661e8d09092de9b034b016515ef9b66085', 'https://git.kernel.org/stable/c/f06af737e4be28c0e926dc25d5f0a111da4e2987', 'https://lore.kernel.org/linux-cve-announce/2024091856-CVE-2024-46797-9174@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46797', 'https://www.cve.org/CVERecord?id=CVE-2024-46797'], 'PublishedDate': '2024-09-18T08:15:06.403Z', 'LastModifiedDate': '2024-09-29T15:15:15.837Z'}, {'VulnerabilityID': 'CVE-2024-46798', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46798', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: Fix UAF for snd_soc_pcm_runtime object\n\nWhen using kernel with the following extra config,\n\n - CONFIG_KASAN=y\n - CONFIG_KASAN_GENERIC=y\n - CONFIG_KASAN_INLINE=y\n - CONFIG_KASAN_VMALLOC=y\n - CONFIG_FRAME_WARN=4096\n\nkernel detects that snd_pcm_suspend_all() access a freed\n'snd_soc_pcm_runtime' object when the system is suspended, which\nleads to a use-after-free bug:\n\n[ 52.047746] BUG: KASAN: use-after-free in snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047765] Read of size 1 at addr ffff0000b9434d50 by task systemd-sleep/2330\n\n[ 52.047785] Call trace:\n[ 52.047787] dump_backtrace+0x0/0x3c0\n[ 52.047794] show_stack+0x34/0x50\n[ 52.047797] dump_stack_lvl+0x68/0x8c\n[ 52.047802] print_address_description.constprop.0+0x74/0x2c0\n[ 52.047809] kasan_report+0x210/0x230\n[ 52.047815] __asan_report_load1_noabort+0x3c/0x50\n[ 52.047820] snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047824] snd_soc_suspend+0x19c/0x4e0\n\nThe snd_pcm_sync_stop() has a NULL check on 'substream->runtime' before\nmaking any access. So we need to always set 'substream->runtime' to NULL\neverytime we kfree() it.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46798', 'https://git.kernel.org/linus/b4a90b543d9f62d3ac34ec1ab97fc5334b048565 (6.11-rc7)', 'https://git.kernel.org/stable/c/3033ed903b4f28b5e1ab66042084fbc2c48f8624', 'https://git.kernel.org/stable/c/5d13afd021eb43868fe03cef6da34ad08831ad6d', 'https://git.kernel.org/stable/c/6a14fad8be178df6c4589667efec1789a3307b4e', 'https://git.kernel.org/stable/c/8ca21e7a27c66b95a4b215edc8e45e5d66679f9f', 'https://git.kernel.org/stable/c/993b60c7f93fa1d8ff296b58f646a867e945ae89', 'https://git.kernel.org/stable/c/b4a90b543d9f62d3ac34ec1ab97fc5334b048565', 'https://git.kernel.org/stable/c/fe5046ca91d631ec432eee3bdb1f1c49b09c8b5e', 'https://lore.kernel.org/linux-cve-announce/2024091856-CVE-2024-46798-ce16@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46798', 'https://www.cve.org/CVERecord?id=CVE-2024-46798'], 'PublishedDate': '2024-09-18T08:15:06.463Z', 'LastModifiedDate': '2024-09-20T18:17:50.763Z'}, {'VulnerabilityID': 'CVE-2024-46800', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46800', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sch/netem: fix use after free in netem_dequeue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsch/netem: fix use after free in netem_dequeue\n\nIf netem_dequeue() enqueues packet to inner qdisc and that qdisc\nreturns __NET_XMIT_STOLEN. The packet is dropped but\nqdisc_tree_reduce_backlog() is not called to update the parent\'s\nq.qlen, leading to the similar use-after-free as Commit\ne04991a48dbaf382 ("netem: fix return value if duplicate enqueue\nfails")\n\nCommands to trigger KASAN UaF:\n\nip link add type dummy\nip link set lo up\nip link set dummy0 up\ntc qdisc add dev lo parent root handle 1: drr\ntc filter add dev lo parent 1: basic classid 1:1\ntc class add dev lo classid 1:1 drr\ntc qdisc add dev lo parent 1:1 handle 2: netem\ntc qdisc add dev lo parent 2: handle 3: drr\ntc filter add dev lo parent 3: basic classid 3:1 action mirred egress\nredirect dev dummy0\ntc class add dev lo classid 3:1 drr\nping -c1 -W0.01 localhost # Trigger bug\ntc class del dev lo classid 1:1\ntc class add dev lo classid 1:1 drr\nping -c1 -W0.01 localhost # UaF', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46800', 'https://git.kernel.org/linus/3b3a2a9c6349e25a025d2330f479bc33a6ccb54a (6.11-rc7)', 'https://git.kernel.org/stable/c/14f91ab8d391f249b845916820a56f42cf747241', 'https://git.kernel.org/stable/c/295ad5afd9efc5f67b86c64fce28fb94e26dc4c9', 'https://git.kernel.org/stable/c/32008ab989ddcff1a485fa2b4906234c25dc5cd6', 'https://git.kernel.org/stable/c/3b3a2a9c6349e25a025d2330f479bc33a6ccb54a', 'https://git.kernel.org/stable/c/98c75d76187944296068d685dfd8a1e9fd8c4fdc', 'https://git.kernel.org/stable/c/db2c235682913a63054e741fe4e19645fdf2d68e', 'https://git.kernel.org/stable/c/dde33a9d0b80aae0c69594d1f462515d7ff1cb3d', 'https://git.kernel.org/stable/c/f0bddb4de043399f16d1969dad5ee5b984a64e7b', 'https://lore.kernel.org/linux-cve-announce/2024091857-CVE-2024-46800-0f62@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46800', 'https://www.cve.org/CVERecord?id=CVE-2024-46800'], 'PublishedDate': '2024-09-18T08:15:06.573Z', 'LastModifiedDate': '2024-09-20T17:18:55.26Z'}, {'VulnerabilityID': 'CVE-2024-46802', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46802', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: added NULL check at start of dc_validate_stream', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: added NULL check at start of dc_validate_stream\n\n[Why]\nprevent invalid memory access\n\n[How]\ncheck if dc and stream are NULL', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46802', 'https://git.kernel.org/linus/26c56049cc4f1705b498df013949427692a4b0d5 (6.11-rc1)', 'https://git.kernel.org/stable/c/154a50bf4221a6a6ccf88d565b8184da7c40a2dd', 'https://git.kernel.org/stable/c/26c56049cc4f1705b498df013949427692a4b0d5', 'https://git.kernel.org/stable/c/356fcce9cdbfe338a275e9e1836adfdd7f5c52a9', 'https://git.kernel.org/stable/c/6bf920193ba1853bad780bba565a789246d9003c', 'https://lore.kernel.org/linux-cve-announce/2024092706-CVE-2024-46802-c5e1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46802', 'https://www.cve.org/CVERecord?id=CVE-2024-46802'], 'PublishedDate': '2024-09-27T13:15:13.483Z', 'LastModifiedDate': '2024-10-07T14:21:55.687Z'}, {'VulnerabilityID': 'CVE-2024-46803', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46803', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdkfd: Check debug trap enable before write dbg_ev_file', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check debug trap enable before write dbg_ev_file\n\nIn interrupt context, write dbg_ev_file will be run by work queue. It\nwill cause write dbg_ev_file execution after debug_trap_disable, which\nwill cause NULL pointer access.\nv2: cancel work "debug_event_workarea" before set dbg_ev_file as NULL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46803', 'https://git.kernel.org/linus/547033b593063eb85bfdf9b25a5f1b8fd1911be2 (6.11-rc1)', 'https://git.kernel.org/stable/c/547033b593063eb85bfdf9b25a5f1b8fd1911be2', 'https://git.kernel.org/stable/c/820dcbd38a77bd5fdc4236d521c1c122841227d0', 'https://git.kernel.org/stable/c/e6ea3b8fe398915338147fe54dd2db8155fdafd8', 'https://lore.kernel.org/linux-cve-announce/2024092708-CVE-2024-46803-689b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46803', 'https://www.cve.org/CVERecord?id=CVE-2024-46803'], 'PublishedDate': '2024-09-27T13:15:13.57Z', 'LastModifiedDate': '2024-10-04T17:45:16.867Z'}, {'VulnerabilityID': 'CVE-2024-46804', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46804', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add array index check for hdcp ddc access', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add array index check for hdcp ddc access\n\n[Why]\nCoverity reports OVERRUN warning. Do not check if array\nindex valid.\n\n[How]\nCheck msg_id valid and valid array index.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46804', 'https://git.kernel.org/linus/4e70c0f5251c25885c31ee84a31f99a01f7cf50e (6.11-rc1)', 'https://git.kernel.org/stable/c/0ee4387c5a4b57ec733c3fb4365188d5979cd9c7', 'https://git.kernel.org/stable/c/2a63c90c7a90ab2bd23deebc2814fc5b52abf6d2', 'https://git.kernel.org/stable/c/4e70c0f5251c25885c31ee84a31f99a01f7cf50e', 'https://git.kernel.org/stable/c/8b5ccf3d011969417be653b5a145c72dbd30472c', 'https://git.kernel.org/stable/c/a3b5ee22a9d3a30045191da5678ca8451ebaea30', 'https://git.kernel.org/stable/c/f338f99f6a04d03c802087d82a83561cbd5bdc99', 'https://lore.kernel.org/linux-cve-announce/2024092708-CVE-2024-46804-c90d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46804', 'https://www.cve.org/CVERecord?id=CVE-2024-46804'], 'PublishedDate': '2024-09-27T13:15:13.637Z', 'LastModifiedDate': '2024-10-04T17:51:43.73Z'}, {'VulnerabilityID': 'CVE-2024-46805', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46805', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix the waring dereferencing hive', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix the waring dereferencing hive\n\nCheck the amdgpu_hive_info *hive that maybe is NULL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46805', 'https://git.kernel.org/linus/1940708ccf5aff76de4e0b399f99267c93a89193 (6.11-rc1)', 'https://git.kernel.org/stable/c/01cd55b971131b07b7ff8d622fa93bb4f8be07df', 'https://git.kernel.org/stable/c/1940708ccf5aff76de4e0b399f99267c93a89193', 'https://git.kernel.org/stable/c/4ab720b6aa1ef5e71db1e534b5b45c80ac4ec58a', 'https://git.kernel.org/stable/c/d3f927ef0607b3c8c3f79ab6d9a4ebead3e35f4c', 'https://git.kernel.org/stable/c/f20d1d5cbb39802f68be24458861094f3e66f356', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46805-b06a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46805', 'https://www.cve.org/CVERecord?id=CVE-2024-46805'], 'PublishedDate': '2024-09-27T13:15:13.707Z', 'LastModifiedDate': '2024-10-02T12:58:59.767Z'}, {'VulnerabilityID': 'CVE-2024-46806', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46806', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix the warning division or modulo by zero', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the warning division or modulo by zero\n\nChecks the partition mode and returns an error for an invalid mode.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46806', 'https://git.kernel.org/linus/1a00f2ac82d6bc6689388c7edcd2a4bd82664f3c (6.11-rc1)', 'https://git.kernel.org/stable/c/1a00f2ac82d6bc6689388c7edcd2a4bd82664f3c', 'https://git.kernel.org/stable/c/a01618adcba78c6bd6c4557a4a5e32f58b658cd1', 'https://git.kernel.org/stable/c/d116bb921e8b104f45d1f30a473ea99ef4262b9a', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46806-2cc7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46806', 'https://www.cve.org/CVERecord?id=CVE-2024-46806'], 'PublishedDate': '2024-09-27T13:15:13.773Z', 'LastModifiedDate': '2024-10-02T13:17:04.64Z'}, {'VulnerabilityID': 'CVE-2024-46807', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46807', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/amdgpu: Check tbo resource pointer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/amdgpu: Check tbo resource pointer\n\nValidate tbo resource pointer, skip if NULL', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46807', 'https://git.kernel.org/linus/6cd2b872643bb29bba01a8ac739138db7bd79007 (6.11-rc1)', 'https://git.kernel.org/stable/c/2be1eb6304d9623ba21dd6f3e68ffb753a759635', 'https://git.kernel.org/stable/c/4dfec5f5501a27e0a0da00e136d65ef9011ded4c', 'https://git.kernel.org/stable/c/6cd2b872643bb29bba01a8ac739138db7bd79007', 'https://git.kernel.org/stable/c/e55e3904ffeaff81715256a711b1a61f4ad5258a', 'https://git.kernel.org/stable/c/e8765364d4f3aaf88c7abe0a4fc99089d059ab49', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46807-b78e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46807', 'https://www.cve.org/CVERecord?id=CVE-2024-46807'], 'PublishedDate': '2024-09-27T13:15:13.84Z', 'LastModifiedDate': '2024-10-04T17:40:08.083Z'}, {'VulnerabilityID': 'CVE-2024-46808', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46808', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range\n\n[Why & How]\nASSERT if return NULL from kcalloc.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46808', 'https://git.kernel.org/linus/5524fa301ba649f8cf00848f91468e0ba7e4f24c (6.11-rc1)', 'https://git.kernel.org/stable/c/5524fa301ba649f8cf00848f91468e0ba7e4f24c', 'https://git.kernel.org/stable/c/ca0b0b0a22306f2e51105ac48f4a09c2fbbb504e', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46808-8886@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46808', 'https://www.cve.org/CVERecord?id=CVE-2024-46808'], 'PublishedDate': '2024-09-27T13:15:13.907Z', 'LastModifiedDate': '2024-10-02T14:23:39.863Z'}, {'VulnerabilityID': 'CVE-2024-46809', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46809', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check BIOS images before it is used', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check BIOS images before it is used\n\nBIOS images may fail to load and null checks are added before they are\nused.\n\nThis fixes 6 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46809', 'https://git.kernel.org/linus/8b0ddf19cca2a352b2a7e01d99d3ba949a99c84c (6.11-rc1)', 'https://git.kernel.org/stable/c/8b0ddf19cca2a352b2a7e01d99d3ba949a99c84c', 'https://git.kernel.org/stable/c/e46b70a7cfed71cb84e985c785c39c16df5c28cb', 'https://git.kernel.org/stable/c/e50bec62acaeec03afc6fa5dfb2426e52d049cf5', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46809-5b37@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46809', 'https://www.cve.org/CVERecord?id=CVE-2024-46809'], 'PublishedDate': '2024-09-27T13:15:13.973Z', 'LastModifiedDate': '2024-10-04T17:33:33.753Z'}, {'VulnerabilityID': 'CVE-2024-46810', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46810', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ\n\nMake sure the connector is fully initialized before signalling any\nHPD events via drm_kms_helper_hotplug_event(), otherwise this may\nlead to NULL pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46810', 'https://git.kernel.org/linus/162e48cb1d84c2c966b649b8ac5c9d4f75f6d44f (6.11-rc1)', 'https://git.kernel.org/stable/c/162e48cb1d84c2c966b649b8ac5c9d4f75f6d44f', 'https://git.kernel.org/stable/c/1fb13693953737783b424aa4712f0a27a9eaf5a8', 'https://git.kernel.org/stable/c/9d567126474e68f959b2c2543c375f3bb32e948a', 'https://git.kernel.org/stable/c/adc5674c23b8191e596ed0dbaa9600265ac896a8', 'https://git.kernel.org/stable/c/e1b121f21bbc56a6ae035aa5b77daac62bfb9be5', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46810-2eb3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46810', 'https://www.cve.org/CVERecord?id=CVE-2024-46810'], 'PublishedDate': '2024-09-27T13:15:14.037Z', 'LastModifiedDate': '2024-10-04T17:43:04.277Z'}, {'VulnerabilityID': 'CVE-2024-46811', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46811', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box\n\n[Why]\nCoverity reports OVERRUN warning. soc.num_states could\nbe 40. But array range of bw_params->clk_table.entries is 8.\n\n[How]\nAssert if soc.num_states greater than 8.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46811', 'https://git.kernel.org/linus/188fd1616ec43033cedbe343b6579e9921e2d898 (6.11-rc1)', 'https://git.kernel.org/stable/c/188fd1616ec43033cedbe343b6579e9921e2d898', 'https://git.kernel.org/stable/c/4003bac784380fed1f94f197350567eaa73a409d', 'https://git.kernel.org/stable/c/aba188d6f4ebaf52acf13f204db2bd2c22072504', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46811-f01c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46811', 'https://www.cve.org/CVERecord?id=CVE-2024-46811'], 'PublishedDate': '2024-09-27T13:15:14.107Z', 'LastModifiedDate': '2024-10-07T14:24:56.86Z'}, {'VulnerabilityID': 'CVE-2024-46812', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46812', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration\n\n[Why]\nCoverity reports Memory - illegal accesses.\n\n[How]\nSkip inactive planes.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46812', 'https://git.kernel.org/linus/a54f7e866cc73a4cb71b8b24bb568ba35c8969df (6.11-rc1)', 'https://git.kernel.org/stable/c/3300a039caf850376bc3416c808cd8879da412bb', 'https://git.kernel.org/stable/c/8406158a546441b73f0b216aedacbf9a1e5748fb', 'https://git.kernel.org/stable/c/a54f7e866cc73a4cb71b8b24bb568ba35c8969df', 'https://git.kernel.org/stable/c/ee9d6df6d9172917d9ddbd948bb882652d5ecd29', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46812-5954@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46812', 'https://www.cve.org/CVERecord?id=CVE-2024-46812'], 'PublishedDate': '2024-09-27T13:15:14.163Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46813', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46813', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check link_index before accessing dc->links[]', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check link_index before accessing dc->links[]\n\n[WHY & HOW]\ndc->links[] has max size of MAX_LINKS and NULL is return when trying to\naccess with out-of-bound index.\n\nThis fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46813', 'https://git.kernel.org/linus/8aa2864044b9d13e95fe224f32e808afbf79ecdf (6.11-rc1)', 'https://git.kernel.org/stable/c/8aa2864044b9d13e95fe224f32e808afbf79ecdf', 'https://git.kernel.org/stable/c/ac04759b4a002969cf0f1384f1b8bb2001cfa782', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46813-5eb9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46813', 'https://www.cve.org/CVERecord?id=CVE-2024-46813'], 'PublishedDate': '2024-09-27T13:15:14.23Z', 'LastModifiedDate': '2024-10-04T17:38:17.74Z'}, {'VulnerabilityID': 'CVE-2024-46814', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46814', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check msg_id before processing transcation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check msg_id before processing transcation\n\n[WHY & HOW]\nHDCP_MESSAGE_ID_INVALID (-1) is not a valid msg_id nor is it a valid\narray index, and it needs checking before used.\n\nThis fixes 4 OVERRUN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46814', 'https://git.kernel.org/linus/fa71face755e27dc44bc296416ebdf2c67163316 (6.11-rc1)', 'https://git.kernel.org/stable/c/0147505f08220c89b3a9c90eb608191276e263a8', 'https://git.kernel.org/stable/c/6590643c5de74098d27933b7d224d5ac065d7755', 'https://git.kernel.org/stable/c/916083054670060023d3f8a8ace895d710e268f4', 'https://git.kernel.org/stable/c/cb63090a17d3abb87f132851fa3711281249b7d2', 'https://git.kernel.org/stable/c/fa71face755e27dc44bc296416ebdf2c67163316', 'https://git.kernel.org/stable/c/fe63daf7b10253b0faaa60c55d6153cd276927aa', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46814-5021@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46814', 'https://www.cve.org/CVERecord?id=CVE-2024-46814'], 'PublishedDate': '2024-09-27T13:15:14.297Z', 'LastModifiedDate': '2024-10-04T17:27:47.45Z'}, {'VulnerabilityID': 'CVE-2024-46815', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46815', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]\n\n[WHY & HOW]\nnum_valid_sets needs to be checked to avoid a negative index when\naccessing reader_wm_sets[num_valid_sets - 1].\n\nThis fixes an OVERRUN issue reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46815', 'https://git.kernel.org/linus/b38a4815f79b87efb196cd5121579fc51e29a7fb (6.11-rc1)', 'https://git.kernel.org/stable/c/21f9cb44f8c60bf6c26487d428b1a09ad3e8aebf', 'https://git.kernel.org/stable/c/6a4a08e45e614cfa7a56498cdfaeb7fae2f07fa0', 'https://git.kernel.org/stable/c/7c47dd2e92341f2989ab73dbed07f8894593ad7b', 'https://git.kernel.org/stable/c/a72d4996409569027b4609414a14a87679b12267', 'https://git.kernel.org/stable/c/b36e9b3104c4ba0f2f5dd083dcf6159cb316c996', 'https://git.kernel.org/stable/c/b38a4815f79b87efb196cd5121579fc51e29a7fb', 'https://git.kernel.org/stable/c/c4a7f7c0062fe2c73f70bb7e335199e25bd71492', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46815-fce2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46815', 'https://www.cve.org/CVERecord?id=CVE-2024-46815'], 'PublishedDate': '2024-09-27T13:15:14.37Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46816', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46816', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links\n\n[Why]\nCoverity report OVERRUN warning. There are\nonly max_links elements within dc->links. link\ncount could up to AMDGPU_DM_MAX_DISPLAY_INDEX 31.\n\n[How]\nMake sure link count less than max_links.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46816', 'https://git.kernel.org/linus/cf8b16857db702ceb8d52f9219a4613363e2b1cf (6.11-rc1)', 'https://git.kernel.org/stable/c/36c39a8dcce210649f2f45f252abaa09fcc1ae87', 'https://git.kernel.org/stable/c/cf8b16857db702ceb8d52f9219a4613363e2b1cf', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46816-0526@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46816', 'https://www.cve.org/CVERecord?id=CVE-2024-46816'], 'PublishedDate': '2024-09-27T13:15:14.433Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46817', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46817', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6\n\n[Why]\nCoverity reports OVERRUN warning. Should abort amdgpu_dm\ninitialize.\n\n[How]\nReturn failure to amdgpu_dm_init.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46817', 'https://git.kernel.org/linus/84723eb6068c50610c5c0893980d230d7afa2105 (6.11-rc1)', 'https://git.kernel.org/stable/c/21bbb39863f10f5fb4bf772d15b07d5d13590e9d', 'https://git.kernel.org/stable/c/28b515c458aa9c92bfcb99884c94713a5f471cea', 'https://git.kernel.org/stable/c/754321ed63f0a4a31252ca72e0bd89a9e1888018', 'https://git.kernel.org/stable/c/84723eb6068c50610c5c0893980d230d7afa2105', 'https://git.kernel.org/stable/c/94cb77700fa4ae6200486bfa0ba2ac547534afd2', 'https://git.kernel.org/stable/c/d398c74c881dee695f6eb6138c9891644e1c3d9d', 'https://git.kernel.org/stable/c/d619b91d3c4af60ac422f1763ce53d721fb91262', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46817-7a2c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46817', 'https://www.cve.org/CVERecord?id=CVE-2024-46817'], 'PublishedDate': '2024-09-27T13:15:14.493Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46818', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46818', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check gpio_id before used as array index', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check gpio_id before used as array index\n\n[WHY & HOW]\nGPIO_ID_UNKNOWN (-1) is not a valid value for array index and therefore\nshould be checked in advance.\n\nThis fixes 5 OVERRUN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46818', 'https://git.kernel.org/linus/2a5626eeb3b5eec7a36886f9556113dd93ec8ed6 (6.11-rc1)', 'https://git.kernel.org/stable/c/0184cca30cad74d88f5c875d4e26999e26325700', 'https://git.kernel.org/stable/c/08e7755f754e3d2cef7d3a7da538d33526bd6f7c', 'https://git.kernel.org/stable/c/276e3fd93e3beb5894eb1cc8480f9f417d51524d', 'https://git.kernel.org/stable/c/2a5626eeb3b5eec7a36886f9556113dd93ec8ed6', 'https://git.kernel.org/stable/c/3d4198ab612ad48f73383ad3bb5663e6f0cdf406', 'https://git.kernel.org/stable/c/40c2e8bc117cab8bca8814735f28a8b121654a84', 'https://git.kernel.org/stable/c/8520fdc8ecc38f240a8e9e7af89cca6739c3e790', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46818-8d41@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46818', 'https://www.cve.org/CVERecord?id=CVE-2024-46818'], 'PublishedDate': '2024-09-27T13:15:14.563Z', 'LastModifiedDate': '2024-10-04T17:18:36.613Z'}, {'VulnerabilityID': 'CVE-2024-46819', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46819', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: the warning dereferencing obj for nbio_v7_4', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: the warning dereferencing obj for nbio_v7_4\n\nif ras_manager obj null, don't print NBIO err data", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46819', 'https://git.kernel.org/linus/d190b459b2a4304307c3468ed97477b808381011 (6.11-rc1)', 'https://git.kernel.org/stable/c/130c2dc75c8c40acc3c96ededea6af80e03c14b8', 'https://git.kernel.org/stable/c/614564a5b28983de53b23a358ebe6c483a2aa21e', 'https://git.kernel.org/stable/c/70e8ec21fcb8c51446899d3bfe416b31adfa3661', 'https://git.kernel.org/stable/c/7d265772e44d403071a2b573eac0db60250b1c21', 'https://git.kernel.org/stable/c/d04ded1e73f1dcf19a71ec8b9cda3faa7acd8828', 'https://git.kernel.org/stable/c/d190b459b2a4304307c3468ed97477b808381011', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46819-d958@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46819', 'https://www.cve.org/CVERecord?id=CVE-2024-46819'], 'PublishedDate': '2024-09-27T13:15:14.64Z', 'LastModifiedDate': '2024-10-04T17:11:00.57Z'}, {'VulnerabilityID': 'CVE-2024-46820', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46820', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/vcn: remove irq disabling in vcn 5 suspend', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: remove irq disabling in vcn 5 suspend\n\nWe do not directly enable/disable VCN IRQ in vcn 5.0.0.\nAnd we do not handle the IRQ state as well. So the calls to\ndisable IRQ and set state are removed. This effectively gets\nrid of the warining of\n "WARN_ON(!amdgpu_irq_enabled(adev, src, type))"\nin amdgpu_irq_put().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46820', 'https://git.kernel.org/linus/10fe1a79cd1bff3048e13120e93c02f8ecd05e9d (6.11-rc1)', 'https://git.kernel.org/stable/c/10fe1a79cd1bff3048e13120e93c02f8ecd05e9d', 'https://git.kernel.org/stable/c/aa92264ba6fd4fb570002f69762634221316e7ae', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46820-6405@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46820', 'https://www.cve.org/CVERecord?id=CVE-2024-46820'], 'PublishedDate': '2024-09-27T13:15:14.707Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46821', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46821', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: Fix negative array index read', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Fix negative array index read\n\nAvoid using the negative values\nfor clk_idex as an index into an array pptable->DpmDescriptor.\n\nV2: fix clk_index return check (Tim Huang)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46821', 'https://git.kernel.org/linus/c8c19ebf7c0b202a6a2d37a52ca112432723db5f (6.11-rc1)', 'https://git.kernel.org/stable/c/06a3810010b525b9958424e344f0c25b09e128fa', 'https://git.kernel.org/stable/c/4711b1347cb9f0c3083da6d87c624d75f9bd1d50', 'https://git.kernel.org/stable/c/60f4a4bc3329e5cb8c4df0cc961f0d5ffd96e22d', 'https://git.kernel.org/stable/c/c8c19ebf7c0b202a6a2d37a52ca112432723db5f', 'https://lore.kernel.org/linux-cve-announce/2024092713-CVE-2024-46821-a13a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46821', 'https://www.cve.org/CVERecord?id=CVE-2024-46821'], 'PublishedDate': '2024-09-27T13:15:14.767Z', 'LastModifiedDate': '2024-10-04T17:06:43.573Z'}, {'VulnerabilityID': 'CVE-2024-46822', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46822', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry\n\nIn a review discussion of the changes to support vCPU hotplug where\na check was added on the GICC being enabled if was online, it was\nnoted that there is need to map back to the cpu and use that to index\ninto a cpumask. As such, a valid ID is needed.\n\nIf an MPIDR check fails in acpi_map_gic_cpu_interface() it is possible\nfor the entry in cpu_madt_gicc[cpu] == NULL. This function would\nthen cause a NULL pointer dereference. Whilst a path to trigger\nthis has not been established, harden this caller against the\npossibility.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46822', 'https://git.kernel.org/linus/2488444274c70038eb6b686cba5f1ce48ebb9cdd (6.11-rc1)', 'https://git.kernel.org/stable/c/2488444274c70038eb6b686cba5f1ce48ebb9cdd', 'https://git.kernel.org/stable/c/40cae0df42e5e7f7a1c0f32deed9c4027c1ba94e', 'https://git.kernel.org/stable/c/4c3b21204abb4fa3ab310fbbb5cf7f0e85f3a1bc', 'https://git.kernel.org/stable/c/62ca6d3a905b4c40cd942f3cc645a6718f8bc7e7', 'https://git.kernel.org/stable/c/945be49f4e832a9184c313fdf8917475438a795b', 'https://git.kernel.org/stable/c/bc7fbb37e3d2df59336eadbd6a56be632e3c7df7', 'https://git.kernel.org/stable/c/f57769ff6fa7f97f1296965f20e8a2bb3ee9fd0f', 'https://lore.kernel.org/linux-cve-announce/2024092749-CVE-2024-46822-b901@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46822', 'https://www.cve.org/CVERecord?id=CVE-2024-46822'], 'PublishedDate': '2024-09-27T13:15:14.83Z', 'LastModifiedDate': '2024-10-02T14:24:01.757Z'}, {'VulnerabilityID': 'CVE-2024-46823', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46823', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kunit/overflow: Fix UB in overflow_allocation_test', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit/overflow: Fix UB in overflow_allocation_test\n\nThe 'device_name' array doesn't exist out of the\n'overflow_allocation_test' function scope. However, it is being used as\na driver name when calling 'kunit_driver_create' from\n'kunit_device_register'. It produces the kernel panic with KASAN\nenabled.\n\nSince this variable is used in one place only, remove it and pass the\ndevice name into kunit_device_register directly as an ascii string.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46823', 'https://git.kernel.org/linus/92e9bac18124682c4b99ede9ee3bcdd68f121e92 (6.11-rc4)', 'https://git.kernel.org/stable/c/92e9bac18124682c4b99ede9ee3bcdd68f121e92', 'https://git.kernel.org/stable/c/d1207f07decc66546a7fa463d2f335a856c986ef', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46823-b19e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46823', 'https://www.cve.org/CVERecord?id=CVE-2024-46823'], 'PublishedDate': '2024-09-27T13:15:14.897Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46824', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46824', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iommufd: Require drivers to supply the cache_invalidate_user ops', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Require drivers to supply the cache_invalidate_user ops\n\nIf drivers don't do this then iommufd will oops invalidation ioctls with\nsomething like:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Mem abort info:\n ESR = 0x0000000086000004\n EC = 0x21: IABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\n user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101059000\n [0000000000000000] pgd=0000000000000000, p4d=0000000000000000\n Internal error: Oops: 0000000086000004 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 2 PID: 371 Comm: qemu-system-aar Not tainted 6.8.0-rc7-gde77230ac23a #9\n Hardware name: linux,dummy-virt (DT)\n pstate: 81400809 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=-c)\n pc : 0x0\n lr : iommufd_hwpt_invalidate+0xa4/0x204\n sp : ffff800080f3bcc0\n x29: ffff800080f3bcf0 x28: ffff0000c369b300 x27: 0000000000000000\n x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n x23: 0000000000000000 x22: 00000000c1e334a0 x21: ffff0000c1e334a0\n x20: ffff800080f3bd38 x19: ffff800080f3bd58 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 0000ffff8240d6d8\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n x8 : 0000001000000002 x7 : 0000fffeac1ec950 x6 : 0000000000000000\n x5 : ffff800080f3bd78 x4 : 0000000000000003 x3 : 0000000000000002\n x2 : 0000000000000000 x1 : ffff800080f3bcc8 x0 : ffff0000c6034d80\n Call trace:\n 0x0\n iommufd_fops_ioctl+0x154/0x274\n __arm64_sys_ioctl+0xac/0xf0\n invoke_syscall+0x48/0x110\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x34/0xb4\n el0t_64_sync_handler+0x120/0x12c\n el0t_64_sync+0x190/0x194\n\nAll existing drivers implement this op for nesting, this is mostly a\nbisection aid.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46824', 'https://git.kernel.org/linus/a11dda723c6493bb1853bbc61c093377f96e2d47 (6.11-rc1)', 'https://git.kernel.org/stable/c/89827a4de802765b1ebb401fc1e73a90108c7520', 'https://git.kernel.org/stable/c/a11dda723c6493bb1853bbc61c093377f96e2d47', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46824-03d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46824', 'https://www.cve.org/CVERecord?id=CVE-2024-46824'], 'PublishedDate': '2024-09-27T13:15:14.96Z', 'LastModifiedDate': '2024-10-02T14:29:08.417Z'}, {'VulnerabilityID': 'CVE-2024-46825', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46825', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check\n\nThe lookup function iwl_mvm_rcu_fw_link_id_to_link_conf() is\nnormally called with input from the firmware, so it should use\nIWL_FW_CHECK() instead of WARN_ON().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46825', 'https://git.kernel.org/linus/9215152677d4b321801a92b06f6d5248b2b4465f (6.11-rc1)', 'https://git.kernel.org/stable/c/3cca098c91391b3fa48142bfda57048b985c87f6', 'https://git.kernel.org/stable/c/415f3634d53c7fb4cf07d2f5a0be7f2e15e6da33', 'https://git.kernel.org/stable/c/9215152677d4b321801a92b06f6d5248b2b4465f', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46825-a5aa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46825', 'https://www.cve.org/CVERecord?id=CVE-2024-46825'], 'PublishedDate': '2024-09-27T13:15:15.027Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46826', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46826', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ELF: fix kernel.randomize_va_space double read', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nELF: fix kernel.randomize_va_space double read\n\nELF loader uses "randomize_va_space" twice. It is sysctl and can change\nat any moment, so 2 loads could see 2 different values in theory with\nunpredictable consequences.\n\nIssue exactly one load for consistent value across one exec.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46826', 'https://git.kernel.org/linus/2a97388a807b6ab5538aa8f8537b2463c6988bd2 (6.11-rc1)', 'https://git.kernel.org/stable/c/1cf8cd80903073440b6ea055811d04edd24fe4f7', 'https://git.kernel.org/stable/c/1f81d51141a234ad0a3874b4d185dc27a521cd27', 'https://git.kernel.org/stable/c/2a97388a807b6ab5538aa8f8537b2463c6988bd2', 'https://git.kernel.org/stable/c/53f17409abf61f66b6f05aff795e938e5ba811d1', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46826-7b80@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46826', 'https://www.cve.org/CVERecord?id=CVE-2024-46826'], 'PublishedDate': '2024-09-27T13:15:15.087Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46827', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46827', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: fix firmware crash due to invalid peer nss', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix firmware crash due to invalid peer nss\n\nCurrently, if the access point receives an association\nrequest containing an Extended HE Capabilities Information\nElement with an invalid MCS-NSS, it triggers a firmware\ncrash.\n\nThis issue arises when EHT-PHY capabilities shows support\nfor a bandwidth and MCS-NSS set for that particular\nbandwidth is filled by zeros and due to this, driver obtains\npeer_nss as 0 and sending this value to firmware causes\ncrash.\n\nAddress this issue by implementing a validation step for\nthe peer_nss value before passing it to the firmware. If\nthe value is greater than zero, proceed with forwarding\nit to the firmware. However, if the value is invalid,\nreject the association request to prevent potential\nfirmware crashes.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46827', 'https://git.kernel.org/linus/db163a463bb93cd3e37e1e7b10b9726fb6f95857 (6.11-rc1)', 'https://git.kernel.org/stable/c/25a15f80253a7c8776e4e4880d797d20ec864154', 'https://git.kernel.org/stable/c/838c2cfdb6be7d7d8c06c711edf893eb34ca2e7c', 'https://git.kernel.org/stable/c/db163a463bb93cd3e37e1e7b10b9726fb6f95857', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46827-0300@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46827', 'https://www.cve.org/CVERecord?id=CVE-2024-46827'], 'PublishedDate': '2024-09-27T13:15:15.153Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46828', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46828', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched: sch_cake: fix bulk flow accounting logic for host fairness', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsched: sch_cake: fix bulk flow accounting logic for host fairness\n\nIn sch_cake, we keep track of the count of active bulk flows per host,\nwhen running in dst/src host fairness mode, which is used as the\nround-robin weight when iterating through flows. The count of active\nbulk flows is updated whenever a flow changes state.\n\nThis has a peculiar interaction with the hash collision handling: when a\nhash collision occurs (after the set-associative hashing), the state of\nthe hash bucket is simply updated to match the new packet that collided,\nand if host fairness is enabled, that also means assigning new per-host\nstate to the flow. For this reason, the bulk flow counters of the\nhost(s) assigned to the flow are decremented, before new state is\nassigned (and the counters, which may not belong to the same host\nanymore, are incremented again).\n\nBack when this code was introduced, the host fairness mode was always\nenabled, so the decrement was unconditional. When the configuration\nflags were introduced the *increment* was made conditional, but\nthe *decrement* was not. Which of course can lead to a spurious\ndecrement (and associated wrap-around to U16_MAX).\n\nAFAICT, when host fairness is disabled, the decrement and wrap-around\nhappens as soon as a hash collision occurs (which is not that common in\nitself, due to the set-associative hashing). However, in most cases this\nis harmless, as the value is only used when host fairness mode is\nenabled. So in order to trigger an array overflow, sch_cake has to first\nbe configured with host fairness disabled, and while running in this\nmode, a hash collision has to occur to cause the overflow. Then, the\nqdisc has to be reconfigured to enable host fairness, which leads to the\narray out-of-bounds because the wrapped-around value is retained and\nused as an array index. It seems that syzbot managed to trigger this,\nwhich is quite impressive in its own right.\n\nThis patch fixes the issue by introducing the same conditional check on\ndecrement as is used on increment.\n\nThe original bug predates the upstreaming of cake, but the commit listed\nin the Fixes tag touched that code, meaning that this patch won't apply\nbefore that.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46828', 'https://git.kernel.org/linus/546ea84d07e3e324644025e2aae2d12ea4c5896e (6.11-rc7)', 'https://git.kernel.org/stable/c/4a4eeefa514db570be025ab46d779af180e2c9bb', 'https://git.kernel.org/stable/c/546ea84d07e3e324644025e2aae2d12ea4c5896e', 'https://git.kernel.org/stable/c/549e407569e08459d16122341d332cb508024094', 'https://git.kernel.org/stable/c/7725152b54d295b7da5e34c2f419539b30d017bd', 'https://git.kernel.org/stable/c/cde71a5677971f4f1b69b25e854891dbe78066a4', 'https://git.kernel.org/stable/c/d4a9039a7b3d8005b90c7b1a55a306444f0e5447', 'https://git.kernel.org/stable/c/d7c01c0714c04431b5e18cf17a9ea68a553d1c3c', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46828-2184@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46828', 'https://www.cve.org/CVERecord?id=CVE-2024-46828'], 'PublishedDate': '2024-09-27T13:15:15.22Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46829', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46829', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: rtmutex: Drop rt_mutex::wait_lock before scheduling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Drop rt_mutex::wait_lock before scheduling\n\nrt_mutex_handle_deadlock() is called with rt_mutex::wait_lock held. In the\ngood case it returns with the lock held and in the deadlock case it emits a\nwarning and goes into an endless scheduling loop with the lock held, which\ntriggers the 'scheduling in atomic' warning.\n\nUnlock rt_mutex::wait_lock in the dead lock case before issuing the warning\nand dropping into the schedule for ever loop.\n\n[ tglx: Moved unlock before the WARN(), removed the pointless comment,\n \tmassaged changelog, added Fixes tag ]", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46829', 'https://git.kernel.org/linus/d33d26036a0274b472299d7dcdaa5fb34329f91b (6.11-rc7)', 'https://git.kernel.org/stable/c/1401da1486dc1cdbef6025fd74a3977df3a3e5d0', 'https://git.kernel.org/stable/c/432efdbe7da5ecfcbc0c2180cfdbab1441752a38', 'https://git.kernel.org/stable/c/6a976e9a47e8e5b326de671811561cab12e6fb1f', 'https://git.kernel.org/stable/c/85f03ca98e07cd0786738b56ae73740bce0ac27f', 'https://git.kernel.org/stable/c/93f44655472d9cd418293d328f9d141ca234ad83', 'https://git.kernel.org/stable/c/a92d81c9efec9280681c27a2c0a963fd0f1338e0', 'https://git.kernel.org/stable/c/d33d26036a0274b472299d7dcdaa5fb34329f91b', 'https://git.kernel.org/stable/c/f13b5afc5c4889569d84c3011ce449f61fccfb28', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46829-da70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46829', 'https://www.cve.org/CVERecord?id=CVE-2024-46829'], 'PublishedDate': '2024-09-27T13:15:15.3Z', 'LastModifiedDate': '2024-10-02T14:27:57.92Z'}, {'VulnerabilityID': 'CVE-2024-46830', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46830', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS\n\nGrab kvm->srcu when processing KVM_SET_VCPU_EVENTS, as KVM will forcibly\nleave nested VMX/SVM if SMM mode is being toggled, and leaving nested VMX\nreads guest memory.\n\nNote, kvm_vcpu_ioctl_x86_set_vcpu_events() can also be called from KVM_RUN\nvia sync_regs(), which already holds SRCU. I.e. trying to precisely use\nkvm_vcpu_srcu_read_lock() around the problematic SMM code would cause\nproblems. Acquiring SRCU isn't all that expensive, so for simplicity,\ngrab it unconditionally for KVM_SET_VCPU_EVENTS.\n\n =============================\n WARNING: suspicious RCU usage\n 6.10.0-rc7-332d2c1d713e-next-vm #552 Not tainted\n -----------------------------\n include/linux/kvm_host.h:1027 suspicious rcu_dereference_check() usage!\n\n other info that might help us debug this:\n\n rcu_scheduler_active = 2, debug_locks = 1\n 1 lock held by repro/1071:\n #0: ffff88811e424430 (&vcpu->mutex){+.+.}-{3:3}, at: kvm_vcpu_ioctl+0x7d/0x970 [kvm]\n\n stack backtrace:\n CPU: 15 PID: 1071 Comm: repro Not tainted 6.10.0-rc7-332d2c1d713e-next-vm #552\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n Call Trace:\n \n dump_stack_lvl+0x7f/0x90\n lockdep_rcu_suspicious+0x13f/0x1a0\n kvm_vcpu_gfn_to_memslot+0x168/0x190 [kvm]\n kvm_vcpu_read_guest+0x3e/0x90 [kvm]\n nested_vmx_load_msr+0x6b/0x1d0 [kvm_intel]\n load_vmcs12_host_state+0x432/0xb40 [kvm_intel]\n vmx_leave_nested+0x30/0x40 [kvm_intel]\n kvm_vcpu_ioctl_x86_set_vcpu_events+0x15d/0x2b0 [kvm]\n kvm_arch_vcpu_ioctl+0x1107/0x1750 [kvm]\n ? mark_held_locks+0x49/0x70\n ? kvm_vcpu_ioctl+0x7d/0x970 [kvm]\n ? kvm_vcpu_ioctl+0x497/0x970 [kvm]\n kvm_vcpu_ioctl+0x497/0x970 [kvm]\n ? lock_acquire+0xba/0x2d0\n ? find_held_lock+0x2b/0x80\n ? do_user_addr_fault+0x40c/0x6f0\n ? lock_release+0xb7/0x270\n __x64_sys_ioctl+0x82/0xb0\n do_syscall_64+0x6c/0x170\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x7ff11eb1b539\n ", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46830', 'https://git.kernel.org/linus/4bcdd831d9d01e0fb64faea50732b59b2ee88da1 (6.11-rc7)', 'https://git.kernel.org/stable/c/4bcdd831d9d01e0fb64faea50732b59b2ee88da1', 'https://git.kernel.org/stable/c/939375737b5a0b1bf9b1e75129054e11bc9ca65e', 'https://git.kernel.org/stable/c/ecdbe8ac86fb5538ccc623a41f88ec96c7168ab9', 'https://git.kernel.org/stable/c/fa297c33faefe51e10244e8a378837fca4963228', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46830-deac@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46830', 'https://www.cve.org/CVERecord?id=CVE-2024-46830'], 'PublishedDate': '2024-09-27T13:15:15.38Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46831', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46831', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: microchip: vcap: Fix use-after-free error in kunit test', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: vcap: Fix use-after-free error in kunit test\n\nThis is a clear use-after-free error. We remove it, and rely on checking\nthe return code of vcap_del_rule.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46831', 'https://git.kernel.org/linus/a3c1e45156ad39f225cd7ddae0f81230a3b1e657 (6.11-rc7)', 'https://git.kernel.org/stable/c/a3c1e45156ad39f225cd7ddae0f81230a3b1e657', 'https://git.kernel.org/stable/c/b0804c286ccfcf5f5c004d5bf8a54c0508b5e86b', 'https://git.kernel.org/stable/c/f7fe95f40c85311c98913fe6ae2c56adb7f767a7', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46831-06bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46831', 'https://www.cve.org/CVERecord?id=CVE-2024-46831'], 'PublishedDate': '2024-09-27T13:15:15.457Z', 'LastModifiedDate': '2024-10-02T14:26:13.807Z'}, {'VulnerabilityID': 'CVE-2024-46832', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46832', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: cevt-r4k: Don\'t call get_c0_compare_int if timer irq is installed\n\nThis avoids warning:\n\n[ 0.118053] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:283\n\nCaused by get_c0_compare_int on secondary CPU.\n\nWe also skipped saving IRQ number to struct clock_event_device *cd as\nit\'s never used by clockevent core, as per comments it\'s only meant\nfor "non CPU local devices".', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46832', 'https://git.kernel.org/linus/50f2b98dc83de7809a5c5bf0ccf9af2e75c37c13 (6.11-rc5)', 'https://git.kernel.org/stable/c/189d3ed3b25beee26ffe2abed278208bece13f52', 'https://git.kernel.org/stable/c/32ee0520159f1e8c2d6597c19690df452c528f30', 'https://git.kernel.org/stable/c/50f2b98dc83de7809a5c5bf0ccf9af2e75c37c13', 'https://git.kernel.org/stable/c/b1d2051373bfc65371ce4ac8911ed984d0178c98', 'https://git.kernel.org/stable/c/d3ff0f98a52f0aafe35aa314d1c442f4318be3db', 'https://git.kernel.org/stable/c/e6cd871627abbb459d0ff6521d6bb9cf9d9f7522', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46832-3ad0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46832', 'https://www.cve.org/CVERecord?id=CVE-2024-46832'], 'PublishedDate': '2024-09-27T13:15:15.517Z', 'LastModifiedDate': '2024-10-09T15:51:20.7Z'}, {'VulnerabilityID': 'CVE-2024-46833', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46833', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: hns3: void array out of bound when loop tnl_num', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: void array out of bound when loop tnl_num\n\nWhen query reg inf of SSU, it loops tnl_num times. However, tnl_num comes\nfrom hardware and the length of array is a fixed value. To void array out\nof bound, make sure the loop time is not greater than the length of array', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46833', 'https://git.kernel.org/linus/86db7bfb06704ef17340eeae71c832f21cfce35c (6.11-rc4)', 'https://git.kernel.org/stable/c/86db7bfb06704ef17340eeae71c832f21cfce35c', 'https://git.kernel.org/stable/c/c33a9806dc806bcb4a31dc71fb06979219181ad4', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46833-0fa0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46833', 'https://www.cve.org/CVERecord?id=CVE-2024-46833'], 'PublishedDate': '2024-09-27T13:15:15.593Z', 'LastModifiedDate': '2024-10-09T15:54:38.123Z'}, {'VulnerabilityID': 'CVE-2024-46834', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46834', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ethtool: fail closed if we can't get max channel used in indirection tables', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: fail closed if we can\'t get max channel used in indirection tables\n\nCommit 0d1b7d6c9274 ("bnxt: fix crashes when reducing ring count with\nactive RSS contexts") proves that allowing indirection table to contain\nchannels with out of bounds IDs may lead to crashes. Currently the\nmax channel check in the core gets skipped if driver can\'t fetch\nthe indirection table or when we can\'t allocate memory.\n\nBoth of those conditions should be extremely rare but if they do\nhappen we should try to be safe and fail the channel change.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46834', 'https://git.kernel.org/linus/2899d58462ba868287d6ff3acad3675e7adf934f (6.11-rc1)', 'https://git.kernel.org/stable/c/101737d8b88dbd4be6010bac398fe810f1950036', 'https://git.kernel.org/stable/c/2899d58462ba868287d6ff3acad3675e7adf934f', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46834-dc7b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46834', 'https://www.cve.org/CVERecord?id=CVE-2024-46834'], 'PublishedDate': '2024-09-27T13:15:15.66Z', 'LastModifiedDate': '2024-10-09T15:57:03.037Z'}, {'VulnerabilityID': 'CVE-2024-46835', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46835', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix smatch static checker warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix smatch static checker warning\n\nadev->gfx.imu.funcs could be NULL', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46835', 'https://git.kernel.org/linus/bdbdc7cecd00305dc844a361f9883d3a21022027 (6.11-rc1)', 'https://git.kernel.org/stable/c/8bc7b3ce33e64c74211ed17aec823fc4e523426a', 'https://git.kernel.org/stable/c/bdbdc7cecd00305dc844a361f9883d3a21022027', 'https://git.kernel.org/stable/c/c2056c7a840f0dbf293bc3b0d91826d001668fb0', 'https://git.kernel.org/stable/c/d40c2c3dd0395fe7fdc19bd96551e87251426d66', 'https://lore.kernel.org/linux-cve-announce/2024092753-CVE-2024-46835-4f99@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46835', 'https://www.cve.org/CVERecord?id=CVE-2024-46835'], 'PublishedDate': '2024-09-27T13:15:15.72Z', 'LastModifiedDate': '2024-10-02T14:24:18.93Z'}, {'VulnerabilityID': 'CVE-2024-46836', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46836', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: gadget: aspeed_udc: validate endpoint index for ast udc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed_udc: validate endpoint index for ast udc\n\nWe should verify the bound of the array to assure that host\nmay not manipulate the index to point past endpoint array.\n\nFound by static analysis.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46836', 'https://git.kernel.org/linus/ee0d382feb44ec0f445e2ad63786cd7f3f6a8199 (6.11-rc1)', 'https://git.kernel.org/stable/c/31bd4fab49c0adc6228848357c1b1df9395858af', 'https://git.kernel.org/stable/c/6fe9ca2ca389114c8da66e534c18273497843e8a', 'https://git.kernel.org/stable/c/b2a50ffdd1a079869a62198a8d1441355c513c7c', 'https://git.kernel.org/stable/c/ee0d382feb44ec0f445e2ad63786cd7f3f6a8199', 'https://lore.kernel.org/linux-cve-announce/2024092753-CVE-2024-46836-acff@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46836', 'https://www.cve.org/CVERecord?id=CVE-2024-46836'], 'PublishedDate': '2024-09-27T13:15:15.78Z', 'LastModifiedDate': '2024-10-09T15:47:55.187Z'}, {'VulnerabilityID': 'CVE-2024-46838', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46838', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: userfaultfd: don't BUG_ON() if khugepaged yanks our page table', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: don\'t BUG_ON() if khugepaged yanks our page table\n\nSince khugepaged was changed to allow retracting page tables in file\nmappings without holding the mmap lock, these BUG_ON()s are wrong - get\nrid of them.\n\nWe could also remove the preceding "if (unlikely(...))" block, but then we\ncould reach pte_offset_map_lock() with transhuge pages not just for file\nmappings but also for anonymous mappings - which would probably be fine\nbut I think is not necessarily expected.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46838', 'https://git.kernel.org/linus/4828d207dc5161dc7ddf9a4f6dcfd80c7dd7d20a (6.11-rc7)', 'https://git.kernel.org/stable/c/4828d207dc5161dc7ddf9a4f6dcfd80c7dd7d20a', 'https://git.kernel.org/stable/c/4a594acc12d5954cdc71d4450a386748bf3d136a', 'https://git.kernel.org/stable/c/db978287e908d48b209e374b00d847b2d785e0a9', 'https://lore.kernel.org/linux-cve-announce/2024092753-CVE-2024-46838-5fa5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46838', 'https://www.cve.org/CVERecord?id=CVE-2024-46838'], 'PublishedDate': '2024-09-27T13:15:15.92Z', 'LastModifiedDate': '2024-10-09T15:35:40.827Z'}, {'VulnerabilityID': 'CVE-2024-46840', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46840', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: clean up our handling of refs == 0 in snapshot delete', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: clean up our handling of refs == 0 in snapshot delete\n\nIn reada we BUG_ON(refs == 0), which could be unkind since we aren't\nholding a lock on the extent leaf and thus could get a transient\nincorrect answer. In walk_down_proc we also BUG_ON(refs == 0), which\ncould happen if we have extent tree corruption. Change that to return\n-EUCLEAN. In do_walk_down() we catch this case and handle it correctly,\nhowever we return -EIO, which -EUCLEAN is a more appropriate error code.\nFinally in walk_up_proc we have the same BUG_ON(refs == 0), so convert\nthat to proper error handling. Also adjust the error message so we can\nactually do something with the information.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46840', 'https://git.kernel.org/linus/b8ccef048354074a548f108e51d0557d6adfd3a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/03804641ec2d0da4fa088ad21c88e703d151ce16', 'https://git.kernel.org/stable/c/71291aa7246645ef622621934d2067400380645e', 'https://git.kernel.org/stable/c/728d4d045b628e006b48a448f3326a7194c88d32', 'https://git.kernel.org/stable/c/7d1df13bf078ffebfedd361d714ff6cee1ff01b9', 'https://git.kernel.org/stable/c/9cc887ac24b7a0598f4042ae9af6b9a33072f75b', 'https://git.kernel.org/stable/c/b8ccef048354074a548f108e51d0557d6adfd3a3', 'https://git.kernel.org/stable/c/c60676b81fab456b672796830f6d8057058f029c', 'https://git.kernel.org/stable/c/c847b28a799733b04574060ab9d00f215970627d', 'https://lore.kernel.org/linux-cve-announce/2024092754-CVE-2024-46840-fc44@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46840', 'https://www.cve.org/CVERecord?id=CVE-2024-46840'], 'PublishedDate': '2024-09-27T13:15:16.057Z', 'LastModifiedDate': '2024-10-08T18:15:07.857Z'}, {'VulnerabilityID': 'CVE-2024-46841', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46841', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc()\n\nWe handle errors here properly, ENOMEM isn't fatal, return the error.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46841', 'https://git.kernel.org/linus/a580fb2c3479d993556e1c31b237c9e5be4944a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/704c359b4093a2af650a20eaa030c435d7c30f91', 'https://git.kernel.org/stable/c/a580fb2c3479d993556e1c31b237c9e5be4944a3', 'https://lore.kernel.org/linux-cve-announce/2024092754-CVE-2024-46841-7572@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46841', 'https://www.cve.org/CVERecord?id=CVE-2024-46841'], 'PublishedDate': '2024-09-27T13:15:16.13Z', 'LastModifiedDate': '2024-10-08T18:17:07.87Z'}, {'VulnerabilityID': 'CVE-2024-46842', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46842', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info\n\nThe MBX_TIMEOUT return code is not handled in lpfc_get_sfp_info and the\nroutine unconditionally frees submitted mailbox commands regardless of\nreturn status. The issue is that for MBX_TIMEOUT cases, when firmware\nreturns SFP information at a later time, that same mailbox memory region\nreferences previously freed memory in its cmpl routine.\n\nFix by adding checks for the MBX_TIMEOUT return code. During mailbox\nresource cleanup, check the mbox flag to make sure that the wait did not\ntimeout. If the MBOX_WAKE flag is not set, then do not free the resources\nbecause it will be freed when firmware completes the mailbox at a later\ntime in its cmpl routine.\n\nAlso, increase the timeout from 30 to 60 seconds to accommodate boot\nscripts requiring longer timeouts.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46842', 'https://git.kernel.org/linus/ede596b1434b57c0b3fd5c02b326efe5c54f6e48 (6.11-rc1)', 'https://git.kernel.org/stable/c/bba47fe3b038cca3d3ebd799665ce69d6d273b58', 'https://git.kernel.org/stable/c/ede596b1434b57c0b3fd5c02b326efe5c54f6e48', 'https://lore.kernel.org/linux-cve-announce/2024092754-CVE-2024-46842-e52c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46842', 'https://www.cve.org/CVERecord?id=CVE-2024-46842'], 'PublishedDate': '2024-09-27T13:15:16.19Z', 'LastModifiedDate': '2024-10-08T18:22:24.997Z'}, {'VulnerabilityID': 'CVE-2024-46843', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46843', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: ufs: core: Remove SCSI host only if added', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Remove SCSI host only if added\n\nIf host tries to remove ufshcd driver from a UFS device it would cause a\nkernel panic if ufshcd_async_scan fails during ufshcd_probe_hba before\nadding a SCSI host with scsi_add_host and MCQ is enabled since SCSI host\nhas been defered after MCQ configuration introduced by commit 0cab4023ec7b\n("scsi: ufs: core: Defer adding host to SCSI if MCQ is supported").\n\nTo guarantee that SCSI host is removed only if it has been added, set the\nscsi_host_added flag to true after adding a SCSI host and check whether it\nis set or not before removing it.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46843', 'https://git.kernel.org/linus/7cbff570dbe8907e23bba06f6414899a0fbb2fcc (6.11-rc1)', 'https://git.kernel.org/stable/c/2f49e05d6b58d660f035a75ff96b77071b4bd5ed', 'https://git.kernel.org/stable/c/3844586e9bd9845140e1078f1e61896b576ac536', 'https://git.kernel.org/stable/c/7cbff570dbe8907e23bba06f6414899a0fbb2fcc', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46843-82c5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46843', 'https://www.cve.org/CVERecord?id=CVE-2024-46843'], 'PublishedDate': '2024-09-27T13:15:16.25Z', 'LastModifiedDate': '2024-10-08T18:23:52.423Z'}, {'VulnerabilityID': 'CVE-2024-46844', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46844', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: um: line: always fill *error_out in setup_one_line()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\num: line: always fill *error_out in setup_one_line()\n\nThe pointer isn't initialized by callers, but I have\nencountered cases where it's still printed; initialize\nit in all possible cases in setup_one_line().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-824'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46844', 'https://git.kernel.org/linus/824ac4a5edd3f7494ab1996826c4f47f8ef0f63d (6.11-rc1)', 'https://git.kernel.org/stable/c/289979d64573f43df1d0e6bc6435de63a0d69cdf', 'https://git.kernel.org/stable/c/3bedb7ce080690d0d6172db790790c1219bcbdd5', 'https://git.kernel.org/stable/c/43f782c27907f306c664b6614fd6f264ac32cce6', 'https://git.kernel.org/stable/c/824ac4a5edd3f7494ab1996826c4f47f8ef0f63d', 'https://git.kernel.org/stable/c/96301fdc2d533a196197c055af875fe33d47ef84', 'https://git.kernel.org/stable/c/c8944d449fda9f58c03bd99649b2df09948fc874', 'https://git.kernel.org/stable/c/ec5b47a370177d79ae7773858042c107e21f8ecc', 'https://git.kernel.org/stable/c/fc843d3837ebcb1c16d3768ef3eb55e25d5331f2', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46844-af64@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46844', 'https://www.cve.org/CVERecord?id=CVE-2024-46844'], 'PublishedDate': '2024-09-27T13:15:16.313Z', 'LastModifiedDate': '2024-10-02T14:22:50.533Z'}, {'VulnerabilityID': 'CVE-2024-46845', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46845', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing/timerlat: Only clear timer if a kthread exists', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Only clear timer if a kthread exists\n\nThe timerlat tracer can use user space threads to check for osnoise and\ntimer latency. If the program using this is killed via a SIGTERM, the\nthreads are shutdown one at a time and another tracing instance can start\nup resetting the threads before they are fully closed. That causes the\nhrtimer assigned to the kthread to be shutdown and freed twice when the\ndying thread finally closes the file descriptors, causing a use-after-free\nbug.\n\nOnly cancel the hrtimer if the associated thread is still around. Also add\nthe interface_lock around the resetting of the tlat_var->kthread.\n\nNote, this is just a quick fix that can be backported to stable. A real\nfix is to have a better synchronization between the shutdown of old\nthreads and the starting of new ones.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46845', 'https://git.kernel.org/linus/e6a53481da292d970d1edf0d8831121d1c5e2f0d (6.11-rc7)', 'https://git.kernel.org/stable/c/8a9d0d405159e9c796ddf771f7cff691c1a2bc1e', 'https://git.kernel.org/stable/c/8c72f0b2c45f21cb8b00fc37f79f632d7e46c2ed', 'https://git.kernel.org/stable/c/e6a53481da292d970d1edf0d8831121d1c5e2f0d', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46845-a529@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46845', 'https://www.cve.org/CVERecord?id=CVE-2024-46845'], 'PublishedDate': '2024-09-27T13:15:16.397Z', 'LastModifiedDate': '2024-10-02T14:18:32.923Z'}, {'VulnerabilityID': 'CVE-2024-46846', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: rockchip: Resolve unbalanced runtime PM / system PM handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: rockchip: Resolve unbalanced runtime PM / system PM handling\n\nCommit e882575efc77 ("spi: rockchip: Suspend and resume the bus during\nNOIRQ_SYSTEM_SLEEP_PM ops") stopped respecting runtime PM status and\nsimply disabled clocks unconditionally when suspending the system. This\ncauses problems when the device is already runtime suspended when we go\nto sleep -- in which case we double-disable clocks and produce a\nWARNing.\n\nSwitch back to pm_runtime_force_{suspend,resume}(), because that still\nseems like the right thing to do, and the aforementioned commit makes no\nexplanation why it stopped using it.\n\nAlso, refactor some of the resume() error handling, because it\'s not\nactually a good idea to re-disable clocks on failure.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46846', 'https://git.kernel.org/linus/be721b451affbecc4ba4eaac3b71cdbdcade1b1b (6.11-rc7)', 'https://git.kernel.org/stable/c/0efbad8445fbba7896402500a1473450a299a08a', 'https://git.kernel.org/stable/c/14f970a8d03d882b15b97beb83bd84ac8ba6298c', 'https://git.kernel.org/stable/c/be721b451affbecc4ba4eaac3b71cdbdcade1b1b', 'https://git.kernel.org/stable/c/d034bff62faea1a2219e0d2f3d17263265f24087', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46846-f264@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46846', 'https://www.cve.org/CVERecord?id=CVE-2024-46846'], 'PublishedDate': '2024-09-27T13:15:16.48Z', 'LastModifiedDate': '2024-10-08T18:25:56.467Z'}, {'VulnerabilityID': 'CVE-2024-46848', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46848', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf/x86/intel: Limit the period on Haswell', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Limit the period on Haswell\n\nRunning the ltp test cve-2015-3290 concurrently reports the following\nwarnings.\n\nperfevents: irq loop stuck!\n WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174\n intel_pmu_handle_irq+0x285/0x370\n Call Trace:\n \n ? __warn+0xa4/0x220\n ? intel_pmu_handle_irq+0x285/0x370\n ? __report_bug+0x123/0x130\n ? intel_pmu_handle_irq+0x285/0x370\n ? __report_bug+0x123/0x130\n ? intel_pmu_handle_irq+0x285/0x370\n ? report_bug+0x3e/0xa0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x18/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? irq_work_claim+0x1e/0x40\n ? intel_pmu_handle_irq+0x285/0x370\n perf_event_nmi_handler+0x3d/0x60\n nmi_handle+0x104/0x330\n\nThanks to Thomas Gleixner's analysis, the issue is caused by the low\ninitial period (1) of the frequency estimation algorithm, which triggers\nthe defects of the HW, specifically erratum HSW11 and HSW143. (For the\ndetails, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)\n\nThe HSW11 requires a period larger than 100 for the INST_RETIRED.ALL\nevent, but the initial period in the freq mode is 1. The erratum is the\nsame as the BDM11, which has been supported in the kernel. A minimum\nperiod of 128 is enforced as well on HSW.\n\nHSW143 is regarding that the fixed counter 1 may overcount 32 with the\nHyper-Threading is enabled. However, based on the test, the hardware\nhas more issues than it tells. Besides the fixed counter 1, the message\n'interrupt took too long' can be observed on any counter which was armed\nwith a period < 32 and two events expired in the same NMI. A minimum\nperiod of 32 is enforced for the rest of the events.\nThe recommended workaround code of the HSW143 is not implemented.\nBecause it only addresses the issue for the fixed counter. It brings\nextra overhead through extra MSR writing. No related overcounting issue\nhas been reported so far.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46848', 'https://git.kernel.org/linus/25dfc9e357af8aed1ca79b318a73f2c59c1f0b2b (6.11-rc7)', 'https://git.kernel.org/stable/c/0eaf812aa1506704f3b78be87036860e5d0fe81d', 'https://git.kernel.org/stable/c/15210b7c8caff4929f25d049ef8404557f8ae468', 'https://git.kernel.org/stable/c/25dfc9e357af8aed1ca79b318a73f2c59c1f0b2b', 'https://git.kernel.org/stable/c/8717dc35c0e5896f4110f4b3882f7ff787a5f73d', 'https://lore.kernel.org/linux-cve-announce/2024092756-CVE-2024-46848-bbd4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46848', 'https://www.cve.org/CVERecord?id=CVE-2024-46848'], 'PublishedDate': '2024-09-27T13:15:16.657Z', 'LastModifiedDate': '2024-10-04T15:23:35.287Z'}, {'VulnerabilityID': 'CVE-2024-46849', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46849', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: meson: axg-card: fix 'use-after-free'', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: axg-card: fix 'use-after-free'\n\nBuffer 'card->dai_link' is reallocated in 'meson_card_reallocate_links()',\nso move 'pad' pointer initialization after this function when memory is\nalready reallocated.\n\nKasan bug report:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in axg_card_add_link+0x76c/0x9bc\nRead of size 8 at addr ffff000000e8b260 by task modprobe/356\n\nCPU: 0 PID: 356 Comm: modprobe Tainted: G O 6.9.12-sdkernel #1\nCall trace:\n dump_backtrace+0x94/0xec\n show_stack+0x18/0x24\n dump_stack_lvl+0x78/0x90\n print_report+0xfc/0x5c0\n kasan_report+0xb8/0xfc\n __asan_load8+0x9c/0xb8\n axg_card_add_link+0x76c/0x9bc [snd_soc_meson_axg_sound_card]\n meson_card_probe+0x344/0x3b8 [snd_soc_meson_card_utils]\n platform_probe+0x8c/0xf4\n really_probe+0x110/0x39c\n __driver_probe_device+0xb8/0x18c\n driver_probe_device+0x108/0x1d8\n __driver_attach+0xd0/0x25c\n bus_for_each_dev+0xe0/0x154\n driver_attach+0x34/0x44\n bus_add_driver+0x134/0x294\n driver_register+0xa8/0x1e8\n __platform_driver_register+0x44/0x54\n axg_card_pdrv_init+0x20/0x1000 [snd_soc_meson_axg_sound_card]\n do_one_initcall+0xdc/0x25c\n do_init_module+0x10c/0x334\n load_module+0x24c4/0x26cc\n init_module_from_file+0xd4/0x128\n __arm64_sys_finit_module+0x1f4/0x41c\n invoke_syscall+0x60/0x188\n el0_svc_common.constprop.0+0x78/0x13c\n do_el0_svc+0x30/0x40\n el0_svc+0x38/0x78\n el0t_64_sync_handler+0x100/0x12c\n el0t_64_sync+0x190/0x194", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46849', 'https://git.kernel.org/linus/4f9a71435953f941969a4f017e2357db62d85a86 (6.11)', 'https://git.kernel.org/stable/c/4f9a71435953f941969a4f017e2357db62d85a86', 'https://git.kernel.org/stable/c/5a2cc2bb81399e9ebc72560541137eb04d61dc3d', 'https://git.kernel.org/stable/c/7d318166bf55e9029d56997c3b134f4ac2ae2607', 'https://git.kernel.org/stable/c/e1a199ec31617242e1a0ea8f312341e682d0c037', 'https://git.kernel.org/stable/c/e43364f578cdc2f8083abbc0cb743ea55e827c29', 'https://git.kernel.org/stable/c/fb0530025d502cb79d2b2801b14a9d5261833f1a', 'https://lore.kernel.org/linux-cve-announce/2024092741-CVE-2024-46849-93c5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46849', 'https://www.cve.org/CVERecord?id=CVE-2024-46849'], 'PublishedDate': '2024-09-27T13:15:16.723Z', 'LastModifiedDate': '2024-10-17T14:15:07.75Z'}, {'VulnerabilityID': 'CVE-2024-46850', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46850', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()\n\ndc_state_destruct() nulls the resource context of the DC state. The pipe\ncontext passed to dcn35_set_drr() is a member of this resource context.\n\nIf dc_state_destruct() is called parallel to the IRQ processing (which\ncalls dcn35_set_drr() at some point), we can end up using already nulled\nfunction callback fields of struct stream_resource.\n\nThe logic in dcn35_set_drr() already tries to avoid this, by checking tg\nagainst NULL. But if the nulling happens exactly after the NULL check and\nbefore the next access, then we get a race.\n\nAvoid this by copying tg first to a local variable, and then use this\nvariable for all the operations. This should work, as long as nobody\nfrees the resource pool where the timing generators live.\n\n(cherry picked from commit 0607a50c004798a96e62c089a4c34c220179dcb5)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46850', 'https://git.kernel.org/linus/e835d5144f5ef78e4f8828c63e2f0d61144f283a (6.11)', 'https://git.kernel.org/stable/c/42850927656a540428e58d370b3c1599a617bac7', 'https://git.kernel.org/stable/c/e835d5144f5ef78e4f8828c63e2f0d61144f283a', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46850-186e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46850', 'https://www.cve.org/CVERecord?id=CVE-2024-46850'], 'PublishedDate': '2024-09-27T13:15:16.787Z', 'LastModifiedDate': '2024-10-04T15:30:32.11Z'}, {'VulnerabilityID': 'CVE-2024-46851', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46851', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct()\n\ndc_state_destruct() nulls the resource context of the DC state. The pipe\ncontext passed to dcn10_set_drr() is a member of this resource context.\n\nIf dc_state_destruct() is called parallel to the IRQ processing (which\ncalls dcn10_set_drr() at some point), we can end up using already nulled\nfunction callback fields of struct stream_resource.\n\nThe logic in dcn10_set_drr() already tries to avoid this, by checking tg\nagainst NULL. But if the nulling happens exactly after the NULL check and\nbefore the next access, then we get a race.\n\nAvoid this by copying tg first to a local variable, and then use this\nvariable for all the operations. This should work, as long as nobody\nfrees the resource pool where the timing generators live.\n\n(cherry picked from commit a3cc326a43bdc48fbdf53443e1027a03e309b643)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46851', 'https://git.kernel.org/linus/a7aeb03888b92304e2fc7d4d1c242f54a312561b (6.11)', 'https://git.kernel.org/stable/c/a7aeb03888b92304e2fc7d4d1c242f54a312561b', 'https://git.kernel.org/stable/c/b6ce047a81f508f5c60756db8dfb5ff486e4dad0', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46851-125b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46851', 'https://www.cve.org/CVERecord?id=CVE-2024-46851'], 'PublishedDate': '2024-09-27T13:15:16.85Z', 'LastModifiedDate': '2024-10-04T16:00:43.913Z'}, {'VulnerabilityID': 'CVE-2024-46852', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46852', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dma-buf: heaps: Fix off-by-one in CMA heap fault handler', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: heaps: Fix off-by-one in CMA heap fault handler\n\nUntil VM_DONTEXPAND was added in commit 1c1914d6e8c6 ("dma-buf: heaps:\nDon\'t track CMA dma-buf pages under RssFile") it was possible to obtain\na mapping larger than the buffer size via mremap and bypass the overflow\ncheck in dma_buf_mmap_internal. When using such a mapping to attempt to\nfault past the end of the buffer, the CMA heap fault handler also checks\nthe fault offset against the buffer size, but gets the boundary wrong by\n1. Fix the boundary check so that we don\'t read off the end of the pages\narray and insert an arbitrary page in the mapping.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-193'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46852', 'https://git.kernel.org/linus/ea5ff5d351b520524019f7ff7f9ce418de2dad87 (6.11)', 'https://git.kernel.org/stable/c/007180fcb6cc4a93211d4cc45fef3f5ccccd56ae', 'https://git.kernel.org/stable/c/79cce5e81d20fa9ad553be439d665ac3302d3c95', 'https://git.kernel.org/stable/c/84175dc5b2c932266a50c04e5ce342c30f817a2f', 'https://git.kernel.org/stable/c/e79050882b857c37634baedbdcf7c2047c24cbff', 'https://git.kernel.org/stable/c/ea5ff5d351b520524019f7ff7f9ce418de2dad87', 'https://git.kernel.org/stable/c/eb7fc8b65cea22f9038c52398c8b22849e9620ea', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46852-91a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46852', 'https://www.cve.org/CVERecord?id=CVE-2024-46852'], 'PublishedDate': '2024-09-27T13:15:16.917Z', 'LastModifiedDate': '2024-10-17T14:15:07.887Z'}, {'VulnerabilityID': 'CVE-2024-46853', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46853', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: nxp-fspi: fix the KASAN report out-of-bounds bug', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: nxp-fspi: fix the KASAN report out-of-bounds bug\n\nChange the memcpy length to fix the out-of-bounds issue when writing the\ndata that is not 4 byte aligned to TX FIFO.\n\nTo reproduce the issue, write 3 bytes data to NOR chip.\n\ndd if=3b of=/dev/mtd0\n[ 36.926103] ==================================================================\n[ 36.933409] BUG: KASAN: slab-out-of-bounds in nxp_fspi_exec_op+0x26ec/0x2838\n[ 36.940514] Read of size 4 at addr ffff00081037c2a0 by task dd/455\n[ 36.946721]\n[ 36.948235] CPU: 3 UID: 0 PID: 455 Comm: dd Not tainted 6.11.0-rc5-gc7b0e37c8434 #1070\n[ 36.956185] Hardware name: Freescale i.MX8QM MEK (DT)\n[ 36.961260] Call trace:\n[ 36.963723] dump_backtrace+0x90/0xe8\n[ 36.967414] show_stack+0x18/0x24\n[ 36.970749] dump_stack_lvl+0x78/0x90\n[ 36.974451] print_report+0x114/0x5cc\n[ 36.978151] kasan_report+0xa4/0xf0\n[ 36.981670] __asan_report_load_n_noabort+0x1c/0x28\n[ 36.986587] nxp_fspi_exec_op+0x26ec/0x2838\n[ 36.990800] spi_mem_exec_op+0x8ec/0xd30\n[ 36.994762] spi_mem_no_dirmap_read+0x190/0x1e0\n[ 36.999323] spi_mem_dirmap_write+0x238/0x32c\n[ 37.003710] spi_nor_write_data+0x220/0x374\n[ 37.007932] spi_nor_write+0x110/0x2e8\n[ 37.011711] mtd_write_oob_std+0x154/0x1f0\n[ 37.015838] mtd_write_oob+0x104/0x1d0\n[ 37.019617] mtd_write+0xb8/0x12c\n[ 37.022953] mtdchar_write+0x224/0x47c\n[ 37.026732] vfs_write+0x1e4/0x8c8\n[ 37.030163] ksys_write+0xec/0x1d0\n[ 37.033586] __arm64_sys_write+0x6c/0x9c\n[ 37.037539] invoke_syscall+0x6c/0x258\n[ 37.041327] el0_svc_common.constprop.0+0x160/0x22c\n[ 37.046244] do_el0_svc+0x44/0x5c\n[ 37.049589] el0_svc+0x38/0x78\n[ 37.052681] el0t_64_sync_handler+0x13c/0x158\n[ 37.057077] el0t_64_sync+0x190/0x194\n[ 37.060775]\n[ 37.062274] Allocated by task 455:\n[ 37.065701] kasan_save_stack+0x2c/0x54\n[ 37.069570] kasan_save_track+0x20/0x3c\n[ 37.073438] kasan_save_alloc_info+0x40/0x54\n[ 37.077736] __kasan_kmalloc+0xa0/0xb8\n[ 37.081515] __kmalloc_noprof+0x158/0x2f8\n[ 37.085563] mtd_kmalloc_up_to+0x120/0x154\n[ 37.089690] mtdchar_write+0x130/0x47c\n[ 37.093469] vfs_write+0x1e4/0x8c8\n[ 37.096901] ksys_write+0xec/0x1d0\n[ 37.100332] __arm64_sys_write+0x6c/0x9c\n[ 37.104287] invoke_syscall+0x6c/0x258\n[ 37.108064] el0_svc_common.constprop.0+0x160/0x22c\n[ 37.112972] do_el0_svc+0x44/0x5c\n[ 37.116319] el0_svc+0x38/0x78\n[ 37.119401] el0t_64_sync_handler+0x13c/0x158\n[ 37.123788] el0t_64_sync+0x190/0x194\n[ 37.127474]\n[ 37.128977] The buggy address belongs to the object at ffff00081037c2a0\n[ 37.128977] which belongs to the cache kmalloc-8 of size 8\n[ 37.141177] The buggy address is located 0 bytes inside of\n[ 37.141177] allocated 3-byte region [ffff00081037c2a0, ffff00081037c2a3)\n[ 37.153465]\n[ 37.154971] The buggy address belongs to the physical page:\n[ 37.160559] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x89037c\n[ 37.168596] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)\n[ 37.175149] page_type: 0xfdffffff(slab)\n[ 37.179021] raw: 0bfffe0000000000 ffff000800002500 dead000000000122 0000000000000000\n[ 37.186788] raw: 0000000000000000 0000000080800080 00000001fdffffff 0000000000000000\n[ 37.194553] page dumped because: kasan: bad access detected\n[ 37.200144]\n[ 37.201647] Memory state around the buggy address:\n[ 37.206460] ffff00081037c180: fa fc fc fc fa fc fc fc fa fc fc fc fa fc fc fc\n[ 37.213701] ffff00081037c200: fa fc fc fc 05 fc fc fc 03 fc fc fc 02 fc fc fc\n[ 37.220946] >ffff00081037c280: 06 fc fc fc 03 fc fc fc fc fc fc fc fc fc fc fc\n[ 37.228186] ^\n[ 37.232473] ffff00081037c300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 37.239718] ffff00081037c380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 37.246962] ==============================================================\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46853', 'https://git.kernel.org/linus/2a8787c1cdc7be24fdd8953ecd1a8743a1006235 (6.11)', 'https://git.kernel.org/stable/c/09af8b0ba70072be831f3ec459f4063d570f9e24', 'https://git.kernel.org/stable/c/2a8787c1cdc7be24fdd8953ecd1a8743a1006235', 'https://git.kernel.org/stable/c/491f9646f7ac31af5fca71be1a3e5eb8aa7663ad', 'https://git.kernel.org/stable/c/609260542cf86b459c57618b8cdec8020394b7ad', 'https://git.kernel.org/stable/c/af9ca9ca3e44f48b2a191e100d452fbf850c3d87', 'https://git.kernel.org/stable/c/d1a1dfcec77c57b1181da93d11a3db1bc4eefa97', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46853-ab04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46853', 'https://www.cve.org/CVERecord?id=CVE-2024-46853'], 'PublishedDate': '2024-09-27T13:15:16.997Z', 'LastModifiedDate': '2024-10-17T14:15:07.993Z'}, {'VulnerabilityID': 'CVE-2024-46854', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46854', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dpaa: Pad packets to ETH_ZLEN', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dpaa: Pad packets to ETH_ZLEN\n\nWhen sending packets under 60 bytes, up to three bytes of the buffer\nfollowing the data may be leaked. Avoid this by extending all packets to\nETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be\nreproduced by running\n\n\t$ ping -s 11 destination', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46854', 'https://git.kernel.org/linus/cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0 (6.11)', 'https://git.kernel.org/stable/c/1f31f51bfc8214a6deaac2920e6342cb9d019133', 'https://git.kernel.org/stable/c/34fcac26216ce17886af3eb392355b459367af1a', 'https://git.kernel.org/stable/c/38f5db5587c0ee53546b28c50ba128253181ac83', 'https://git.kernel.org/stable/c/cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0', 'https://git.kernel.org/stable/c/ce8eabc912fe9b9a62be1a5c6af5ad2196e90fc2', 'https://git.kernel.org/stable/c/f43190e33224c49e1c7ebbc25923ff400d87ec00', 'https://lore.kernel.org/linux-cve-announce/2024092743-CVE-2024-46854-3404@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46854', 'https://www.cve.org/CVERecord?id=CVE-2024-46854'], 'PublishedDate': '2024-09-27T13:15:17.063Z', 'LastModifiedDate': '2024-10-17T14:15:08.107Z'}, {'VulnerabilityID': 'CVE-2024-46855', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46855', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: nft_socket: fix sk refcount leaks', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_socket: fix sk refcount leaks\n\nWe must put 'sk' reference before returning.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46855', 'https://git.kernel.org/linus/8b26ff7af8c32cb4148b3e147c52f9e4c695209c (6.11)', 'https://git.kernel.org/stable/c/1f68e097e20d3c695281a9c6433acc37be47fe11', 'https://git.kernel.org/stable/c/33c2258bf8cb17fba9e58b111d4c4f4cf43a4896', 'https://git.kernel.org/stable/c/83e6fb59040e8964888afcaa5612cc1243736715', 'https://git.kernel.org/stable/c/8b26ff7af8c32cb4148b3e147c52f9e4c695209c', 'https://git.kernel.org/stable/c/ddc7c423c4a5386bf865474c694b48178efd311a', 'https://lore.kernel.org/linux-cve-announce/2024092743-CVE-2024-46855-4382@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46855', 'https://www.cve.org/CVERecord?id=CVE-2024-46855'], 'PublishedDate': '2024-09-27T13:15:17.133Z', 'LastModifiedDate': '2024-10-17T14:15:12.79Z'}, {'VulnerabilityID': 'CVE-2024-46857', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46857', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix bridge mode operations when there are no VFs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix bridge mode operations when there are no VFs\n\nCurrently, trying to set the bridge mode attribute when numvfs=0 leads to a\ncrash:\n\nbridge link set dev eth2 hwmode vepa\n\n[ 168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030\n[...]\n[ 168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core]\n[...]\n[ 168.976037] Call Trace:\n[ 168.976188] \n[ 168.978620] _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core]\n[ 168.979074] mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core]\n[ 168.979471] rtnl_bridge_setlink+0xe9/0x1f0\n[ 168.979714] rtnetlink_rcv_msg+0x159/0x400\n[ 168.980451] netlink_rcv_skb+0x54/0x100\n[ 168.980675] netlink_unicast+0x241/0x360\n[ 168.980918] netlink_sendmsg+0x1f6/0x430\n[ 168.981162] ____sys_sendmsg+0x3bb/0x3f0\n[ 168.982155] ___sys_sendmsg+0x88/0xd0\n[ 168.985036] __sys_sendmsg+0x59/0xa0\n[ 168.985477] do_syscall_64+0x79/0x150\n[ 168.987273] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 168.987773] RIP: 0033:0x7f8f7950f917\n\n(esw->fdb_table.legacy.vepa_fdb is null)\n\nThe bridge mode is only relevant when there are multiple functions per\nport. Therefore, prevent setting and getting this setting when there are no\nVFs.\n\nNote that after this change, there are no settings to change on the PF\ninterface using `bridge link` when there are no VFs, so the interface no\nlonger appears in the `bridge link` output.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46857', 'https://git.kernel.org/linus/b1d305abef4640af1b4f1b4774d513cd81b10cfc (6.11)', 'https://git.kernel.org/stable/c/505ae01f75f839b54329164bbfecf24cc1361b31', 'https://git.kernel.org/stable/c/52c4beb79e095e0631b5cac46ed48a2aefe51985', 'https://git.kernel.org/stable/c/65feee671e37f3b6eda0b6af28f204b5bcf7fa50', 'https://git.kernel.org/stable/c/b1d305abef4640af1b4f1b4774d513cd81b10cfc', 'https://lore.kernel.org/linux-cve-announce/2024092743-CVE-2024-46857-3bc3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46857', 'https://www.cve.org/CVERecord?id=CVE-2024-46857'], 'PublishedDate': '2024-09-27T13:15:17.277Z', 'LastModifiedDate': '2024-10-01T17:10:29.657Z'}, {'VulnerabilityID': 'CVE-2024-46858', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46858', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: Fix uaf in __timer_delete_sync', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: Fix uaf in __timer_delete_sync\n\nThere are two paths to access mptcp_pm_del_add_timer, result in a race\ncondition:\n\n CPU1\t\t\t\tCPU2\n ==== ====\n net_rx_action\n napi_poll netlink_sendmsg\n __napi_poll netlink_unicast\n process_backlog netlink_unicast_kernel\n __netif_receive_skb genl_rcv\n __netif_receive_skb_one_core netlink_rcv_skb\n NF_HOOK genl_rcv_msg\n ip_local_deliver_finish genl_family_rcv_msg\n ip_protocol_deliver_rcu genl_family_rcv_msg_doit\n tcp_v4_rcv mptcp_pm_nl_flush_addrs_doit\n tcp_v4_do_rcv mptcp_nl_remove_addrs_list\n tcp_rcv_established mptcp_pm_remove_addrs_and_subflows\n tcp_data_queue remove_anno_list_by_saddr\n mptcp_incoming_options mptcp_pm_del_add_timer\n mptcp_pm_del_add_timer kfree(entry)\n\nIn remove_anno_list_by_saddr(running on CPU2), after leaving the critical\nzone protected by "pm.lock", the entry will be released, which leads to the\noccurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1).\n\nKeeping a reference to add_timer inside the lock, and calling\nsk_stop_timer_sync() with this reference, instead of "entry->add_timer".\n\nMove list_del(&entry->list) to mptcp_pm_del_add_timer and inside the pm lock,\ndo not directly access any members of the entry outside the pm lock, which\ncan avoid similar "entry->x" uaf.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46858', 'https://git.kernel.org/linus/b4cd80b0338945a94972ac3ed54f8338d2da2076 (6.11)', 'https://git.kernel.org/stable/c/0e7814b028cd50b3ff79659d23dfa9da6a1e75e1', 'https://git.kernel.org/stable/c/12134a652b0a10064844ea235173e70246eba6dc', 'https://git.kernel.org/stable/c/3554482f4691571fc4b5490c17ae26896e62171c', 'https://git.kernel.org/stable/c/6452b162549c7f9ef54655d3fb9977b9192e6e5b', 'https://git.kernel.org/stable/c/67409b358500c71632116356a0b065f112d7b707', 'https://git.kernel.org/stable/c/b4cd80b0338945a94972ac3ed54f8338d2da2076', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46858-dab6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46858', 'https://www.cve.org/CVERecord?id=CVE-2024-46858'], 'PublishedDate': '2024-09-27T13:15:17.353Z', 'LastModifiedDate': '2024-10-17T14:15:13.017Z'}, {'VulnerabilityID': 'CVE-2024-46859', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46859', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: panasonic-laptop: Fix SINF array out of bounds accesses\n\nThe panasonic laptop code in various places uses the SINF array with index\nvalues of 0 - SINF_CUR_BRIGHT(0x0d) without checking that the SINF array\nis big enough.\n\nNot all panasonic laptops have this many SINF array entries, for example\nthe Toughbook CF-18 model only has 10 SINF array entries. So it only\nsupports the AC+DC brightness entries and mute.\n\nCheck that the SINF array has a minimum size which covers all AC+DC\nbrightness entries and refuse to load if the SINF array is smaller.\n\nFor higher SINF indexes hide the sysfs attributes when the SINF array\ndoes not contain an entry for that attribute, avoiding show()/store()\naccessing the array out of bounds and add bounds checking to the probe()\nand resume() code accessing these.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46859', 'https://git.kernel.org/linus/f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4 (6.11)', 'https://git.kernel.org/stable/c/6821a82616f60aa72c5909b3e252ad97fb9f7e2a', 'https://git.kernel.org/stable/c/9291fadbd2720a869b1d2fcf82305648e2e62a16', 'https://git.kernel.org/stable/c/b38c19783286a71693c2194ed1b36665168c09c4', 'https://git.kernel.org/stable/c/b7c2f692307fe704be87ea80d7328782b33c3cef', 'https://git.kernel.org/stable/c/f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46859-e785@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46859', 'https://www.cve.org/CVERecord?id=CVE-2024-46859'], 'PublishedDate': '2024-09-27T13:15:17.43Z', 'LastModifiedDate': '2024-10-17T14:15:13.183Z'}, {'VulnerabilityID': 'CVE-2024-46860', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46860', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change\n\nWhen disabling wifi mt7921_ipv6_addr_change() is called as a notifier.\nAt this point mvif->phy is already NULL so we cannot use it here.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46860', 'https://git.kernel.org/linus/479ffee68d59c599f8aed8fa2dcc8e13e7bd13c3 (6.11-rc4)', 'https://git.kernel.org/stable/c/479ffee68d59c599f8aed8fa2dcc8e13e7bd13c3', 'https://git.kernel.org/stable/c/4bfee9346d8c17d928ef6da2b8bffab88fa2a553', 'https://git.kernel.org/stable/c/8d92bafd4c67efb692f722d73a07412b5f88c6d6', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46860-1dfc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46860', 'https://www.cve.org/CVERecord?id=CVE-2024-46860'], 'PublishedDate': '2024-09-27T13:15:17.493Z', 'LastModifiedDate': '2024-10-02T14:04:38.863Z'}, {'VulnerabilityID': 'CVE-2024-46861', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46861', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usbnet: ipheth: do not stop RX on failing RX callback', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: ipheth: do not stop RX on failing RX callback\n\nRX callbacks can fail for multiple reasons:\n\n* Payload too short\n* Payload formatted incorrecly (e.g. bad NCM framing)\n* Lack of memory\n\nNone of these should cause the driver to seize up.\n\nMake such failures non-critical and continue processing further\nincoming URBs.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46861', 'https://git.kernel.org/linus/74efed51e0a4d62f998f806c307778b47fc73395 (6.11-rc4)', 'https://git.kernel.org/stable/c/08ca800b0cd56d5e26722f68b18bbbf6840bf44b', 'https://git.kernel.org/stable/c/4d1cfa3afb8627435744ecdc6d8b58bc72ee0f4c', 'https://git.kernel.org/stable/c/74efed51e0a4d62f998f806c307778b47fc73395', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46861-f2f9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46861', 'https://www.cve.org/CVERecord?id=CVE-2024-46861'], 'PublishedDate': '2024-09-27T13:15:17.563Z', 'LastModifiedDate': '2024-10-03T15:36:06.543Z'}, {'VulnerabilityID': 'CVE-2024-46864', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46864', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/hyperv: fix kexec crash due to VP assist page corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/hyperv: fix kexec crash due to VP assist page corruption\n\ncommit 9636be85cc5b ("x86/hyperv: Fix hyperv_pcpu_input_arg handling when\nCPUs go online/offline") introduces a new cpuhp state for hyperv\ninitialization.\n\ncpuhp_setup_state() returns the state number if state is\nCPUHP_AP_ONLINE_DYN or CPUHP_BP_PREPARE_DYN and 0 for all other states.\nFor the hyperv case, since a new cpuhp state was introduced it would\nreturn 0. However, in hv_machine_shutdown(), the cpuhp_remove_state() call\nis conditioned upon "hyperv_init_cpuhp > 0". This will never be true and\nso hv_cpu_die() won\'t be called on all CPUs. This means the VP assist page\nwon\'t be reset. When the kexec kernel tries to setup the VP assist page\nagain, the hypervisor corrupts the memory region of the old VP assist page\ncausing a panic in case the kexec kernel is using that memory elsewhere.\nThis was originally fixed in commit dfe94d4086e4 ("x86/hyperv: Fix kexec\npanic/hang issues").\n\nGet rid of hyperv_init_cpuhp entirely since we are no longer using a\ndynamic cpuhp state and use CPUHP_AP_HYPERV_ONLINE directly with\ncpuhp_remove_state().', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46864', 'https://git.kernel.org/linus/b9af6418279c4cf73ca073f8ea024992b38be8ab (6.11)', 'https://git.kernel.org/stable/c/2ae1beb3ab4f28868cc5d1541d05e1fbee3ad825', 'https://git.kernel.org/stable/c/b9af6418279c4cf73ca073f8ea024992b38be8ab', 'https://git.kernel.org/stable/c/d6f018a3b49d0a94ddbd0e479c2af6b19724e434', 'https://lore.kernel.org/linux-cve-announce/2024092745-CVE-2024-46864-0343@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46864', 'https://www.cve.org/CVERecord?id=CVE-2024-46864'], 'PublishedDate': '2024-09-27T13:15:17.747Z', 'LastModifiedDate': '2024-10-03T15:29:34.927Z'}, {'VulnerabilityID': 'CVE-2024-46866', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46866', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/client: add missing bo locking in show_meminfo()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: add missing bo locking in show_meminfo()\n\nbo_meminfo() wants to inspect bo state like tt and the ttm resource,\nhowever this state can change at any point leading to stuff like NPD and\nUAF, if the bo lock is not held. Grab the bo lock when calling\nbo_meminfo(), ensuring we drop any spinlocks first. In the case of\nobject_idr we now also need to hold a ref.\n\nv2 (MattB)\n - Also add xe_bo_assert_held()\n\n(cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46866', 'https://git.kernel.org/linus/94c4aa266111262c96c98f822d1bccc494786fee (6.11)', 'https://git.kernel.org/stable/c/94c4aa266111262c96c98f822d1bccc494786fee', 'https://git.kernel.org/stable/c/abc8feacacf8fae10eecf6fea7865e8c1fee419c', 'https://lore.kernel.org/linux-cve-announce/2024092746-CVE-2024-46866-c414@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46866', 'https://www.cve.org/CVERecord?id=CVE-2024-46866'], 'PublishedDate': '2024-09-27T13:15:17.887Z', 'LastModifiedDate': '2024-10-01T17:09:30Z'}, {'VulnerabilityID': 'CVE-2024-46867', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46867', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/client: fix deadlock in show_meminfo()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: fix deadlock in show_meminfo()\n\nThere is a real deadlock as well as sleeping in atomic() bug in here, if\nthe bo put happens to be the last ref, since bo destruction wants to\ngrab the same spinlock and sleeping locks. Fix that by dropping the ref\nusing xe_bo_put_deferred(), and moving the final commit outside of the\nlock. Dropping the lock around the put is tricky since the bo can go\nout of scope and delete itself from the list, making it difficult to\nnavigate to the next list entry.\n\n(cherry picked from commit 0083b8e6f11d7662283a267d4ce7c966812ffd8a)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46867', 'https://git.kernel.org/linus/9bd7ff293fc84792514aeafa06c5a17f05cb5f4b (6.11)', 'https://git.kernel.org/stable/c/9bd7ff293fc84792514aeafa06c5a17f05cb5f4b', 'https://git.kernel.org/stable/c/9d3de463e23bfb1ff1567a32b099b1b3e5286a48', 'https://lore.kernel.org/linux-cve-announce/2024092746-CVE-2024-46867-7fe4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46867', 'https://www.cve.org/CVERecord?id=CVE-2024-46867'], 'PublishedDate': '2024-09-27T13:15:17.937Z', 'LastModifiedDate': '2024-10-01T17:09:58.147Z'}, {'VulnerabilityID': 'CVE-2024-46868', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46868', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire()\n\nIf the __qcuefi pointer is not set, then in the original code, we would\nhold onto the lock. That means that if we tried to set it later, then\nit would cause a deadlock. Drop the lock on the error path. That's\nwhat all the callers are expecting.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46868', 'https://git.kernel.org/linus/db213b0cfe3268d8b1d382b3bcc999c687a2567f (6.11)', 'https://git.kernel.org/stable/c/8c6a5a1fc02ad1d62d06897ab330693d4d27cd03', 'https://git.kernel.org/stable/c/db213b0cfe3268d8b1d382b3bcc999c687a2567f', 'https://lore.kernel.org/linux-cve-announce/2024092746-CVE-2024-46868-f3a3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46868', 'https://www.cve.org/CVERecord?id=CVE-2024-46868'], 'PublishedDate': '2024-09-27T13:15:18.007Z', 'LastModifiedDate': '2024-10-01T17:09:12.247Z'}, {'VulnerabilityID': 'CVE-2024-46870', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46870', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Disable DMCUB timeout for DCN35', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Disable DMCUB timeout for DCN35\n\n[Why]\nDMCUB can intermittently take longer than expected to process commands.\n\nOld ASIC policy was to continue while logging a diagnostic error - which\nworks fine for ASIC without IPS, but with IPS this could lead to a race\ncondition where we attempt to access DCN state while it's inaccessible,\nleading to a system hang when the NIU port is not disabled or register\naccesses that timeout and the display configuration in an undefined\nstate.\n\n[How]\nWe need to investigate why these accesses take longer than expected, but\nfor now we should disable the timeout on DCN35 to avoid this race\ncondition. Since the waits happen only at lower interrupt levels the\nrisk of taking too long at higher IRQ and causing a system watchdog\ntimeout are minimal.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46870', 'https://git.kernel.org/stable/c/31c254c9cd4b122a10db297124f867107a696d83', 'https://git.kernel.org/stable/c/7c70e60fbf4bff1123f0e8d5cb1ae71df6164d7f', 'https://lore.kernel.org/linux-cve-announce/2024100958-CVE-2024-46870-f347@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46870', 'https://www.cve.org/CVERecord?id=CVE-2024-46870'], 'PublishedDate': '2024-10-09T14:15:07.463Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-46871', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46871', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX\n\n[Why & How]\nIt actually exposes '6' types in enum dmub_notification_type. Not 5. Using smaller\nnumber to create array dmub_callback & dmub_thread_offload has potential to access\nitem out of array bound. Fix it.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46871', 'https://git.kernel.org/stable/c/800a5ab673c4a61ca220cce177386723d91bdb37', 'https://git.kernel.org/stable/c/9f404b0bc2df3880758fb3c3bc7496f596f347d7', 'https://git.kernel.org/stable/c/ad28d7c3d989fc5689581664653879d664da76f0', 'https://git.kernel.org/stable/c/c592b6355b9b57b8e59fc5978ce1e14f64488a98', 'https://lore.kernel.org/linux-cve-announce/2024100958-CVE-2024-46871-15f4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46871', 'https://www.cve.org/CVERecord?id=CVE-2024-46871'], 'PublishedDate': '2024-10-09T14:15:07.533Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47658', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47658', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: crypto: stm32/cryp - call finalize with bh disabled', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: stm32/cryp - call finalize with bh disabled\n\nThe finalize operation in interrupt mode produce a produces a spinlock\nrecursion warning. The reason is the fact that BH must be disabled\nduring this process.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47658', 'https://git.kernel.org/stable/c/56ddb9aa3b324c2d9645b5a7343e46010cf3f6ce', 'https://git.kernel.org/stable/c/5d734665cd5d93270731e0ff1dd673fec677f447', 'https://git.kernel.org/stable/c/d93a2f86b0a998aa1f0870c85a2a60a0771ef89a', 'https://lore.kernel.org/linux-cve-announce/2024100959-CVE-2024-47658-0b23@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47658', 'https://www.cve.org/CVERecord?id=CVE-2024-47658'], 'PublishedDate': '2024-10-09T14:15:07.603Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47659', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47659', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: smack: tcp: ipv4, fix incorrect labeling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: tcp: ipv4, fix incorrect labeling\n\nCurrently, Smack mirrors the label of incoming tcp/ipv4 connections:\nwhen a label 'foo' connects to a label 'bar' with tcp/ipv4,\n'foo' always gets 'foo' in returned ipv4 packets. So,\n1) returned packets are incorrectly labeled ('foo' instead of 'bar')\n2) 'bar' can write to 'foo' without being authorized to write.\n\nHere is a scenario how to see this:\n\n* Take two machines, let's call them C and S,\n with active Smack in the default state\n (no settings, no rules, no labeled hosts, only builtin labels)\n\n* At S, add Smack rule 'foo bar w'\n (labels 'foo' and 'bar' are instantiated at S at this moment)\n\n* At S, at label 'bar', launch a program\n that listens for incoming tcp/ipv4 connections\n\n* From C, at label 'foo', connect to the listener at S.\n (label 'foo' is instantiated at C at this moment)\n Connection succeedes and works.\n\n* Send some data in both directions.\n* Collect network traffic of this connection.\n\nAll packets in both directions are labeled with the CIPSO\nof the label 'foo'. Hence, label 'bar' writes to 'foo' without\nbeing authorized, and even without ever being known at C.\n\nIf anybody cares: exactly the same happens with DCCP.\n\nThis behavior 1st manifested in release 2.6.29.4 (see Fixes below)\nand it looks unintentional. At least, no explanation was provided.\n\nI changed returned packes label into the 'bar',\nto bring it into line with the Smack documentation claims.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47659', 'https://git.kernel.org/stable/c/0776bcf9cb6de46fdd94d10118de1cf9b05f83b9', 'https://git.kernel.org/stable/c/0aea09e82eafa50a373fc8a4b84c1d4734751e2c', 'https://git.kernel.org/stable/c/2fe209d0ad2e2729f7e22b9b31a86cc3ff0db550', 'https://git.kernel.org/stable/c/4be9fd15c3c88775bdf6fa37acabe6de85beebff', 'https://git.kernel.org/stable/c/5b4b304f196c070342e32a4752e1fa2e22fc0671', 'https://git.kernel.org/stable/c/a948ec993541db4ef392b555c37a1186f4d61670', 'https://git.kernel.org/stable/c/d3703fa94116fed91f64c7d1c7d284fb4369070f', 'https://git.kernel.org/stable/c/d3f56c653c65f170b172d3c23120bc64ada645d8', 'https://lore.kernel.org/linux-cve-announce/2024100959-CVE-2024-47659-03a8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47659', 'https://www.cve.org/CVERecord?id=CVE-2024-47659'], 'PublishedDate': '2024-10-09T14:15:07.66Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47660', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47660', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fsnotify: clear PARENT_WATCHED flags lazily', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: clear PARENT_WATCHED flags lazily\n\nIn some setups directories can have many (usually negative) dentries.\nHence __fsnotify_update_child_dentry_flags() function can take a\nsignificant amount of time. Since the bulk of this function happens\nunder inode->i_lock this causes a significant contention on the lock\nwhen we remove the watch from the directory as the\n__fsnotify_update_child_dentry_flags() call from fsnotify_recalc_mask()\nraces with __fsnotify_update_child_dentry_flags() calls from\n__fsnotify_parent() happening on children. This can lead upto softlockup\nreports reported by users.\n\nFix the problem by calling fsnotify_update_children_dentry_flags() to\nset PARENT_WATCHED flags only when parent starts watching children.\n\nWhen parent stops watching children, clear false positive PARENT_WATCHED\nflags lazily in __fsnotify_parent() for each accessed child.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47660', 'https://git.kernel.org/stable/c/172e422ffea20a89bfdc672741c1aad6fbb5044e', 'https://git.kernel.org/stable/c/3f3ef1d9f66b93913ce2171120d9226b55acd41d', 'https://git.kernel.org/stable/c/7ef1d2e240c32b1f337a37232d037b07e3919e1a', 'https://git.kernel.org/stable/c/d8c42405fc3507cc43ba7e4986a773c3fc633f6e', 'https://git.kernel.org/stable/c/f9a48bc3dd9099935751458a5bbbea4b7c28abc8', 'https://git.kernel.org/stable/c/fc1b1e135c3f72382f792e6c319fc088d5523ad5', 'https://lore.kernel.org/linux-cve-announce/2024100959-CVE-2024-47660-2d61@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47660', 'https://www.cve.org/CVERecord?id=CVE-2024-47660'], 'PublishedDate': '2024-10-09T14:15:07.73Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47661', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47661', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Avoid overflow from uint32_t to uint8_t', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid overflow from uint32_t to uint8_t\n\n[WHAT & HOW]\ndmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned\n0xFFFF. Fix it by changing it to uint8_t with value of 0xFF.\n\nThis fixes 2 INTEGER_OVERFLOW issues reported by Coverity.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47661', 'https://git.kernel.org/stable/c/30d1b783b6eeaf49d311a072c70d618d993d01ec', 'https://git.kernel.org/stable/c/d6b54900c564e35989cf6813e4071504fa0a90e0', 'https://lore.kernel.org/linux-cve-announce/2024100930-CVE-2024-47661-a6c1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47661', 'https://www.cve.org/CVERecord?id=CVE-2024-47661'], 'PublishedDate': '2024-10-09T15:15:15.02Z', 'LastModifiedDate': '2024-10-15T16:03:29.26Z'}, {'VulnerabilityID': 'CVE-2024-47662', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47662', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Remove register from DCN35 DMCUB diagnostic collection\n\n[Why]\nThese registers should not be read from driver and triggering the\nsecurity violation when DMCUB work times out and diagnostics are\ncollected blocks Z8 entry.\n\n[How]\nRemove the register read from DCN35.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47662', 'https://git.kernel.org/stable/c/466423c6dd8af23ebb3a69d43434d01aed0db356', 'https://git.kernel.org/stable/c/eba4b2a38ccdf074a053834509545703d6df1d57', 'https://lore.kernel.org/linux-cve-announce/2024100931-CVE-2024-47662-74f4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47662', 'https://www.cve.org/CVERecord?id=CVE-2024-47662'], 'PublishedDate': '2024-10-09T15:15:15.08Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47663', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47663', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: staging: iio: frequency: ad9834: Validate frequency parameter value', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: iio: frequency: ad9834: Validate frequency parameter value\n\nIn ad9834_write_frequency() clk_get_rate() can return 0. In such case\nad9834_calc_freqreg() call will lead to division by zero. Checking\n'if (fout > (clk_freq / 2))' doesn't protect in case of 'fout' is 0.\nad9834_write_frequency() is called from ad9834_write(), where fout is\ntaken from text buffer, which can contain any value.\n\nModify parameters checking.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47663', 'https://git.kernel.org/stable/c/0e727707a239d5c519fc9abc2f0fd913516a7e47', 'https://git.kernel.org/stable/c/3ba9abfcaa9e16bb91ed7e0e2b42e94a157a953e', 'https://git.kernel.org/stable/c/41cc91e3138fe52f8da92a81bebcd0e6cf488c53', 'https://git.kernel.org/stable/c/8961b245e8f92bccbaacfbbdf69eba60e3e7c227', 'https://git.kernel.org/stable/c/b48aa991758999d4e8f9296c5bbe388f293ef465', 'https://git.kernel.org/stable/c/d8b09a5edc4a634373158c1a405491de3c52e58a', 'https://git.kernel.org/stable/c/dc12e49f970b08d8b007b8981b97e2eb93c0e89d', 'https://lore.kernel.org/linux-cve-announce/2024100904-CVE-2024-47663-9bdc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47663', 'https://www.cve.org/CVERecord?id=CVE-2024-47663'], 'PublishedDate': '2024-10-09T15:15:15.15Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47664', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47664', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware\n\nIf the value of max_speed_hz is 0, it may cause a division by zero\nerror in hisi_calc_effective_speed().\nThe value of max_speed_hz is provided by firmware.\nFirmware is generally considered as a trusted domain. However, as\ndivision by zero errors can cause system failure, for defense measure,\nthe value of max_speed is validated here. So 0 is regarded as invalid\nand an error code is returned.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47664', 'https://git.kernel.org/stable/c/16ccaf581da4fcf1e4d66086cf37263f9a656d43', 'https://git.kernel.org/stable/c/5127c42c77de18651aa9e8e0a3ced190103b449c', 'https://git.kernel.org/stable/c/ee73a15d4a8ce8fb02d7866f7cf78fcdd16f0fcc', 'https://lore.kernel.org/linux-cve-announce/2024100904-CVE-2024-47664-f6bd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47664', 'https://www.cve.org/CVERecord?id=CVE-2024-47664'], 'PublishedDate': '2024-10-09T15:15:15.223Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47665', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47665', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup\n\nDefinitely condition dma_get_cache_alignment * defined value > 256\nduring driver initialization is not reason to BUG_ON(). Turn that to\ngraceful error out with -EINVAL.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47665', 'https://git.kernel.org/stable/c/2666085335bdfedf90d91f4071490ad3980be785', 'https://git.kernel.org/stable/c/5a022269abb22809f2a174b90f200fc4b9526058', 'https://git.kernel.org/stable/c/8a2be2f1db268ec735419e53ef04ca039fc027dc', 'https://git.kernel.org/stable/c/cacb76df247a7cd842ff29755a523b1cba6c0508', 'https://git.kernel.org/stable/c/e2d14bfda9eb5393f8a17008afe2aa7fe0a29815', 'https://lore.kernel.org/linux-cve-announce/2024100905-CVE-2024-47665-901e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47665', 'https://www.cve.org/CVERecord?id=CVE-2024-47665'], 'PublishedDate': '2024-10-09T15:15:15.29Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47666', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47666', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: pm80xx: Set phy->enable_completion only when we wait for it', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm80xx: Set phy->enable_completion only when we wait for it\n\npm8001_phy_control() populates the enable_completion pointer with a stack\naddress, sends a PHY_LINK_RESET / PHY_HARD_RESET, waits 300 ms, and\nreturns. The problem arises when a phy control response comes late. After\n300 ms the pm8001_phy_control() function returns and the passed\nenable_completion stack address is no longer valid. Late phy control\nresponse invokes complete() on a dangling enable_completion pointer which\nleads to a kernel crash.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47666', 'https://git.kernel.org/stable/c/7b1d779647afaea9185fa2f150b1721e7c1aae89', 'https://git.kernel.org/stable/c/e4f949ef1516c0d74745ee54a0f4882c1f6c7aea', 'https://git.kernel.org/stable/c/f14d3e1aa613311c744af32d75125e95fc8ffb84', 'https://lore.kernel.org/linux-cve-announce/2024100905-CVE-2024-47666-0015@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47666', 'https://www.cve.org/CVERecord?id=CVE-2024-47666'], 'PublishedDate': '2024-10-09T15:15:15.353Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47667', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47667', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)\n\nErrata #i2037 in AM65x/DRA80xM Processors Silicon Revision 1.0\n(SPRZ452D_July 2018_Revised December 2019 [1]) mentions when an\ninbound PCIe TLP spans more than two internal AXI 128-byte bursts,\nthe bus may corrupt the packet payload and the corrupt data may\ncause associated applications or the processor to hang.\n\nThe workaround for Errata #i2037 is to limit the maximum read\nrequest size and maximum payload size to 128 bytes. Add workaround\nfor Errata #i2037 here.\n\nThe errata and workaround is applicable only to AM65x SR 1.0 and\nlater versions of the silicon will have this fixed.\n\n[1] -> https://www.ti.com/lit/er/sprz452i/sprz452i.pdf', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47667', 'https://git.kernel.org/stable/c/135843c351c08df72bdd4b4ebea53c8052a76881', 'https://git.kernel.org/stable/c/576d0fb6f8d4bd4695e70eee173a1b9c7bae9572', 'https://git.kernel.org/stable/c/86f271f22bbb6391410a07e08d6ca3757fda01fa', 'https://git.kernel.org/stable/c/af218c803fe298ddf00abef331aa526b20d7ea61', 'https://git.kernel.org/stable/c/cfb006e185f64edbbdf7869eac352442bc76b8f6', 'https://git.kernel.org/stable/c/dd47051c76c8acd8cb983f01b4d1265da29cb66a', 'https://git.kernel.org/stable/c/ebbdbbc580c1695dec283d0ba6448729dc993246', 'https://lore.kernel.org/linux-cve-announce/2024100905-CVE-2024-47667-2d01@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47667', 'https://www.cve.org/CVERecord?id=CVE-2024-47667'], 'PublishedDate': '2024-10-09T15:15:15.43Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47668', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47668', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()\n\nIf we need to increase the tree depth, allocate a new node, and then\nrace with another thread that increased the tree depth before us, we'll\nstill have a preallocated node that might be used later.\n\nIf we then use that node for a new non-root node, it'll still have a\npointer to the old root instead of being zeroed - fix this by zeroing it\nin the cmpxchg failure path.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47668', 'https://git.kernel.org/stable/c/0f078f8ca93b28a34e20bd050f12cd4efeee7c0f', 'https://git.kernel.org/stable/c/0f27f4f445390cb7f73d4209cb2bf32834dc53da', 'https://git.kernel.org/stable/c/99418ec776a39609f50934720419e0b464ca2283', 'https://git.kernel.org/stable/c/ad5ee9feebc2eb8cfc76ed74a2d6e55343b0e169', 'https://git.kernel.org/stable/c/b2f11c6f3e1fc60742673b8675c95b78447f3dae', 'https://git.kernel.org/stable/c/d942e855324a60107025c116245095632476613e', 'https://git.kernel.org/stable/c/ebeff038744c498a036e7a92eb8e433ae0a386d7', 'https://lore.kernel.org/linux-cve-announce/2024100906-CVE-2024-47668-6b53@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47668', 'https://www.cve.org/CVERecord?id=CVE-2024-47668'], 'PublishedDate': '2024-10-09T15:15:15.513Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47669', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47669', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: fix state management in error path of log writing function', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix state management in error path of log writing function\n\nAfter commit a694291a6211 ("nilfs2: separate wait function from\nnilfs_segctor_write") was applied, the log writing function\nnilfs_segctor_do_construct() was able to issue I/O requests continuously\neven if user data blocks were split into multiple logs across segments,\nbut two potential flaws were introduced in its error handling.\n\nFirst, if nilfs_segctor_begin_construction() fails while creating the\nsecond or subsequent logs, the log writing function returns without\ncalling nilfs_segctor_abort_construction(), so the writeback flag set on\npages/folios will remain uncleared. This causes page cache operations to\nhang waiting for the writeback flag. For example,\ntruncate_inode_pages_final(), which is called via nilfs_evict_inode() when\nan inode is evicted from memory, will hang.\n\nSecond, the NILFS_I_COLLECTED flag set on normal inodes remain uncleared. \nAs a result, if the next log write involves checkpoint creation, that\'s\nfine, but if a partial log write is performed that does not, inodes with\nNILFS_I_COLLECTED set are erroneously removed from the "sc_dirty_files"\nlist, and their data and b-tree blocks may not be written to the device,\ncorrupting the block mapping.\n\nFix these issues by uniformly calling nilfs_segctor_abort_construction()\non failure of each step in the loop in nilfs_segctor_do_construct(),\nhaving it clean up logs and segment usages according to progress, and\ncorrecting the conditions for calling nilfs_redirty_inodes() to ensure\nthat the NILFS_I_COLLECTED flag is cleared.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47669', 'https://git.kernel.org/stable/c/036441e8438b29111fa75008f0ce305fb4e83c0a', 'https://git.kernel.org/stable/c/0a1a961bde4351dc047ffdeb2f1311ca16a700cc', 'https://git.kernel.org/stable/c/30562eff4a6dd35c4b5be9699ef61ad9f5f20a06', 'https://git.kernel.org/stable/c/3e349d7191f0688fc9808ef24fd4e4b4ef5ca876', 'https://git.kernel.org/stable/c/40a2757de2c376ef8a08d9ee9c81e77f3c750adf', 'https://git.kernel.org/stable/c/6576dd6695f2afca3f4954029ac4a64f82ba60ab', 'https://git.kernel.org/stable/c/74866c16ea2183f52925fa5d76061a1fe7f7737b', 'https://git.kernel.org/stable/c/efdde00d4a1ef10bb71e09ebc67823a3d3ad725b', 'https://lore.kernel.org/linux-cve-announce/2024100906-CVE-2024-47669-135c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47669', 'https://www.cve.org/CVERecord?id=CVE-2024-47669'], 'PublishedDate': '2024-10-09T15:15:15.59Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47670', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47670', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ocfs2: add bounds checking to ocfs2_xattr_find_entry()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: add bounds checking to ocfs2_xattr_find_entry()\n\nAdd a paranoia check to make sure it doesn't stray beyond valid memory\nregion containing ocfs2 xattr entries when scanning for a match. It will\nprevent out-of-bound access in case of crafted images.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47670', 'https://git.kernel.org/stable/c/1f6e167d6753fe3ea493cdc7f7de8d03147a4d39', 'https://git.kernel.org/stable/c/34759b7e4493d7337cbc414c132cef378c492a2c', 'https://git.kernel.org/stable/c/5bbe51eaf01a5dd6fb3f0dea81791e5dbc6dc6dd', 'https://git.kernel.org/stable/c/8e7bef408261746c160853fc27df3139659f5f77', 'https://git.kernel.org/stable/c/9b32539590a8e6400ac2f6e7cf9cbb8e08711a2f', 'https://git.kernel.org/stable/c/9e3041fecdc8f78a5900c3aa51d3d756e73264d6', 'https://lore.kernel.org/linux-cve-announce/2024100919-CVE-2024-47670-53f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47670', 'https://www.cve.org/CVERecord?id=CVE-2024-47670'], 'PublishedDate': '2024-10-09T15:15:15.673Z', 'LastModifiedDate': '2024-10-17T14:15:13.56Z'}, {'VulnerabilityID': 'CVE-2024-47671', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47671', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: USB: usbtmc: prevent kernel-usb-infoleak', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: usbtmc: prevent kernel-usb-infoleak\n\nThe syzbot reported a kernel-usb-infoleak in usbtmc_write,\nwe need to clear the structure before filling fields.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47671', 'https://git.kernel.org/stable/c/0c927dfc0b9bd177f7ab6ee59ef0c4ea06c110a7', 'https://git.kernel.org/stable/c/16e0ab9ed3ae7d19ca8ee718ba4e09d5c0f909ca', 'https://git.kernel.org/stable/c/51297ef7ad7824ad577337f273cd092e81a9fa08', 'https://git.kernel.org/stable/c/625fa77151f00c1bd00d34d60d6f2e710b3f9aad', 'https://git.kernel.org/stable/c/6c7fc36da021b13c34c572a26ba336cd102418f8', 'https://git.kernel.org/stable/c/ba6269e187aa1b1f20faf3c458831a0d6350304b', 'https://git.kernel.org/stable/c/e872738e670ddd63e19f22d0d784f0bdf26ecba5', 'https://lore.kernel.org/linux-cve-announce/2024100922-CVE-2024-47671-6c52@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47671', 'https://www.cve.org/CVERecord?id=CVE-2024-47671'], 'PublishedDate': '2024-10-09T15:15:15.753Z', 'LastModifiedDate': '2024-10-17T14:15:13.697Z'}, {'VulnerabilityID': 'CVE-2024-47672', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47672', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead\n\nThere is a WARNING in iwl_trans_wait_tx_queues_empty() (that was\nrecently converted from just a message), that can be hit if we\nwait for TX queues to become empty after firmware died. Clearly,\nwe can't expect anything from the firmware after it's declared dead.\n\nDon't call iwl_trans_wait_tx_queues_empty() in this case. While it could\nbe a good idea to stop the flow earlier, the flush functions do some\nmaintenance work that is not related to the firmware, so keep that part\nof the code running even when the firmware is not running.\n\n[edit commit message]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47672', 'https://git.kernel.org/stable/c/1afed66cb271b3e65fe9df1c9fba2bf4b1f55669', 'https://git.kernel.org/stable/c/1b0cd832c9607f41f84053b818e0b7908510a3b9', 'https://git.kernel.org/stable/c/3a84454f5204718ca5b4ad2c1f0bf2031e2403d1', 'https://git.kernel.org/stable/c/4d0a900ec470d392476c428875dbf053f8a0ae5e', 'https://git.kernel.org/stable/c/7188b7a72320367554b76d8f298417b070b05dd3', 'https://git.kernel.org/stable/c/de46b1d24f5f752b3bd8b46673c2ea4239661244', 'https://lore.kernel.org/linux-cve-announce/2024100922-CVE-2024-47672-9bef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47672', 'https://www.cve.org/CVERecord?id=CVE-2024-47672'], 'PublishedDate': '2024-10-09T15:15:15.827Z', 'LastModifiedDate': '2024-10-17T14:15:13.78Z'}, {'VulnerabilityID': 'CVE-2024-47673', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47673', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: pause TCM when the firmware is stopped\n\nNot doing so will make us send a host command to the transport while the\nfirmware is not alive, which will trigger a WARNING.\n\nbad state = 0\nWARNING: CPU: 2 PID: 17434 at drivers/net/wireless/intel/iwlwifi/iwl-trans.c:115 iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi]\nRIP: 0010:iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi]\nCall Trace:\n \n iwl_mvm_send_cmd+0x40/0xc0 [iwlmvm]\n iwl_mvm_config_scan+0x198/0x260 [iwlmvm]\n iwl_mvm_recalc_tcm+0x730/0x11d0 [iwlmvm]\n iwl_mvm_tcm_work+0x1d/0x30 [iwlmvm]\n process_one_work+0x29e/0x640\n worker_thread+0x2df/0x690\n ? rescuer_thread+0x540/0x540\n kthread+0x192/0x1e0\n ? set_kthread_struct+0x90/0x90\n ret_from_fork+0x22/0x30', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47673', 'https://git.kernel.org/stable/c/0668ebc8c2282ca1e7eb96092a347baefffb5fe7', 'https://git.kernel.org/stable/c/2c61b561baf92a2860c76c2302a62169e22c21cc', 'https://git.kernel.org/stable/c/55086c97a55d781b04a2667401c75ffde190135c', 'https://git.kernel.org/stable/c/5948a191906b54e10f02f6b7a7670243a39f99f4', 'https://git.kernel.org/stable/c/a15df5f37fa3a8b7a8ec7a339d1e897bc524e28f', 'https://lore.kernel.org/linux-cve-announce/2024100922-CVE-2024-47673-9110@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47673', 'https://www.cve.org/CVERecord?id=CVE-2024-47673'], 'PublishedDate': '2024-10-09T15:15:15.9Z', 'LastModifiedDate': '2024-10-17T14:15:13.853Z'}, {'VulnerabilityID': 'CVE-2024-47674', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47674', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: avoid leaving partial pfn mappings around in error case', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: avoid leaving partial pfn mappings around in error case\n\nAs Jann points out, PFN mappings are special, because unlike normal\nmemory mappings, there is no lifetime information associated with the\nmapping - it is just a raw mapping of PFNs with no reference counting of\na 'struct page'.\n\nThat's all very much intentional, but it does mean that it's easy to\nmess up the cleanup in case of errors. Yes, a failed mmap() will always\neventually clean up any partial mappings, but without any explicit\nlifetime in the page table mapping itself, it's very easy to do the\nerror handling in the wrong order.\n\nIn particular, it's easy to mistakenly free the physical backing store\nbefore the page tables are actually cleaned up and (temporarily) have\nstale dangling PTE entries.\n\nTo make this situation less error-prone, just make sure that any partial\npfn mapping is torn down early, before any other error handling.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47674', 'https://git.kernel.org/linus/79a61cc3fc0466ad2b7b89618a6157785f0293b3 (6.11)', 'https://git.kernel.org/stable/c/5b2c8b34f6d76bfbd1dd4936eb8a0fbfb9af3959', 'https://git.kernel.org/stable/c/65d0db500d7c07f0f76fc24a4d837791c4862cd2', 'https://git.kernel.org/stable/c/79a61cc3fc0466ad2b7b89618a6157785f0293b3', 'https://git.kernel.org/stable/c/954fd4c81f22c4b6ba65379a81fd252971bf4ef3', 'https://git.kernel.org/stable/c/a95a24fcaee1b892e47d5e6dcc403f713874ee80', 'https://lore.kernel.org/linux-cve-announce/2024101538-CVE-2024-47674-ba1f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47674', 'https://www.cve.org/CVERecord?id=CVE-2024-47674'], 'PublishedDate': '2024-10-15T11:15:13.073Z', 'LastModifiedDate': '2024-10-18T14:50:02.71Z'}, {'VulnerabilityID': 'CVE-2017-0537', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-0537', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'An information disclosure vulnerability in the kernel USB gadget driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-31614969.', 'Severity': 'LOW', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N', 'V2Score': 2.6, 'V3Score': 4.7}}, 'References': ['http://www.securityfocus.com/bid/96831', 'http://www.securitytracker.com/id/1037968', 'https://android.googlesource.com/kernel/tegra.git/+/389b185cb2f17fff994dbdf8d4bac003d4b2b6b3%5E%21/#F0', 'https://lore.kernel.org/lkml/1484647168-30135-1-git-send-email-jilin@nvidia.com/#t', 'https://source.android.com/security/bulletin/2017-01-01.html', 'https://source.android.com/security/bulletin/2017-03-01', 'https://source.android.com/security/bulletin/2017-03-01.html', 'https://www.cve.org/CVERecord?id=CVE-2017-0537'], 'PublishedDate': '2017-03-08T01:59:03.127Z', 'LastModifiedDate': '2017-07-17T13:18:15.89Z'}, {'VulnerabilityID': 'CVE-2017-13165', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13165', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.', 'Severity': 'LOW', 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 4.6, 'V3Score': 7.8}}, 'References': ['https://github.com/aosp-mirror/platform_system_core/commit/15ffc53f6d57a46e3041453865311035a18e047a', 'https://source.android.com/security/bulletin/pixel/2017-12-01', 'https://www.cve.org/CVERecord?id=CVE-2017-13165'], 'PublishedDate': '2017-12-06T14:29:01.333Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2017-13693', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13693', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ACPI operand cache leak in dsutils.c', 'Description': 'The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.', 'Severity': 'LOW', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:C/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/100502', 'https://access.redhat.com/security/cve/CVE-2017-13693', 'https://github.com/acpica/acpica/pull/295/commits/987a3b5cf7175916e2a4b6ea5b8e70f830dfe732', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13693', 'https://patchwork.kernel.org/patch/9919053/', 'https://www.cve.org/CVERecord?id=CVE-2017-13693'], 'PublishedDate': '2017-08-25T08:29:00.273Z', 'LastModifiedDate': '2017-09-20T14:51:00.41Z'}, {'VulnerabilityID': 'CVE-2018-1121', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-1121', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'procps: process hiding through race condition enumerating /proc', 'Description': "procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.", 'Severity': 'LOW', 'CweIDs': ['CWE-362', 'CWE-367'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:P/A:N', 'V3Vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V2Score': 4.3, 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L', 'V3Score': 3.9}}, 'References': ['http://seclists.org/oss-sec/2018/q2/122', 'http://www.securityfocus.com/bid/104214', 'https://access.redhat.com/security/cve/CVE-2018-1121', 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121', 'https://nvd.nist.gov/vuln/detail/CVE-2018-1121', 'https://www.cve.org/CVERecord?id=CVE-2018-1121', 'https://www.exploit-db.com/exploits/44806/', 'https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt'], 'PublishedDate': '2018-06-13T20:29:00.337Z', 'LastModifiedDate': '2020-06-30T16:15:14.393Z'}, {'VulnerabilityID': 'CVE-2018-12928', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12928', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: NULL pointer dereference in hfs_ext_read_extent in hfs.ko', 'Description': 'In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5}}, 'References': ['http://www.securityfocus.com/bid/104593', 'https://access.redhat.com/security/cve/CVE-2018-12928', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763384', 'https://groups.google.com/forum/#!msg/syzkaller-bugs/9SgQk_6tSZ4/zLhTm4r1AwAJ', 'https://lore.kernel.org/linux-fsdevel/20180418173028.GA30953@bombadil.infradead.org/', 'https://marc.info/?l=linux-fsdevel&m=152407263325766&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12928', 'https://www.cve.org/CVERecord?id=CVE-2018-12928'], 'PublishedDate': '2018-06-28T14:29:00.353Z', 'LastModifiedDate': '2018-08-21T11:55:37.35Z'}, {'VulnerabilityID': 'CVE-2018-12929', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12929', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free in ntfs_read_locked_inode in the ntfs.ko', 'Description': 'ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['http://www.securityfocus.com/bid/104588', 'https://access.redhat.com/errata/RHSA-2019:0641', 'https://access.redhat.com/security/cve/CVE-2018-12929', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403', 'https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12929', 'https://www.cve.org/CVERecord?id=CVE-2018-12929'], 'PublishedDate': '2018-06-28T14:29:00.417Z', 'LastModifiedDate': '2019-03-26T13:35:51.317Z'}, {'VulnerabilityID': 'CVE-2018-12930', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12930', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: stack-based out-of-bounds write in ntfs_end_buffer_async_read in the ntfs.ko', 'Description': 'ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 7.2, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['http://www.securityfocus.com/bid/104588', 'https://access.redhat.com/errata/RHSA-2019:0641', 'https://access.redhat.com/security/cve/CVE-2018-12930', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403', 'https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12930', 'https://www.cve.org/CVERecord?id=CVE-2018-12930'], 'PublishedDate': '2018-06-28T14:29:00.463Z', 'LastModifiedDate': '2019-03-26T13:35:37.397Z'}, {'VulnerabilityID': 'CVE-2018-12931', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12931', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: stack-based out-of-bounds write in ntfs_attr_find in the ntfs.ko', 'Description': 'ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 7.2, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['http://www.securityfocus.com/bid/104588', 'https://access.redhat.com/errata/RHSA-2019:0641', 'https://access.redhat.com/security/cve/CVE-2018-12931', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403', 'https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12931', 'https://www.cve.org/CVERecord?id=CVE-2018-12931'], 'PublishedDate': '2018-06-28T14:29:00.51Z', 'LastModifiedDate': '2019-03-26T13:35:20.957Z'}, {'VulnerabilityID': 'CVE-2019-14899', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-14899', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel', 'Description': 'A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.', 'Severity': 'LOW', 'CweIDs': ['CWE-300'], 'CVSS': {'nvd': {'V2Vector': 'AV:A/AC:M/Au:S/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 4.9, 'V3Score': 7.4}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.4}}, 'References': ['http://seclists.org/fulldisclosure/2020/Dec/32', 'http://seclists.org/fulldisclosure/2020/Jul/23', 'http://seclists.org/fulldisclosure/2020/Jul/24', 'http://seclists.org/fulldisclosure/2020/Jul/25', 'http://seclists.org/fulldisclosure/2020/Nov/20', 'http://www.openwall.com/lists/oss-security/2020/08/13/2', 'http://www.openwall.com/lists/oss-security/2020/10/07/3', 'http://www.openwall.com/lists/oss-security/2021/07/05/1', 'https://access.redhat.com/security/cve/CVE-2019-14899', 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899', 'https://nvd.nist.gov/vuln/detail/CVE-2019-14899', 'https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/', 'https://support.apple.com/kb/HT211288', 'https://support.apple.com/kb/HT211289', 'https://support.apple.com/kb/HT211290', 'https://support.apple.com/kb/HT211850', 'https://support.apple.com/kb/HT211931', 'https://www.cve.org/CVERecord?id=CVE-2019-14899', 'https://www.openwall.com/lists/oss-security/2019/12/05/1'], 'PublishedDate': '2019-12-11T15:15:14.263Z', 'LastModifiedDate': '2023-03-01T16:40:04.14Z'}, {'VulnerabilityID': 'CVE-2019-15213', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-15213', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free caused by malicious USB device in drivers/media/usb/dvb-usb/dvb-usb-init.c', 'Description': 'An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.', 'Severity': 'LOW', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 4.6}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.3}}, 'References': ['http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html', 'http://www.openwall.com/lists/oss-security/2019/08/20/2', 'https://access.redhat.com/security/cve/CVE-2019-15213', 'https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6cf97230cd5f36b7665099083272595c55d72be7', 'https://linux.oracle.com/cve/CVE-2019-15213.html', 'https://linux.oracle.com/errata/ELSA-2019-4872.html', 'https://lore.kernel.org/linux-media/fe983331d14442a96db3f71066ca0488a8921840.camel@decadent.org.uk/', 'https://nvd.nist.gov/vuln/detail/CVE-2019-15213', 'https://security.netapp.com/advisory/ntap-20190905-0002/', 'https://syzkaller.appspot.com/bug?id=a53c9c9dd2981bfdbfbcbc1ddbd35595eda8bced', 'https://www.cve.org/CVERecord?id=CVE-2019-15213'], 'PublishedDate': '2019-08-19T22:15:11.253Z', 'LastModifiedDate': '2023-11-09T14:44:33.733Z'}, {'VulnerabilityID': 'CVE-2019-19378', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-19378', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: out-of-bounds write in index_rbio_pages in fs/btrfs/raid56.c', 'Description': 'In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 6.8, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-19378', 'https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19378', 'https://nvd.nist.gov/vuln/detail/CVE-2019-19378', 'https://security.netapp.com/advisory/ntap-20200103-0001/', 'https://www.cve.org/CVERecord?id=CVE-2019-19378'], 'PublishedDate': '2019-11-29T17:15:11.84Z', 'LastModifiedDate': '2020-01-03T11:15:14.997Z'}, {'VulnerabilityID': 'CVE-2019-19814', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-19814', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: out-of-bounds write in __remove_dirty_segment in fs/f2fs/segment.c', 'Description': 'In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 9.3, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-19814', 'https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19814', 'https://nvd.nist.gov/vuln/detail/CVE-2019-19814', 'https://security.netapp.com/advisory/ntap-20200103-0001/', 'https://www.cve.org/CVERecord?id=CVE-2019-19814'], 'PublishedDate': '2019-12-17T06:15:12.843Z', 'LastModifiedDate': '2020-01-03T11:15:16.48Z'}, {'VulnerabilityID': 'CVE-2020-35501', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2020-35501', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: audit not logging access to syscall open_by_handle_at for users with CAP_DAC_READ_SEARCH capability', 'Description': 'A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem', 'Severity': 'LOW', 'CweIDs': ['CWE-863'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:P/A:N', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N', 'V2Score': 3.6, 'V3Score': 3.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 3.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2020-35501', 'https://bugzilla.redhat.com/show_bug.cgi?id=1908577', 'https://listman.redhat.com/archives/linux-audit/2018-July/msg00041.html', 'https://nvd.nist.gov/vuln/detail/CVE-2020-35501', 'https://www.cve.org/CVERecord?id=CVE-2020-35501', 'https://www.openwall.com/lists/oss-security/2021/02/18/1'], 'PublishedDate': '2022-03-30T16:15:08.673Z', 'LastModifiedDate': '2022-12-02T19:54:37.647Z'}, {'VulnerabilityID': 'CVE-2021-26934', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-26934', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'An issue was discovered in the Linux kernel 4.18 through 5.10.16, as u ...', 'Description': "An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.", 'Severity': 'LOW', 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 4.6, 'V3Score': 7.8}}, 'References': ['http://xenbits.xen.org/xsa/advisory-363.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4GELN5E6MDR5KQBJF5M5COUUED3YFZTD/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOAJBVAVR6RSCUCHNXPVSNRPSFM7INMP/', 'https://nvd.nist.gov/vuln/detail/CVE-2021-26934', 'https://security.netapp.com/advisory/ntap-20210326-0001/', 'https://www.cve.org/CVERecord?id=CVE-2021-26934', 'https://www.openwall.com/lists/oss-security/2021/02/16/2', 'https://xenbits.xen.org/xsa/advisory-363.html'], 'PublishedDate': '2021-02-17T02:15:13.143Z', 'LastModifiedDate': '2023-11-07T03:31:50.59Z'}, {'VulnerabilityID': 'CVE-2022-44034', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-44034', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'Kernel: A use-after-free due to race between scr24x_open() and scr24x_remove()', 'Description': 'An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().', 'Severity': 'LOW', 'CweIDs': ['CWE-362'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-44034', 'https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b12f050c76f090cc6d0aebe0ef76fed79ec3f15', 'https://lore.kernel.org/lkml/20220916050333.GA188358%40ubuntu/', 'https://lore.kernel.org/lkml/20220916050333.GA188358@ubuntu/', 'https://lore.kernel.org/lkml/20220919101825.GA313940%40ubuntu/', 'https://lore.kernel.org/lkml/20220919101825.GA313940@ubuntu/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-44034', 'https://www.cve.org/CVERecord?id=CVE-2022-44034'], 'PublishedDate': '2022-10-30T01:15:08.937Z', 'LastModifiedDate': '2024-03-25T01:15:52.787Z'}, {'VulnerabilityID': 'CVE-2022-45884', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-45884', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free due to race condition occurring in dvb_register_device()', 'Description': 'An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.', 'Severity': 'LOW', 'CweIDs': ['CWE-362', 'CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:7549', 'https://access.redhat.com/security/cve/CVE-2022-45884', 'https://bugzilla.redhat.com/2148510', 'https://bugzilla.redhat.com/2148517', 'https://bugzilla.redhat.com/2151956', 'https://bugzilla.redhat.com/2154178', 'https://bugzilla.redhat.com/2224048', 'https://bugzilla.redhat.com/2240249', 'https://bugzilla.redhat.com/2241924', 'https://bugzilla.redhat.com/show_bug.cgi?id=2148510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2148517', 'https://bugzilla.redhat.com/show_bug.cgi?id=2151956', 'https://bugzilla.redhat.com/show_bug.cgi?id=2154178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2224048', 'https://bugzilla.redhat.com/show_bug.cgi?id=2240249', 'https://bugzilla.redhat.com/show_bug.cgi?id=2241924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45884', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45919', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1192', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2163', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3812', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5178', 'https://errata.almalinux.org/8/ALSA-2023-7549.html', 'https://errata.rockylinux.org/RLSA-2023:7549', 'https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=627bb528b086b4136315c25d6a447a98ea9448d3', 'https://linux.oracle.com/cve/CVE-2022-45884.html', 'https://linux.oracle.com/errata/ELSA-2023-7549.html', 'https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel%40gmail.com/', 'https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel@gmail.com/', 'https://lore.kernel.org/linux-media/20221115131822.6640-4-imv4bel%40gmail.com/', 'https://lore.kernel.org/linux-media/20221115131822.6640-4-imv4bel@gmail.com/', 'https://lore.kernel.org/linux-media/20221117045925.14297-4-imv4bel@gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-45884', 'https://security.netapp.com/advisory/ntap-20230113-0006/', 'https://www.cve.org/CVERecord?id=CVE-2022-45884'], 'PublishedDate': '2022-11-25T04:15:09.18Z', 'LastModifiedDate': '2024-03-25T01:15:52.84Z'}, {'VulnerabilityID': 'CVE-2023-33053', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-33053', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'Memory corruption in Kernel while parsing metadata.', 'Severity': 'LOW', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://git.codelinaro.org/clo/la/kernel/msm-5.4/-/commit/06426824a281c9aef5bf0c50927eae9c7431db1e', 'https://www.cve.org/CVERecord?id=CVE-2023-33053', 'https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin'], 'PublishedDate': '2023-12-05T03:15:11.707Z', 'LastModifiedDate': '2024-04-12T16:15:18.403Z'}, {'VulnerabilityID': 'CVE-2023-4010', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-4010', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: hcd: malformed USB descriptor leads to infinite loop in usb_giveback_urb()', 'Description': 'A flaw was found in the USB Host Controller Driver framework in the Linux kernel. The usb_giveback_urb function has a logic loophole in its implementation. Due to the inappropriate judgment condition of the goto statement, the function cannot return under the input of a specific malformed descriptor file, so it falls into an endless loop, resulting in a denial of service.', 'Severity': 'LOW', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-4010', 'https://bugzilla.redhat.com/show_bug.cgi?id=2227726', 'https://github.com/wanrenmi/a-usb-kernel-bug', 'https://github.com/wanrenmi/a-usb-kernel-bug/issues/1', 'https://nvd.nist.gov/vuln/detail/CVE-2023-4010', 'https://www.cve.org/CVERecord?id=CVE-2023-4010'], 'PublishedDate': '2023-07-31T17:15:10.277Z', 'LastModifiedDate': '2023-11-07T04:22:02.797Z'}, {'VulnerabilityID': 'CVE-2023-6238', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-6238', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: memory corruption via unprivileged user passthrough', 'Description': 'A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.', 'Severity': 'LOW', 'CweIDs': ['CWE-120'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-6238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2250834', 'https://lore.kernel.org/linux-nvme/20231013051458.39987-1-joshi.k@samsung.com/T/#u', 'https://lore.kernel.org/linux-nvme/20231016060519.231880-1-joshi.k@samsung.com/T/#u', 'https://nvd.nist.gov/vuln/detail/CVE-2023-6238', 'https://www.cve.org/CVERecord?id=CVE-2023-6238'], 'PublishedDate': '2023-11-21T21:15:09.273Z', 'LastModifiedDate': '2024-02-07T00:15:55.24Z'}, {'VulnerabilityID': 'CVE-2024-0564', 'PkgID': 'linux-aws-6.8-headers-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-headers-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-0564', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: max page sharing of Kernel Samepage Merging (KSM) may cause memory deduplication', 'Description': 'A flaw was found in the Linux kernel\'s memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the unmap to merge with the victim\'s page. The unmapping time depends on whether it merges with the victim\'s page and additional physical pages are created beyond the KSM\'s "max page share". Through these operations, the attacker can leak the victim\'s page.', 'Severity': 'LOW', 'CweIDs': ['CWE-99', 'CWE-203'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-0564', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1680513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2258514', 'https://link.springer.com/conference/wisa', 'https://nvd.nist.gov/vuln/detail/CVE-2024-0564', 'https://wisa.or.kr/accepted', 'https://www.cve.org/CVERecord?id=CVE-2024-0564'], 'PublishedDate': '2024-01-30T15:15:08.687Z', 'LastModifiedDate': '2024-10-16T15:15:14.11Z'}, {'VulnerabilityID': 'CVE-2024-43882', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43882', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: exec: Fix ToCToU between perm check and set-uid/gid usage', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Fix ToCToU between perm check and set-uid/gid usage\n\nWhen opening a file for exec via do_filp_open(), permission checking is\ndone against the file\'s metadata at that moment, and on success, a file\npointer is passed back. Much later in the execve() code path, the file\nmetadata (specifically mode, uid, and gid) is used to determine if/how\nto set the uid and gid. However, those values may have changed since the\npermissions check, meaning the execution may gain unintended privileges.\n\nFor example, if a file could change permissions from executable and not\nset-id:\n\n---------x 1 root root 16048 Aug 7 13:16 target\n\nto set-id and non-executable:\n\n---S------ 1 root root 16048 Aug 7 13:16 target\n\nit is possible to gain root privileges when execution should have been\ndisallowed.\n\nWhile this race condition is rare in real-world scenarios, it has been\nobserved (and proven exploitable) when package managers are updating\nthe setuid bits of installed programs. Such files start with being\nworld-executable but then are adjusted to be group-exec with a set-uid\nbit. For example, "chmod o-x,u+s target" makes "target" executable only\nby uid "root" and gid "cdrom", while also becoming setuid-root:\n\n-rwxr-xr-x 1 root cdrom 16048 Aug 7 13:16 target\n\nbecomes:\n\n-rwsr-xr-- 1 root cdrom 16048 Aug 7 13:16 target\n\nBut racing the chmod means users without group "cdrom" membership can\nget the permission to execute "target" just before the chmod, and when\nthe chmod finishes, the exec reaches brpm_fill_uid(), and performs the\nsetuid to root, violating the expressed authorization of "only cdrom\ngroup members can setuid to root".\n\nRe-check that we still have execute permissions in case the metadata\nhas changed. It would be better to keep a copy from the perm-check time,\nbut until we can do that refactoring, the least-bad option is to do a\nfull inode_permission() call (under inode lock). It is understood that\nthis is safe against dead-locks, but hardly optimal.', 'Severity': 'HIGH', 'CweIDs': ['CWE-367'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43882', 'https://git.kernel.org/linus/f50733b45d865f91db90919f8311e2127ce5a0cb (6.11-rc4)', 'https://git.kernel.org/stable/c/15469d46ba34559bfe7e3de6659115778c624759', 'https://git.kernel.org/stable/c/368f6985d46657b8b466a421dddcacd4051f7ada', 'https://git.kernel.org/stable/c/90dfbba89ad4f0d9c9744ecbb1adac4aa2ff4f3e', 'https://git.kernel.org/stable/c/9b424c5d4130d56312e2a3be17efb0928fec4d64', 'https://git.kernel.org/stable/c/d2a2a4714d80d09b0f8eb6438ab4224690b7121e', 'https://git.kernel.org/stable/c/d5c3c7e26275a2d83b894d30f7582a42853a958f', 'https://git.kernel.org/stable/c/f50733b45d865f91db90919f8311e2127ce5a0cb', 'https://git.kernel.org/stable/c/f6cfc6bcfd5e1cf76115b6450516ea4c99897ae1', 'https://linux.oracle.com/cve/CVE-2024-43882.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082152-CVE-2024-43882-4fa4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43882', 'https://www.cve.org/CVERecord?id=CVE-2024-43882'], 'PublishedDate': '2024-08-21T01:15:12.34Z', 'LastModifiedDate': '2024-09-03T13:25:39.747Z'}, {'VulnerabilityID': 'CVE-2013-7445', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2013-7445', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memory exhaustion via crafted Graphics Execution Manager (GEM) objects', 'Description': 'The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-399'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:C', 'V2Score': 7.8}, 'redhat': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V2Score': 4.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2013-7445', 'https://bugzilla.kernel.org/show_bug.cgi?id=60533', 'https://lists.freedesktop.org/archives/dri-devel/2015-September/089778.html (potential start towards fixing)', 'https://nvd.nist.gov/vuln/detail/CVE-2013-7445', 'https://www.cve.org/CVERecord?id=CVE-2013-7445'], 'PublishedDate': '2015-10-16T01:59:00.12Z', 'LastModifiedDate': '2015-10-16T16:22:25.587Z'}, {'VulnerabilityID': 'CVE-2015-8553', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2015-8553', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'xen: non-maskable interrupts triggerable by guests (xsa120)', 'Description': 'Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N', 'V2Score': 2.1, 'V3Score': 6.5}, 'redhat': {'V2Vector': 'AV:A/AC:M/Au:S/C:N/I:N/A:C', 'V2Score': 5.2}}, 'References': ['http://thread.gmane.org/gmane.linux.kernel/1924087/focus=1930758 (regression mention)', 'http://xenbits.xen.org/xsa/advisory-120.html', 'https://access.redhat.com/security/cve/CVE-2015-8553', 'https://nvd.nist.gov/vuln/detail/CVE-2015-8553', 'https://seclists.org/bugtraq/2019/Aug/18', 'https://www.cve.org/CVERecord?id=CVE-2015-8553', 'https://www.debian.org/security/2019/dsa-4497'], 'PublishedDate': '2016-04-13T15:59:07.307Z', 'LastModifiedDate': '2019-08-13T23:15:11.203Z'}, {'VulnerabilityID': 'CVE-2016-8660', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-8660', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: local DoS due to a page lock order bug in the XFS seek hole/data implementation', 'Description': 'The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implementation."', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-19'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V2Vector': 'AV:L/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.7, 'V3Score': 5.5}}, 'References': ['http://www.openwall.com/lists/oss-security/2016/10/13/8', 'http://www.securityfocus.com/bid/93558', 'https://access.redhat.com/security/cve/CVE-2016-8660', 'https://bugzilla.redhat.com/show_bug.cgi?id=1384851', 'https://lore.kernel.org/linux-xfs/895314622.769515.1476375930648.JavaMail.zimbra@redhat.com/', 'https://marc.info/?l=linux-fsdevel&m=147639177409294&w=2', 'https://marc.info/?l=linux-xfs&m=149498118228320&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2016-8660', 'https://www.cve.org/CVERecord?id=CVE-2016-8660'], 'PublishedDate': '2016-10-16T21:59:14.333Z', 'LastModifiedDate': '2016-11-28T20:41:02.59Z'}, {'VulnerabilityID': 'CVE-2018-17977', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-17977', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service', 'Description': 'The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-400'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.9}}, 'References': ['http://www.securityfocus.com/bid/105539', 'https://access.redhat.com/security/cve/CVE-2018-17977', 'https://bugzilla.suse.com/show_bug.cgi?id=1111609', 'https://nvd.nist.gov/vuln/detail/CVE-2018-17977', 'https://www.cve.org/CVERecord?id=CVE-2018-17977', 'https://www.openwall.com/lists/oss-security/2018/10/05/5'], 'PublishedDate': '2018-10-08T17:29:00.653Z', 'LastModifiedDate': '2018-11-26T15:51:30.427Z'}, {'VulnerabilityID': 'CVE-2021-3714', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-3714', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Remote Page Deduplication Attacks', 'Description': 'A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-3714', 'https://arxiv.org/abs/2111.08553', 'https://arxiv.org/pdf/2111.08553.pdf', 'https://bugzilla.redhat.com/show_bug.cgi?id=1931327', 'https://nvd.nist.gov/vuln/detail/CVE-2021-3714', 'https://www.cve.org/CVERecord?id=CVE-2021-3714'], 'PublishedDate': '2022-08-23T16:15:09.6Z', 'LastModifiedDate': '2024-02-01T18:51:23.66Z'}, {'VulnerabilityID': 'CVE-2021-47599', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-47599', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: use latest_dev in btrfs_show_devname', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: use latest_dev in btrfs_show_devname\n\nThe test case btrfs/238 reports the warning below:\n\n WARNING: CPU: 3 PID: 481 at fs/btrfs/super.c:2509 btrfs_show_devname+0x104/0x1e8 [btrfs]\n CPU: 2 PID: 1 Comm: systemd Tainted: G W O 5.14.0-rc1-custom #72\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n Call trace:\n btrfs_show_devname+0x108/0x1b4 [btrfs]\n show_mountinfo+0x234/0x2c4\n m_show+0x28/0x34\n seq_read_iter+0x12c/0x3c4\n vfs_read+0x29c/0x2c8\n ksys_read+0x80/0xec\n __arm64_sys_read+0x28/0x34\n invoke_syscall+0x50/0xf8\n do_el0_svc+0x88/0x138\n el0_svc+0x2c/0x8c\n el0t_64_sync_handler+0x84/0xe4\n el0t_64_sync+0x198/0x19c\n\nReason:\nWhile btrfs_prepare_sprout() moves the fs_devices::devices into\nfs_devices::seed_list, the btrfs_show_devname() searches for the devices\nand found none, leading to the warning as in above.\n\nFix:\nlatest_dev is updated according to the changes to the device list.\nThat means we could use the latest_dev->name to show the device name in\n/proc/self/mounts, the pointer will be always valid as it's assigned\nbefore the device is deleted from the list in remove or replace.\nThe RCU protection is sufficient as the device structure is freed after\nsynchronization.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-47599', 'https://git.kernel.org/linus/6605fd2f394bba0a0059df2b6cfc87b0b6d393a2 (5.16-rc1)', 'https://git.kernel.org/stable/c/6605fd2f394bba0a0059df2b6cfc87b0b6d393a2', 'https://git.kernel.org/stable/c/e342c2558016ead462f376b6c6c2ac5efc17f3b1', 'https://lore.kernel.org/linux-cve-announce/2024061921-CVE-2021-47599-37b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2021-47599', 'https://www.cve.org/CVERecord?id=CVE-2021-47599'], 'PublishedDate': '2024-06-19T15:15:54.483Z', 'LastModifiedDate': '2024-06-20T12:43:25.663Z'}, {'VulnerabilityID': 'CVE-2021-47615', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-47615', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/mlx5: Fix releasing unallocated memory in dereg MR flow', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix releasing unallocated memory in dereg MR flow\n\nFor the case of IB_MR_TYPE_DM the mr does doesn't have a umem, even though\nit is a user MR. This causes function mlx5_free_priv_descs() to think that\nit is a kernel MR, leading to wrongly accessing mr->descs that will get\nwrong values in the union which leads to attempt to release resources that\nwere not allocated in the first place.\n\nFor example:\n DMA-API: mlx5_core 0000:08:00.1: device driver tries to free DMA memory it has not allocated [device address=0x0000000000000000] [size=0 bytes]\n WARNING: CPU: 8 PID: 1021 at kernel/dma/debug.c:961 check_unmap+0x54f/0x8b0\n RIP: 0010:check_unmap+0x54f/0x8b0\n Call Trace:\n debug_dma_unmap_page+0x57/0x60\n mlx5_free_priv_descs+0x57/0x70 [mlx5_ib]\n mlx5_ib_dereg_mr+0x1fb/0x3d0 [mlx5_ib]\n ib_dereg_mr_user+0x60/0x140 [ib_core]\n uverbs_destroy_uobject+0x59/0x210 [ib_uverbs]\n uobj_destroy+0x3f/0x80 [ib_uverbs]\n ib_uverbs_cmd_verbs+0x435/0xd10 [ib_uverbs]\n ? uverbs_finalize_object+0x50/0x50 [ib_uverbs]\n ? lock_acquire+0xc4/0x2e0\n ? lock_acquired+0x12/0x380\n ? lock_acquire+0xc4/0x2e0\n ? lock_acquire+0xc4/0x2e0\n ? ib_uverbs_ioctl+0x7c/0x140 [ib_uverbs]\n ? lock_release+0x28a/0x400\n ib_uverbs_ioctl+0xc0/0x140 [ib_uverbs]\n ? ib_uverbs_ioctl+0x7c/0x140 [ib_uverbs]\n __x64_sys_ioctl+0x7f/0xb0\n do_syscall_64+0x38/0x90\n\nFix it by reorganizing the dereg flow and mlx5_ib_mr structure:\n - Move the ib_umem field into the user MRs structure in the union as it's\n applicable only there.\n - Function mlx5_ib_dereg_mr() will now call mlx5_free_priv_descs() only\n in case there isn't udata, which indicates that this isn't a user MR.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-47615', 'https://git.kernel.org/linus/f0ae4afe3d35e67db042c58a52909e06262b740f (5.16-rc5)', 'https://git.kernel.org/stable/c/c44979ace49b4aede3cc7cb5542316e53a4005c9', 'https://git.kernel.org/stable/c/e3bc4d4b50cae7db08e50dbe43f771c906e97701', 'https://git.kernel.org/stable/c/f0ae4afe3d35e67db042c58a52909e06262b740f', 'https://lore.kernel.org/linux-cve-announce/2024061909-CVE-2021-47615-3c6a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2021-47615', 'https://www.cve.org/CVERecord?id=CVE-2021-47615'], 'PublishedDate': '2024-06-19T15:15:56.03Z', 'LastModifiedDate': '2024-06-20T12:43:25.663Z'}, {'VulnerabilityID': 'CVE-2022-0400', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-0400', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Out of bounds read in the smc protocol stack', 'Description': 'An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-0400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2040604', 'https://bugzilla.redhat.com/show_bug.cgi?id=2040604 (not public)', 'https://bugzilla.redhat.com/show_bug.cgi?id=2044575', 'https://nvd.nist.gov/vuln/detail/CVE-2022-0400', 'https://www.cve.org/CVERecord?id=CVE-2022-0400'], 'PublishedDate': '2022-08-29T15:15:09.423Z', 'LastModifiedDate': '2022-09-01T20:18:18.247Z'}, {'VulnerabilityID': 'CVE-2022-0480', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-0480', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion', 'Description': 'A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-0480', 'https://bugzilla.redhat.com/show_bug.cgi?id=2049700', 'https://git.kernel.org/linus/0f12156dff2862ac54235fc72703f18770769042 (5.15-rc1)', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0f12156dff2862ac54235fc72703f18770769042', 'https://github.com/kata-containers/kata-containers/issues/3373', 'https://linux.oracle.com/cve/CVE-2022-0480.html', 'https://linux.oracle.com/errata/ELSA-2024-2394.html', 'https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm%40linux-foundation.org/', 'https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm@linux-foundation.org/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-0480', 'https://ubuntu.com/security/CVE-2022-0480', 'https://www.cve.org/CVERecord?id=CVE-2022-0480'], 'PublishedDate': '2022-08-29T15:15:09.477Z', 'LastModifiedDate': '2023-03-03T18:49:53.213Z'}, {'VulnerabilityID': 'CVE-2022-3238', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3238', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously', 'Description': 'A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415', 'CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127927', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3238', 'https://www.cve.org/CVERecord?id=CVE-2022-3238'], 'PublishedDate': '2022-11-14T21:15:16.163Z', 'LastModifiedDate': '2022-11-17T20:24:18.537Z'}, {'VulnerabilityID': 'CVE-2022-48846', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: release rq qos structures for queue without disk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: release rq qos structures for queue without disk\n\nblkcg_init_queue() may add rq qos structures to request queue, previously\nblk_cleanup_queue() calls rq_qos_exit() to release them, but commit\n8e141f9eb803 ("block: drain file system I/O on del_gendisk")\nmoves rq_qos_exit() into del_gendisk(), so memory leak is caused\nbecause queues may not have disk, such as un-present scsi luns, nvme\nadmin queue, ...\n\nFixes the issue by adding rq_qos_exit() to blk_cleanup_queue() back.\n\nBTW, v5.18 won\'t need this patch any more since we move\nblkcg_init_queue()/blkcg_exit_queue() into disk allocation/release\nhandler, and patches have been in for-5.18/block.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48846', 'https://git.kernel.org/linus/daaca3522a8e67c46e39ef09c1d542e866f85f3b (5.17)', 'https://git.kernel.org/stable/c/60c2c8e2ef3a3ec79de8cbc80a06ca0c21df8c29', 'https://git.kernel.org/stable/c/d4ad8736ac982111bb0be8306bf19c8207f6600e', 'https://git.kernel.org/stable/c/daaca3522a8e67c46e39ef09c1d542e866f85f3b', 'https://lore.kernel.org/linux-cve-announce/2024071623-CVE-2022-48846-a1a8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48846', 'https://www.cve.org/CVERecord?id=CVE-2022-48846'], 'PublishedDate': '2024-07-16T13:15:11.883Z', 'LastModifiedDate': '2024-07-24T17:56:26.767Z'}, {'VulnerabilityID': 'CVE-2022-48929', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48929', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids.', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix crash due to out of bounds access into reg2btf_ids.\n\nWhen commit e6ac2450d6de ("bpf: Support bpf program calling kernel function") added\nkfunc support, it defined reg2btf_ids as a cheap way to translate the verifier\nreg type to the appropriate btf_vmlinux BTF ID, however\ncommit c25b2ae13603 ("bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL")\nmoved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after\nthe base register types, and defined other variants using type flag\ncomposition. However, now, the direct usage of reg->type to index into\nreg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to\nout of bounds access and kernel crash on dereference of bad pointer.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48929', 'https://git.kernel.org/linus/45ce4b4f9009102cd9f581196d480a59208690c1 (5.17-rc6)', 'https://git.kernel.org/stable/c/45ce4b4f9009102cd9f581196d480a59208690c1', 'https://git.kernel.org/stable/c/8c39925e98d498b9531343066ef82ae39e41adae', 'https://git.kernel.org/stable/c/f0ce1bc9e0235dd7412240be493d7ea65ed9eadc', 'https://lore.kernel.org/linux-cve-announce/2024082222-CVE-2022-48929-857d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48929', 'https://www.cve.org/CVERecord?id=CVE-2022-48929'], 'PublishedDate': '2024-08-22T04:15:15.773Z', 'LastModifiedDate': '2024-08-23T02:00:22.653Z'}, {'VulnerabilityID': 'CVE-2023-0030', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-0030', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Use after Free in nvkm_vmm_pfn_map', 'Description': 'A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-0030', 'https://bugzilla.redhat.com/show_bug.cgi?id=2157270', 'https://git.kernel.org/linus/729eba3355674f2d9524629b73683ba1d1cd3f10 (5.0-rc1)', 'https://github.com/torvalds/linux/commit/729eba3355674f2d9524629b73683ba1d1cd3f10', 'https://lore.kernel.org/all/20221230072758.443644-1-zyytlz.wz@163.com/', 'https://lore.kernel.org/all/63d485b2.170a0220.4af4c.d54f@mx.google.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-0030', 'https://security.netapp.com/advisory/ntap-20230413-0010/', 'https://www.cve.org/CVERecord?id=CVE-2023-0030'], 'PublishedDate': '2023-03-08T23:15:10.963Z', 'LastModifiedDate': '2023-04-13T17:15:09.433Z'}, {'VulnerabilityID': 'CVE-2023-0160', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-0160', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: possibility of deadlock in libbpf function sock_hash_delete_elem', 'Description': 'A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667', 'CWE-833'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-0160', 'https://bugzilla.redhat.com/show_bug.cgi?id=2159764', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ed17aa92dc56', 'https://lore.kernel.org/all/20230406122622.109978-1-liuxin350@huawei.com/', 'https://lore.kernel.org/all/CABcoxUayum5oOqFMMqAeWuS8+EzojquSOSyDA3J_2omY=2EeAg@mail.gmail.com/', 'https://lore.kernel.org/bpf/000000000000f1db9605f939720e@google.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-0160', 'https://www.cve.org/CVERecord?id=CVE-2023-0160'], 'PublishedDate': '2023-07-18T17:15:11.313Z', 'LastModifiedDate': '2023-11-07T03:59:46.343Z'}, {'VulnerabilityID': 'CVE-2023-1193', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-1193', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free in setup_async_work()', 'Description': 'A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-1193', 'https://bugzilla.redhat.com/show_bug.cgi?id=2154177', 'https://lkml.kernel.org/linux-cifs/20230401084951.6085-2-linkinjeon@kernel.org/T/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-1193', 'https://www.cve.org/CVERecord?id=CVE-2023-1193'], 'PublishedDate': '2023-11-01T20:15:08.663Z', 'LastModifiedDate': '2023-11-09T15:13:51.737Z'}, {'VulnerabilityID': 'CVE-2023-26242', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-26242', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the ...', 'Description': 'afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://bugzilla.suse.com/show_bug.cgi?id=1208518', 'https://lore.kernel.org/all/20230206054326.89323-1-k1rh4.lee@gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-26242', 'https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee%40gmail.com', 'https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee@gmail.com/', 'https://security.netapp.com/advisory/ntap-20230406-0002/', 'https://www.cve.org/CVERecord?id=CVE-2023-26242'], 'PublishedDate': '2023-02-21T01:15:11.423Z', 'LastModifiedDate': '2024-03-25T01:15:53.57Z'}, {'VulnerabilityID': 'CVE-2023-31082', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-31082', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sleeping function called from an invalid context in gsmld_write', 'Description': 'An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-763'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-31082', 'https://bugzilla.suse.com/show_bug.cgi?id=1210781', 'https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A%40mail.gmail.com/', 'https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A@mail.gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-31082', 'https://security.netapp.com/advisory/ntap-20230929-0003/', 'https://www.cve.org/CVERecord?id=CVE-2023-31082'], 'PublishedDate': '2023-04-24T06:15:07.783Z', 'LastModifiedDate': '2024-08-02T15:16:00.853Z'}, {'VulnerabilityID': 'CVE-2023-52879', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52879', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Have trace_event_file have ref counters', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have trace_event_file have ref counters\n\nThe following can crash the kernel:\n\n # cd /sys/kernel/tracing\n # echo \'p:sched schedule\' > kprobe_events\n # exec 5>>events/kprobes/sched/enable\n # > kprobe_events\n # exec 5>&-\n\nThe above commands:\n\n 1. Change directory to the tracefs directory\n 2. Create a kprobe event (doesn\'t matter what one)\n 3. Open bash file descriptor 5 on the enable file of the kprobe event\n 4. Delete the kprobe event (removes the files too)\n 5. Close the bash file descriptor 5\n\nThe above causes a crash!\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 6 PID: 877 Comm: bash Not tainted 6.5.0-rc4-test-00008-g2c6b6b1029d4-dirty #186\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\n RIP: 0010:tracing_release_file_tr+0xc/0x50\n\nWhat happens here is that the kprobe event creates a trace_event_file\n"file" descriptor that represents the file in tracefs to the event. It\nmaintains state of the event (is it enabled for the given instance?).\nOpening the "enable" file gets a reference to the event "file" descriptor\nvia the open file descriptor. When the kprobe event is deleted, the file is\nalso deleted from the tracefs system which also frees the event "file"\ndescriptor.\n\nBut as the tracefs file is still opened by user space, it will not be\ntotally removed until the final dput() is called on it. But this is not\ntrue with the event "file" descriptor that is already freed. If the user\ndoes a write to or simply closes the file descriptor it will reference the\nevent "file" descriptor that was just freed, causing a use-after-free bug.\n\nTo solve this, add a ref count to the event "file" descriptor as well as a\nnew flag called "FREED". The "file" will not be freed until the last\nreference is released. But the FREE flag will be set when the event is\nremoved to prevent any more modifications to that event from happening,\neven if there\'s still a reference to the event "file" descriptor.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-52879', 'https://git.kernel.org/linus/bb32500fb9b78215e4ef6ee8b4345c5f5d7eafb4 (6.7-rc1)', 'https://git.kernel.org/stable/c/2c9de867ca285c397cd71af703763fe416265706', 'https://git.kernel.org/stable/c/2fa74d29fc1899c237d51bf9a6e132ea5c488976', 'https://git.kernel.org/stable/c/9034c87d61be8cff989017740a91701ac8195a1d', 'https://git.kernel.org/stable/c/961c4511c7578d6b8f39118be919016ec3db1c1e', 'https://git.kernel.org/stable/c/a98172e36e5f1b3d29ad71fade2d611cfcc2fe6f', 'https://git.kernel.org/stable/c/bb32500fb9b78215e4ef6ee8b4345c5f5d7eafb4', 'https://git.kernel.org/stable/c/cbc7c29dff0fa18162f2a3889d82eeefd67305e0', 'https://lore.kernel.org/linux-cve-announce/2024052122-CVE-2023-52879-fa4d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52879', 'https://www.cve.org/CVERecord?id=CVE-2023-52879'], 'PublishedDate': '2024-05-21T16:15:24.53Z', 'LastModifiedDate': '2024-05-21T16:53:56.55Z'}, {'VulnerabilityID': 'CVE-2023-52889', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52889', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: apparmor: Fix null pointer deref when receiving skb during sock creation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: Fix null pointer deref when receiving skb during sock creation\n\nThe panic below is observed when receiving ICMP packets with secmark set\nwhile an ICMP raw socket is being created. SK_CTX(sk)->label is updated\nin apparmor_socket_post_create(), but the packet is delivered to the\nsocket before that, causing the null pointer dereference.\nDrop the packet if label context is not set.\n\n BUG: kernel NULL pointer dereference, address: 000000000000004c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 PID: 407 Comm: a.out Not tainted 6.4.12-arch1-1 #1 3e6fa2753a2d75925c34ecb78e22e85a65d083df\n Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 05/28/2020\n RIP: 0010:aa_label_next_confined+0xb/0x40\n Code: 00 00 48 89 ef e8 d5 25 0c 00 e9 66 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 89 f0 <8b> 77 4c 39 c6 7e 1f 48 63 d0 48 8d 14 d7 eb 0b 83 c0 01 48 83 c2\n RSP: 0018:ffffa92940003b08 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 000000000000000e\n RDX: ffffa92940003be8 RSI: 0000000000000000 RDI: 0000000000000000\n RBP: ffff8b57471e7800 R08: ffff8b574c642400 R09: 0000000000000002\n R10: ffffffffbd820eeb R11: ffffffffbeb7ff00 R12: ffff8b574c642400\n R13: 0000000000000001 R14: 0000000000000001 R15: 0000000000000000\n FS: 00007fb092ea7640(0000) GS:ffff8b577bc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000004c CR3: 00000001020f2005 CR4: 00000000007706f0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? aa_label_next_confined+0xb/0x40\n apparmor_secmark_check+0xec/0x330\n security_sock_rcv_skb+0x35/0x50\n sk_filter_trim_cap+0x47/0x250\n sock_queue_rcv_skb_reason+0x20/0x60\n raw_rcv+0x13c/0x210\n raw_local_deliver+0x1f3/0x250\n ip_protocol_deliver_rcu+0x4f/0x2f0\n ip_local_deliver_finish+0x76/0xa0\n __netif_receive_skb_one_core+0x89/0xa0\n netif_receive_skb+0x119/0x170\n ? __netdev_alloc_skb+0x3d/0x140\n vmxnet3_rq_rx_complete+0xb23/0x1010 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a]\n vmxnet3_poll_rx_only+0x36/0xb0 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a]\n __napi_poll+0x28/0x1b0\n net_rx_action+0x2a4/0x380\n __do_softirq+0xd1/0x2c8\n __irq_exit_rcu+0xbb/0xf0\n common_interrupt+0x86/0xa0\n \n \n asm_common_interrupt+0x26/0x40\n RIP: 0010:apparmor_socket_post_create+0xb/0x200\n Code: 08 48 85 ff 75 a1 eb b1 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 <55> 48 89 fd 53 45 85 c0 0f 84 b2 00 00 00 48 8b 1d 80 56 3f 02 48\n RSP: 0018:ffffa92940ce7e50 EFLAGS: 00000286\n RAX: ffffffffbc756440 RBX: 0000000000000000 RCX: 0000000000000001\n RDX: 0000000000000003 RSI: 0000000000000002 RDI: ffff8b574eaab740\n RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff8b57444cec70 R11: 0000000000000000 R12: 0000000000000003\n R13: 0000000000000002 R14: ffff8b574eaab740 R15: ffffffffbd8e4748\n ? __pfx_apparmor_socket_post_create+0x10/0x10\n security_socket_post_create+0x4b/0x80\n __sock_create+0x176/0x1f0\n __sys_socket+0x89/0x100\n __x64_sys_socket+0x17/0x20\n do_syscall_64+0x5d/0x90\n ? do_syscall_64+0x6c/0x90\n ? do_syscall_64+0x6c/0x90\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-52889', 'https://git.kernel.org/linus/fce09ea314505a52f2436397608fa0a5d0934fb1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0abe35bc48d4ec80424b1f4b3560c0e082cbd5c1', 'https://git.kernel.org/stable/c/290a6b88e8c19b6636ed1acc733d1458206f7697', 'https://git.kernel.org/stable/c/347dcb84a4874b5fb375092c08d8cc4069b94f81', 'https://git.kernel.org/stable/c/46c17ead5b7389e22e7dc9903fd0ba865d05bda2', 'https://git.kernel.org/stable/c/6c920754f62cefc63fccdc38a062c7c3452e2961', 'https://git.kernel.org/stable/c/ead2ad1d9f045f26fdce3ef1644913b3a6cd38f2', 'https://git.kernel.org/stable/c/fce09ea314505a52f2436397608fa0a5d0934fb1', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2023-52889-cdd0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52889', 'https://www.cve.org/CVERecord?id=CVE-2023-52889'], 'PublishedDate': '2024-08-17T09:15:07.073Z', 'LastModifiedDate': '2024-08-19T21:19:16.97Z'}, {'VulnerabilityID': 'CVE-2024-26713', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26713', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/pseries/iommu: Fix iommu initialisation during DLPAR add', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: Fix iommu initialisation during DLPAR add\n\nWhen a PCI device is dynamically added, the kernel oopses with a NULL\npointer dereference:\n\n BUG: Kernel NULL pointer dereference on read at 0x00000030\n Faulting instruction address: 0xc0000000006bbe5c\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: rpadlpar_io rpaphp rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs xsk_diag bonding nft_compat nf_tables nfnetlink rfkill binfmt_misc dm_multipath rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi ib_ipoib rdma_cm iw_cm ib_cm mlx5_ib ib_uverbs ib_core pseries_rng drm drm_panel_orientation_quirks xfs libcrc32c mlx5_core mlxfw sd_mod t10_pi sg tls ibmvscsi ibmveth scsi_transport_srp vmx_crypto pseries_wdt psample dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 17 PID: 2685 Comm: drmgr Not tainted 6.7.0-203405+ #66\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c0000000006bbe5c LR: c000000000a13e68 CTR: c0000000000579f8\n REGS: c00000009924f240 TRAP: 0300 Not tainted (6.7.0-203405+)\n MSR: 8000000000009033 CR: 24002220 XER: 20040006\n CFAR: c000000000a13e64 DAR: 0000000000000030 DSISR: 40000000 IRQMASK: 0\n ...\n NIP sysfs_add_link_to_group+0x34/0x94\n LR iommu_device_link+0x5c/0x118\n Call Trace:\n iommu_init_device+0x26c/0x318 (unreliable)\n iommu_device_link+0x5c/0x118\n iommu_init_device+0xa8/0x318\n iommu_probe_device+0xc0/0x134\n iommu_bus_notifier+0x44/0x104\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n bus_notify+0x50/0x7c\n device_add+0x640/0x918\n pci_device_add+0x23c/0x298\n of_create_pci_dev+0x400/0x884\n of_scan_pci_dev+0x124/0x1b0\n __of_scan_bus+0x78/0x18c\n pcibios_scan_phb+0x2a4/0x3b0\n init_phb_dynamic+0xb8/0x110\n dlpar_add_slot+0x170/0x3b8 [rpadlpar_io]\n add_slot_store.part.0+0xb4/0x130 [rpadlpar_io]\n kobj_attr_store+0x2c/0x48\n sysfs_kf_write+0x64/0x78\n kernfs_fop_write_iter+0x1b0/0x290\n vfs_write+0x350/0x4a0\n ksys_write+0x84/0x140\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nCommit a940904443e4 ("powerpc/iommu: Add iommu_ops to report capabilities\nand allow blocking domains") broke DLPAR add of PCI devices.\n\nThe above added iommu_device structure to pci_controller. During\nsystem boot, PCI devices are discovered and this newly added iommu_device\nstructure is initialized by a call to iommu_device_register().\n\nDuring DLPAR add of a PCI device, a new pci_controller structure is\nallocated but there are no calls made to iommu_device_register()\ninterface.\n\nFix is to register the iommu device during DLPAR add as well.\n\n[mpe: Trim oops and tweak some change log wording]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26713', 'https://git.kernel.org/linus/ed8b94f6e0acd652ce69bd69d678a0c769172df8 (6.8-rc5)', 'https://git.kernel.org/stable/c/9978d5b744e0227afe19e3bcb4c5f75442dde753', 'https://git.kernel.org/stable/c/d4f762d6403f7419de90d7749fa83dd92ffb0e1d', 'https://git.kernel.org/stable/c/ed8b94f6e0acd652ce69bd69d678a0c769172df8', 'https://lore.kernel.org/linux-cve-announce/2024040342-CVE-2024-26713-1b52@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26713', 'https://www.cve.org/CVERecord?id=CVE-2024-26713'], 'PublishedDate': '2024-04-03T15:15:53.647Z', 'LastModifiedDate': '2024-04-03T17:24:18.15Z'}, {'VulnerabilityID': 'CVE-2024-27025', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-27025', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nbd: null check for nla_nest_start', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: null check for nla_nest_start\n\nnla_nest_start() may fail and return NULL. Insert a check and set errno\nbased on other call sites within the same source code.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:5102', 'https://access.redhat.com/security/cve/CVE-2024-27025', 'https://bugzilla.redhat.com/2263879', 'https://bugzilla.redhat.com/2265645', 'https://bugzilla.redhat.com/2265797', 'https://bugzilla.redhat.com/2266341', 'https://bugzilla.redhat.com/2266347', 'https://bugzilla.redhat.com/2266497', 'https://bugzilla.redhat.com/2267787', 'https://bugzilla.redhat.com/2268118', 'https://bugzilla.redhat.com/2269070', 'https://bugzilla.redhat.com/2269211', 'https://bugzilla.redhat.com/2270084', 'https://bugzilla.redhat.com/2270100', 'https://bugzilla.redhat.com/2271686', 'https://bugzilla.redhat.com/2271688', 'https://bugzilla.redhat.com/2272782', 'https://bugzilla.redhat.com/2272795', 'https://bugzilla.redhat.com/2273109', 'https://bugzilla.redhat.com/2273174', 'https://bugzilla.redhat.com/2273236', 'https://bugzilla.redhat.com/2273242', 'https://bugzilla.redhat.com/2273247', 'https://bugzilla.redhat.com/2273268', 'https://bugzilla.redhat.com/2273427', 'https://bugzilla.redhat.com/2273654', 'https://bugzilla.redhat.com/2275565', 'https://bugzilla.redhat.com/2275573', 'https://bugzilla.redhat.com/2275580', 'https://bugzilla.redhat.com/2275694', 'https://bugzilla.redhat.com/2275711', 'https://bugzilla.redhat.com/2275748', 'https://bugzilla.redhat.com/2275761', 'https://bugzilla.redhat.com/2275928', 'https://bugzilla.redhat.com/2277166', 'https://bugzilla.redhat.com/2277238', 'https://bugzilla.redhat.com/2277840', 'https://bugzilla.redhat.com/2278176', 'https://bugzilla.redhat.com/2278178', 'https://bugzilla.redhat.com/2278182', 'https://bugzilla.redhat.com/2278218', 'https://bugzilla.redhat.com/2278256', 'https://bugzilla.redhat.com/2278258', 'https://bugzilla.redhat.com/2278277', 'https://bugzilla.redhat.com/2278279', 'https://bugzilla.redhat.com/2278380', 'https://bugzilla.redhat.com/2278484', 'https://bugzilla.redhat.com/2278515', 'https://bugzilla.redhat.com/2278535', 'https://bugzilla.redhat.com/2278539', 'https://bugzilla.redhat.com/2278989', 'https://bugzilla.redhat.com/2280440', 'https://bugzilla.redhat.com/2281054', 'https://bugzilla.redhat.com/2281133', 'https://bugzilla.redhat.com/2281149', 'https://bugzilla.redhat.com/2281207', 'https://bugzilla.redhat.com/2281215', 'https://bugzilla.redhat.com/2281221', 'https://bugzilla.redhat.com/2281235', 'https://bugzilla.redhat.com/2281268', 'https://bugzilla.redhat.com/2281326', 'https://bugzilla.redhat.com/2281360', 'https://bugzilla.redhat.com/2281510', 'https://bugzilla.redhat.com/2281519', 'https://bugzilla.redhat.com/2281636', 'https://bugzilla.redhat.com/2281641', 'https://bugzilla.redhat.com/2281664', 'https://bugzilla.redhat.com/2281667', 'https://bugzilla.redhat.com/2281672', 'https://bugzilla.redhat.com/2281675', 'https://bugzilla.redhat.com/2281682', 'https://bugzilla.redhat.com/2281725', 'https://bugzilla.redhat.com/2281752', 'https://bugzilla.redhat.com/2281758', 'https://bugzilla.redhat.com/2281819', 'https://bugzilla.redhat.com/2281821', 'https://bugzilla.redhat.com/2281833', 'https://bugzilla.redhat.com/2281938', 'https://bugzilla.redhat.com/2281949', 'https://bugzilla.redhat.com/2281968', 'https://bugzilla.redhat.com/2281989', 'https://bugzilla.redhat.com/2282328', 'https://bugzilla.redhat.com/2282373', 'https://bugzilla.redhat.com/2282479', 'https://bugzilla.redhat.com/2282553', 'https://bugzilla.redhat.com/2282615', 'https://bugzilla.redhat.com/2282623', 'https://bugzilla.redhat.com/2282640', 'https://bugzilla.redhat.com/2282642', 'https://bugzilla.redhat.com/2282645', 'https://bugzilla.redhat.com/2282717', 'https://bugzilla.redhat.com/2282719', 'https://bugzilla.redhat.com/2282727', 'https://bugzilla.redhat.com/2282742', 'https://bugzilla.redhat.com/2282743', 'https://bugzilla.redhat.com/2282744', 'https://bugzilla.redhat.com/2282759', 'https://bugzilla.redhat.com/2282763', 'https://bugzilla.redhat.com/2282766', 'https://bugzilla.redhat.com/2282772', 'https://bugzilla.redhat.com/2282780', 'https://bugzilla.redhat.com/2282887', 'https://bugzilla.redhat.com/2282896', 'https://bugzilla.redhat.com/2282923', 'https://bugzilla.redhat.com/2282925', 'https://bugzilla.redhat.com/2282950', 'https://bugzilla.redhat.com/2283401', 'https://bugzilla.redhat.com/2283894', 'https://bugzilla.redhat.com/2284400', 'https://bugzilla.redhat.com/2284417', 'https://bugzilla.redhat.com/2284421', 'https://bugzilla.redhat.com/2284474', 'https://bugzilla.redhat.com/2284477', 'https://bugzilla.redhat.com/2284488', 'https://bugzilla.redhat.com/2284496', 'https://bugzilla.redhat.com/2284500', 'https://bugzilla.redhat.com/2284513', 'https://bugzilla.redhat.com/2284519', 'https://bugzilla.redhat.com/2284539', 'https://bugzilla.redhat.com/2284541', 'https://bugzilla.redhat.com/2284556', 'https://bugzilla.redhat.com/2284571', 'https://bugzilla.redhat.com/2284590', 'https://bugzilla.redhat.com/2284625', 'https://bugzilla.redhat.com/2290408', 'https://bugzilla.redhat.com/2292331', 'https://bugzilla.redhat.com/2293078', 'https://bugzilla.redhat.com/2293250', 'https://bugzilla.redhat.com/2293276', 'https://bugzilla.redhat.com/2293312', 'https://bugzilla.redhat.com/2293316', 'https://bugzilla.redhat.com/2293348', 'https://bugzilla.redhat.com/2293371', 'https://bugzilla.redhat.com/2293383', 'https://bugzilla.redhat.com/2293418', 'https://bugzilla.redhat.com/2293420', 'https://bugzilla.redhat.com/2293444', 'https://bugzilla.redhat.com/2293461', 'https://bugzilla.redhat.com/2293653', 'https://bugzilla.redhat.com/2293657', 'https://bugzilla.redhat.com/2293684', 'https://bugzilla.redhat.com/2293687', 'https://bugzilla.redhat.com/2293700', 'https://bugzilla.redhat.com/2293711', 'https://bugzilla.redhat.com/2294274', 'https://bugzilla.redhat.com/2295914', 'https://bugzilla.redhat.com/2296067', 'https://bugzilla.redhat.com/2297056', 'https://bugzilla.redhat.com/2297474', 'https://bugzilla.redhat.com/2297511', 'https://bugzilla.redhat.com/2298108', 'https://bugzilla.redhat.com/show_bug.cgi?id=2263879', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265650', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265797', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266341', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266347', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266497', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266594', 'https://bugzilla.redhat.com/show_bug.cgi?id=2267787', 'https://bugzilla.redhat.com/show_bug.cgi?id=2268118', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269070', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269211', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270084', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270100', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271686', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271688', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272782', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272795', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273109', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273117', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273174', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273242', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273247', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273427', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273654', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275565', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275573', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275580', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275694', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275748', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275761', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275928', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277840', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278176', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278182', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278218', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278256', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278258', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278277', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278279', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278380', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278484', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278515', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278535', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2280440', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281054', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281133', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281149', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281189', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281190', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281207', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281215', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281221', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281235', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281326', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281360', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281636', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281641', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281664', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281667', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281675', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281682', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281725', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281752', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281758', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281819', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281821', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281833', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281938', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281949', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281968', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282328', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282373', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282479', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282553', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282615', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282623', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282640', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282642', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282690', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282717', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282719', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282727', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282742', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282743', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282759', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282763', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282766', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282772', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282780', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282887', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282896', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282923', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282925', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282950', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283401', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283894', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284417', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284421', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284465', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284477', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284488', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284496', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284500', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284541', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284556', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284571', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284590', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284625', 'https://bugzilla.redhat.com/show_bug.cgi?id=2290408', 'https://bugzilla.redhat.com/show_bug.cgi?id=2292331', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293078', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293250', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293276', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293312', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293316', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293348', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293367', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293371', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293383', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293418', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293420', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293444', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293461', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293653', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293657', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293684', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293687', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2294274', 'https://bugzilla.redhat.com/show_bug.cgi?id=2295914', 'https://bugzilla.redhat.com/show_bug.cgi?id=2296067', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297056', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297558', 'https://bugzilla.redhat.com/show_bug.cgi?id=2298108', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47018', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47257', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47304', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47373', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47408', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47468', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47491', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47548', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47579', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48743', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48747', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52451', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52463', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52469', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52471', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52486', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52530', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52619', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52622', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52623', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52648', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52653', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52662', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52679', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52707', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52730', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52756', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52762', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52764', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52775', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52777', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52784', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52791', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52796', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52803', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52811', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52832', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52845', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52864', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2201', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25739', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26586', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26614', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26640', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26686', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26698', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26704', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26772', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26773', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26802', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26837', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26840', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26843', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26852', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26870', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26878', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26908', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26961', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27011', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27019', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27065', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27388', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27395', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27434', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31076', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33621', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35790', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35801', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35807', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35814', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35824', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35876', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35893', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35897', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35899', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35900', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35910', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35912', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35930', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35937', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35938', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35952', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36000', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36005', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36006', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36016', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36017', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36270', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36489', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36917', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36929', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36933', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36941', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36945', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36950', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36954', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36971', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36978', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36979', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38538', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38555', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38573', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38575', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38596', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38598', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38615', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38627', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39276', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39472', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39476', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39487', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39502', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40974', 'https://errata.almalinux.org/8/ALSA-2024-5102.html', 'https://errata.rockylinux.org/RLSA-2024:5101', 'https://git.kernel.org/linus/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d (6.9-rc1)', 'https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d', 'https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19e', 'https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dced', 'https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8', 'https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797', 'https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983', 'https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596a', 'https://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcf', 'https://linux.oracle.com/cve/CVE-2024-27025.html', 'https://linux.oracle.com/errata/ELSA-2024-5101.html', 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'https://lore.kernel.org/linux-cve-announce/2024050107-CVE-2024-27025-babd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-27025', 'https://www.cve.org/CVERecord?id=CVE-2024-27025'], 'PublishedDate': '2024-05-01T13:15:48.89Z', 'LastModifiedDate': '2024-06-25T22:15:28.24Z'}, {'VulnerabilityID': 'CVE-2024-35928', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35928', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()\n\nThis ensures that the memory mapped by ioremap for adev->rmmio, is\nproperly handled in amdgpu_device_init(). If the function exits early\ndue to an error, the memory is unmapped. If the function completes\nsuccessfully, the memory remains mapped.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/amdgpu_device.c:4337 amdgpu_device_init() warn: 'adev->rmmio' from ioremap() not released on lines: 4035,4045,4051,4058,4068,4337", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35928', 'https://git.kernel.org/linus/eb4f139888f636614dab3bcce97ff61cefc4b3a7 (6.9-rc1)', 'https://git.kernel.org/stable/c/14ac934db851642ea8cd1bd4121c788a8899ef69', 'https://git.kernel.org/stable/c/aa665c3a2aca2ffe31b9645bda278e96dfc3b55c', 'https://git.kernel.org/stable/c/c5f9fe2c1e5023fa096189a8bfba6420aa035587', 'https://git.kernel.org/stable/c/eb4f139888f636614dab3bcce97ff61cefc4b3a7', 'https://lore.kernel.org/linux-cve-announce/2024051915-CVE-2024-35928-ead3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35928', 'https://www.cve.org/CVERecord?id=CVE-2024-35928'], 'PublishedDate': '2024-05-19T11:15:48.93Z', 'LastModifiedDate': '2024-05-20T13:00:04.957Z'}, {'VulnerabilityID': 'CVE-2024-35948', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35948', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bcachefs: Check for journal entries overruning end of sb clean section', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: Check for journal entries overruning end of sb clean section\n\nFix a missing bounds check in superblock validation.\n\nNote that we don't yet have repair code for this case - repair code for\nindividual items is generally low priority, since the whole superblock\nis checksummed, validated prior to write, and we have backups.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-400'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35948', 'https://git.kernel.org/linus/fcdbc1d7a4b638e5d5668de461f320386f3002aa (6.9-rc6)', 'https://git.kernel.org/stable/c/fcdbc1d7a4b638e5d5668de461f320386f3002aa', 'https://lore.kernel.org/linux-cve-announce/2024052043-CVE-2024-35948-a92f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35948', 'https://www.cve.org/CVERecord?id=CVE-2024-35948'], 'PublishedDate': '2024-05-20T10:15:09.44Z', 'LastModifiedDate': '2024-07-03T02:02:27.897Z'}, {'VulnerabilityID': 'CVE-2024-35995', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35995', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Use access_width over bit_width for system memory accesses\n\nTo align with ACPI 6.3+, since bit_width can be any 8-bit value, it\ncannot be depended on to be always on a clean 8b boundary. This was\nuncovered on the Cobalt 100 platform.\n\nSError Interrupt on CPU26, code 0xbe000011 -- SError\n CPU: 26 PID: 1510 Comm: systemd-udevd Not tainted 5.15.2.1-13 #1\n Hardware name: MICROSOFT CORPORATION, BIOS MICROSOFT CORPORATION\n pstate: 62400009 (nZCv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)\n pc : cppc_get_perf_caps+0xec/0x410\n lr : cppc_get_perf_caps+0xe8/0x410\n sp : ffff8000155ab730\n x29: ffff8000155ab730 x28: ffff0080139d0038 x27: ffff0080139d0078\n x26: 0000000000000000 x25: ffff0080139d0058 x24: 00000000ffffffff\n x23: ffff0080139d0298 x22: ffff0080139d0278 x21: 0000000000000000\n x20: ffff00802b251910 x19: ffff0080139d0000 x18: ffffffffffffffff\n x17: 0000000000000000 x16: ffffdc7e111bad04 x15: ffff00802b251008\n x14: ffffffffffffffff x13: ffff013f1fd63300 x12: 0000000000000006\n x11: ffffdc7e128f4420 x10: 0000000000000000 x9 : ffffdc7e111badec\n x8 : ffff00802b251980 x7 : 0000000000000000 x6 : ffff0080139d0028\n x5 : 0000000000000000 x4 : ffff0080139d0018 x3 : 00000000ffffffff\n x2 : 0000000000000008 x1 : ffff8000155ab7a0 x0 : 0000000000000000\n Kernel panic - not syncing: Asynchronous SError Interrupt\n CPU: 26 PID: 1510 Comm: systemd-udevd Not tainted\n5.15.2.1-13 #1\n Hardware name: MICROSOFT CORPORATION, BIOS MICROSOFT CORPORATION\n Call trace:\n dump_backtrace+0x0/0x1e0\n show_stack+0x24/0x30\n dump_stack_lvl+0x8c/0xb8\n dump_stack+0x18/0x34\n panic+0x16c/0x384\n add_taint+0x0/0xc0\n arm64_serror_panic+0x7c/0x90\n arm64_is_fatal_ras_serror+0x34/0xa4\n do_serror+0x50/0x6c\n el1h_64_error_handler+0x40/0x74\n el1h_64_error+0x7c/0x80\n cppc_get_perf_caps+0xec/0x410\n cppc_cpufreq_cpu_init+0x74/0x400 [cppc_cpufreq]\n cpufreq_online+0x2dc/0xa30\n cpufreq_add_dev+0xc0/0xd4\n subsys_interface_register+0x134/0x14c\n cpufreq_register_driver+0x1b0/0x354\n cppc_cpufreq_init+0x1a8/0x1000 [cppc_cpufreq]\n do_one_initcall+0x50/0x250\n do_init_module+0x60/0x27c\n load_module+0x2300/0x2570\n __do_sys_finit_module+0xa8/0x114\n __arm64_sys_finit_module+0x2c/0x3c\n invoke_syscall+0x78/0x100\n el0_svc_common.constprop.0+0x180/0x1a0\n do_el0_svc+0x84/0xa0\n el0_svc+0x2c/0xc0\n el0t_64_sync_handler+0xa4/0x12c\n el0t_64_sync+0x1a4/0x1a8\n\nInstead, use access_width to determine the size and use the offset and\nwidth to shift and mask the bits to read/write out. Make sure to add a\ncheck for system memory since pcc redefines the access_width to\nsubspace id.\n\nIf access_width is not set, then fall back to using bit_width.\n\n[ rjw: Subject and changelog edits, comment adjustments ]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35995', 'https://git.kernel.org/linus/2f4a4d63a193be6fd530d180bb13c3592052904c (6.9-rc1)', 'https://git.kernel.org/stable/c/01fc53be672acae37e611c80cc0b4f3939584de3', 'https://git.kernel.org/stable/c/1b890ae474d19800a6be1696df7fb4d9a41676e4', 'https://git.kernel.org/stable/c/2f4a4d63a193be6fd530d180bb13c3592052904c', 'https://git.kernel.org/stable/c/4949affd5288b867cdf115f5b08d6166b2027f87', 'https://git.kernel.org/stable/c/6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1', 'https://git.kernel.org/stable/c/6dfd79ed04c578f1d9a9a41ba5b2015cf9f03fc3', 'https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2', 'https://lore.kernel.org/linux-cve-announce/2024052021-CVE-2024-35995-abbc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35995', 'https://www.cve.org/CVERecord?id=CVE-2024-35995'], 'PublishedDate': '2024-05-20T10:15:13.597Z', 'LastModifiedDate': '2024-05-20T13:00:04.957Z'}, {'VulnerabilityID': 'CVE-2024-36885', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-36885', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()\n\nCurrently, enabling SG_DEBUG in the kernel will cause nouveau to hit a\nBUG() on startup:\n\n kernel BUG at include/linux/scatterlist.h:187!\n invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 7 PID: 930 Comm: (udev-worker) Not tainted 6.9.0-rc3Lyude-Test+ #30\n Hardware name: MSI MS-7A39/A320M GAMING PRO (MS-7A39), BIOS 1.I0 01/22/2019\n RIP: 0010:sg_init_one+0x85/0xa0\n Code: 69 88 32 01 83 e1 03 f6 c3 03 75 20 a8 01 75 1e 48 09 cb 41 89 54\n 24 08 49 89 1c 24 41 89 6c 24 0c 5b 5d 41 5c e9 7b b9 88 00 <0f> 0b 0f 0b\n 0f 0b 48 8b 05 5e 46 9a 01 eb b2 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffa776017bf6a0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffffa77600d87000 RCX: 000000000000002b\n RDX: 0000000000000001 RSI: 0000000000000000 RDI: ffffa77680d87000\n RBP: 000000000000e000 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff98f4c46aa508 R11: 0000000000000000 R12: ffff98f4c46aa508\n R13: ffff98f4c46aa008 R14: ffffa77600d4a000 R15: ffffa77600d4a018\n FS: 00007feeb5aae980(0000) GS:ffff98f5c4dc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f22cb9a4520 CR3: 00000001043ba000 CR4: 00000000003506f0\n Call Trace:\n \n ? die+0x36/0x90\n ? do_trap+0xdd/0x100\n ? sg_init_one+0x85/0xa0\n ? do_error_trap+0x65/0x80\n ? sg_init_one+0x85/0xa0\n ? exc_invalid_op+0x50/0x70\n ? sg_init_one+0x85/0xa0\n ? asm_exc_invalid_op+0x1a/0x20\n ? sg_init_one+0x85/0xa0\n nvkm_firmware_ctor+0x14a/0x250 [nouveau]\n nvkm_falcon_fw_ctor+0x42/0x70 [nouveau]\n ga102_gsp_booter_ctor+0xb4/0x1a0 [nouveau]\n r535_gsp_oneinit+0xb3/0x15f0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? nvkm_udevice_new+0x95/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? ktime_get+0x47/0xb0\n ? srso_return_thunk+0x5/0x5f\n nvkm_subdev_oneinit_+0x4f/0x120 [nouveau]\n nvkm_subdev_init_+0x39/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n nvkm_subdev_init+0x44/0x90 [nouveau]\n nvkm_device_init+0x166/0x2e0 [nouveau]\n nvkm_udevice_init+0x47/0x70 [nouveau]\n nvkm_object_init+0x41/0x1c0 [nouveau]\n nvkm_ioctl_new+0x16a/0x290 [nouveau]\n ? __pfx_nvkm_client_child_new+0x10/0x10 [nouveau]\n ? __pfx_nvkm_udevice_new+0x10/0x10 [nouveau]\n nvkm_ioctl+0x126/0x290 [nouveau]\n nvif_object_ctor+0x112/0x190 [nouveau]\n nvif_device_ctor+0x23/0x60 [nouveau]\n nouveau_cli_init+0x164/0x640 [nouveau]\n nouveau_drm_device_init+0x97/0x9e0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? pci_update_current_state+0x72/0xb0\n ? srso_return_thunk+0x5/0x5f\n nouveau_drm_probe+0x12c/0x280 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n local_pci_probe+0x45/0xa0\n pci_device_probe+0xc7/0x270\n really_probe+0xe6/0x3a0\n __driver_probe_device+0x87/0x160\n driver_probe_device+0x1f/0xc0\n __driver_attach+0xec/0x1f0\n ? __pfx___driver_attach+0x10/0x10\n bus_for_each_dev+0x88/0xd0\n bus_add_driver+0x116/0x220\n driver_register+0x59/0x100\n ? __pfx_nouveau_drm_init+0x10/0x10 [nouveau]\n do_one_initcall+0x5b/0x320\n do_init_module+0x60/0x250\n init_module_from_file+0x86/0xc0\n idempotent_init_module+0x120/0x2b0\n __x64_sys_finit_module+0x5e/0xb0\n do_syscall_64+0x83/0x160\n ? srso_return_thunk+0x5/0x5f\n entry_SYSCALL_64_after_hwframe+0x71/0x79\n RIP: 0033:0x7feeb5cc20cd\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0\n ff ff 73 01 c3 48 8b 0d 1b cd 0c 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffcf220b2c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n RAX: ffffffffffffffda RBX: 000055fdd2916aa0 RCX: 00007feeb5cc20cd\n RDX: 0000000000000000 RSI: 000055fdd29161e0 RDI: 0000000000000035\n RBP: 00007ffcf220b380 R08: 00007feeb5d8fb20 R09: 00007ffcf220b310\n R10: 000055fdd2909dc0 R11: 0000000000000246 R12: 000055\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-36885', 'https://git.kernel.org/linus/52a6947bf576b97ff8e14bb0a31c5eaf2d0d96e2 (6.9-rc7)', 'https://git.kernel.org/stable/c/1a88c18da464db0ba8ea25196d0a06490f65322e', 'https://git.kernel.org/stable/c/52a6947bf576b97ff8e14bb0a31c5eaf2d0d96e2', 'https://git.kernel.org/stable/c/e05af009302893f39b072811a68fa4a196284c75', 'https://lore.kernel.org/linux-cve-announce/2024053032-CVE-2024-36885-cb0b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-36885', 'https://www.cve.org/CVERecord?id=CVE-2024-36885'], 'PublishedDate': '2024-05-30T16:15:12.067Z', 'LastModifiedDate': '2024-05-30T18:18:58.87Z'}, {'VulnerabilityID': 'CVE-2024-36970', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-36970', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: Use request_module_nowait', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: Use request_module_nowait\n\nThis appears to work around a deadlock regression that came in\nwith the LED merge in 6.9.\n\nThe deadlock happens on my system with 24 iwlwifi radios, so maybe\nit something like all worker threads are busy and some work that needs\nto complete cannot complete.\n\n[also remove unnecessary "load_module" var and now-wrong comment]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-36970', 'https://git.kernel.org/linus/3d913719df14c28c4d3819e7e6d150760222bda4 (6.10-rc1)', 'https://git.kernel.org/stable/c/3d913719df14c28c4d3819e7e6d150760222bda4', 'https://git.kernel.org/stable/c/d20013259539e2fde2deeac85354851097afdf9e', 'https://lore.kernel.org/linux-cve-announce/2024060855-CVE-2024-36970-2eb9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-36970', 'https://www.cve.org/CVERecord?id=CVE-2024-36970'], 'PublishedDate': '2024-06-08T13:15:58.26Z', 'LastModifiedDate': '2024-06-10T02:52:08.267Z'}, {'VulnerabilityID': 'CVE-2024-38581', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-38581', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/mes: fix use-after-free issue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/mes: fix use-after-free issue\n\nDelete fence fallback timer to fix the ramdom\nuse-after-free issue.\n\nv2: move to amdgpu_mes.c', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-38581', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/948255282074d9367e01908b3f5dcf8c10fc9c3d (6.9-rc6)', 'https://git.kernel.org/stable/c/0f98c144c15c8fc0f3176c994bd4e727ef718a5c', 'https://git.kernel.org/stable/c/39cfce75168c11421d70b8c0c65f6133edccb82a', 'https://git.kernel.org/stable/c/70b1bf6d9edc8692d241f59a65f073aec6d501de', 'https://git.kernel.org/stable/c/948255282074d9367e01908b3f5dcf8c10fc9c3d', 'https://linux.oracle.com/cve/CVE-2024-38581.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024061948-CVE-2024-38581-592d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-38581', 'https://www.cve.org/CVERecord?id=CVE-2024-38581'], 'PublishedDate': '2024-06-19T14:15:18.15Z', 'LastModifiedDate': '2024-08-01T20:12:00.623Z'}, {'VulnerabilityID': 'CVE-2024-38608', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-38608', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Fix netif state handling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix netif state handling\n\nmlx5e_suspend cleans resources only if netif_device_present() returns\ntrue. However, mlx5e_resume changes the state of netif, via\nmlx5e_nic_enable, only if reg_state == NETREG_REGISTERED.\nIn the below case, the above leads to NULL-ptr Oops[1] and memory\nleaks:\n\nmlx5e_probe\n _mlx5e_resume\n mlx5e_attach_netdev\n mlx5e_nic_enable <-- netdev not reg, not calling netif_device_attach()\n register_netdev <-- failed for some reason.\nERROR_FLOW:\n _mlx5e_suspend <-- netif_device_present return false, resources aren't freed :(\n\nHence, clean resources in this case as well.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0010 [#1] SMP\nCPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at0xffffffffffffffd6.\nRSP: 0018:ffff888178aaf758 EFLAGS: 00010246\nCall Trace:\n \n ? __die+0x20/0x60\n ? page_fault_oops+0x14c/0x3c0\n ? exc_page_fault+0x75/0x140\n ? asm_exc_page_fault+0x22/0x30\n notifier_call_chain+0x35/0xb0\n blocking_notifier_call_chain+0x3d/0x60\n mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core]\n mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core]\n mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib]\n mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib]\n __mlx5_ib_add+0x34/0xd0 [mlx5_ib]\n mlx5r_probe+0xe1/0x210 [mlx5_ib]\n ? auxiliary_match_id+0x6a/0x90\n auxiliary_bus_probe+0x38/0x80\n ? driver_sysfs_add+0x51/0x80\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n bus_probe_device+0x86/0xa0\n device_add+0x637/0x840\n __auxiliary_device_add+0x3b/0xa0\n add_adev+0xc9/0x140 [mlx5_core]\n mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core]\n mlx5_register_device+0x53/0xa0 [mlx5_core]\n mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core]\n mlx5_init_one+0x3b/0x60 [mlx5_core]\n probe_one+0x44c/0x730 [mlx5_core]\n local_pci_probe+0x3e/0x90\n pci_device_probe+0xbf/0x210\n ? kernfs_create_link+0x5d/0xa0\n ? sysfs_do_create_link_sd+0x60/0xc0\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n pci_bus_add_device+0x54/0x80\n pci_iov_add_virtfn+0x2e6/0x320\n sriov_enable+0x208/0x420\n mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core]\n sriov_numvfs_store+0xae/0x1a0\n kernfs_fop_write_iter+0x10c/0x1a0\n vfs_write+0x291/0x3c0\n ksys_write+0x5f/0xe0\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n CR2: 0000000000000000\n ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-38608', 'https://git.kernel.org/linus/3d5918477f94e4c2f064567875c475468e264644 (6.10-rc1)', 'https://git.kernel.org/stable/c/3d5918477f94e4c2f064567875c475468e264644', 'https://git.kernel.org/stable/c/f7e6cfb864a53af71c5cc904f1cc22215d68f5c6', 'https://linux.oracle.com/cve/CVE-2024-38608.html', 'https://linux.oracle.com/errata/ELSA-2024-5928.html', 'https://lore.kernel.org/linux-cve-announce/2024061920-CVE-2024-38608-4068@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-38608', 'https://www.cve.org/CVERecord?id=CVE-2024-38608'], 'PublishedDate': '2024-06-19T14:15:20.737Z', 'LastModifiedDate': '2024-08-27T15:58:56.9Z'}, {'VulnerabilityID': 'CVE-2024-39293', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-39293', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "xsk: Support redirect to any socket bound to the same umem"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "xsk: Support redirect to any socket bound to the same umem"\n\nThis reverts commit 2863d665ea41282379f108e4da6c8a2366ba66db.\n\nThis patch introduced a potential kernel crash when multiple napi instances\nredirect to the same AF_XDP socket. By removing the queue_index check, it is\npossible for multiple napi instances to access the Rx ring at the same time,\nwhich will result in a corrupted ring state which can lead to a crash when\nflushing the rings in __xsk_flush(). This can happen when the linked list of\nsockets to flush gets corrupted by concurrent accesses. A quick and small fix\nis not possible, so let us revert this for now.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-39293', 'https://git.kernel.org/linus/7fcf26b315bbb728036da0862de6b335da83dff2 (6.10-rc3)', 'https://git.kernel.org/stable/c/19cb40b1064566ea09538289bfcf5bc7ecb9b6f5', 'https://git.kernel.org/stable/c/7fcf26b315bbb728036da0862de6b335da83dff2', 'https://lore.kernel.org/linux-cve-announce/2024062548-CVE-2024-39293-d42a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-39293', 'https://www.cve.org/CVERecord?id=CVE-2024-39293'], 'PublishedDate': '2024-06-25T15:15:13.993Z', 'LastModifiedDate': '2024-06-25T18:50:42.04Z'}, {'VulnerabilityID': 'CVE-2024-39472', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-39472', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix log recovery buffer allocation for the legacy h_size fixup\n\nCommit a70f9fe52daa ("xfs: detect and handle invalid iclog size set by\nmkfs") added a fixup for incorrect h_size values used for the initial\numount record in old xfsprogs versions. Later commit 0c771b99d6c9\n("xfs: clean up calculation of LR header blocks") cleaned up the log\nreover buffer calculation, but stoped using the fixed up h_size value\nto size the log recovery buffer, which can lead to an out of bounds\naccess when the incorrect h_size does not come from the old mkfs\ntool, but a fuzzer.\n\nFix this by open coding xlog_logrec_hblks and taking the fixed h_size\ninto account for this calculation.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:5102', 'https://access.redhat.com/security/cve/CVE-2024-39472', 'https://bugzilla.redhat.com/2263879', 'https://bugzilla.redhat.com/2265645', 'https://bugzilla.redhat.com/2265797', 'https://bugzilla.redhat.com/2266341', 'https://bugzilla.redhat.com/2266347', 'https://bugzilla.redhat.com/2266497', 'https://bugzilla.redhat.com/2267787', 'https://bugzilla.redhat.com/2268118', 'https://bugzilla.redhat.com/2269070', 'https://bugzilla.redhat.com/2269211', 'https://bugzilla.redhat.com/2270084', 'https://bugzilla.redhat.com/2270100', 'https://bugzilla.redhat.com/2271686', 'https://bugzilla.redhat.com/2271688', 'https://bugzilla.redhat.com/2272782', 'https://bugzilla.redhat.com/2272795', 'https://bugzilla.redhat.com/2273109', 'https://bugzilla.redhat.com/2273174', 'https://bugzilla.redhat.com/2273236', 'https://bugzilla.redhat.com/2273242', 'https://bugzilla.redhat.com/2273247', 'https://bugzilla.redhat.com/2273268', 'https://bugzilla.redhat.com/2273427', 'https://bugzilla.redhat.com/2273654', 'https://bugzilla.redhat.com/2275565', 'https://bugzilla.redhat.com/2275573', 'https://bugzilla.redhat.com/2275580', 'https://bugzilla.redhat.com/2275694', 'https://bugzilla.redhat.com/2275711', 'https://bugzilla.redhat.com/2275748', 'https://bugzilla.redhat.com/2275761', 'https://bugzilla.redhat.com/2275928', 'https://bugzilla.redhat.com/2277166', 'https://bugzilla.redhat.com/2277238', 'https://bugzilla.redhat.com/2277840', 'https://bugzilla.redhat.com/2278176', 'https://bugzilla.redhat.com/2278178', 'https://bugzilla.redhat.com/2278182', 'https://bugzilla.redhat.com/2278218', 'https://bugzilla.redhat.com/2278256', 'https://bugzilla.redhat.com/2278258', 'https://bugzilla.redhat.com/2278277', 'https://bugzilla.redhat.com/2278279', 'https://bugzilla.redhat.com/2278380', 'https://bugzilla.redhat.com/2278484', 'https://bugzilla.redhat.com/2278515', 'https://bugzilla.redhat.com/2278535', 'https://bugzilla.redhat.com/2278539', 'https://bugzilla.redhat.com/2278989', 'https://bugzilla.redhat.com/2280440', 'https://bugzilla.redhat.com/2281054', 'https://bugzilla.redhat.com/2281133', 'https://bugzilla.redhat.com/2281149', 'https://bugzilla.redhat.com/2281207', 'https://bugzilla.redhat.com/2281215', 'https://bugzilla.redhat.com/2281221', 'https://bugzilla.redhat.com/2281235', 'https://bugzilla.redhat.com/2281268', 'https://bugzilla.redhat.com/2281326', 'https://bugzilla.redhat.com/2281360', 'https://bugzilla.redhat.com/2281510', 'https://bugzilla.redhat.com/2281519', 'https://bugzilla.redhat.com/2281636', 'https://bugzilla.redhat.com/2281641', 'https://bugzilla.redhat.com/2281664', 'https://bugzilla.redhat.com/2281667', 'https://bugzilla.redhat.com/2281672', 'https://bugzilla.redhat.com/2281675', 'https://bugzilla.redhat.com/2281682', 'https://bugzilla.redhat.com/2281725', 'https://bugzilla.redhat.com/2281752', 'https://bugzilla.redhat.com/2281758', 'https://bugzilla.redhat.com/2281819', 'https://bugzilla.redhat.com/2281821', 'https://bugzilla.redhat.com/2281833', 'https://bugzilla.redhat.com/2281938', 'https://bugzilla.redhat.com/2281949', 'https://bugzilla.redhat.com/2281968', 'https://bugzilla.redhat.com/2281989', 'https://bugzilla.redhat.com/2282328', 'https://bugzilla.redhat.com/2282373', 'https://bugzilla.redhat.com/2282479', 'https://bugzilla.redhat.com/2282553', 'https://bugzilla.redhat.com/2282615', 'https://bugzilla.redhat.com/2282623', 'https://bugzilla.redhat.com/2282640', 'https://bugzilla.redhat.com/2282642', 'https://bugzilla.redhat.com/2282645', 'https://bugzilla.redhat.com/2282717', 'https://bugzilla.redhat.com/2282719', 'https://bugzilla.redhat.com/2282727', 'https://bugzilla.redhat.com/2282742', 'https://bugzilla.redhat.com/2282743', 'https://bugzilla.redhat.com/2282744', 'https://bugzilla.redhat.com/2282759', 'https://bugzilla.redhat.com/2282763', 'https://bugzilla.redhat.com/2282766', 'https://bugzilla.redhat.com/2282772', 'https://bugzilla.redhat.com/2282780', 'https://bugzilla.redhat.com/2282887', 'https://bugzilla.redhat.com/2282896', 'https://bugzilla.redhat.com/2282923', 'https://bugzilla.redhat.com/2282925', 'https://bugzilla.redhat.com/2282950', 'https://bugzilla.redhat.com/2283401', 'https://bugzilla.redhat.com/2283894', 'https://bugzilla.redhat.com/2284400', 'https://bugzilla.redhat.com/2284417', 'https://bugzilla.redhat.com/2284421', 'https://bugzilla.redhat.com/2284474', 'https://bugzilla.redhat.com/2284477', 'https://bugzilla.redhat.com/2284488', 'https://bugzilla.redhat.com/2284496', 'https://bugzilla.redhat.com/2284500', 'https://bugzilla.redhat.com/2284513', 'https://bugzilla.redhat.com/2284519', 'https://bugzilla.redhat.com/2284539', 'https://bugzilla.redhat.com/2284541', 'https://bugzilla.redhat.com/2284556', 'https://bugzilla.redhat.com/2284571', 'https://bugzilla.redhat.com/2284590', 'https://bugzilla.redhat.com/2284625', 'https://bugzilla.redhat.com/2290408', 'https://bugzilla.redhat.com/2292331', 'https://bugzilla.redhat.com/2293078', 'https://bugzilla.redhat.com/2293250', 'https://bugzilla.redhat.com/2293276', 'https://bugzilla.redhat.com/2293312', 'https://bugzilla.redhat.com/2293316', 'https://bugzilla.redhat.com/2293348', 'https://bugzilla.redhat.com/2293371', 'https://bugzilla.redhat.com/2293383', 'https://bugzilla.redhat.com/2293418', 'https://bugzilla.redhat.com/2293420', 'https://bugzilla.redhat.com/2293444', 'https://bugzilla.redhat.com/2293461', 'https://bugzilla.redhat.com/2293653', 'https://bugzilla.redhat.com/2293657', 'https://bugzilla.redhat.com/2293684', 'https://bugzilla.redhat.com/2293687', 'https://bugzilla.redhat.com/2293700', 'https://bugzilla.redhat.com/2293711', 'https://bugzilla.redhat.com/2294274', 'https://bugzilla.redhat.com/2295914', 'https://bugzilla.redhat.com/2296067', 'https://bugzilla.redhat.com/2297056', 'https://bugzilla.redhat.com/2297474', 'https://bugzilla.redhat.com/2297511', 'https://bugzilla.redhat.com/2298108', 'https://bugzilla.redhat.com/show_bug.cgi?id=2263879', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265650', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265797', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266341', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266347', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266497', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266594', 'https://bugzilla.redhat.com/show_bug.cgi?id=2267787', 'https://bugzilla.redhat.com/show_bug.cgi?id=2268118', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269070', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269211', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270084', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270100', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271686', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271688', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272782', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272795', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273109', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273117', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273174', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273242', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273247', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273427', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273654', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275565', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275573', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275580', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275694', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275748', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275761', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275928', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277840', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278176', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278182', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278218', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278256', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278258', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278277', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278279', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278380', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278484', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278515', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278535', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2280440', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281054', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281133', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281149', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281189', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281190', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281207', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281215', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281221', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281235', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281326', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281360', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281636', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281641', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281664', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281667', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281675', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281682', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281725', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281752', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281758', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281819', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281821', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281833', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281938', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281949', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281968', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282328', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282373', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282479', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282553', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282615', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282623', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282640', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282642', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282690', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282717', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282719', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282727', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282742', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282743', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282759', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282763', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282766', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282772', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282780', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282887', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282896', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282923', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282925', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282950', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283401', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283894', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284417', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284421', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284465', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284477', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284488', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284496', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284500', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284541', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284556', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284571', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284590', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284625', 'https://bugzilla.redhat.com/show_bug.cgi?id=2290408', 'https://bugzilla.redhat.com/show_bug.cgi?id=2292331', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293078', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293250', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293276', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293312', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293316', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293348', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293367', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293371', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293383', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293418', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293420', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293444', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293461', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293653', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293657', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293684', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293687', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2294274', 'https://bugzilla.redhat.com/show_bug.cgi?id=2295914', 'https://bugzilla.redhat.com/show_bug.cgi?id=2296067', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297056', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297558', 'https://bugzilla.redhat.com/show_bug.cgi?id=2298108', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47018', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47257', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47304', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47373', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47408', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47468', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47491', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47548', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47579', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48743', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48747', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52451', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52463', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52469', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52471', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52486', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52530', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52619', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52622', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52623', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52648', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52653', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52662', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52679', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52707', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52730', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52756', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52762', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52764', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52775', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52777', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52784', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52791', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52796', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52803', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52811', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52832', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52845', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52864', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2201', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25739', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26586', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26614', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26640', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26686', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26698', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26704', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26772', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26773', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26802', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26837', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26840', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26843', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26852', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26870', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26878', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26908', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26961', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27011', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27019', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27065', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27388', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27395', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27434', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31076', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33621', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35790', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35801', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35807', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35814', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35824', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35876', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35893', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35897', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35899', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35900', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35910', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35912', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35930', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35937', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35938', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35952', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36000', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36005', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36006', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36016', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36017', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36270', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36489', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36917', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36929', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36933', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36941', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36945', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36950', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36954', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36971', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36978', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36979', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38538', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38555', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38573', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38575', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38596', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38598', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38615', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38627', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39276', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39472', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39476', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39487', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39502', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40974', 'https://errata.almalinux.org/8/ALSA-2024-5102.html', 'https://errata.rockylinux.org/RLSA-2024:5101', 'https://git.kernel.org/linus/45cf976008ddef4a9c9a30310c9b4fb2a9a6602a (6.10-rc1)', 'https://git.kernel.org/stable/c/45cf976008ddef4a9c9a30310c9b4fb2a9a6602a', 'https://git.kernel.org/stable/c/57835c0e7152e36b03875dd6c56dfeed685c1b1f', 'https://git.kernel.org/stable/c/c2389c074973aa94e34992e7f66dac0de37595b5', 'https://git.kernel.org/stable/c/f754591b17d0ee91c2b45fe9509d0cdc420527cb', 'https://linux.oracle.com/cve/CVE-2024-39472.html', 'https://linux.oracle.com/errata/ELSA-2024-5101.html', 'https://lore.kernel.org/linux-cve-announce/2024070512-CVE-2024-39472-f977@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-39472', 'https://www.cve.org/CVERecord?id=CVE-2024-39472'], 'PublishedDate': '2024-07-05T07:15:10.02Z', 'LastModifiedDate': '2024-08-19T05:15:06.543Z'}, {'VulnerabilityID': 'CVE-2024-41008', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: change vm->task_info handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: change vm->task_info handling\n\nThis patch changes the handling and lifecycle of vm->task_info object.\nThe major changes are:\n- vm->task_info is a dynamically allocated ptr now, and its uasge is\n reference counted.\n- introducing two new helper funcs for task_info lifecycle management\n - amdgpu_vm_get_task_info: reference counts up task_info before\n returning this info\n - amdgpu_vm_put_task_info: reference counts down task_info\n- last put to task_info() frees task_info from the vm.\n\nThis patch also does logistical changes required for existing usage\nof vm->task_info.\n\nV2: Do not block all the prints when task_info not found (Felix)\n\nV3: Fixed review comments from Felix\n - Fix wrong indentation\n - No debug message for -ENOMEM\n - Add NULL check for task_info\n - Do not duplicate the debug messages (ti vs no ti)\n - Get first reference of task_info in vm_init(), put last\n in vm_fini()\n\nV4: Fixed review comments from Felix\n - fix double reference increment in create_task_info\n - change amdgpu_vm_get_task_info_pasid\n - additional changes in amdgpu_gem.c while porting', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41008', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c (6.9-rc1)', 'https://git.kernel.org/stable/c/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c', 'https://linux.oracle.com/cve/CVE-2024-41008.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/20240716080357.2696435-2-lee@kernel.org/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41008', 'https://www.cve.org/CVERecord?id=CVE-2024-41008'], 'PublishedDate': '2024-07-16T08:15:02.24Z', 'LastModifiedDate': '2024-07-16T13:43:58.773Z'}, {'VulnerabilityID': 'CVE-2024-41009', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41009', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix overrunning reservations in ringbuf', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix overrunning reservations in ringbuf\n\nThe BPF ring buffer internally is implemented as a power-of-2 sized circular\nbuffer, with two logical and ever-increasing counters: consumer_pos is the\nconsumer counter to show which logical position the consumer consumed the\ndata, and producer_pos which is the producer counter denoting the amount of\ndata reserved by all producers.\n\nEach time a record is reserved, the producer that "owns" the record will\nsuccessfully advance producer counter. In user space each time a record is\nread, the consumer of the data advanced the consumer counter once it finished\nprocessing. Both counters are stored in separate pages so that from user\nspace, the producer counter is read-only and the consumer counter is read-write.\n\nOne aspect that simplifies and thus speeds up the implementation of both\nproducers and consumers is how the data area is mapped twice contiguously\nback-to-back in the virtual memory, allowing to not take any special measures\nfor samples that have to wrap around at the end of the circular buffer data\narea, because the next page after the last data page would be first data page\nagain, and thus the sample will still appear completely contiguous in virtual\nmemory.\n\nEach record has a struct bpf_ringbuf_hdr { u32 len; u32 pg_off; } header for\nbook-keeping the length and offset, and is inaccessible to the BPF program.\nHelpers like bpf_ringbuf_reserve() return `(void *)hdr + BPF_RINGBUF_HDR_SZ`\nfor the BPF program to use. Bing-Jhong and Muhammad reported that it is however\npossible to make a second allocated memory chunk overlapping with the first\nchunk and as a result, the BPF program is now able to edit first chunk\'s\nheader.\n\nFor example, consider the creation of a BPF_MAP_TYPE_RINGBUF map with size\nof 0x4000. Next, the consumer_pos is modified to 0x3000 /before/ a call to\nbpf_ringbuf_reserve() is made. This will allocate a chunk A, which is in\n[0x0,0x3008], and the BPF program is able to edit [0x8,0x3008]. Now, lets\nallocate a chunk B with size 0x3000. This will succeed because consumer_pos\nwas edited ahead of time to pass the `new_prod_pos - cons_pos > rb->mask`\ncheck. Chunk B will be in range [0x3008,0x6010], and the BPF program is able\nto edit [0x3010,0x6010]. Due to the ring buffer memory layout mentioned\nearlier, the ranges [0x0,0x4000] and [0x4000,0x8000] point to the same data\npages. This means that chunk B at [0x4000,0x4008] is chunk A\'s header.\nbpf_ringbuf_submit() / bpf_ringbuf_discard() use the header\'s pg_off to then\nlocate the bpf_ringbuf itself via bpf_ringbuf_restore_from_rec(). Once chunk\nB modified chunk A\'s header, then bpf_ringbuf_commit() refers to the wrong\npage and could cause a crash.\n\nFix it by calculating the oldest pending_pos and check whether the range\nfrom the oldest outstanding record to the newest would span beyond the ring\nbuffer size. If that is the case, then reject the request. We\'ve tested with\nthe ring buffer benchmark in BPF selftests (./benchs/run_bench_ringbufs.sh)\nbefore/after the fix and while it seems a bit slower on some benchmarks, it\nis still not significantly enough to matter.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41009', 'https://git.kernel.org/linus/cfa1a2329a691ffd991fcf7248a57d752e712881 (6.10-rc6)', 'https://git.kernel.org/stable/c/0f98f40eb1ed52af8b81f61901b6c0289ff59de4', 'https://git.kernel.org/stable/c/47416c852f2a04d348ea66ee451cbdcf8119f225', 'https://git.kernel.org/stable/c/511804ab701c0503b72eac08217eabfd366ba069', 'https://git.kernel.org/stable/c/be35504b959f2749bab280f4671e8df96dcf836f', 'https://git.kernel.org/stable/c/cfa1a2329a691ffd991fcf7248a57d752e712881', 'https://git.kernel.org/stable/c/d1b9df0435bc61e0b44f578846516df8ef476686', 'https://lore.kernel.org/linux-cve-announce/2024071715-CVE-2024-41009-cac5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41009', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-41009'], 'PublishedDate': '2024-07-17T07:15:01.973Z', 'LastModifiedDate': '2024-07-29T07:15:04.56Z'}, {'VulnerabilityID': 'CVE-2024-41013', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: don't walk off the end of a directory data block', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't walk off the end of a directory data block\n\nThis adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry\nto make sure don't stray beyond valid memory region. Before patching, the\nloop simply checks that the start offset of the dup and dep is within the\nrange. So in a crafted image, if last entry is xfs_dir2_data_unused, we\ncan change dup->length to dup->length-1 and leave 1 byte of space. In the\nnext traversal, this space will be considered as dup or dep. We may\nencounter an out of bound read when accessing the fixed members.\n\nIn the patch, we make sure that the remaining bytes large enough to hold\nan unused entry before accessing xfs_dir2_data_unused and\nxfs_dir2_data_unused is XFS_DIR2_DATA_ALIGN byte aligned. We also make\nsure that the remaining bytes large enough to hold a dirent with a\nsingle-byte name before accessing xfs_dir2_data_entry.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41013', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/0c7fcdb6d06cdf8b19b57c17605215b06afa864a (6.11-rc1)', 'https://git.kernel.org/stable/c/0c7fcdb6d06cdf8b19b57c17605215b06afa864a', 'https://linux.oracle.com/cve/CVE-2024-41013.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024072908-CVE-2024-41013-2996@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41013', 'https://www.cve.org/CVERecord?id=CVE-2024-41013'], 'PublishedDate': '2024-07-29T07:15:05.43Z', 'LastModifiedDate': '2024-07-29T14:12:08.783Z'}, {'VulnerabilityID': 'CVE-2024-41014', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41014', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: add bounds checking to xlog_recover_process_data', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: add bounds checking to xlog_recover_process_data\n\nThere is a lack of verification of the space occupied by fixed members\nof xlog_op_header in the xlog_recover_process_data.\n\nWe can create a crafted image to trigger an out of bounds read by\nfollowing these steps:\n 1) Mount an image of xfs, and do some file operations to leave records\n 2) Before umounting, copy the image for subsequent steps to simulate\n abnormal exit. Because umount will ensure that tail_blk and\n head_blk are the same, which will result in the inability to enter\n xlog_recover_process_data\n 3) Write a tool to parse and modify the copied image in step 2\n 4) Make the end of the xlog_op_header entries only 1 byte away from\n xlog_rec_header->h_size\n 5) xlog_rec_header->h_num_logops++\n 6) Modify xlog_rec_header->h_crc\n\nFix:\nAdd a check to make sure there is sufficient space to access fixed members\nof xlog_op_header.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41014', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/fb63435b7c7dc112b1ae1baea5486e0a6e27b196 (6.11-rc1)', 'https://git.kernel.org/stable/c/fb63435b7c7dc112b1ae1baea5486e0a6e27b196', 'https://linux.oracle.com/cve/CVE-2024-41014.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41014-9186@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41014', 'https://www.cve.org/CVERecord?id=CVE-2024-41014'], 'PublishedDate': '2024-07-29T07:15:05.81Z', 'LastModifiedDate': '2024-07-29T14:12:08.783Z'}, {'VulnerabilityID': 'CVE-2024-41016', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41016', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()\n\nxattr in ocfs2 maybe 'non-indexed', which saved with additional space\nrequested. It's better to check if the memory is out of bound before\nmemcmp, although this possibility mainly comes from crafted poisonous\nimages.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41016', 'https://git.kernel.org/linus/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 (6.11-rc1)', 'https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637', 'https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262', 'https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e', 'https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e', 'https://git.kernel.org/stable/c/cfb926051fab19b10d1e65976211f364aa820180', 'https://git.kernel.org/stable/c/e4ffea01adf3323c821b6f37e9577d2d400adbaa', 'https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41016-fcf9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41016', 'https://www.cve.org/CVERecord?id=CVE-2024-41016'], 'PublishedDate': '2024-07-29T07:15:06.293Z', 'LastModifiedDate': '2024-10-17T14:15:07.01Z'}, {'VulnerabilityID': 'CVE-2024-41024', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41024', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: misc: fastrpc: Restrict untrusted app to attach to privileged PD', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Restrict untrusted app to attach to privileged PD\n\nUntrusted application with access to only non-secure fastrpc device\nnode can attach to root_pd or static PDs if it can make the respective\ninit request. This can cause problems as the untrusted application\ncan send bad requests to root_pd or static PDs. Add changes to reject\nattach to privileged PDs if the request is being made using non-secure\nfastrpc device node.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41024', 'https://git.kernel.org/linus/bab2f5e8fd5d2f759db26b78d9db57412888f187 (6.10)', 'https://git.kernel.org/stable/c/2eb973ee4770a26d9b5e292b58ad29822d321c7f', 'https://git.kernel.org/stable/c/5e305b5986dc52122a9368a1461f0c13e1de3fd6', 'https://git.kernel.org/stable/c/bab2f5e8fd5d2f759db26b78d9db57412888f187', 'https://git.kernel.org/stable/c/c69fd8afacebfdf2f8a1ee1ea7e0723786529874', 'https://git.kernel.org/stable/c/ea13bd807f1cef1af375d999980a9b9794c789b6', 'https://lore.kernel.org/all/20240628114501.14310-7-srinivas.kandagatla@linaro.org/', 'https://lore.kernel.org/linux-cve-announce/2024072919-CVE-2024-41024-be39@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41024', 'https://www.cve.org/CVERecord?id=CVE-2024-41024'], 'PublishedDate': '2024-07-29T15:15:11.27Z', 'LastModifiedDate': '2024-08-29T17:15:07.913Z'}, {'VulnerabilityID': 'CVE-2024-42107', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42107', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: ice: Don't process extts if PTP is disabled", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Don't process extts if PTP is disabled\n\nThe ice_ptp_extts_event() function can race with ice_ptp_release() and\nresult in a NULL pointer dereference which leads to a kernel panic.\n\nPanic occurs because the ice_ptp_extts_event() function calls\nptp_clock_event() with a NULL pointer. The ice driver has already\nreleased the PTP clock by the time the interrupt for the next external\ntimestamp event occurs.\n\nTo fix this, modify the ice_ptp_extts_event() function to check the\nPTP state and bail early if PTP is not ready.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42107', 'https://git.kernel.org/linus/996422e3230e41468f652d754fefd1bdbcd4604e (6.10-rc7)', 'https://git.kernel.org/stable/c/1c4e524811918600683b1ea87a5e0fc2db64fa9b', 'https://git.kernel.org/stable/c/996422e3230e41468f652d754fefd1bdbcd4604e', 'https://lore.kernel.org/linux-cve-announce/2024073020-CVE-2024-42107-65cc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42107', 'https://www.cve.org/CVERecord?id=CVE-2024-42107'], 'PublishedDate': '2024-07-30T08:15:03.22Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42116', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42116', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: igc: fix a log entry using uninitialized netdev', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nigc: fix a log entry using uninitialized netdev\n\nDuring successful probe, igc logs this:\n\n[ 5.133667] igc 0000:01:00.0 (unnamed net_device) (uninitialized): PHC added\n ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe reason is that igc_ptp_init() is called very early, even before\nregister_netdev() has been called. So the netdev_info() call works\non a partially uninitialized netdev.\n\nFix this by calling igc_ptp_init() after register_netdev(), right\nafter the media autosense check, just as in igb. Add a comment,\njust as in igb.\n\nNow the log message is fine:\n\n[ 5.200987] igc 0000:01:00.0 eth0: PHC added', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42116', 'https://git.kernel.org/linus/86167183a17e03ec77198897975e9fdfbd53cb0b (6.10-rc1)', 'https://git.kernel.org/stable/c/86167183a17e03ec77198897975e9fdfbd53cb0b', 'https://git.kernel.org/stable/c/96839f3f588236593de36465f142b0126267f8b6', 'https://git.kernel.org/stable/c/98c8958980e829f023a490b9a9816ca1fe2f8b79', 'https://git.kernel.org/stable/c/991f036cabc3d13e886a37faeea1b6800181fdda', 'https://git.kernel.org/stable/c/d478ec838cf2b1e1051a8709cfc744fe1c03110f', 'https://linux.oracle.com/cve/CVE-2024-42116.html', 'https://linux.oracle.com/errata/ELSA-2024-12618.html', 'https://lore.kernel.org/linux-cve-announce/2024073023-CVE-2024-42116-b420@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42116', 'https://www.cve.org/CVERecord?id=CVE-2024-42116'], 'PublishedDate': '2024-07-30T08:15:03.95Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42122', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42122', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add NULL pointer check for kzalloc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL pointer check for kzalloc\n\n[Why & How]\nCheck return pointer of kzalloc before using it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42122', 'https://git.kernel.org/linus/8e65a1b7118acf6af96449e1e66b7adbc9396912 (6.10-rc1)', 'https://git.kernel.org/stable/c/062edd612fcd300f0f79a36fca5b8b6a5e2fce70', 'https://git.kernel.org/stable/c/8e65a1b7118acf6af96449e1e66b7adbc9396912', 'https://lore.kernel.org/linux-cve-announce/2024073025-CVE-2024-42122-2f70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42122', 'https://www.cve.org/CVERecord?id=CVE-2024-42122'], 'PublishedDate': '2024-07-30T08:15:04.43Z', 'LastModifiedDate': '2024-09-16T13:49:27.837Z'}, {'VulnerabilityID': 'CVE-2024-42125', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42125', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw89: fw: scan offload prohibit all 6 GHz channel if no 6 GHz sband', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fw: scan offload prohibit all 6 GHz channel if no 6 GHz sband\n\nWe have some policy via BIOS to block uses of 6 GHz. In this case, 6 GHz\nsband will be NULL even if it is WiFi 7 chip. So, add NULL handling here\nto avoid crash.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42125', 'https://git.kernel.org/linus/bb38626f3f97e16e6d368a9ff6daf320f3fe31d9 (6.10-rc1)', 'https://git.kernel.org/stable/c/bb38626f3f97e16e6d368a9ff6daf320f3fe31d9', 'https://git.kernel.org/stable/c/ce4ba62f8bc5195a9a0d49c6235a9c99e619cadc', 'https://lore.kernel.org/linux-cve-announce/2024073026-CVE-2024-42125-b515@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42125', 'https://www.cve.org/CVERecord?id=CVE-2024-42125'], 'PublishedDate': '2024-07-30T08:15:04.667Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42139', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42139', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Fix improper extts handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix improper extts handling\n\nExtts events are disabled and enabled by the application ts2phc.\nHowever, in case where the driver is removed when the application is\nrunning, a specific extts event remains enabled and can cause a kernel\ncrash.\nAs a side effect, when the driver is reloaded and application is started\nagain, remaining extts event for the channel from a previous run will\nkeep firing and the message "extts on unexpected channel" might be\nprinted to the user.\n\nTo avoid that, extts events shall be disabled when PTP is released.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42139', 'https://git.kernel.org/linus/00d3b4f54582d4e4a02cda5886bb336eeab268cc (6.10-rc7)', 'https://git.kernel.org/stable/c/00d3b4f54582d4e4a02cda5886bb336eeab268cc', 'https://git.kernel.org/stable/c/9f69b31ae9e25dec27ad31fbc64dd99af16ee3d3', 'https://lore.kernel.org/linux-cve-announce/2024073030-CVE-2024-42139-f8ef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42139', 'https://www.cve.org/CVERecord?id=CVE-2024-42139'], 'PublishedDate': '2024-07-30T08:15:05.757Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42154', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42154', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp_metrics: validate source addr length', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_metrics: validate source addr length\n\nI don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4\nis at least 4 bytes long, and the policy doesn't have an entry\nfor this attribute at all (neither does it for IPv6 but v6 is\nmanually validated).", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42154', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/66be40e622e177316ae81717aa30057ba9e61dff (6.10-rc7)', 'https://git.kernel.org/stable/c/19d997b59fa1fd7a02e770ee0881c0652b9c32c9', 'https://git.kernel.org/stable/c/2a2e79dbe2236a1289412d2044994f7ab419b44c', 'https://git.kernel.org/stable/c/31f03bb04146c1c6df6c03e9f45401f5f5a985d3', 'https://git.kernel.org/stable/c/3d550dd5418729a6e77fe7721d27adea7152e321', 'https://git.kernel.org/stable/c/66be40e622e177316ae81717aa30057ba9e61dff', 'https://git.kernel.org/stable/c/8c2debdd170e395934ac0e039748576dfde14e99', 'https://git.kernel.org/stable/c/cdffc358717e436bb67122bb82c1a2a26e050f98', 'https://git.kernel.org/stable/c/ef7c428b425beeb52b894e16f1c4b629d6cebfb6', 'https://linux.oracle.com/cve/CVE-2024-42154.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024073034-CVE-2024-42154-cf82@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42154', 'https://ubuntu.com/security/notices/USN-7003-1', 'https://ubuntu.com/security/notices/USN-7003-2', 'https://ubuntu.com/security/notices/USN-7003-3', 'https://ubuntu.com/security/notices/USN-7003-4', 'https://ubuntu.com/security/notices/USN-7003-5', 'https://ubuntu.com/security/notices/USN-7006-1', 'https://ubuntu.com/security/notices/USN-7007-1', 'https://ubuntu.com/security/notices/USN-7007-2', 'https://ubuntu.com/security/notices/USN-7007-3', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://ubuntu.com/security/notices/USN-7019-1', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://ubuntu.com/security/notices/USN-7039-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42154'], 'PublishedDate': '2024-07-30T08:15:06.933Z', 'LastModifiedDate': '2024-10-01T19:32:18.31Z'}, {'VulnerabilityID': 'CVE-2024-42159', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42159', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: mpi3mr: Sanitise num_phys', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Sanitise num_phys\n\nInformation is stored in mr_sas_port->phy_mask, values larger then size of\nthis field shouldn't be allowed.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42159', 'https://git.kernel.org/linus/3668651def2c1622904e58b0280ee93121f2b10b (6.10-rc1)', 'https://git.kernel.org/stable/c/3668651def2c1622904e58b0280ee93121f2b10b', 'https://git.kernel.org/stable/c/586b41060113ae43032ec6c4a16d518cef5da6e0', 'https://git.kernel.org/stable/c/b869ec89d2ee923d46608b76e54c006680c9b4df', 'https://git.kernel.org/stable/c/c8707901b53a48106d7501bdbd0350cefaefa4cf', 'https://linux.oracle.com/cve/CVE-2024-42159.html', 'https://linux.oracle.com/errata/ELSA-2024-12682.html', 'https://lore.kernel.org/linux-cve-announce/2024073036-CVE-2024-42159-c19e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42159', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42159'], 'PublishedDate': '2024-07-30T08:15:07.3Z', 'LastModifiedDate': '2024-08-02T14:29:46.24Z'}, {'VulnerabilityID': 'CVE-2024-42160', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42160', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: check validation of fault attrs in f2fs_build_fault_attr()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: check validation of fault attrs in f2fs_build_fault_attr()\n\n- It missed to check validation of fault attrs in parse_options(),\nlet's fix to add check condition in f2fs_build_fault_attr().\n- Use f2fs_build_fault_attr() in __sbi_store() to clean up code.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42160', 'https://git.kernel.org/linus/4ed886b187f47447ad559619c48c086f432d2b77 (6.10-rc1)', 'https://git.kernel.org/stable/c/44958ca9e400f57bd0478115519ffc350fcee61e', 'https://git.kernel.org/stable/c/4ed886b187f47447ad559619c48c086f432d2b77', 'https://git.kernel.org/stable/c/bc84dd2c33e0c10fd90d60f0cfc0bfb504d4692d', 'https://git.kernel.org/stable/c/ecb641f424d6d1f055d149a15b892edcc92c504b', 'https://lore.kernel.org/linux-cve-announce/2024073036-CVE-2024-42160-c733@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42160', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7022-1', 'https://ubuntu.com/security/notices/USN-7022-2', 'https://ubuntu.com/security/notices/USN-7022-3', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42160'], 'PublishedDate': '2024-07-30T08:15:07.37Z', 'LastModifiedDate': '2024-08-02T14:29:26.33Z'}, {'VulnerabilityID': 'CVE-2024-42224', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42224', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: mv88e6xxx: Correct check for empty list', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Correct check for empty list\n\nSince commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO\nbusses") mv88e6xxx_default_mdio_bus() has checked that the\nreturn value of list_first_entry() is non-NULL.\n\nThis appears to be intended to guard against the list chip->mdios being\nempty. However, it is not the correct check as the implementation of\nlist_first_entry is not designed to return NULL for empty lists.\n\nInstead, use list_first_entry_or_null() which does return NULL if the\nlist is empty.\n\nFlagged by Smatch.\nCompile tested only.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 6.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42224', 'https://git.kernel.org/linus/4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b (6.10-rc1)', 'https://git.kernel.org/stable/c/2a2fe25a103cef73cde356e6d09da10f607e93f5', 'https://git.kernel.org/stable/c/3bf8d70e1455f87856640c3433b3660a31001618', 'https://git.kernel.org/stable/c/3f25b5f1635449036692a44b771f39f772190c1d', 'https://git.kernel.org/stable/c/47d28dde172696031c880c5778633cdca30394ee', 'https://git.kernel.org/stable/c/4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b', 'https://git.kernel.org/stable/c/8c2c3cca816d074c75a2801d1ca0dea7b0148114', 'https://git.kernel.org/stable/c/aa03f591ef31ba603a4a99d05d25a0f21ab1cd89', 'https://git.kernel.org/stable/c/f75625db838ade28f032dacd0f0c8baca42ecde4', 'https://linux.oracle.com/cve/CVE-2024-42224.html', 'https://linux.oracle.com/errata/ELSA-2024-12779.html', 'https://lore.kernel.org/linux-cve-announce/2024073037-CVE-2024-42224-863a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42224', 'https://ubuntu.com/security/notices/USN-7003-1', 'https://ubuntu.com/security/notices/USN-7003-2', 'https://ubuntu.com/security/notices/USN-7003-3', 'https://ubuntu.com/security/notices/USN-7003-4', 'https://ubuntu.com/security/notices/USN-7003-5', 'https://ubuntu.com/security/notices/USN-7006-1', 'https://ubuntu.com/security/notices/USN-7007-1', 'https://ubuntu.com/security/notices/USN-7007-2', 'https://ubuntu.com/security/notices/USN-7007-3', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://ubuntu.com/security/notices/USN-7019-1', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42224'], 'PublishedDate': '2024-07-30T08:15:07.667Z', 'LastModifiedDate': '2024-09-25T15:55:09.027Z'}, {'VulnerabilityID': 'CVE-2024-42228', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42228', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc\n\nInitialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001.\nV2: To really improve the handling we would actually\n need to have a separate value of 0xffffffff.(Christian)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 6.3}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42228', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/88a9a467c548d0b3c7761b4fd54a68e70f9c0944 (6.10-rc1)', 'https://git.kernel.org/stable/c/3b505759447637dcccb50cbd98ec6f8d2a04fc46', 'https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef', 'https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944', 'https://git.kernel.org/stable/c/9ee1534ecdd5b4c013064663502d7fde824d2144', 'https://git.kernel.org/stable/c/d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8', 'https://git.kernel.org/stable/c/da6a85d197888067e8d38b5d22c986b5b5cab712', 'https://git.kernel.org/stable/c/df02642c21c984303fe34c3f7d72965792fb1a15', 'https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440', 'https://linux.oracle.com/cve/CVE-2024-42228.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024073038-CVE-2024-42228-86f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42228', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7022-1', 'https://ubuntu.com/security/notices/USN-7022-2', 'https://ubuntu.com/security/notices/USN-7022-3', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://ubuntu.com/security/notices/USN-7039-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42228'], 'PublishedDate': '2024-07-30T08:15:07.96Z', 'LastModifiedDate': '2024-09-04T12:15:04.577Z'}, {'VulnerabilityID': 'CVE-2024-42258', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42258', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines\n\nYves-Alexis Perez reported commit 4ef9ad19e176 ("mm: huge_memory: don\'t\nforce huge page alignment on 32 bit") didn\'t work for x86_32 [1]. It is\nbecause x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT.\n\n!CONFIG_64BIT should cover all 32 bit machines.\n\n[1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42258', 'https://git.kernel.org/linus/d9592025000b3cf26c742f3505da7b83aedc26d5 (6.11-rc1)', 'https://git.kernel.org/stable/c/7e1f4efb8d6140b2ec79bf760c43e1fc186e8dfc', 'https://git.kernel.org/stable/c/89f2914dd4b47d2fad3deef0d700f9526d98d11f', 'https://git.kernel.org/stable/c/a5c399fe433a115e9d3693169b5f357f3194af0a', 'https://git.kernel.org/stable/c/d9592025000b3cf26c742f3505da7b83aedc26d5', 'https://lore.kernel.org/linux-cve-announce/2024081216-CVE-2024-42258-e3f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42258', 'https://www.cve.org/CVERecord?id=CVE-2024-42258'], 'PublishedDate': '2024-08-12T15:15:20.983Z', 'LastModifiedDate': '2024-08-14T14:15:27.727Z'}, {'VulnerabilityID': 'CVE-2024-42259', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42259', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/i915/gem: Fix Virtual Memory mapping boundaries calculation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix Virtual Memory mapping boundaries calculation\n\nCalculating the size of the mapped area as the lesser value\nbetween the requested size and the actual size does not consider\nthe partial mapping offset. This can cause page fault access.\n\nFix the calculation of the starting and ending addresses, the\ntotal size is now deduced from the difference between the end and\nstart addresses.\n\nAdditionally, the calculations have been rewritten in a clearer\nand more understandable form.\n\n[Joonas: Add Requires: tag]\nRequires: 60a2066c5005 ("drm/i915/gem: Adjust vma offset for framebuffer mmap offset")\n(cherry picked from commit 97b6784753da06d9d40232328efc5c5367e53417)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-131'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42259', 'https://git.kernel.org/linus/8bdd9ef7e9b1b2a73e394712b72b22055e0e26c3 (6.11-rc3)', 'https://git.kernel.org/stable/c/3e06073d24807f04b4694108a8474decb7b99e60', 'https://git.kernel.org/stable/c/4b09513ce93b3dcb590baaaff2ce96f2d098312d', 'https://git.kernel.org/stable/c/50111a8098fb9ade621eeff82228a997d42732ab', 'https://git.kernel.org/stable/c/8bdd9ef7e9b1b2a73e394712b72b22055e0e26c3', 'https://git.kernel.org/stable/c/911f8055f175c82775d0fd8cedcd0b75413f4ba7', 'https://git.kernel.org/stable/c/a256d019eaf044864c7e50312f0a65b323c24f39', 'https://git.kernel.org/stable/c/e8a68aa842d3f8dd04a46b9d632e5f67fde1da9b', 'https://git.kernel.org/stable/c/ead9289a51ea82eb5b27029fcf4c34b2dd60cf06', 'https://linux.oracle.com/cve/CVE-2024-42259.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081452-CVE-2024-42259-4cef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42259', 'https://project-zero.issues.chromium.org/issues/42451707', 'https://www.cve.org/CVERecord?id=CVE-2024-42259'], 'PublishedDate': '2024-08-14T15:15:31.673Z', 'LastModifiedDate': '2024-09-25T01:15:42.137Z'}, {'VulnerabilityID': 'CVE-2024-42260', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42260', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Validate passed in drm syncobj handles in the performance extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Validate passed in drm syncobj handles in the performance extension\n\nIf userspace provides an unknown or invalid handle anywhere in the handle\narray the rest of the driver will not handle that well.\n\nFix it by checking handle was looked up successfully or otherwise fail the\nextension by jumping into the existing unwind.\n\n(cherry picked from commit a546b7e4d73c23838d7e4d2c92882b3ca902d213)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42260', 'https://git.kernel.org/linus/4ecc24a84d7e0254efd150ec23e0b89638386516 (6.11-rc2)', 'https://git.kernel.org/stable/c/4ecc24a84d7e0254efd150ec23e0b89638386516', 'https://git.kernel.org/stable/c/5d4aa25f47cd05e9eeac272906588728588605dd', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-42260-0ce0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42260', 'https://www.cve.org/CVERecord?id=CVE-2024-42260'], 'PublishedDate': '2024-08-17T09:15:07.53Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42261', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42261', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Validate passed in drm syncobj handles in the timestamp extension\n\nIf userspace provides an unknown or invalid handle anywhere in the handle\narray the rest of the driver will not handle that well.\n\nFix it by checking handle was looked up successfully or otherwise fail the\nextension by jumping into the existing unwind.\n\n(cherry picked from commit 8d1276d1b8f738c3afe1457d4dff5cc66fc848a3)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42261', 'https://git.kernel.org/linus/023d22e8bb0cdd6900382ad1ed06df3b6c2ea791 (6.11-rc2)', 'https://git.kernel.org/stable/c/023d22e8bb0cdd6900382ad1ed06df3b6c2ea791', 'https://git.kernel.org/stable/c/5c56f104edd02a537e9327dc543574e55713e1d7', 'https://lore.kernel.org/linux-cve-announce/2024081736-CVE-2024-42261-f6a2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42261', 'https://www.cve.org/CVERecord?id=CVE-2024-42261'], 'PublishedDate': '2024-08-17T09:15:07.6Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42262', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42262', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix potential memory leak in the performance extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix potential memory leak in the performance extension\n\nIf fetching of userspace memory fails during the main loop, all drm sync\nobjs looked up until that point will be leaked because of the missing\ndrm_syncobj_put.\n\nFix it by exporting and using a common cleanup helper.\n\n(cherry picked from commit 484de39fa5f5b7bd0c5f2e2c5265167250ef7501)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42262', 'https://git.kernel.org/linus/32df4abc44f24dbec239d43e2b26d5768c5d1a78 (6.11-rc2)', 'https://git.kernel.org/stable/c/32df4abc44f24dbec239d43e2b26d5768c5d1a78', 'https://git.kernel.org/stable/c/ad5fdc48f7a63b8a98493c667505fe4d3864ae21', 'https://lore.kernel.org/linux-cve-announce/2024081736-CVE-2024-42262-7156@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42262', 'https://www.cve.org/CVERecord?id=CVE-2024-42262'], 'PublishedDate': '2024-08-17T09:15:07.68Z', 'LastModifiedDate': '2024-08-19T20:05:15.407Z'}, {'VulnerabilityID': 'CVE-2024-42263', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42263', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix potential memory leak in the timestamp extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix potential memory leak in the timestamp extension\n\nIf fetching of userspace memory fails during the main loop, all drm sync\nobjs looked up until that point will be leaked because of the missing\ndrm_syncobj_put.\n\nFix it by exporting and using a common cleanup helper.\n\n(cherry picked from commit 753ce4fea62182c77e1691ab4f9022008f25b62e)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42263', 'https://git.kernel.org/linus/0e50fcc20bd87584840266e8004f9064a8985b4f (6.11-rc2)', 'https://git.kernel.org/stable/c/0e50fcc20bd87584840266e8004f9064a8985b4f', 'https://git.kernel.org/stable/c/9b5033ee2c5af6d1135a403df32d219ab57e55f9', 'https://lore.kernel.org/linux-cve-announce/2024081737-CVE-2024-42263-31b3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42263', 'https://www.cve.org/CVERecord?id=CVE-2024-42263'], 'PublishedDate': '2024-08-17T09:15:07.77Z', 'LastModifiedDate': '2024-08-19T20:41:11.24Z'}, {'VulnerabilityID': 'CVE-2024-42264', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42264', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Prevent out of bounds access in performance query extensions', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Prevent out of bounds access in performance query extensions\n\nCheck that the number of perfmons userspace is passing in the copy and\nreset extensions is not greater than the internal kernel storage where\nthe ids will be copied into.\n\n(cherry picked from commit f32b5128d2c440368b5bf3a7a356823e235caabb)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42264', 'https://git.kernel.org/linus/6ce9efd12ae81cf46bf44eb0348594558dfbb9d2 (6.11-rc2)', 'https://git.kernel.org/stable/c/6ce9efd12ae81cf46bf44eb0348594558dfbb9d2', 'https://git.kernel.org/stable/c/73ad583bd4938bf37d2709fc36901eb6f22f2722', 'https://lore.kernel.org/linux-cve-announce/2024081737-CVE-2024-42264-5d23@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42264', 'https://www.cve.org/CVERecord?id=CVE-2024-42264'], 'PublishedDate': '2024-08-17T09:15:07.833Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42267', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42267', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv/mm: Add handling for VM_FAULT_SIGSEGV in mm_fault_error()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/mm: Add handling for VM_FAULT_SIGSEGV in mm_fault_error()\n\nHandle VM_FAULT_SIGSEGV in the page fault path so that we correctly\nkill the process and we don't BUG() the kernel.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42267', 'https://git.kernel.org/linus/0c710050c47d45eb77b28c271cddefc5c785cb40 (6.11-rc2)', 'https://git.kernel.org/stable/c/0c710050c47d45eb77b28c271cddefc5c785cb40', 'https://git.kernel.org/stable/c/20dbdebc5580cd472a310d56a6e252275ee4c864', 'https://git.kernel.org/stable/c/59be4a167782d68e21068a761b90b01fadc09146', 'https://git.kernel.org/stable/c/917f598209f3f5e4ab175d5079d8aeb523e58b1f', 'https://git.kernel.org/stable/c/d4e7db757e2d7f4c407a007e92c98477eab215d2', 'https://git.kernel.org/stable/c/d7ccf2ca772bfe33e2c53ef80fa20d2d87eb6144', 'https://lore.kernel.org/linux-cve-announce/2024081738-CVE-2024-42267-9f79@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42267', 'https://www.cve.org/CVERecord?id=CVE-2024-42267'], 'PublishedDate': '2024-08-17T09:15:08.047Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42268', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42268', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix missing lock on sync reset reload', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix missing lock on sync reset reload\n\nOn sync reset reload work, when remote host updates devlink on reload\nactions performed on that host, it misses taking devlink lock before\ncalling devlink_remote_reload_actions_performed() which results in\ntriggering lock assert like the following:\n\nWARNING: CPU: 4 PID: 1164 at net/devlink/core.c:261 devl_assert_locked+0x3e/0x50\n…\n CPU: 4 PID: 1164 Comm: kworker/u96:6 Tainted: G S W 6.10.0-rc2+ #116\n Hardware name: Supermicro SYS-2028TP-DECTR/X10DRT-PT, BIOS 2.0 12/18/2015\n Workqueue: mlx5_fw_reset_events mlx5_sync_reset_reload_work [mlx5_core]\n RIP: 0010:devl_assert_locked+0x3e/0x50\n…\n Call Trace:\n \n ? __warn+0xa4/0x210\n ? devl_assert_locked+0x3e/0x50\n ? report_bug+0x160/0x280\n ? handle_bug+0x3f/0x80\n ? exc_invalid_op+0x17/0x40\n ? asm_exc_invalid_op+0x1a/0x20\n ? devl_assert_locked+0x3e/0x50\n devlink_notify+0x88/0x2b0\n ? mlx5_attach_device+0x20c/0x230 [mlx5_core]\n ? __pfx_devlink_notify+0x10/0x10\n ? process_one_work+0x4b6/0xbb0\n process_one_work+0x4b6/0xbb0\n[…]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42268', 'https://git.kernel.org/linus/572f9caa9e7295f8c8822e4122c7ae8f1c412ff9 (6.11-rc2)', 'https://git.kernel.org/stable/c/091268f3c27a5b6d7858a3bb2a0dbcc9cd26ddb5', 'https://git.kernel.org/stable/c/572f9caa9e7295f8c8822e4122c7ae8f1c412ff9', 'https://git.kernel.org/stable/c/5d07d1d40aabfd61bab21115639bd4f641db6002', 'https://git.kernel.org/stable/c/98884e89c90d077f6fe6ba18e6cf6f914642f04e', 'https://lore.kernel.org/linux-cve-announce/2024081738-CVE-2024-42268-2084@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42268', 'https://www.cve.org/CVERecord?id=CVE-2024-42268'], 'PublishedDate': '2024-08-17T09:15:08.11Z', 'LastModifiedDate': '2024-08-19T20:52:49.323Z'}, {'VulnerabilityID': 'CVE-2024-42269', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42269', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().\n\nip6table_nat_table_init() accesses net->gen->ptr[ip6table_nat_net_ops.id],\nbut the function is exposed to user space before the entry is allocated\nvia register_pernet_subsys().\n\nLet's call register_pernet_subsys() before xt_register_template().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42269', 'https://git.kernel.org/linus/c22921df777de5606f1047b1345b8d22ef1c0b34 (6.11-rc2)', 'https://git.kernel.org/stable/c/419ee6274c5153b89c4393c1946faa4c3cad4f9e', 'https://git.kernel.org/stable/c/87dba44e9471b79b255d0736858a897332db9226', 'https://git.kernel.org/stable/c/91b6df6611b7edb28676c4f63f90c56c30d3e601', 'https://git.kernel.org/stable/c/c22921df777de5606f1047b1345b8d22ef1c0b34', 'https://git.kernel.org/stable/c/e85b9b6a87be4cb3710082038b677e97f2389003', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42269-7d0a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42269', 'https://www.cve.org/CVERecord?id=CVE-2024-42269'], 'PublishedDate': '2024-08-17T09:15:08.177Z', 'LastModifiedDate': '2024-08-19T20:53:51.717Z'}, {'VulnerabilityID': 'CVE-2024-42270', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42270', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().\n\nWe had a report that iptables-restore sometimes triggered null-ptr-deref\nat boot time. [0]\n\nThe problem is that iptable_nat_table_init() is exposed to user space\nbefore the kernel fully initialises netns.\n\nIn the small race window, a user could call iptable_nat_table_init()\nthat accesses net_generic(net, iptable_nat_net_id), which is available\nonly after registering iptable_nat_net_ops.\n\nLet's call register_pernet_subsys() before xt_register_template().\n\n[0]:\nbpfilter: Loaded bpfilter_umh pid 11702\nStarted bpfilter\nBUG: kernel NULL pointer dereference, address: 0000000000000013\n PF: supervisor write access in kernel mode\n PF: error_code(0x0002) - not-present page\nPGD 0 P4D 0\nPREEMPT SMP NOPTI\nCPU: 2 PID: 11879 Comm: iptables-restor Not tainted 6.1.92-99.174.amzn2023.x86_64 #1\nHardware name: Amazon EC2 c6i.4xlarge/, BIOS 1.0 10/16/2017\nRIP: 0010:iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat\nCode: 10 4c 89 f6 48 89 ef e8 0b 19 bb ff 41 89 c4 85 c0 75 38 41 83 c7 01 49 83 c6 28 41 83 ff 04 75 dc 48 8b 44 24 08 48 8b 0c 24 <48> 89 08 4c 89 ef e8 a2 3b a2 cf 48 83 c4 10 44 89 e0 5b 5d 41 5c\nRSP: 0018:ffffbef902843cd0 EFLAGS: 00010246\nRAX: 0000000000000013 RBX: ffff9f4b052caa20 RCX: ffff9f4b20988d80\nRDX: 0000000000000000 RSI: 0000000000000064 RDI: ffffffffc04201c0\nRBP: ffff9f4b29394000 R08: ffff9f4b07f77258 R09: ffff9f4b07f77240\nR10: 0000000000000000 R11: ffff9f4b09635388 R12: 0000000000000000\nR13: ffff9f4b1a3c6c00 R14: ffff9f4b20988e20 R15: 0000000000000004\nFS: 00007f6284340000(0000) GS:ffff9f51fe280000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000013 CR3: 00000001d10a6005 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? xt_find_table_lock (net/netfilter/x_tables.c:1259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? page_fault_oops (arch/x86/mm/fault.c:727)\n ? exc_page_fault (./arch/x86/include/asm/irqflags.h:40 ./arch/x86/include/asm/irqflags.h:75 arch/x86/mm/fault.c:1470 arch/x86/mm/fault.c:1518)\n ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570)\n ? iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat\n xt_find_table_lock (net/netfilter/x_tables.c:1259)\n xt_request_find_table_lock (net/netfilter/x_tables.c:1287)\n get_info (net/ipv4/netfilter/ip_tables.c:965)\n ? security_capable (security/security.c:809 (discriminator 13))\n ? ns_capable (kernel/capability.c:376 kernel/capability.c:397)\n ? do_ipt_get_ctl (net/ipv4/netfilter/ip_tables.c:1656)\n ? bpfilter_send_req (net/bpfilter/bpfilter_kern.c:52) bpfilter\n nf_getsockopt (net/netfilter/nf_sockopt.c:116)\n ip_getsockopt (net/ipv4/ip_sockglue.c:1827)\n __sys_getsockopt (net/socket.c:2327)\n __x64_sys_getsockopt (net/socket.c:2342 net/socket.c:2339 net/socket.c:2339)\n do_syscall_64 (arch/x86/entry/common.c:51 arch/x86/entry/common.c:81)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\nRIP: 0033:0x7f62844685ee\nCode: 48 8b 0d 45 28 0f 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 37 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 09\nRSP: 002b:00007ffd1f83d638 EFLAGS: 00000246 ORIG_RAX: 0000000000000037\nRAX: ffffffffffffffda RBX: 00007ffd1f83d680 RCX: 00007f62844685ee\nRDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000004\nRBP: 0000000000000004 R08: 00007ffd1f83d670 R09: 0000558798ffa2a0\nR10: 00007ffd1f83d680 R11: 0000000000000246 R12: 00007ffd1f83e3b2\nR13: 00007f6284\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42270', 'https://git.kernel.org/linus/5830aa863981d43560748aa93589c0695191d95d (6.11-rc2)', 'https://git.kernel.org/stable/c/08ed888b69a22647153fe2bec55b7cd0a46102cc', 'https://git.kernel.org/stable/c/5830aa863981d43560748aa93589c0695191d95d', 'https://git.kernel.org/stable/c/70014b73d7539fcbb6b4ff5f37368d7241d8e626', 'https://git.kernel.org/stable/c/95590a4929027769af35b153645c0ab6fd22b29b', 'https://git.kernel.org/stable/c/b98ddb65fa1674b0e6b52de8af9103b63f51b643', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42270-c752@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42270', 'https://ubuntu.com/security/notices/USN-7004-1', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://www.cve.org/CVERecord?id=CVE-2024-42270'], 'PublishedDate': '2024-08-17T09:15:08.24Z', 'LastModifiedDate': '2024-08-19T20:01:09.52Z'}, {'VulnerabilityID': 'CVE-2024-42272', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42272', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched: act_ct: take care of padding in struct zones_ht_key', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched: act_ct: take care of padding in struct zones_ht_key\n\nBlamed commit increased lookup key size from 2 bytes to 16 bytes,\nbecause zones_ht_key got a struct net pointer.\n\nMake sure rhashtable_lookup() is not using the padding bytes\nwhich are not initialized.\n\n BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline]\n BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline]\n BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329\n rht_ptr_rcu include/linux/rhashtable.h:376 [inline]\n __rhashtable_lookup include/linux/rhashtable.h:607 [inline]\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329\n tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408\n tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425\n tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488\n tcf_action_add net/sched/act_api.c:2061 [inline]\n tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118\n rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647\n netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550\n rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665\n netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]\n netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357\n netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n ____sys_sendmsg+0x877/0xb60 net/socket.c:2597\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651\n __sys_sendmsg net/socket.c:2680 [inline]\n __do_sys_sendmsg net/socket.c:2689 [inline]\n __se_sys_sendmsg net/socket.c:2687 [inline]\n __x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2687\n x64_sys_call+0x2dd6/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable key created at:\n tcf_ct_flow_table_get+0x4a/0x2260 net/sched/act_ct.c:324\n tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42272', 'https://git.kernel.org/linus/2191a54f63225b548fd8346be3611c3219a24738 (6.11-rc2)', 'https://git.kernel.org/stable/c/2191a54f63225b548fd8346be3611c3219a24738', 'https://git.kernel.org/stable/c/3a5b68869dbe14f1157c6a24ac71923db060eeab', 'https://git.kernel.org/stable/c/3ddefcb8f75e312535e2e7d5fef9932019ba60f2', 'https://git.kernel.org/stable/c/7c03ab555eb1ba26c77fd7c25bdf44a0ac23edee', 'https://git.kernel.org/stable/c/d06daf0ad645d9225a3ff6958dd82e1f3988fa64', 'https://git.kernel.org/stable/c/d7cc186d0973afce0e1237c37f7512c01981fb79', 'https://linux.oracle.com/cve/CVE-2024-42272.html', 'https://linux.oracle.com/errata/ELSA-2024-8162.html', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42272-c687@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42272', 'https://www.cve.org/CVERecord?id=CVE-2024-42272'], 'PublishedDate': '2024-08-17T09:15:08.37Z', 'LastModifiedDate': '2024-09-30T13:40:21.843Z'}, {'VulnerabilityID': 'CVE-2024-42273', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42273', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid\n\nmkdir /mnt/test/comp\nf2fs_io setflags compression /mnt/test/comp\ndd if=/dev/zero of=/mnt/test/comp/testfile bs=16k count=1\ntruncate --size 13 /mnt/test/comp/testfile\n\nIn the above scenario, we can get a BUG_ON.\n kernel BUG at fs/f2fs/segment.c:3589!\n Call Trace:\n do_write_page+0x78/0x390 [f2fs]\n f2fs_outplace_write_data+0x62/0xb0 [f2fs]\n f2fs_do_write_data_page+0x275/0x740 [f2fs]\n f2fs_write_single_data_page+0x1dc/0x8f0 [f2fs]\n f2fs_write_multi_pages+0x1e5/0xae0 [f2fs]\n f2fs_write_cache_pages+0xab1/0xc60 [f2fs]\n f2fs_write_data_pages+0x2d8/0x330 [f2fs]\n do_writepages+0xcf/0x270\n __writeback_single_inode+0x44/0x350\n writeback_sb_inodes+0x242/0x530\n __writeback_inodes_wb+0x54/0xf0\n wb_writeback+0x192/0x310\n wb_workfn+0x30d/0x400\n\nThe reason is we gave CURSEG_ALL_DATA_ATGC to COMPR_ADDR where the\npage was set the gcing flag by set_cluster_dirty().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42273', 'https://git.kernel.org/linus/8cb1f4080dd91c6e6b01dbea013a3f42341cb6a1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0cd106612396656d6f1ca17ef192c6759bb60791', 'https://git.kernel.org/stable/c/4239571c5db46a42f723b8fa8394039187c34439', 'https://git.kernel.org/stable/c/5fd057160ab240dd816ae09b625395d54c297de1', 'https://git.kernel.org/stable/c/8cb1f4080dd91c6e6b01dbea013a3f42341cb6a1', 'https://lore.kernel.org/linux-cve-announce/2024081740-CVE-2024-42273-9b87@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42273', 'https://www.cve.org/CVERecord?id=CVE-2024-42273'], 'PublishedDate': '2024-08-17T09:15:08.45Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42274', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42274', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "ALSA: firewire-lib: operate for period elapse event in process context"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "ALSA: firewire-lib: operate for period elapse event in process context"\n\nCommit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period elapse event\nin process context") removed the process context workqueue from\namdtp_domain_stream_pcm_pointer() and update_pcm_pointers() to remove\nits overhead.\n\nWith RME Fireface 800, this lead to a regression since\nKernels 5.14.0, causing an AB/BA deadlock competition for the\nsubstream lock with eventual system freeze under ALSA operation:\n\nthread 0:\n * (lock A) acquire substream lock by\n\tsnd_pcm_stream_lock_irq() in\n\tsnd_pcm_status64()\n * (lock B) wait for tasklet to finish by calling\n \ttasklet_unlock_spin_wait() in\n\ttasklet_disable_in_atomic() in\n\tohci_flush_iso_completions() of ohci.c\n\nthread 1:\n * (lock B) enter tasklet\n * (lock A) attempt to acquire substream lock,\n \twaiting for it to be released:\n\tsnd_pcm_stream_lock_irqsave() in\n \tsnd_pcm_period_elapsed() in\n\tupdate_pcm_pointers() in\n\tprocess_ctx_payloads() in\n\tprocess_rx_packets() of amdtp-stream.c\n\n? tasklet_unlock_spin_wait\n \n \nohci_flush_iso_completions firewire_ohci\namdtp_domain_stream_pcm_pointer snd_firewire_lib\nsnd_pcm_update_hw_ptr0 snd_pcm\nsnd_pcm_status64 snd_pcm\n\n? native_queued_spin_lock_slowpath\n \n \n_raw_spin_lock_irqsave\nsnd_pcm_period_elapsed snd_pcm\nprocess_rx_packets snd_firewire_lib\nirq_target_callback snd_firewire_lib\nhandle_it_packet firewire_ohci\ncontext_tasklet firewire_ohci\n\nRestore the process context work queue to prevent deadlock\nAB/BA deadlock competition for ALSA substream lock of\nsnd_pcm_stream_lock_irq() in snd_pcm_status64()\nand snd_pcm_stream_lock_irqsave() in snd_pcm_period_elapsed().\n\nrevert commit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period\nelapse event in process context")\n\nReplace inline description to prevent future deadlock.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42274', 'https://git.kernel.org/linus/3dab73ab925a51ab05543b491bf17463a48ca323 (6.11-rc2)', 'https://git.kernel.org/stable/c/36c255db5a25edd42d1aca48e38b8e95ee5fd9ef', 'https://git.kernel.org/stable/c/3dab73ab925a51ab05543b491bf17463a48ca323', 'https://git.kernel.org/stable/c/7c07220cf634002f93a87ca2252a32766850f2d1', 'https://git.kernel.org/stable/c/b239a37d68e8bc59f9516444da222841e3b13ba9', 'https://git.kernel.org/stable/c/f5043e69aeb2786f32e84132817a007a6430aa7d', 'https://lore.kernel.org/linux-cve-announce/2024081740-CVE-2024-42274-9dc6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42274', 'https://www.cve.org/CVERecord?id=CVE-2024-42274'], 'PublishedDate': '2024-08-17T09:15:08.53Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42276', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42276', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme-pci: add missing condition check for existence of mapped data', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: add missing condition check for existence of mapped data\n\nnvme_map_data() is called when request has physical segments, hence\nthe nvme_unmap_data() should have same condition to avoid dereference.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42276', 'https://git.kernel.org/linus/c31fad1470389666ac7169fe43aa65bf5b7e2cfd (6.11-rc1)', 'https://git.kernel.org/stable/c/3f8ec1d6b0ebd8268307d52be8301973fa5a01ec', 'https://git.kernel.org/stable/c/70100fe721840bf6d8e5abd25b8bffe4d2e049b7', 'https://git.kernel.org/stable/c/77848b379e9f85a08048a2c8b3b4a7e8396f5f83', 'https://git.kernel.org/stable/c/7cc1f4cd90a00b6191cb8cda2d1302fdce59361c', 'https://git.kernel.org/stable/c/be23ae63080e0bf9e246ab20207200bca6585eba', 'https://git.kernel.org/stable/c/c31fad1470389666ac7169fe43aa65bf5b7e2cfd', 'https://git.kernel.org/stable/c/d135c3352f7c947a922da93c8e763ee6bc208b64', 'https://linux.oracle.com/cve/CVE-2024-42276.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081741-CVE-2024-42276-cb0a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42276', 'https://www.cve.org/CVERecord?id=CVE-2024-42276'], 'PublishedDate': '2024-08-17T09:15:08.673Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42277', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42277', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu: sprd: Avoid NULL deref in sprd_iommu_hw_en\n\nIn sprd_iommu_cleanup() before calling function sprd_iommu_hw_en()\ndom->sdev is equal to NULL, which leads to null dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42277', 'https://git.kernel.org/linus/630482ee0653decf9e2482ac6181897eb6cde5b8 (6.11-rc1)', 'https://git.kernel.org/stable/c/630482ee0653decf9e2482ac6181897eb6cde5b8', 'https://git.kernel.org/stable/c/8c79ceb4ecf823e6ec10fee6febb0fca3de79922', 'https://git.kernel.org/stable/c/b62841e49a2b7938f6fdeaaf93fb57e4eb880bdb', 'https://git.kernel.org/stable/c/d5fe884ce28c5005f8582c35333c195a168f841c', 'https://git.kernel.org/stable/c/dfe90030a0cfa26dca4cb6510de28920e5ad22fb', 'https://lore.kernel.org/linux-cve-announce/2024081741-CVE-2024-42277-997a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42277', 'https://www.cve.org/CVERecord?id=CVE-2024-42277'], 'PublishedDate': '2024-08-17T09:15:08.75Z', 'LastModifiedDate': '2024-09-10T18:46:21.62Z'}, {'VulnerabilityID': 'CVE-2024-42278', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42278', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: TAS2781: Fix tasdev_load_calibrated_data()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: TAS2781: Fix tasdev_load_calibrated_data()\n\nThis function has a reversed if statement so it's either a no-op or it\nleads to a NULL dereference.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42278', 'https://git.kernel.org/linus/92c78222168e9035a9bfb8841c2e56ce23e51f73 (6.11-rc1)', 'https://git.kernel.org/stable/c/51be301d29d674ff328dfcf23705851f326f35b3', 'https://git.kernel.org/stable/c/6d98741dbd1309a6f2d7cffbb10a8f036ec3ca06', 'https://git.kernel.org/stable/c/92c78222168e9035a9bfb8841c2e56ce23e51f73', 'https://lore.kernel.org/linux-cve-announce/2024081742-CVE-2024-42278-e639@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42278', 'https://www.cve.org/CVERecord?id=CVE-2024-42278'], 'PublishedDate': '2024-08-17T09:15:08.813Z', 'LastModifiedDate': '2024-09-30T12:53:36.42Z'}, {'VulnerabilityID': 'CVE-2024-42279', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42279', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer\n\nWhile transmitting with rx_len == 0, the RX FIFO is not going to be\nemptied in the interrupt handler. A subsequent transfer could then\nread crap from the previous transfer out of the RX FIFO into the\nstart RX buffer. The core provides a register that will empty the RX and\nTX FIFOs, so do that before each transfer.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L', 'V3Score': 5.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42279', 'https://git.kernel.org/linus/9cf71eb0faef4bff01df4264841b8465382d7927 (6.11-rc1)', 'https://git.kernel.org/stable/c/3feda3677e8bbe833c3a62a4091377a08f015b80', 'https://git.kernel.org/stable/c/45e03d35229b680b79dfea1103a1f2f07d0b5d75', 'https://git.kernel.org/stable/c/9cf71eb0faef4bff01df4264841b8465382d7927', 'https://lore.kernel.org/linux-cve-announce/2024081742-CVE-2024-42279-91b0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42279', 'https://www.cve.org/CVERecord?id=CVE-2024-42279'], 'PublishedDate': '2024-08-17T09:15:08.88Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42281', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42281', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix a segment issue when downgrading gso_size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a segment issue when downgrading gso_size\n\nLinearize the skb when downgrading gso_size because it may trigger a\nBUG_ON() later when the skb is segmented as described in [1,2].', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42281', 'https://git.kernel.org/linus/fa5ef655615a01533035c6139248c5b33aa27028 (6.11-rc1)', 'https://git.kernel.org/stable/c/11ec79f5c7f74261874744039bc1551023edd6b2', 'https://git.kernel.org/stable/c/a689f5eb13a90f892a088865478b3cd39f53d5dc', 'https://git.kernel.org/stable/c/c3496314c53e7e82ddb544c825defc3e8c0e45cf', 'https://git.kernel.org/stable/c/dda518dea60d556a2d171c0122ca7d9fdb7d473a', 'https://git.kernel.org/stable/c/ec4eea14d75f7b0491194dd413f540dd19b8c733', 'https://git.kernel.org/stable/c/f6bb8c90cab97a3e03f8d30e3069efe6a742e0be', 'https://git.kernel.org/stable/c/fa5ef655615a01533035c6139248c5b33aa27028', 'https://linux.oracle.com/cve/CVE-2024-42281.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42281-780b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42281', 'https://www.cve.org/CVERecord?id=CVE-2024-42281'], 'PublishedDate': '2024-08-17T09:15:09.013Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42283', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42283', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: nexthop: Initialize all fields in dumped nexthops', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nexthop: Initialize all fields in dumped nexthops\n\nstruct nexthop_grp contains two reserved fields that are not initialized by\nnla_put_nh_group(), and carry garbage. This can be observed e.g. with\nstrace (edited for clarity):\n\n # ip nexthop add id 1 dev lo\n # ip nexthop add id 101 group 1\n # strace -e recvmsg ip nexthop get id 101\n ...\n recvmsg(... [{nla_len=12, nla_type=NHA_GROUP},\n [{id=1, weight=0, resvd1=0x69, resvd2=0x67}]] ...) = 52\n\nThe fields are reserved and therefore not currently used. But as they are, they\nleak kernel memory, and the fact they are not just zero complicates repurposing\nof the fields for new ends. Initialize the full structure.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42283', 'https://git.kernel.org/linus/6d745cd0e9720282cd291d36b9db528aea18add2 (6.11-rc1)', 'https://git.kernel.org/stable/c/1377de719652d868f5317ba8398b7e74c5f0430b', 'https://git.kernel.org/stable/c/5cc4d71dda2dd4f1520f40e634a527022e48ccd8', 'https://git.kernel.org/stable/c/6d745cd0e9720282cd291d36b9db528aea18add2', 'https://git.kernel.org/stable/c/7704460acd7f5d35eb07c52500987dc9b95313fb', 'https://git.kernel.org/stable/c/9e8f558a3afe99ce51a642ce0d3637ddc2b5d5d0', 'https://git.kernel.org/stable/c/a13d3864b76ac87085ec530b2ff8e37482a63a96', 'https://git.kernel.org/stable/c/fd06cb4a5fc7bda3dea31712618a62af72a1c6cb', 'https://linux.oracle.com/cve/CVE-2024-42283.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42283-15a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42283', 'https://www.cve.org/CVERecord?id=CVE-2024-42283'], 'PublishedDate': '2024-08-17T09:15:09.163Z', 'LastModifiedDate': '2024-08-19T19:54:33.213Z'}, {'VulnerabilityID': 'CVE-2024-42284', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42284', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Return non-zero value from tipc_udp_addr2str() on error\n\ntipc_udp_addr2str() should return non-zero value if the UDP media\naddress is invalid. Otherwise, a buffer overflow access can occur in\ntipc_media_addr_printf(). Fix this by returning 1 on an invalid UDP\nmedia address.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42284', 'https://git.kernel.org/linus/fa96c6baef1b5385e2f0c0677b32b3839e716076 (6.11-rc1)', 'https://git.kernel.org/stable/c/253405541be2f15ffebdeac2f4cf4b7e9144d12f', 'https://git.kernel.org/stable/c/2abe350db1aa599eeebc6892237d0bce0f1de62a', 'https://git.kernel.org/stable/c/5eea127675450583680c8170358bcba43227bd69', 'https://git.kernel.org/stable/c/728734352743a78b4c5a7285b282127696a4a813', 'https://git.kernel.org/stable/c/76ddf84a52f0d8ec3f5db6ccce08faf202a17d28', 'https://git.kernel.org/stable/c/7ec3335dd89c8d169e9650e4bac64fde71fdf15b', 'https://git.kernel.org/stable/c/aa38bf74899de07cf70b50cd17f8ad45fb6654c8', 'https://git.kernel.org/stable/c/fa96c6baef1b5385e2f0c0677b32b3839e716076', 'https://linux.oracle.com/cve/CVE-2024-42284.html', 'https://linux.oracle.com/errata/ELSA-2024-8162.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42284-bbfa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42284', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-42284'], 'PublishedDate': '2024-08-17T09:15:09.233Z', 'LastModifiedDate': '2024-08-19T19:47:55.623Z'}, {'VulnerabilityID': 'CVE-2024-42285', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42285', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/iwcm: Fix a use-after-free related to destroying CM IDs\n\niw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with\nan existing struct iw_cm_id (cm_id) as follows:\n\n conn_id->cm_id.iw = cm_id;\n cm_id->context = conn_id;\n cm_id->cm_handler = cma_iw_handler;\n\nrdma_destroy_id() frees both the cm_id and the struct rdma_id_private. Make\nsure that cm_work_handler() does not trigger a use-after-free by only\nfreeing of the struct rdma_id_private after all pending work has finished.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42285', 'https://git.kernel.org/linus/aee2424246f9f1dadc33faa78990c1e2eb7826e4 (6.11-rc1)', 'https://git.kernel.org/stable/c/557d035fe88d78dd51664f4dc0e1896c04c97cf6', 'https://git.kernel.org/stable/c/7f25f296fc9bd0435be14e89bf657cd615a23574', 'https://git.kernel.org/stable/c/94ee7ff99b87435ec63211f632918dc7f44dac79', 'https://git.kernel.org/stable/c/aee2424246f9f1dadc33faa78990c1e2eb7826e4', 'https://git.kernel.org/stable/c/d91d253c87fd1efece521ff2612078a35af673c6', 'https://git.kernel.org/stable/c/dc8074b8901caabb97c2d353abd6b4e7fa5a59a5', 'https://git.kernel.org/stable/c/ee39384ee787e86e9db4efb843818ef0ea9cb8ae', 'https://git.kernel.org/stable/c/ff5bbbdee08287d75d72e65b72a2b76d9637892a', 'https://linux.oracle.com/cve/CVE-2024-42285.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42285-37ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42285', 'https://www.cve.org/CVERecord?id=CVE-2024-42285'], 'PublishedDate': '2024-08-17T09:15:09.3Z', 'LastModifiedDate': '2024-08-19T19:45:41.59Z'}, {'VulnerabilityID': 'CVE-2024-42286', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42286', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: validate nvme_local_port correctly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: validate nvme_local_port correctly\n\nThe driver load failed with error message,\n\nqla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef\n\nand with a kernel crash,\n\n\tBUG: unable to handle kernel NULL pointer dereference at 0000000000000070\n\tWorkqueue: events_unbound qla_register_fcport_fn [qla2xxx]\n\tRIP: 0010:nvme_fc_register_remoteport+0x16/0x430 [nvme_fc]\n\tRSP: 0018:ffffaaa040eb3d98 EFLAGS: 00010282\n\tRAX: 0000000000000000 RBX: ffff9dfb46b78c00 RCX: 0000000000000000\n\tRDX: ffff9dfb46b78da8 RSI: ffffaaa040eb3e08 RDI: 0000000000000000\n\tRBP: ffff9dfb612a0a58 R08: ffffffffaf1d6270 R09: 3a34303a30303030\n\tR10: 34303a303030305b R11: 2078787832616c71 R12: ffff9dfb46b78dd4\n\tR13: ffff9dfb46b78c24 R14: ffff9dfb41525300 R15: ffff9dfb46b78da8\n\tFS: 0000000000000000(0000) GS:ffff9dfc67c00000(0000) knlGS:0000000000000000\n\tCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n\tCR2: 0000000000000070 CR3: 000000018da10004 CR4: 00000000000206f0\n\tCall Trace:\n\tqla_nvme_register_remote+0xeb/0x1f0 [qla2xxx]\n\t? qla2x00_dfs_create_rport+0x231/0x270 [qla2xxx]\n\tqla2x00_update_fcport+0x2a1/0x3c0 [qla2xxx]\n\tqla_register_fcport_fn+0x54/0xc0 [qla2xxx]\n\nExit the qla_nvme_register_remote() function when qla_nvme_register_hba()\nfails and correctly validate nvme_local_port.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42286', 'https://git.kernel.org/linus/eb1d4ce2609584eeb7694866f34d4b213caa3af9 (6.11-rc1)', 'https://git.kernel.org/stable/c/3eac973eb5cb2b874b3918f924798afc5affd46b', 'https://git.kernel.org/stable/c/549aac9655320c9b245a24271b204668c5d40430', 'https://git.kernel.org/stable/c/7cec2c3bfe84539c415f5e16f989228eba1d2f1e', 'https://git.kernel.org/stable/c/a3ab508a4853a9f5ae25a7816a4889f09938f63c', 'https://git.kernel.org/stable/c/cde43031df533751b4ead37d173922feee2f550f', 'https://git.kernel.org/stable/c/e1f010844443c389bc552884ac5cfa47de34d54c', 'https://git.kernel.org/stable/c/eb1d4ce2609584eeb7694866f34d4b213caa3af9', 'https://git.kernel.org/stable/c/f6be298cc1042f24d521197af29c7c4eb95af4d5', 'https://linux.oracle.com/cve/CVE-2024-42286.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42286-e856@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42286', 'https://www.cve.org/CVERecord?id=CVE-2024-42286'], 'PublishedDate': '2024-08-17T09:15:09.38Z', 'LastModifiedDate': '2024-09-10T19:02:12.36Z'}, {'VulnerabilityID': 'CVE-2024-42287', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42287', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: Complete command early within lock', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Complete command early within lock\n\nA crash was observed while performing NPIV and FW reset,\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 1 PREEMPT_RT SMP NOPTI\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffc90026f47b88 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000002\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8881041130d0\n RBP: ffff8881041130d0 R08: 0000000000000000 R09: 0000000000000034\n R10: ffffc90026f47c48 R11: 0000000000000031 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8881565e4a20 R15: 0000000000000000\n FS: 00007f4c69ed3d00(0000) GS:ffff889faac80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000000288a50002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die_body+0x1a/0x60\n ? page_fault_oops+0x16f/0x4a0\n ? do_user_addr_fault+0x174/0x7f0\n ? exc_page_fault+0x69/0x1a0\n ? asm_exc_page_fault+0x22/0x30\n ? dma_direct_unmap_sg+0x51/0x1e0\n ? preempt_count_sub+0x96/0xe0\n qla2xxx_qpair_sp_free_dma+0x29f/0x3b0 [qla2xxx]\n qla2xxx_qpair_sp_compl+0x60/0x80 [qla2xxx]\n __qla2x00_abort_all_cmds+0xa2/0x450 [qla2xxx]\n\nThe command completion was done early while aborting the commands in driver\nunload path but outside lock to avoid the WARN_ON condition of performing\ndma_free_attr within the lock. However this caused race condition while\ncommand completion via multiple paths causing system crash.\n\nHence complete the command early in unload path but within the lock to\navoid race condition.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42287', 'https://git.kernel.org/linus/4475afa2646d3fec176fc4d011d3879b26cb26e3 (6.11-rc1)', 'https://git.kernel.org/stable/c/314efe3f87949a568f512f05df20bf47b81cf232', 'https://git.kernel.org/stable/c/36fdc5319c4d0ec8b8938ec4769764098a246bfb', 'https://git.kernel.org/stable/c/4475afa2646d3fec176fc4d011d3879b26cb26e3', 'https://git.kernel.org/stable/c/57ba7563712227647f82a92547e82c96cd350553', 'https://git.kernel.org/stable/c/814f4a53cc86f7ea8b501bfb1723f24fd29ef5ee', 'https://git.kernel.org/stable/c/9117337b04d789bd08fdd9854a40bec2815cd3f6', 'https://git.kernel.org/stable/c/af46649304b0c9cede4ccfc2be2561ce8ed6a2ea', 'https://linux.oracle.com/cve/CVE-2024-42287.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42287-d635@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42287', 'https://www.cve.org/CVERecord?id=CVE-2024-42287'], 'PublishedDate': '2024-08-17T09:15:09.453Z', 'LastModifiedDate': '2024-09-10T19:05:07.67Z'}, {'VulnerabilityID': 'CVE-2024-42288', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42288', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: Fix for possible memory corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix for possible memory corruption\n\nInit Control Block is dereferenced incorrectly. Correctly dereference ICB', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42288', 'https://git.kernel.org/linus/c03d740152f78e86945a75b2ad541bf972fab92a (6.11-rc1)', 'https://git.kernel.org/stable/c/2a15b59a2c5afac89696e44acf5bbfc0599c6c5e', 'https://git.kernel.org/stable/c/571d7f2a08836698c2fb0d792236424575b9829b', 'https://git.kernel.org/stable/c/8192c533e89d9fb69b2490398939236b78cda79b', 'https://git.kernel.org/stable/c/87db8d7b7520e99de71791260989f06f9c94953d', 'https://git.kernel.org/stable/c/b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce', 'https://git.kernel.org/stable/c/c03d740152f78e86945a75b2ad541bf972fab92a', 'https://git.kernel.org/stable/c/dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb', 'https://linux.oracle.com/cve/CVE-2024-42288.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42288-c59b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42288', 'https://www.cve.org/CVERecord?id=CVE-2024-42288'], 'PublishedDate': '2024-08-17T09:15:09.523Z', 'LastModifiedDate': '2024-09-05T17:38:38.383Z'}, {'VulnerabilityID': 'CVE-2024-42289', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42289', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: During vport delete send async logout explicitly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: During vport delete send async logout explicitly\n\nDuring vport delete, it is observed that during unload we hit a crash\nbecause of stale entries in outstanding command array. For all these stale\nI/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but\nI/Os could not complete while vport delete is in process of deleting.\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n Workqueue: qla2xxx_wq qla_do_work [qla2xxx]\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0\n RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8\n R10: ffff8ce378aac8a0 R11: ffffa1e1e150f9d8 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8ce378aac9c8 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8d217f000000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000002089acc000 CR4: 0000000000350ee0\n Call Trace:\n \n qla2xxx_qpair_sp_free_dma+0x417/0x4e0\n ? qla2xxx_qpair_sp_compl+0x10d/0x1a0\n ? qla2x00_status_entry+0x768/0x2830\n ? newidle_balance+0x2f0/0x430\n ? dequeue_entity+0x100/0x3c0\n ? qla24xx_process_response_queue+0x6a1/0x19e0\n ? __schedule+0x2d5/0x1140\n ? qla_do_work+0x47/0x60\n ? process_one_work+0x267/0x440\n ? process_one_work+0x440/0x440\n ? worker_thread+0x2d/0x3d0\n ? process_one_work+0x440/0x440\n ? kthread+0x156/0x180\n ? set_kthread_struct+0x50/0x50\n ? ret_from_fork+0x22/0x30\n \n\nSend out async logout explicitly for all the ports during vport delete.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42289', 'https://git.kernel.org/linus/76f480d7c717368f29a3870f7d64471ce0ff8fb2 (6.11-rc1)', 'https://git.kernel.org/stable/c/086489256696eb774654a5410e86381c346356fe', 'https://git.kernel.org/stable/c/171ac4b495f9473bc134356a00095b47e6409e52', 'https://git.kernel.org/stable/c/76f480d7c717368f29a3870f7d64471ce0ff8fb2', 'https://git.kernel.org/stable/c/87c25fcb95aafabb6a4914239f4ab41b07a4f9b7', 'https://git.kernel.org/stable/c/b12c54e51ba83c1fbc619d35083d7872e42ecdef', 'https://git.kernel.org/stable/c/b35d6d5a2f38605cddea7d5c64cded894fbe8ede', 'https://git.kernel.org/stable/c/d28a2075bb530489715a3b011e1dd8765ba20313', 'https://git.kernel.org/stable/c/e5ed6a26ffdec0c91cf0b6138afbd675c00ad5fc', 'https://linux.oracle.com/cve/CVE-2024-42289.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42289-fe68@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42289', 'https://www.cve.org/CVERecord?id=CVE-2024-42289'], 'PublishedDate': '2024-08-17T09:15:09.59Z', 'LastModifiedDate': '2024-09-05T17:37:49.057Z'}, {'VulnerabilityID': 'CVE-2024-42290', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42290', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: irqchip/imx-irqsteer: Handle runtime power management correctly', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/imx-irqsteer: Handle runtime power management correctly\n\nThe power domain is automatically activated from clk_prepare(). However, on\ncertain platforms like i.MX8QM and i.MX8QXP, the power-on handling invokes\nsleeping functions, which triggers the 'scheduling while atomic' bug in the\ncontext switch path during device probing:\n\n BUG: scheduling while atomic: kworker/u13:1/48/0x00000002\n Call trace:\n __schedule_bug+0x54/0x6c\n __schedule+0x7f0/0xa94\n schedule+0x5c/0xc4\n schedule_preempt_disabled+0x24/0x40\n __mutex_lock.constprop.0+0x2c0/0x540\n __mutex_lock_slowpath+0x14/0x20\n mutex_lock+0x48/0x54\n clk_prepare_lock+0x44/0xa0\n clk_prepare+0x20/0x44\n imx_irqsteer_resume+0x28/0xe0\n pm_generic_runtime_resume+0x2c/0x44\n __genpd_runtime_resume+0x30/0x80\n genpd_runtime_resume+0xc8/0x2c0\n __rpm_callback+0x48/0x1d8\n rpm_callback+0x6c/0x78\n rpm_resume+0x490/0x6b4\n __pm_runtime_resume+0x50/0x94\n irq_chip_pm_get+0x2c/0xa0\n __irq_do_set_handler+0x178/0x24c\n irq_set_chained_handler_and_data+0x60/0xa4\n mxc_gpio_probe+0x160/0x4b0\n\nCure this by implementing the irq_bus_lock/sync_unlock() interrupt chip\ncallbacks and handle power management in them as they are invoked from\nnon-atomic context.\n\n[ tglx: Rewrote change log, added Fixes tag ]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42290', 'https://git.kernel.org/linus/33b1c47d1fc0b5f06a393bb915db85baacba18ea (6.11-rc1)', 'https://git.kernel.org/stable/c/21bd3f9e7f924cd2fc892a484e7a50c7e1847565', 'https://git.kernel.org/stable/c/33b1c47d1fc0b5f06a393bb915db85baacba18ea', 'https://git.kernel.org/stable/c/3a2884a44e5cda192df1b28e9925661f79f599a1', 'https://git.kernel.org/stable/c/58c56735facb225a5c46fa4b8bbbe7f31d1cb894', 'https://git.kernel.org/stable/c/a590e8dea3df2639921f874d763be961dd74e8f9', 'https://git.kernel.org/stable/c/f8ae38f1dfe652779c7c613facbc257cec00ac44', 'https://git.kernel.org/stable/c/fa1803401e1c360efe6342fb41d161cc51748a11', 'https://linux.oracle.com/cve/CVE-2024-42290.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42290-c966@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42290', 'https://www.cve.org/CVERecord?id=CVE-2024-42290'], 'PublishedDate': '2024-08-17T09:15:09.663Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42291', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42291', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Add a per-VF limit on number of FDIR filters', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add a per-VF limit on number of FDIR filters\n\nWhile the iavf driver adds a s/w limit (128) on the number of FDIR\nfilters that the VF can request, a malicious VF driver can request more\nthan that and exhaust the resources for other VFs.\n\nAdd a similar limit in ice.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42291', 'https://git.kernel.org/linus/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97 (6.11-rc1)', 'https://git.kernel.org/stable/c/292081c4e7f575a79017d5cbe1a0ec042783976f', 'https://git.kernel.org/stable/c/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97', 'https://git.kernel.org/stable/c/8e02cd98a6e24389d476e28436d41e620ed8e559', 'https://git.kernel.org/stable/c/d62389073a5b937413e2d1bc1da06ccff5103c0c', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42291-6f31@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42291', 'https://www.cve.org/CVERecord?id=CVE-2024-42291'], 'PublishedDate': '2024-08-17T09:15:09.73Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42292', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42292', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kobject_uevent: Fix OOB access within zap_modalias_env()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkobject_uevent: Fix OOB access within zap_modalias_env()\n\nzap_modalias_env() wrongly calculates size of memory block to move, so\nwill cause OOB memory access issue if variable MODALIAS is not the last\none within its @env parameter, fixed by correcting size to memmove.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42292', 'https://git.kernel.org/linus/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc (6.11-rc1)', 'https://git.kernel.org/stable/c/57fe01d3d04276875c7e3a6dc763517fc05b8762', 'https://git.kernel.org/stable/c/648d5490460d38436640da0812bf7f6351c150d2', 'https://git.kernel.org/stable/c/68d63ace80b76395e7935687ecdb86421adc2168', 'https://git.kernel.org/stable/c/81a15d28f32af01493ae8c5457e0d55314a4167d', 'https://git.kernel.org/stable/c/b59a5e86a3934f1b6a5bd1368902dbc79bdecc90', 'https://git.kernel.org/stable/c/c5ee8adc8d98a49703320d13878ba2b923b142f5', 'https://git.kernel.org/stable/c/d4663536754defff75ff1eca0aaebc41da165a8d', 'https://git.kernel.org/stable/c/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc', 'https://linux.oracle.com/cve/CVE-2024-42292.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42292-5387@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42292', 'https://www.cve.org/CVERecord?id=CVE-2024-42292'], 'PublishedDate': '2024-08-17T09:15:09.797Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42294', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42294', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: fix deadlock between sd_remove & sd_release', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix deadlock between sd_remove & sd_release\n\nOur test report the following hung task:\n\n[ 2538.459400] INFO: task "kworker/0:0":7 blocked for more than 188 seconds.\n[ 2538.459427] Call trace:\n[ 2538.459430] __switch_to+0x174/0x338\n[ 2538.459436] __schedule+0x628/0x9c4\n[ 2538.459442] schedule+0x7c/0xe8\n[ 2538.459447] schedule_preempt_disabled+0x24/0x40\n[ 2538.459453] __mutex_lock+0x3ec/0xf04\n[ 2538.459456] __mutex_lock_slowpath+0x14/0x24\n[ 2538.459459] mutex_lock+0x30/0xd8\n[ 2538.459462] del_gendisk+0xdc/0x350\n[ 2538.459466] sd_remove+0x30/0x60\n[ 2538.459470] device_release_driver_internal+0x1c4/0x2c4\n[ 2538.459474] device_release_driver+0x18/0x28\n[ 2538.459478] bus_remove_device+0x15c/0x174\n[ 2538.459483] device_del+0x1d0/0x358\n[ 2538.459488] __scsi_remove_device+0xa8/0x198\n[ 2538.459493] scsi_forget_host+0x50/0x70\n[ 2538.459497] scsi_remove_host+0x80/0x180\n[ 2538.459502] usb_stor_disconnect+0x68/0xf4\n[ 2538.459506] usb_unbind_interface+0xd4/0x280\n[ 2538.459510] device_release_driver_internal+0x1c4/0x2c4\n[ 2538.459514] device_release_driver+0x18/0x28\n[ 2538.459518] bus_remove_device+0x15c/0x174\n[ 2538.459523] device_del+0x1d0/0x358\n[ 2538.459528] usb_disable_device+0x84/0x194\n[ 2538.459532] usb_disconnect+0xec/0x300\n[ 2538.459537] hub_event+0xb80/0x1870\n[ 2538.459541] process_scheduled_works+0x248/0x4dc\n[ 2538.459545] worker_thread+0x244/0x334\n[ 2538.459549] kthread+0x114/0x1bc\n\n[ 2538.461001] INFO: task "fsck.":15415 blocked for more than 188 seconds.\n[ 2538.461014] Call trace:\n[ 2538.461016] __switch_to+0x174/0x338\n[ 2538.461021] __schedule+0x628/0x9c4\n[ 2538.461025] schedule+0x7c/0xe8\n[ 2538.461030] blk_queue_enter+0xc4/0x160\n[ 2538.461034] blk_mq_alloc_request+0x120/0x1d4\n[ 2538.461037] scsi_execute_cmd+0x7c/0x23c\n[ 2538.461040] ioctl_internal_command+0x5c/0x164\n[ 2538.461046] scsi_set_medium_removal+0x5c/0xb0\n[ 2538.461051] sd_release+0x50/0x94\n[ 2538.461054] blkdev_put+0x190/0x28c\n[ 2538.461058] blkdev_release+0x28/0x40\n[ 2538.461063] __fput+0xf8/0x2a8\n[ 2538.461066] __fput_sync+0x28/0x5c\n[ 2538.461070] __arm64_sys_close+0x84/0xe8\n[ 2538.461073] invoke_syscall+0x58/0x114\n[ 2538.461078] el0_svc_common+0xac/0xe0\n[ 2538.461082] do_el0_svc+0x1c/0x28\n[ 2538.461087] el0_svc+0x38/0x68\n[ 2538.461090] el0t_64_sync_handler+0x68/0xbc\n[ 2538.461093] el0t_64_sync+0x1a8/0x1ac\n\n T1:\t\t\t\tT2:\n sd_remove\n del_gendisk\n __blk_mark_disk_dead\n blk_freeze_queue_start\n ++q->mq_freeze_depth\n \t\t\t\tbdev_release\n \t\t\t\tmutex_lock(&disk->open_mutex)\n \t\t\t\tsd_release\n \t\t\t\tscsi_execute_cmd\n \t\t\t\tblk_queue_enter\n \t\t\t\twait_event(!q->mq_freeze_depth)\n mutex_lock(&disk->open_mutex)\n\nSCSI does not set GD_OWNS_QUEUE, so QUEUE_FLAG_DYING is not set in\nthis scenario. This is a classic ABBA deadlock. To fix the deadlock,\nmake sure we don\'t try to acquire disk->open_mutex after freezing\nthe queue.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42294', 'https://git.kernel.org/stable/c/5a5625a83eac91fdff1d5f0202ecfc45a31983c9', 'https://git.kernel.org/stable/c/7e04da2dc7013af50ed3a2beb698d5168d1e594b', 'https://git.kernel.org/stable/c/f5418f48a93b69ed9e6a2281eee06b412f14a544', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42294-0145@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42294', 'https://www.cve.org/CVERecord?id=CVE-2024-42294'], 'PublishedDate': '2024-08-17T09:15:09.947Z', 'LastModifiedDate': '2024-08-19T19:43:22.46Z'}, {'VulnerabilityID': 'CVE-2024-42295', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42295', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: handle inconsistent state in nilfs_btnode_create_block()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: handle inconsistent state in nilfs_btnode_create_block()\n\nSyzbot reported that a buffer state inconsistency was detected in\nnilfs_btnode_create_block(), triggering a kernel bug.\n\nIt is not appropriate to treat this inconsistency as a bug; it can occur\nif the argument block address (the buffer index of the newly created\nblock) is a virtual block number and has been reallocated due to\ncorruption of the bitmap used to manage its allocation state.\n\nSo, modify nilfs_btnode_create_block() and its callers to treat it as a\npossible filesystem error, rather than triggering a kernel bug.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42295', 'https://git.kernel.org/linus/4811f7af6090e8f5a398fbdd766f903ef6c0d787 (6.11-rc1)', 'https://git.kernel.org/stable/c/012be828a118bf496e666ef1fc47fc0e7358ada2', 'https://git.kernel.org/stable/c/02b87e6334a38c65eef49848d3f1ac422f0b2a44', 'https://git.kernel.org/stable/c/19cce46238ffe3546e44b9c74057103ff8b24c62', 'https://git.kernel.org/stable/c/366c3f688dd0288cbe38af1d3a886b5c62372e4a', 'https://git.kernel.org/stable/c/4811f7af6090e8f5a398fbdd766f903ef6c0d787', 'https://git.kernel.org/stable/c/5f0a6800b8aec1b453c7fe4c44fcaac5ffe9d52e', 'https://git.kernel.org/stable/c/be56dfc9be0604291267c07b0e27a69a6bda4899', 'https://git.kernel.org/stable/c/e34191cce3ee63dfa5fb241904aaf2a042d5b6d8', 'https://linux.oracle.com/cve/CVE-2024-42295.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42295-4f43@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42295', 'https://www.cve.org/CVERecord?id=CVE-2024-42295'], 'PublishedDate': '2024-08-17T09:15:10.017Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42296', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42296', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix return value of f2fs_convert_inline_inode()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix return value of f2fs_convert_inline_inode()\n\nIf device is readonly, make f2fs_convert_inline_inode()\nreturn EROFS instead of zero, otherwise it may trigger\npanic during writeback of inline inode's dirty page as\nbelow:\n\n f2fs_write_single_data_page+0xbb6/0x1e90 fs/f2fs/data.c:2888\n f2fs_write_cache_pages fs/f2fs/data.c:3187 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3342 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3369\n do_writepages+0x359/0x870 mm/page-writeback.c:2634\n filemap_fdatawrite_wbc+0x125/0x180 mm/filemap.c:397\n __filemap_fdatawrite_range mm/filemap.c:430 [inline]\n file_write_and_wait_range+0x1aa/0x290 mm/filemap.c:788\n f2fs_do_sync_file+0x68a/0x1ae0 fs/f2fs/file.c:276\n generic_write_sync include/linux/fs.h:2806 [inline]\n f2fs_file_write_iter+0x7bd/0x24e0 fs/f2fs/file.c:4977\n call_write_iter include/linux/fs.h:2114 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xa72/0xc90 fs/read_write.c:590\n ksys_write+0x1a0/0x2c0 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42296', 'https://git.kernel.org/linus/a8eb3de28e7a365690c61161e7a07a4fc7c60bbf (6.11-rc1)', 'https://git.kernel.org/stable/c/077f0e24b27c4b44841593c7edbd1993be9eecb5', 'https://git.kernel.org/stable/c/1e7725814361c8c008d131db195cef8274ff26b8', 'https://git.kernel.org/stable/c/47a8ddcdcaccd9b891db4574795e46a33a121ac2', 'https://git.kernel.org/stable/c/70f5ef5f33c333cfb286116fa3af74ac9bc84f1b', 'https://git.kernel.org/stable/c/a8eb3de28e7a365690c61161e7a07a4fc7c60bbf', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42296-3f50@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42296', 'https://www.cve.org/CVERecord?id=CVE-2024-42296'], 'PublishedDate': '2024-08-17T09:15:10.08Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42297', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42297', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: f2fs: fix to don't dirty inode for readonly filesystem", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to don't dirty inode for readonly filesystem\n\nsyzbot reports f2fs bug as below:\n\nkernel BUG at fs/f2fs/inode.c:933!\nRIP: 0010:f2fs_evict_inode+0x1576/0x1590 fs/f2fs/inode.c:933\nCall Trace:\n evict+0x2a4/0x620 fs/inode.c:664\n dispose_list fs/inode.c:697 [inline]\n evict_inodes+0x5f8/0x690 fs/inode.c:747\n generic_shutdown_super+0x9d/0x2c0 fs/super.c:675\n kill_block_super+0x44/0x90 fs/super.c:1667\n kill_f2fs_super+0x303/0x3b0 fs/f2fs/super.c:4894\n deactivate_locked_super+0xc1/0x130 fs/super.c:484\n cleanup_mnt+0x426/0x4c0 fs/namespace.c:1256\n task_work_run+0x24a/0x300 kernel/task_work.c:180\n ptrace_notify+0x2cd/0x380 kernel/signal.c:2399\n ptrace_report_syscall include/linux/ptrace.h:411 [inline]\n ptrace_report_syscall_exit include/linux/ptrace.h:473 [inline]\n syscall_exit_work kernel/entry/common.c:251 [inline]\n syscall_exit_to_user_mode_prepare kernel/entry/common.c:278 [inline]\n __syscall_exit_to_user_mode_work kernel/entry/common.c:283 [inline]\n syscall_exit_to_user_mode+0x15c/0x280 kernel/entry/common.c:296\n do_syscall_64+0x50/0x110 arch/x86/entry/common.c:88\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nThe root cause is:\n- do_sys_open\n - f2fs_lookup\n - __f2fs_find_entry\n - f2fs_i_depth_write\n - f2fs_mark_inode_dirty_sync\n - f2fs_dirty_inode\n - set_inode_flag(inode, FI_DIRTY_INODE)\n\n- umount\n - kill_f2fs_super\n - kill_block_super\n - generic_shutdown_super\n - sync_filesystem\n : sb is readonly, skip sync_filesystem()\n - evict_inodes\n - iput\n - f2fs_evict_inode\n - f2fs_bug_on(sbi, is_inode_flag_set(inode, FI_DIRTY_INODE))\n : trigger kernel panic\n\nWhen we try to repair i_current_depth in readonly filesystem, let's\nskip dirty inode to avoid panic in later f2fs_evict_inode().", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42297', 'https://git.kernel.org/linus/192b8fb8d1c8ca3c87366ebbef599fa80bb626b8 (6.11-rc1)', 'https://git.kernel.org/stable/c/192b8fb8d1c8ca3c87366ebbef599fa80bb626b8', 'https://git.kernel.org/stable/c/2434344559f6743efb3ac15d11af9a0db9543bd3', 'https://git.kernel.org/stable/c/2d2916516577f2239b3377d9e8d12da5e6ccdfcf', 'https://git.kernel.org/stable/c/54162974aea37a8cae00742470a78c7f6bd6f915', 'https://git.kernel.org/stable/c/54bc4e88447e385c4d4ffa85d93e0dce628fcfa6', 'https://git.kernel.org/stable/c/9ce8135accf103f7333af472709125878704fdd4', 'https://git.kernel.org/stable/c/e62ff092a42f4a1bae3b310cf46673b4f3aac3b5', 'https://git.kernel.org/stable/c/ec56571b4b146a1cfbedab49d5fcaf19fe8bf4f1', 'https://linux.oracle.com/cve/CVE-2024-42297.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42297-fcec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42297', 'https://www.cve.org/CVERecord?id=CVE-2024-42297'], 'PublishedDate': '2024-08-17T09:15:10.147Z', 'LastModifiedDate': '2024-09-30T13:41:26.463Z'}, {'VulnerabilityID': 'CVE-2024-42298', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42298', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value\n\ndevm_kasprintf() can return a NULL pointer on failure but this returned\nvalue is not checked.\n\nFix this lack and check the returned value.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42298', 'https://git.kernel.org/linus/e62599902327d27687693f6e5253a5d56583db58 (6.11-rc1)', 'https://git.kernel.org/stable/c/af466037fa2b263e8ea5c47285513d2487e17d90', 'https://git.kernel.org/stable/c/b4205dfcfe96182118e54343954827eda51b2135', 'https://git.kernel.org/stable/c/e62599902327d27687693f6e5253a5d56583db58', 'https://lore.kernel.org/linux-cve-announce/2024081748-CVE-2024-42298-d6a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42298', 'https://www.cve.org/CVERecord?id=CVE-2024-42298'], 'PublishedDate': '2024-08-17T09:15:10.23Z', 'LastModifiedDate': '2024-09-10T18:42:19.607Z'}, {'VulnerabilityID': 'CVE-2024-42299', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42299', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fs/ntfs3: Update log->page_{mask,bits} if log->page_size changed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Update log->page_{mask,bits} if log->page_size changed\n\nIf an NTFS file system is mounted to another system with different\nPAGE_SIZE from the original system, log->page_size will change in\nlog_replay(), but log->page_{mask,bits} don\'t change correspondingly.\nThis will cause a panic because "u32 bytes = log->page_size - page_off"\nwill get a negative value in the later read_log_page().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42299', 'https://git.kernel.org/linus/2fef55d8f78383c8e6d6d4c014b9597375132696 (6.11-rc1)', 'https://git.kernel.org/stable/c/0484adcb5fbcadd9ba0fd4485c42630f72e97da9', 'https://git.kernel.org/stable/c/0a4ae2644e2a3b3b219aad9639fb2b0691d08420', 'https://git.kernel.org/stable/c/2cac0df3324b5e287d8020bc0708f7d2dec88a6f', 'https://git.kernel.org/stable/c/2fef55d8f78383c8e6d6d4c014b9597375132696', 'https://git.kernel.org/stable/c/b90ceffdc975502bc085ce8e79c6adeff05f9521', 'https://lore.kernel.org/linux-cve-announce/2024081748-CVE-2024-42299-a588@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42299', 'https://www.cve.org/CVERecord?id=CVE-2024-42299'], 'PublishedDate': '2024-08-17T09:15:10.293Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42301', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42301', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dev/parport: fix the array out-of-bounds risk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndev/parport: fix the array out-of-bounds risk\n\nFixed array out-of-bounds issues caused by sprintf\nby replacing it with snprintf for safer data copying,\nensuring the destination buffer is not overflowed.\n\nBelow is the stack trace I encountered during the actual issue:\n\n[ 66.575408s] [pid:5118,cpu4,QThread,4]Kernel panic - not syncing: stack-protector:\nKernel stack is corrupted in: do_hardware_base_addr+0xcc/0xd0 [parport]\n[ 66.575408s] [pid:5118,cpu4,QThread,5]CPU: 4 PID: 5118 Comm:\nQThread Tainted: G S W O 5.10.97-arm64-desktop #7100.57021.2\n[ 66.575439s] [pid:5118,cpu4,QThread,6]TGID: 5087 Comm: EFileApp\n[ 66.575439s] [pid:5118,cpu4,QThread,7]Hardware name: HUAWEI HUAWEI QingYun\nPGUX-W515x-B081/SP1PANGUXM, BIOS 1.00.07 04/29/2024\n[ 66.575439s] [pid:5118,cpu4,QThread,8]Call trace:\n[ 66.575469s] [pid:5118,cpu4,QThread,9] dump_backtrace+0x0/0x1c0\n[ 66.575469s] [pid:5118,cpu4,QThread,0] show_stack+0x14/0x20\n[ 66.575469s] [pid:5118,cpu4,QThread,1] dump_stack+0xd4/0x10c\n[ 66.575500s] [pid:5118,cpu4,QThread,2] panic+0x1d8/0x3bc\n[ 66.575500s] [pid:5118,cpu4,QThread,3] __stack_chk_fail+0x2c/0x38\n[ 66.575500s] [pid:5118,cpu4,QThread,4] do_hardware_base_addr+0xcc/0xd0 [parport]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42301', 'https://git.kernel.org/linus/ab11dac93d2d568d151b1918d7b84c2d02bacbd5 (6.11-rc1)', 'https://git.kernel.org/stable/c/166a0bddcc27de41fe13f861c8348e8e53e988c8', 'https://git.kernel.org/stable/c/47b3dce100778001cd76f7e9188944b5cb27a76d', 'https://git.kernel.org/stable/c/7789a1d6792af410aa9b39a1eb237ed24fa2170a', 'https://git.kernel.org/stable/c/7f4da759092a1a6ce35fb085182d02de8cc4cc84', 'https://git.kernel.org/stable/c/a44f88f7576bc1916d8d6293f5c62fbe7cbe03e0', 'https://git.kernel.org/stable/c/ab11dac93d2d568d151b1918d7b84c2d02bacbd5', 'https://git.kernel.org/stable/c/b579ea3516c371ecf59d073772bc45dfd28c8a0e', 'https://git.kernel.org/stable/c/c719b393374d3763e64900ee19aaed767d5a08d6', 'https://linux.oracle.com/cve/CVE-2024-42301.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42301-4026@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42301', 'https://www.cve.org/CVERecord?id=CVE-2024-42301'], 'PublishedDate': '2024-08-17T09:15:10.423Z', 'LastModifiedDate': '2024-08-22T16:31:18.667Z'}, {'VulnerabilityID': 'CVE-2024-42302', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42302', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/DPC: Fix use-after-free on concurrent DPC and hot-removal\n\nKeith reports a use-after-free when a DPC event occurs concurrently to\nhot-removal of the same portion of the hierarchy:\n\nThe dpc_handler() awaits readiness of the secondary bus below the\nDownstream Port where the DPC event occurred. To do so, it polls the\nconfig space of the first child device on the secondary bus. If that\nchild device is concurrently removed, accesses to its struct pci_dev\ncause the kernel to oops.\n\nThat\'s because pci_bridge_wait_for_secondary_bus() neglects to hold a\nreference on the child device. Before v6.3, the function was only\ncalled on resume from system sleep or on runtime resume. Holding a\nreference wasn\'t necessary back then because the pciehp IRQ thread\ncould never run concurrently. (On resume from system sleep, IRQs are\nnot enabled until after the resume_noirq phase. And runtime resume is\nalways awaited before a PCI device is removed.)\n\nHowever starting with v6.3, pci_bridge_wait_for_secondary_bus() is also\ncalled on a DPC event. Commit 53b54ad074de ("PCI/DPC: Await readiness\nof secondary bus after reset"), which introduced that, failed to\nappreciate that pci_bridge_wait_for_secondary_bus() now needs to hold a\nreference on the child device because dpc_handler() and pciehp may\nindeed run concurrently. The commit was backported to v5.10+ stable\nkernels, so that\'s the oldest one affected.\n\nAdd the missing reference acquisition.\n\nAbridged stack trace:\n\n BUG: unable to handle page fault for address: 00000000091400c0\n CPU: 15 PID: 2464 Comm: irq/53-pcie-dpc 6.9.0\n RIP: pci_bus_read_config_dword+0x17/0x50\n pci_dev_wait()\n pci_bridge_wait_for_secondary_bus()\n dpc_reset_link()\n pcie_do_recovery()\n dpc_handler()', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42302', 'https://git.kernel.org/linus/11a1f4bc47362700fcbde717292158873fb847ed (6.11-rc1)', 'https://git.kernel.org/stable/c/11a1f4bc47362700fcbde717292158873fb847ed', 'https://git.kernel.org/stable/c/2c111413f38ca5cf87557cab89f6d82b0e3433e7', 'https://git.kernel.org/stable/c/2cc8973bdc4d6c928ebe38b88090a2cdfe81f42f', 'https://git.kernel.org/stable/c/b16f3ea1db47a6766a9f1169244cf1fc287a7c62', 'https://git.kernel.org/stable/c/c52f9e1a9eb40f13993142c331a6cfd334d4b91d', 'https://git.kernel.org/stable/c/f63df70b439bb8331358a306541893bf415bf1da', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42302-c0d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42302', 'https://www.cve.org/CVERecord?id=CVE-2024-42302'], 'PublishedDate': '2024-08-17T09:15:10.487Z', 'LastModifiedDate': '2024-08-22T16:37:26.237Z'}, {'VulnerabilityID': 'CVE-2024-42303', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42303', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: imx-pxp: Fix ERR_PTR dereference in pxp_probe()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: imx-pxp: Fix ERR_PTR dereference in pxp_probe()\n\ndevm_regmap_init_mmio() can fail, add a check and bail out in case of\nerror.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42303', 'https://git.kernel.org/linus/57e9ce68ae98551da9c161aaab12b41fe8601856 (6.11-rc1)', 'https://git.kernel.org/stable/c/358bc85269d6a359fea597ef9fbb429cd3626e08', 'https://git.kernel.org/stable/c/57e9ce68ae98551da9c161aaab12b41fe8601856', 'https://git.kernel.org/stable/c/5ab6ac4e9e165b0fe8a326308218337007224f05', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42303-4d12@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42303', 'https://www.cve.org/CVERecord?id=CVE-2024-42303'], 'PublishedDate': '2024-08-17T09:15:10.56Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42304', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42304', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: make sure the first directory block is not a hole', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: make sure the first directory block is not a hole\n\nThe syzbot constructs a directory that has no dirblock but is non-inline,\ni.e. the first directory block is a hole. And no errors are reported when\ncreating files in this directory in the following flow.\n\n ext4_mknod\n ...\n ext4_add_entry\n // Read block 0\n ext4_read_dirblock(dir, block, DIRENT)\n bh = ext4_bread(NULL, inode, block, 0)\n if (!bh && (type == INDEX || type == DIRENT_HTREE))\n // The first directory block is a hole\n // But type == DIRENT, so no error is reported.\n\nAfter that, we get a directory block without '.' and '..' but with a valid\ndentry. This may cause some code that relies on dot or dotdot (such as\nmake_indexed_dir()) to crash.\n\nTherefore when ext4_read_dirblock() finds that the first directory block\nis a hole report that the filesystem is corrupted and return an error to\navoid loading corrupted data from disk causing something bad.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42304', 'https://git.kernel.org/linus/f9ca51596bbfd0f9c386dd1c613c394c78d9e5e6 (6.11-rc1)', 'https://git.kernel.org/stable/c/299bc6ffa57e04e74c6cce866d6c0741fb4897a1', 'https://git.kernel.org/stable/c/9771e3d8365ae1dd5e8846a204cb9af14e3e656a', 'https://git.kernel.org/stable/c/b609753cbbd38f8c0affd4956c0af178348523ac', 'https://git.kernel.org/stable/c/c3893d9de8ee153baac56d127d844103488133b5', 'https://git.kernel.org/stable/c/d81d7e347d1f1f48a5634607d39eb90c161c8afe', 'https://git.kernel.org/stable/c/de2a011a13a46468a6e8259db58b1b62071fe136', 'https://git.kernel.org/stable/c/e02f9941e8c011aa3eafa799def6a134ce06bcfa', 'https://git.kernel.org/stable/c/f9ca51596bbfd0f9c386dd1c613c394c78d9e5e6', 'https://linux.oracle.com/cve/CVE-2024-42304.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42304-d0e4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42304', 'https://www.cve.org/CVERecord?id=CVE-2024-42304'], 'PublishedDate': '2024-08-17T09:15:10.617Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42305', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42305', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: check dot and dotdot of dx_root before making dir indexed', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: check dot and dotdot of dx_root before making dir indexed\n\nSyzbot reports a issue as follows:\n============================================\nBUG: unable to handle page fault for address: ffffed11022e24fe\nPGD 23ffee067 P4D 23ffee067 PUD 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 0 PID: 5079 Comm: syz-executor306 Not tainted 6.10.0-rc5-g55027e689933 #0\nCall Trace:\n \n make_indexed_dir+0xdaf/0x13c0 fs/ext4/namei.c:2341\n ext4_add_entry+0x222a/0x25d0 fs/ext4/namei.c:2451\n ext4_rename fs/ext4/namei.c:3936 [inline]\n ext4_rename2+0x26e5/0x4370 fs/ext4/namei.c:4214\n[...]\n============================================\n\nThe immediate cause of this problem is that there is only one valid dentry\nfor the block to be split during do_split, so split==0 results in out of\nbounds accesses to the map triggering the issue.\n\n do_split\n unsigned split\n dx_make_map\n count = 1\n split = count/2 = 0;\n continued = hash2 == map[split - 1].hash;\n ---> map[4294967295]\n\nThe maximum length of a filename is 255 and the minimum block size is 1024,\nso it is always guaranteed that the number of entries is greater than or\nequal to 2 when do_split() is called.\n\nBut syzbot's crafted image has no dot and dotdot in dir, and the dentry\ndistribution in dirblock is as follows:\n\n bus dentry1 hole dentry2 free\n|xx--|xx-------------|...............|xx-------------|...............|\n0 12 (8+248)=256 268 256 524 (8+256)=264 788 236 1024\n\nSo when renaming dentry1 increases its name_len length by 1, neither hole\nnor free is sufficient to hold the new dentry, and make_indexed_dir() is\ncalled.\n\nIn make_indexed_dir() it is assumed that the first two entries of the\ndirblock must be dot and dotdot, so bus and dentry1 are left in dx_root\nbecause they are treated as dot and dotdot, and only dentry2 is moved\nto the new leaf block. That's why count is equal to 1.\n\nTherefore add the ext4_check_dx_root() helper function to add more sanity\nchecks to dot and dotdot before starting the conversion to avoid the above\nissue.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42305', 'https://git.kernel.org/linus/50ea741def587a64e08879ce6c6a30131f7111e7 (6.11-rc1)', 'https://git.kernel.org/stable/c/19e13b4d7f0303186fcc891aba8d0de7c8fdbda8', 'https://git.kernel.org/stable/c/42d420517072028fb0eb852c358056b7717ba5aa', 'https://git.kernel.org/stable/c/50ea741def587a64e08879ce6c6a30131f7111e7', 'https://git.kernel.org/stable/c/8afe06ed3be7a874b3cd82ef5f8959aca8d6429a', 'https://git.kernel.org/stable/c/9d241b7a39af192d1bb422714a458982c7cc67a2', 'https://git.kernel.org/stable/c/abb411ac991810c0bcbe51c2e76d2502bf611b5c', 'https://git.kernel.org/stable/c/b80575ffa98b5bb3a5d4d392bfe4c2e03e9557db', 'https://git.kernel.org/stable/c/cdd345321699042ece4a9d2e70754d2397d378c5', 'https://linux.oracle.com/cve/CVE-2024-42305.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42305-94ed@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42305', 'https://www.cve.org/CVERecord?id=CVE-2024-42305'], 'PublishedDate': '2024-08-17T09:15:10.69Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42306', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42306', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Avoid using corrupted block bitmap buffer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid using corrupted block bitmap buffer\n\nWhen the filesystem block bitmap is corrupted, we detect the corruption\nwhile loading the bitmap and fail the allocation with error. However the\nnext allocation from the same bitmap will notice the bitmap buffer is\nalready loaded and tries to allocate from the bitmap with mixed results\n(depending on the exact nature of the bitmap corruption). Fix the\nproblem by using BH_verified bit to indicate whether the bitmap is valid\nor not.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42306', 'https://git.kernel.org/linus/a90d4471146de21745980cba51ce88e7926bcc4f (6.11-rc1)', 'https://git.kernel.org/stable/c/2199e157a465aaf98294d3932797ecd7fce942d5', 'https://git.kernel.org/stable/c/271cab2ca00652bc984e269cf1208699a1e09cdd', 'https://git.kernel.org/stable/c/57053b3bcf3403b80db6f65aba284d7dfe7326af', 'https://git.kernel.org/stable/c/6a43e3c210df6c5f00570f4be49a897677dbcb64', 'https://git.kernel.org/stable/c/8ca170c39eca7cad6e0cfeb24e351d8f8eddcd65', 'https://git.kernel.org/stable/c/a90d4471146de21745980cba51ce88e7926bcc4f', 'https://git.kernel.org/stable/c/cae9e59cc41683408b70b9ab569f8654866ba914', 'https://linux.oracle.com/cve/CVE-2024-42306.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42306-647c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42306', 'https://www.cve.org/CVERecord?id=CVE-2024-42306'], 'PublishedDate': '2024-08-17T09:15:10.777Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42307', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42307', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential null pointer use in destroy_workqueue in init_cifs error path\n\nDan Carpenter reported a Smack static checker warning:\n fs/smb/client/cifsfs.c:1981 init_cifs()\n error: we previously assumed 'serverclose_wq' could be null (see line 1895)\n\nThe patch which introduced the serverclose workqueue used the wrong\noredering in error paths in init_cifs() for freeing it on errors.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42307', 'https://git.kernel.org/linus/193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2 (6.11-rc1)', 'https://git.kernel.org/stable/c/160235efb4f9b55212dedff5de0094c606c4b303', 'https://git.kernel.org/stable/c/193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2', 'https://git.kernel.org/stable/c/3739d711246d8fbc95ff73dbdace9741cdce4777', 'https://git.kernel.org/stable/c/6018971710fdc7739f8655c1540832b4bb903671', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42307-7c2c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42307', 'https://www.cve.org/CVERecord?id=CVE-2024-42307'], 'PublishedDate': '2024-08-17T09:15:10.843Z', 'LastModifiedDate': '2024-09-05T17:49:58.257Z'}, {'VulnerabilityID': 'CVE-2024-42308', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42308', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check for NULL pointer', 'Description': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42308', 'https://git.kernel.org/linus/4ab68e168ae1695f7c04fae98930740aaf7c50fa (6.11-rc1)', 'https://git.kernel.org/stable/c/185616085b12e651cdfd11ef00d1449f54552d89', 'https://git.kernel.org/stable/c/4ab68e168ae1695f7c04fae98930740aaf7c50fa', 'https://git.kernel.org/stable/c/4ccd37085976ea5d3c499b1e6d0b3f4deaf2cd5a', 'https://git.kernel.org/stable/c/6b5ed0648213e9355cc78f4a264d9afe8536d692', 'https://git.kernel.org/stable/c/71dbf95359347c2ecc5a6dfc02783fcfccb2e9fb', 'https://git.kernel.org/stable/c/9ce89824ff04d261fc855e0ca6e6025251d9fa40', 'https://git.kernel.org/stable/c/f068494430d15b5fc551ac928de9dac7e5e27602', 'https://linux.oracle.com/cve/CVE-2024-42308.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42308-562d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42308', 'https://www.cve.org/CVERecord?id=CVE-2024-42308'], 'PublishedDate': '2024-08-17T09:15:10.92Z', 'LastModifiedDate': '2024-10-09T14:15:05.227Z'}, {'VulnerabilityID': 'CVE-2024-42309', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42309', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes\n\nIn psb_intel_lvds_get_modes(), the return value of drm_mode_duplicate() is\nassigned to mode, which will lead to a possible NULL pointer dereference\non failure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42309', 'https://git.kernel.org/linus/2df7aac81070987b0f052985856aa325a38debf6 (6.11-rc1)', 'https://git.kernel.org/stable/c/13b5f3ee94bdbdc4b5f40582aab62977905aedee', 'https://git.kernel.org/stable/c/2df7aac81070987b0f052985856aa325a38debf6', 'https://git.kernel.org/stable/c/46d2ef272957879cbe30a884574320e7f7d78692', 'https://git.kernel.org/stable/c/475a5b3b7c8edf6e583a9eb59cf28ea770602e14', 'https://git.kernel.org/stable/c/6735d02ead7dd3adf74eb8b70aebd09e0ce78ec9', 'https://git.kernel.org/stable/c/7e52c62ff029f95005915c0a11863b5fb5185c8c', 'https://git.kernel.org/stable/c/d6ad202f73f8edba0cbc0065aa57a79ffe8fdcdc', 'https://git.kernel.org/stable/c/f70ffeca546452d1acd3a70ada56ecb2f3e7f811', 'https://linux.oracle.com/cve/CVE-2024-42309.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42309-9560@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42309', 'https://www.cve.org/CVERecord?id=CVE-2024-42309'], 'PublishedDate': '2024-08-17T09:15:10.987Z', 'LastModifiedDate': '2024-08-22T16:01:29.287Z'}, {'VulnerabilityID': 'CVE-2024-42310', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42310', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes\n\nIn cdv_intel_lvds_get_modes(), the return value of drm_mode_duplicate()\nis assigned to mode, which will lead to a NULL pointer dereference on\nfailure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42310', 'https://git.kernel.org/linus/cb520c3f366c77e8d69e4e2e2781a8ce48d98e79 (6.11-rc1)', 'https://git.kernel.org/stable/c/08f45102c81ad8bc9f85f7a25e9f64e128edb87d', 'https://git.kernel.org/stable/c/2d209b2f862f6b8bff549ede541590a8d119da23', 'https://git.kernel.org/stable/c/977ee4fe895e1729cd36cc26916bbb10084713d6', 'https://git.kernel.org/stable/c/a658ae2173ab74667c009e2550455e6de5b33ddc', 'https://git.kernel.org/stable/c/b6ac46a00188cde50ffba233e6efb366354a1de5', 'https://git.kernel.org/stable/c/cb520c3f366c77e8d69e4e2e2781a8ce48d98e79', 'https://git.kernel.org/stable/c/e74eb5e8089427c8c49e0dd5067e5f39ce3a4d56', 'https://git.kernel.org/stable/c/f392c36cebf4c1d6997a4cc2c0f205254acef42a', 'https://linux.oracle.com/cve/CVE-2024-42310.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42310-58b0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42310', 'https://www.cve.org/CVERecord?id=CVE-2024-42310'], 'PublishedDate': '2024-08-17T09:15:11.067Z', 'LastModifiedDate': '2024-08-22T16:01:46.263Z'}, {'VulnerabilityID': 'CVE-2024-42311', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42311', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()\n\nSyzbot reports uninitialized value access issue as below:\n\nloop0: detected capacity change from 0 to 64\n=====================================================\nBUG: KMSAN: uninit-value in hfs_revalidate_dentry+0x307/0x3f0 fs/hfs/sysdep.c:30\n hfs_revalidate_dentry+0x307/0x3f0 fs/hfs/sysdep.c:30\n d_revalidate fs/namei.c:862 [inline]\n lookup_fast+0x89e/0x8e0 fs/namei.c:1649\n walk_component fs/namei.c:2001 [inline]\n link_path_walk+0x817/0x1480 fs/namei.c:2332\n path_lookupat+0xd9/0x6f0 fs/namei.c:2485\n filename_lookup+0x22e/0x740 fs/namei.c:2515\n user_path_at_empty+0x8b/0x390 fs/namei.c:2924\n user_path_at include/linux/namei.h:57 [inline]\n do_mount fs/namespace.c:3689 [inline]\n __do_sys_mount fs/namespace.c:3898 [inline]\n __se_sys_mount+0x66b/0x810 fs/namespace.c:3875\n __x64_sys_mount+0xe4/0x140 fs/namespace.c:3875\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nBUG: KMSAN: uninit-value in hfs_ext_read_extent fs/hfs/extent.c:196 [inline]\nBUG: KMSAN: uninit-value in hfs_get_block+0x92d/0x1620 fs/hfs/extent.c:366\n hfs_ext_read_extent fs/hfs/extent.c:196 [inline]\n hfs_get_block+0x92d/0x1620 fs/hfs/extent.c:366\n block_read_full_folio+0x4ff/0x11b0 fs/buffer.c:2271\n hfs_read_folio+0x55/0x60 fs/hfs/inode.c:39\n filemap_read_folio+0x148/0x4f0 mm/filemap.c:2426\n do_read_cache_folio+0x7c8/0xd90 mm/filemap.c:3553\n do_read_cache_page mm/filemap.c:3595 [inline]\n read_cache_page+0xfb/0x2f0 mm/filemap.c:3604\n read_mapping_page include/linux/pagemap.h:755 [inline]\n hfs_btree_open+0x928/0x1ae0 fs/hfs/btree.c:78\n hfs_mdb_get+0x260c/0x3000 fs/hfs/mdb.c:204\n hfs_fill_super+0x1fb1/0x2790 fs/hfs/super.c:406\n mount_bdev+0x628/0x920 fs/super.c:1359\n hfs_mount+0xcd/0xe0 fs/hfs/super.c:456\n legacy_get_tree+0x167/0x2e0 fs/fs_context.c:610\n vfs_get_tree+0xdc/0x5d0 fs/super.c:1489\n do_new_mount+0x7a9/0x16f0 fs/namespace.c:3145\n path_mount+0xf98/0x26a0 fs/namespace.c:3475\n do_mount fs/namespace.c:3488 [inline]\n __do_sys_mount fs/namespace.c:3697 [inline]\n __se_sys_mount+0x919/0x9e0 fs/namespace.c:3674\n __ia32_sys_mount+0x15b/0x1b0 fs/namespace.c:3674\n do_syscall_32_irqs_on arch/x86/entry/common.c:112 [inline]\n __do_fast_syscall_32+0xa2/0x100 arch/x86/entry/common.c:178\n do_fast_syscall_32+0x37/0x80 arch/x86/entry/common.c:203\n do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:246\n entry_SYSENTER_compat_after_hwframe+0x70/0x82\n\nUninit was created at:\n __alloc_pages+0x9a6/0xe00 mm/page_alloc.c:4590\n __alloc_pages_node include/linux/gfp.h:238 [inline]\n alloc_pages_node include/linux/gfp.h:261 [inline]\n alloc_slab_page mm/slub.c:2190 [inline]\n allocate_slab mm/slub.c:2354 [inline]\n new_slab+0x2d7/0x1400 mm/slub.c:2407\n ___slab_alloc+0x16b5/0x3970 mm/slub.c:3540\n __slab_alloc mm/slub.c:3625 [inline]\n __slab_alloc_node mm/slub.c:3678 [inline]\n slab_alloc_node mm/slub.c:3850 [inline]\n kmem_cache_alloc_lru+0x64d/0xb30 mm/slub.c:3879\n alloc_inode_sb include/linux/fs.h:3018 [inline]\n hfs_alloc_inode+0x5a/0xc0 fs/hfs/super.c:165\n alloc_inode+0x83/0x440 fs/inode.c:260\n new_inode_pseudo fs/inode.c:1005 [inline]\n new_inode+0x38/0x4f0 fs/inode.c:1031\n hfs_new_inode+0x61/0x1010 fs/hfs/inode.c:186\n hfs_mkdir+0x54/0x250 fs/hfs/dir.c:228\n vfs_mkdir+0x49a/0x700 fs/namei.c:4126\n do_mkdirat+0x529/0x810 fs/namei.c:4149\n __do_sys_mkdirat fs/namei.c:4164 [inline]\n __se_sys_mkdirat fs/namei.c:4162 [inline]\n __x64_sys_mkdirat+0xc8/0x120 fs/namei.c:4162\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nIt missed to initialize .tz_secondswest, .cached_start and .cached_blocks\nfields in struct hfs_inode_info after hfs_alloc_inode(), fix it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42311', 'https://git.kernel.org/linus/26a2ed107929a855155429b11e1293b83e6b2a8b (6.11-rc1)', 'https://git.kernel.org/stable/c/10f7163bfb5f8b4e0c9c05a939f20b8540e33c65', 'https://git.kernel.org/stable/c/26a2ed107929a855155429b11e1293b83e6b2a8b', 'https://git.kernel.org/stable/c/4a52861cd76e79f1a593beb23d096523eb9732c2', 'https://git.kernel.org/stable/c/58d83fc160505a7009c39dec64effaac5129b971', 'https://git.kernel.org/stable/c/9c4e40b9b731220f9464975e49da75496e3865c4', 'https://git.kernel.org/stable/c/d3493d6f0dfb1ab5225b62faa77732983f2187a1', 'https://git.kernel.org/stable/c/d55aae5c1730d6b70d5d8eaff00113cd34772ea3', 'https://git.kernel.org/stable/c/f7316b2b2f11cf0c6de917beee8d3de728be24db', 'https://linux.oracle.com/cve/CVE-2024-42311.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42311-f825@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42311', 'https://www.cve.org/CVERecord?id=CVE-2024-42311'], 'PublishedDate': '2024-08-17T09:15:11.147Z', 'LastModifiedDate': '2024-09-03T17:38:24.21Z'}, {'VulnerabilityID': 'CVE-2024-42312', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42312', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sysctl: always initialize i_uid/i_gid', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsysctl: always initialize i_uid/i_gid\n\nAlways initialize i_uid/i_gid inside the sysfs core so set_ownership()\ncan safely skip setting them.\n\nCommit 5ec27ec735ba ("fs/proc/proc_sysctl.c: fix the default values of\ni_uid/i_gid on /proc/sys inodes.") added defaults for i_uid/i_gid when\nset_ownership() was not implemented. It also missed adjusting\nnet_ctl_set_ownership() to use the same default values in case the\ncomputation of a better value failed.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42312', 'https://git.kernel.org/linus/98ca62ba9e2be5863c7d069f84f7166b45a5b2f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/1deae34db9f4f8e0e03f891be2e2e15c15c8ac05', 'https://git.kernel.org/stable/c/34a86adea1f2b3c3f9d864c8cce09dca644601ab', 'https://git.kernel.org/stable/c/98ca62ba9e2be5863c7d069f84f7166b45a5b2f4', 'https://git.kernel.org/stable/c/b2591c89a6e2858796111138c38fcb6851aa1955', 'https://git.kernel.org/stable/c/c7e2f43d182f5dde473389dbb39f16c9f0d64536', 'https://git.kernel.org/stable/c/ffde3af4b29bf97d62d82e1d45275587e10a991a', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42312-bddc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42312', 'https://www.cve.org/CVERecord?id=CVE-2024-42312'], 'PublishedDate': '2024-08-17T09:15:11.24Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42313', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42313', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: venus: fix use after free in vdec_close', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: fix use after free in vdec_close\n\nThere appears to be a possible use after free with vdec_close().\nThe firmware will add buffer release work to the work queue through\nHFI callbacks as a normal part of decoding. Randomly closing the\ndecoder device from userspace during normal decoding can incur\na read after free for inst.\n\nFix it by cancelling the work in vdec_close.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42313', 'https://git.kernel.org/linus/a0157b5aa34eb43ec4c5510f9c260bbb03be937e (6.11-rc1)', 'https://git.kernel.org/stable/c/4c9d235630d35db762b85a4149bbb0be9d504c36', 'https://git.kernel.org/stable/c/66fa52edd32cdbb675f0803b3c4da10ea19b6635', 'https://git.kernel.org/stable/c/6a96041659e834dc0b172dda4b2df512d63920c2', 'https://git.kernel.org/stable/c/72aff311194c8ceda934f24fd6f250b8827d7567', 'https://git.kernel.org/stable/c/a0157b5aa34eb43ec4c5510f9c260bbb03be937e', 'https://git.kernel.org/stable/c/ad8cf035baf29467158e0550c7a42b7bb43d1db6', 'https://git.kernel.org/stable/c/da55685247f409bf7f976cc66ba2104df75d8dad', 'https://git.kernel.org/stable/c/f8e9a63b982a8345470c225679af4ba86e4a7282', 'https://linux.oracle.com/cve/CVE-2024-42313.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42313-09b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42313', 'https://www.cve.org/CVERecord?id=CVE-2024-42313'], 'PublishedDate': '2024-08-17T09:15:11.32Z', 'LastModifiedDate': '2024-08-22T16:01:59.467Z'}, {'VulnerabilityID': 'CVE-2024-42314', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42314', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix extent map use-after-free when adding pages to compressed bio', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix extent map use-after-free when adding pages to compressed bio\n\nAt add_ra_bio_pages() we are accessing the extent map to calculate\n'add_size' after we dropped our reference on the extent map, resulting\nin a use-after-free. Fix this by computing 'add_size' before dropping our\nextent map reference.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42314', 'https://git.kernel.org/linus/8e7860543a94784d744c7ce34b78a2e11beefa5c (6.11-rc1)', 'https://git.kernel.org/stable/c/8e7860543a94784d744c7ce34b78a2e11beefa5c', 'https://git.kernel.org/stable/c/b7859ff398b6b656e1689daa860eb34837b4bb89', 'https://git.kernel.org/stable/c/c1cc3326e27b0bd7a2806b40bc48e49afaf951e7', 'https://git.kernel.org/stable/c/c205565e0f2f439f278a4a94ee97b67ef7b56ae8', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42314-de1f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42314', 'https://www.cve.org/CVERecord?id=CVE-2024-42314'], 'PublishedDate': '2024-08-17T09:15:11.397Z', 'LastModifiedDate': '2024-09-04T12:15:04.723Z'}, {'VulnerabilityID': 'CVE-2024-42315', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42315', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: exfat: fix potential deadlock on __exfat_get_dentry_set', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix potential deadlock on __exfat_get_dentry_set\n\nWhen accessing a file with more entries than ES_MAX_ENTRY_NUM, the bh-array\nis allocated in __exfat_get_entry_set. The problem is that the bh-array is\nallocated with GFP_KERNEL. It does not make sense. In the following cases,\na deadlock for sbi->s_lock between the two processes may occur.\n\n CPU0 CPU1\n ---- ----\n kswapd\n balance_pgdat\n lock(fs_reclaim)\n exfat_iterate\n lock(&sbi->s_lock)\n exfat_readdir\n exfat_get_uniname_from_ext_entry\n exfat_get_dentry_set\n __exfat_get_dentry_set\n kmalloc_array\n ...\n lock(fs_reclaim)\n ...\n evict\n exfat_evict_inode\n lock(&sbi->s_lock)\n\nTo fix this, let's allocate bh-array with GFP_NOFS.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42315', 'https://git.kernel.org/linus/89fc548767a2155231128cb98726d6d2ea1256c9 (6.11-rc1)', 'https://git.kernel.org/stable/c/1d1970493c289e3f44b9ec847ed26a5dbdf56a62', 'https://git.kernel.org/stable/c/89fc548767a2155231128cb98726d6d2ea1256c9', 'https://git.kernel.org/stable/c/a7ac198f8dba791e3144c4da48a5a9b95773ee4b', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42315-a707@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42315', 'https://www.cve.org/CVERecord?id=CVE-2024-42315'], 'PublishedDate': '2024-08-17T09:15:11.47Z', 'LastModifiedDate': '2024-08-22T15:51:03.077Z'}, {'VulnerabilityID': 'CVE-2024-42316', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42316', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/mglru: fix div-by-zero in vmpressure_calc_level()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mglru: fix div-by-zero in vmpressure_calc_level()\n\nevict_folios() uses a second pass to reclaim folios that have gone through\npage writeback and become clean before it finishes the first pass, since\nfolio_rotate_reclaimable() cannot handle those folios due to the\nisolation.\n\nThe second pass tries to avoid potential double counting by deducting\nscan_control->nr_scanned. However, this can result in underflow of\nnr_scanned, under a condition where shrink_folio_list() does not increment\nnr_scanned, i.e., when folio_trylock() fails.\n\nThe underflow can cause the divisor, i.e., scale=scanned+reclaimed in\nvmpressure_calc_level(), to become zero, resulting in the following crash:\n\n [exception RIP: vmpressure_work_fn+101]\n process_one_work at ffffffffa3313f2b\n\nSince scan_control->nr_scanned has no established semantics, the potential\ndouble counting has minimal risks. Therefore, fix the problem by not\ndeducting scan_control->nr_scanned in evict_folios().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42316', 'https://git.kernel.org/linus/8b671fe1a879923ecfb72dda6caf01460dd885ef (6.11-rc1)', 'https://git.kernel.org/stable/c/8b671fe1a879923ecfb72dda6caf01460dd885ef', 'https://git.kernel.org/stable/c/8de7bf77f21068a5f602bb1e59adbc5ab533509d', 'https://git.kernel.org/stable/c/a39e38be632f0e1c908d70d1c9cd071c03faf895', 'https://git.kernel.org/stable/c/d6510f234c7d117790397f9bb150816b0a954a04', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42316-8b49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42316', 'https://www.cve.org/CVERecord?id=CVE-2024-42316'], 'PublishedDate': '2024-08-17T09:15:11.547Z', 'LastModifiedDate': '2024-08-22T15:52:38.52Z'}, {'VulnerabilityID': 'CVE-2024-42317', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42317', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/huge_memory: avoid PMD-size page cache if needed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: avoid PMD-size page cache if needed\n\nxarray can\'t support arbitrary page cache size. the largest and supported\npage cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71\n("mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray"). However,\nit\'s possible to have 512MB page cache in the huge memory\'s collapsing\npath on ARM64 system whose base page size is 64KB. 512MB page cache is\nbreaking the limitation and a warning is raised when the xarray entry is\nsplit as shown in the following example.\n\n[root@dhcp-10-26-1-207 ~]# cat /proc/1/smaps | grep KernelPageSize\nKernelPageSize: 64 kB\n[root@dhcp-10-26-1-207 ~]# cat /tmp/test.c\n :\nint main(int argc, char **argv)\n{\n\tconst char *filename = TEST_XFS_FILENAME;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret = 0;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stdout, "System with 64KB base page size is required!\\n");\n\t\treturn -EPERM;\n\t}\n\n\tsystem("echo 0 > /sys/devices/virtual/bdi/253:0/read_ahead_kb");\n\tsystem("echo 1 > /proc/sys/vm/drop_caches");\n\n\t/* Open the xfs file */\n\tfd = open(filename, O_RDONLY);\n\tassert(fd > 0);\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE, PROT_READ, MAP_SHARED, fd, 0);\n\tassert(buf != (void *)-1);\n\tfprintf(stdout, "mapped buffer at 0x%p\\n", buf);\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_NOHUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_READ);\n\tassert(ret == 0);\n\n\t/* Collapse VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_COLLAPSE);\n\tif (ret) {\n\t\tfprintf(stdout, "Error %d to madvise(MADV_COLLAPSE)\\n", errno);\n\t\tgoto out;\n\t}\n\n\t/* Split xarray entry. Write permission is needed */\n\tmunmap(buf, TEST_MEM_SIZE);\n\tbuf = (void *)-1;\n\tclose(fd);\n\tfd = open(filename, O_RDWR);\n\tassert(fd > 0);\n\tfallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n \t\t TEST_MEM_SIZE - pgsize, pgsize);\nout:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn ret;\n}\n\n[root@dhcp-10-26-1-207 ~]# gcc /tmp/test.c -o /tmp/test\n[root@dhcp-10-26-1-207 ~]# /tmp/test\n ------------[ cut here ]------------\n WARNING: CPU: 25 PID: 7560 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\n Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\\n nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\\n nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\n ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse \\\n xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 virtio_net \\\n sha1_ce net_failover virtio_blk virtio_console failover dimlib virtio_mmio\n CPU: 25 PID: 7560 Comm: test Kdump: loaded Not tainted 6.10.0-rc7-gavin+ #9\n Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\n pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : xas_split_alloc+0xf8/0x128\n lr : split_huge_page_to_list_to_order+0x1c4/0x780\n sp : ffff8000ac32f660\n x29: ffff8000ac32f660 x28: ffff0000e0969eb0 x27: ffff8000ac32f6c0\n x26: 0000000000000c40 x25: ffff0000e0969eb0 x24: 000000000000000d\n x23: ffff8000ac32f6c0 x22: ffffffdfc0700000 x21: 0000000000000000\n x20: 0000000000000000 x19: ffffffdfc0700000 x18: 0000000000000000\n x17: 0000000000000000 x16: ffffd5f3708ffc70 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: ffffffffffffffc0 x10: 0000000000000040 x9 : ffffd5f3708e692c\n x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff0000e0969eb8\n x5 : ffffd5f37289e378 x4 : 0000000000000000 x3 : 0000000000000c40\n x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\n Call trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x780\n truncate_inode_partial_folio+0xdc/0x160\n truncate_inode_pages_range+0x1b4/0x4a8\n truncate_pagecache_range+0x84/0xa\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42317', 'https://git.kernel.org/linus/d659b715e94ac039803d7601505d3473393fc0be (6.11-rc1)', 'https://git.kernel.org/stable/c/d659b715e94ac039803d7601505d3473393fc0be', 'https://git.kernel.org/stable/c/e60f62f75c99740a28e2bf7e6044086033012a16', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42317-cf87@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42317', 'https://www.cve.org/CVERecord?id=CVE-2024-42317'], 'PublishedDate': '2024-08-17T09:15:11.633Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42318', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42318', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: landlock: Don't lose track of restrictions on cred_transfer', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Don't lose track of restrictions on cred_transfer\n\nWhen a process' cred struct is replaced, this _almost_ always invokes\nthe cred_prepare LSM hook; but in one special case (when\nKEYCTL_SESSION_TO_PARENT updates the parent's credentials), the\ncred_transfer LSM hook is used instead. Landlock only implements the\ncred_prepare hook, not cred_transfer, so KEYCTL_SESSION_TO_PARENT causes\nall information on Landlock restrictions to be lost.\n\nThis basically means that a process with the ability to use the fork()\nand keyctl() syscalls can get rid of all Landlock restrictions on\nitself.\n\nFix it by adding a cred_transfer hook that does the same thing as the\nexisting cred_prepare hook. (Implemented by having hook_cred_prepare()\ncall hook_cred_transfer() so that the two functions are less likely to\naccidentally diverge in the future.)", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42318', 'https://bugs.chromium.org/p/project-zero/issues/detail?id=2566', 'https://git.kernel.org/linus/39705a6c29f8a2b93cf5b99528a55366c50014d1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c', 'https://git.kernel.org/stable/c/16896914bace82d7811c62f3b6d5320132384f49', 'https://git.kernel.org/stable/c/39705a6c29f8a2b93cf5b99528a55366c50014d1', 'https://git.kernel.org/stable/c/916c648323fa53b89eedb34a0988ddaf01406117', 'https://git.kernel.org/stable/c/b14cc2cf313bd29056fadbc8ecd7f957cf5791ff', 'https://lore.kernel.org/all/20240817.shahka3Ee1iy@digikod.net/', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42318-f0c9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42318', 'https://www.cve.org/CVERecord?id=CVE-2024-42318', 'https://www.openwall.com/lists/oss-security/2024/08/17/2'], 'PublishedDate': '2024-08-17T09:15:11.7Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42319', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42319', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()\n\nWhen mtk-cmdq unbinds, a WARN_ON message with condition\npm_runtime_get_sync() < 0 occurs.\n\nAccording to the call tracei below:\n cmdq_mbox_shutdown\n mbox_free_channel\n mbox_controller_unregister\n __devm_mbox_controller_unregister\n ...\n\nThe root cause can be deduced to be calling pm_runtime_get_sync() after\ncalling pm_runtime_disable() as observed below:\n1. CMDQ driver uses devm_mbox_controller_register() in cmdq_probe()\n to bind the cmdq device to the mbox_controller, so\n devm_mbox_controller_unregister() will automatically unregister\n the device bound to the mailbox controller when the device-managed\n resource is removed. That means devm_mbox_controller_unregister()\n and cmdq_mbox_shoutdown() will be called after cmdq_remove().\n2. CMDQ driver also uses devm_pm_runtime_enable() in cmdq_probe() after\n devm_mbox_controller_register(), so that devm_pm_runtime_disable()\n will be called after cmdq_remove(), but before\n devm_mbox_controller_unregister().\n\nTo fix this problem, cmdq_probe() needs to move\ndevm_mbox_controller_register() after devm_pm_runtime_enable() to make\ndevm_pm_runtime_disable() be called after\ndevm_mbox_controller_unregister().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42319', 'https://git.kernel.org/linus/a8bd68e4329f9a0ad1b878733e0f80be6a971649 (6.11-rc1)', 'https://git.kernel.org/stable/c/11fa625b45faf0649118b9deaf2d31c86ac41911', 'https://git.kernel.org/stable/c/a8bd68e4329f9a0ad1b878733e0f80be6a971649', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42319-ec7c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42319', 'https://www.cve.org/CVERecord?id=CVE-2024-42319'], 'PublishedDate': '2024-08-17T09:15:11.767Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42320', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42320', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/dasd: fix error checks in dasd_copy_pair_store()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix error checks in dasd_copy_pair_store()\n\ndasd_add_busid() can return an error via ERR_PTR() if an allocation\nfails. However, two callsites in dasd_copy_pair_store() do not check\nthe result, potentially resulting in a NULL pointer dereference. Fix\nthis by checking the result with IS_ERR() and returning the error up\nthe stack.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42320', 'https://git.kernel.org/linus/8e64d2356cbc800b4cd0e3e614797f76bcf0cdb8 (6.11-rc1)', 'https://git.kernel.org/stable/c/68d4c3722290ad300c295fb3435e835d200d5cb2', 'https://git.kernel.org/stable/c/8e64d2356cbc800b4cd0e3e614797f76bcf0cdb8', 'https://git.kernel.org/stable/c/cc8b7284d5076722e0b8062373b68d8e47c3bace', 'https://git.kernel.org/stable/c/e511167e65d332d07b3c7a3d5a741ee9c19a8c27', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42320-cdea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42320', 'https://www.cve.org/CVERecord?id=CVE-2024-42320'], 'PublishedDate': '2024-08-17T09:15:11.833Z', 'LastModifiedDate': '2024-09-30T12:54:12.897Z'}, {'VulnerabilityID': 'CVE-2024-42321', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42321', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: flow_dissector: use DEBUG_NET_WARN_ON_ONCE', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: flow_dissector: use DEBUG_NET_WARN_ON_ONCE\n\nThe following splat is easy to reproduce upstream as well as in -stable\nkernels. Florian Westphal provided the following commit:\n\n d1dab4f71d37 ("net: add and use __skb_get_hash_symmetric_net")\n\nbut this complementary fix has been also suggested by Willem de Bruijn\nand it can be easily backported to -stable kernel which consists in\nusing DEBUG_NET_WARN_ON_ONCE instead to silence the following splat\ngiven __skb_get_hash() is used by the nftables tracing infrastructure to\nto identify packets in traces.\n\n[69133.561393] ------------[ cut here ]------------\n[69133.561404] WARNING: CPU: 0 PID: 43576 at net/core/flow_dissector.c:1104 __skb_flow_dissect+0x134f/\n[...]\n[69133.561944] CPU: 0 PID: 43576 Comm: socat Not tainted 6.10.0-rc7+ #379\n[69133.561959] RIP: 0010:__skb_flow_dissect+0x134f/0x2ad0\n[69133.561970] Code: 83 f9 04 0f 84 b3 00 00 00 45 85 c9 0f 84 aa 00 00 00 41 83 f9 02 0f 84 81 fc ff\nff 44 0f b7 b4 24 80 00 00 00 e9 8b f9 ff ff <0f> 0b e9 20 f3 ff ff 41 f6 c6 20 0f 84 e4 ef ff ff 48 8d 7b 12 e8\n[69133.561979] RSP: 0018:ffffc90000006fc0 EFLAGS: 00010246\n[69133.561988] RAX: 0000000000000000 RBX: ffffffff82f33e20 RCX: ffffffff81ab7e19\n[69133.561994] RDX: dffffc0000000000 RSI: ffffc90000007388 RDI: ffff888103a1b418\n[69133.562001] RBP: ffffc90000007310 R08: 0000000000000000 R09: 0000000000000000\n[69133.562007] R10: ffffc90000007388 R11: ffffffff810cface R12: ffff888103a1b400\n[69133.562013] R13: 0000000000000000 R14: ffffffff82f33e2a R15: ffffffff82f33e28\n[69133.562020] FS: 00007f40f7131740(0000) GS:ffff888390800000(0000) knlGS:0000000000000000\n[69133.562027] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[69133.562033] CR2: 00007f40f7346ee0 CR3: 000000015d200001 CR4: 00000000001706f0\n[69133.562040] Call Trace:\n[69133.562044] \n[69133.562049] ? __warn+0x9f/0x1a0\n[ 1211.841384] ? __skb_flow_dissect+0x107e/0x2860\n[...]\n[ 1211.841496] ? bpf_flow_dissect+0x160/0x160\n[ 1211.841753] __skb_get_hash+0x97/0x280\n[ 1211.841765] ? __skb_get_hash_symmetric+0x230/0x230\n[ 1211.841776] ? mod_find+0xbf/0xe0\n[ 1211.841786] ? get_stack_info_noinstr+0x12/0xe0\n[ 1211.841798] ? bpf_ksym_find+0x56/0xe0\n[ 1211.841807] ? __rcu_read_unlock+0x2a/0x70\n[ 1211.841819] nft_trace_init+0x1b9/0x1c0 [nf_tables]\n[ 1211.841895] ? nft_trace_notify+0x830/0x830 [nf_tables]\n[ 1211.841964] ? get_stack_info+0x2b/0x80\n[ 1211.841975] ? nft_do_chain_arp+0x80/0x80 [nf_tables]\n[ 1211.842044] nft_do_chain+0x79c/0x850 [nf_tables]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42321', 'https://git.kernel.org/linus/120f1c857a73e52132e473dee89b340440cb692b (6.11-rc1)', 'https://git.kernel.org/stable/c/120f1c857a73e52132e473dee89b340440cb692b', 'https://git.kernel.org/stable/c/4afbac11f2f629d1e62817c4e210bdfaa7521107', 'https://git.kernel.org/stable/c/c5d21aabf1b31a79f228508af33aee83456bc1b0', 'https://git.kernel.org/stable/c/eb03d9826aa646577342a952d658d4598381c035', 'https://lore.kernel.org/linux-cve-announce/2024081755-CVE-2024-42321-4b46@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42321', 'https://www.cve.org/CVERecord?id=CVE-2024-42321'], 'PublishedDate': '2024-08-17T09:15:11.917Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42322', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42322', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipvs: properly dereference pe in ip_vs_add_service', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: properly dereference pe in ip_vs_add_service\n\nUse pe directly to resolve sparse warning:\n\n net/netfilter/ipvs/ip_vs_ctl.c:1471:27: warning: dereference of noderef expression', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42322', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/cbd070a4ae62f119058973f6d2c984e325bce6e7 (6.11-rc1)', 'https://git.kernel.org/stable/c/3dd428039e06e1967ce294e2cd6342825aaaad77', 'https://git.kernel.org/stable/c/c420cd5d5bc6797f3a8824e7d74f38f0c286fca5', 'https://git.kernel.org/stable/c/cbd070a4ae62f119058973f6d2c984e325bce6e7', 'https://linux.oracle.com/cve/CVE-2024-42322.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024081755-CVE-2024-42322-e2ef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42322', 'https://www.cve.org/CVERecord?id=CVE-2024-42322'], 'PublishedDate': '2024-08-17T09:15:11.977Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43817', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43817', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: missing check virtio', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: missing check virtio\n\nTwo missing check in virtio_net_hdr_to_skb() allowed syzbot\nto crash kernels again\n\n1. After the skb_segment function the buffer may become non-linear\n(nr_frags != 0), but since the SKBTX_SHARED_FRAG flag is not set anywhere\nthe __skb_linearize function will not be executed, then the buffer will\nremain non-linear. Then the condition (offset >= skb_headlen(skb))\nbecomes true, which causes WARN_ON_ONCE in skb_checksum_help.\n\n2. The struct sk_buff and struct virtio_net_hdr members must be\nmathematically related.\n(gso_size) must be greater than (needed) otherwise WARN_ON_ONCE.\n(remainder) must be greater than (needed) otherwise WARN_ON_ONCE.\n(remainder) may be 0 if division is without remainder.\n\noffset+2 (4191) > skb_headlen() (1116)\nWARNING: CPU: 1 PID: 5084 at net/core/dev.c:3303 skb_checksum_help+0x5e2/0x740 net/core/dev.c:3303\nModules linked in:\nCPU: 1 PID: 5084 Comm: syz-executor336 Not tainted 6.7.0-rc3-syzkaller-00014-gdf60cee26a2e #0\nHardware name: Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023\nRIP: 0010:skb_checksum_help+0x5e2/0x740 net/core/dev.c:3303\nCode: 89 e8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 52 01 00 00 44 89 e2 2b 53 74 4c 89 ee 48 c7 c7 40 57 e9 8b e8 af 8f dd f8 90 <0f> 0b 90 90 e9 87 fe ff ff e8 40 0f 6e f9 e9 4b fa ff ff 48 89 ef\nRSP: 0018:ffffc90003a9f338 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff888025125780 RCX: ffffffff814db209\nRDX: ffff888015393b80 RSI: ffffffff814db216 RDI: 0000000000000001\nRBP: ffff8880251257f4 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000001 R12: 000000000000045c\nR13: 000000000000105f R14: ffff8880251257f0 R15: 000000000000105d\nFS: 0000555555c24380(0000) GS:ffff8880b9900000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000002000f000 CR3: 0000000023151000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ip_do_fragment+0xa1b/0x18b0 net/ipv4/ip_output.c:777\n ip_fragment.constprop.0+0x161/0x230 net/ipv4/ip_output.c:584\n ip_finish_output_gso net/ipv4/ip_output.c:286 [inline]\n __ip_finish_output net/ipv4/ip_output.c:308 [inline]\n __ip_finish_output+0x49c/0x650 net/ipv4/ip_output.c:295\n ip_finish_output+0x31/0x310 net/ipv4/ip_output.c:323\n NF_HOOK_COND include/linux/netfilter.h:303 [inline]\n ip_output+0x13b/0x2a0 net/ipv4/ip_output.c:433\n dst_output include/net/dst.h:451 [inline]\n ip_local_out+0xaf/0x1a0 net/ipv4/ip_output.c:129\n iptunnel_xmit+0x5b4/0x9b0 net/ipv4/ip_tunnel_core.c:82\n ipip6_tunnel_xmit net/ipv6/sit.c:1034 [inline]\n sit_tunnel_xmit+0xed2/0x28f0 net/ipv6/sit.c:1076\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3545 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3561\n __dev_queue_xmit+0x7c1/0x3d60 net/core/dev.c:4346\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n packet_xmit+0x257/0x380 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3087 [inline]\n packet_sendmsg+0x24ca/0x5240 net/packet/af_packet.c:3119\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0xd5/0x180 net/socket.c:745\n __sys_sendto+0x255/0x340 net/socket.c:2190\n __do_sys_sendto net/socket.c:2202 [inline]\n __se_sys_sendto net/socket.c:2198 [inline]\n __x64_sys_sendto+0xe0/0x1b0 net/socket.c:2198\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x40/0x110 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43817', 'https://git.kernel.org/linus/e269d79c7d35aa3808b1f3c1737d63dab504ddc8 (6.11-rc1)', 'https://git.kernel.org/stable/c/27874ca77bd2b05a3779c7b3a5c75d8dd7f0b40f', 'https://git.kernel.org/stable/c/5b1997487a3f3373b0f580c8a20b56c1b64b0775', 'https://git.kernel.org/stable/c/90d41ebe0cd4635f6410471efc1dd71b33e894cf', 'https://git.kernel.org/stable/c/e269d79c7d35aa3808b1f3c1737d63dab504ddc8', 'https://git.kernel.org/stable/c/e9164903b8b303c34723177b02fe91e49e3c4cd7', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43817-2e95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43817', 'https://www.cve.org/CVERecord?id=CVE-2024-43817'], 'PublishedDate': '2024-08-17T10:15:08.01Z', 'LastModifiedDate': '2024-09-03T17:41:46.407Z'}, {'VulnerabilityID': 'CVE-2024-43818', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43818', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: amd: Adjust error handling in case of absent codec device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: Adjust error handling in case of absent codec device\n\nacpi_get_first_physical_node() can return NULL in several cases (no such\ndevice, ACPI table error, reference count drop to 0, etc).\nExisting check just emit error message, but doesn't perform return.\nThen this NULL pointer is passed to devm_acpi_dev_add_driver_gpios()\nwhere it is dereferenced.\n\nAdjust this error handling by adding error code return.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43818', 'https://git.kernel.org/linus/5080808c3339de2220c602ab7c7fa23dc6c1a5a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/1ba9856cf7f6492b47c1edf853137f320d583db5', 'https://git.kernel.org/stable/c/5080808c3339de2220c602ab7c7fa23dc6c1a5a3', 'https://git.kernel.org/stable/c/99b642dac24f6d09ba3ebf1d690be8aefff86164', 'https://git.kernel.org/stable/c/b1173d64edd276c957b6d09e1f971c85b38f1519', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43818-71ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43818', 'https://www.cve.org/CVERecord?id=CVE-2024-43818'], 'PublishedDate': '2024-08-17T10:15:08.08Z', 'LastModifiedDate': '2024-09-03T17:45:30Z'}, {'VulnerabilityID': 'CVE-2024-43819', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43819', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kvm: s390: Reject memory region operations for ucontrol VMs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkvm: s390: Reject memory region operations for ucontrol VMs\n\nThis change rejects the KVM_SET_USER_MEMORY_REGION and\nKVM_SET_USER_MEMORY_REGION2 ioctls when called on a ucontrol VM.\nThis is necessary since ucontrol VMs have kvm->arch.gmap set to 0 and\nwould thus result in a null pointer dereference further in.\nMemory management needs to be performed in userspace and using the\nioctls KVM_S390_UCAS_MAP and KVM_S390_UCAS_UNMAP.\n\nAlso improve s390 specific documentation for KVM_SET_USER_MEMORY_REGION\nand KVM_SET_USER_MEMORY_REGION2.\n\n[frankja@linux.ibm.com: commit message spelling fix, subject prefix fix]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43819', 'https://git.kernel.org/linus/7816e58967d0e6cadce05c8540b47ed027dc2499 (6.11-rc1)', 'https://git.kernel.org/stable/c/49c9945c054df4c22008e2bf87ca74d3e2507aa6', 'https://git.kernel.org/stable/c/7816e58967d0e6cadce05c8540b47ed027dc2499', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43819-88ce@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43819', 'https://www.cve.org/CVERecord?id=CVE-2024-43819'], 'PublishedDate': '2024-08-17T10:15:08.147Z', 'LastModifiedDate': '2024-09-03T17:47:10.54Z'}, {'VulnerabilityID': 'CVE-2024-43820', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43820', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume\n\nrm-raid devices will occasionally trigger the following warning when\nbeing resumed after a table load because DM_RECOVERY_RUNNING is set:\n\nWARNING: CPU: 7 PID: 5660 at drivers/md/dm-raid.c:4105 raid_resume+0xee/0x100 [dm_raid]\n\nThe failing check is:\nWARN_ON_ONCE(test_bit(MD_RECOVERY_RUNNING, &mddev->recovery));\n\nThis check is designed to make sure that the sync thread isn't\nregistered, but md_check_recovery can set MD_RECOVERY_RUNNING without\nthe sync_thread ever getting registered. Instead of checking if\nMD_RECOVERY_RUNNING is set, check if sync_thread is non-NULL.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43820', 'https://git.kernel.org/linus/3199a34bfaf7561410e0be1e33a61eba870768fc (6.11-rc1)', 'https://git.kernel.org/stable/c/3199a34bfaf7561410e0be1e33a61eba870768fc', 'https://git.kernel.org/stable/c/a5c15a78c0e1631b7df822b56e8b6424e4d1ca3e', 'https://lore.kernel.org/linux-cve-announce/2024081724-CVE-2024-43820-1bd6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43820', 'https://www.cve.org/CVERecord?id=CVE-2024-43820'], 'PublishedDate': '2024-08-17T10:15:08.207Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43821', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43821', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: lpfc: Fix a possible null pointer dereference', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix a possible null pointer dereference\n\nIn function lpfc_xcvr_data_show, the memory allocation with kmalloc might\nfail, thereby making rdp_context a null pointer. In the following context\nand functions that use this pointer, there are dereferencing operations,\nleading to null pointer dereference.\n\nTo fix this issue, a null pointer check should be added. If it is null,\nuse scnprintf to notify the user and return len.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43821', 'https://git.kernel.org/linus/5e0bf3e8aec2cbc51123f84b29aaacbd91fc56fa (6.11-rc1)', 'https://git.kernel.org/stable/c/45b2a23e00d448a9e6d1f371ca3a4d4b073fe78c', 'https://git.kernel.org/stable/c/57600a7dd2b52c904f7c8d2cac0fd8c23868e680', 'https://git.kernel.org/stable/c/5e0bf3e8aec2cbc51123f84b29aaacbd91fc56fa', 'https://lore.kernel.org/linux-cve-announce/2024081724-CVE-2024-43821-6ffc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43821', 'https://www.cve.org/CVERecord?id=CVE-2024-43821'], 'PublishedDate': '2024-08-17T10:15:08.277Z', 'LastModifiedDate': '2024-09-03T17:49:54.28Z'}, {'VulnerabilityID': 'CVE-2024-43823', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43823', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()\n\nIf IORESOURCE_MEM is not provided in Device Tree due to\nany error, resource_list_first_type() will return NULL and\npci_parse_request_of_pci_ranges() will just emit a warning.\n\nThis will cause a NULL pointer dereference. Fix this bug by adding NULL\nreturn check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43823', 'https://git.kernel.org/linus/a231707a91f323af1e5d9f1722055ec2fc1c7775 (6.11-rc1)', 'https://git.kernel.org/stable/c/0a6f1b5fe8ef8268aaa069035639968ceeea0a23', 'https://git.kernel.org/stable/c/a231707a91f323af1e5d9f1722055ec2fc1c7775', 'https://git.kernel.org/stable/c/bbba48ad67c53feea05936ea1e029dcca8057506', 'https://git.kernel.org/stable/c/dbcdd1863ba2ec9b76ec131df25d797709e05597', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43823-4bdd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43823', 'https://www.cve.org/CVERecord?id=CVE-2024-43823'], 'PublishedDate': '2024-08-17T10:15:08.4Z', 'LastModifiedDate': '2024-09-03T17:49:03.91Z'}, {'VulnerabilityID': 'CVE-2024-43824', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43824', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: pci-epf-test: Make use of cached \'epc_features\' in pci_epf_test_core_init()\n\nInstead of getting the epc_features from pci_epc_get_features() API, use\nthe cached pci_epf_test::epc_features value to avoid the NULL check. Since\nthe NULL check is already performed in pci_epf_test_bind(), having one more\ncheck in pci_epf_test_core_init() is redundant and it is not possible to\nhit the NULL pointer dereference.\n\nAlso with commit a01e7214bef9 ("PCI: endpoint: Remove "core_init_notifier"\nflag"), \'epc_features\' got dereferenced without the NULL check, leading to\nthe following false positive Smatch warning:\n\n drivers/pci/endpoint/functions/pci-epf-test.c:784 pci_epf_test_core_init() error: we previously assumed \'epc_features\' could be null (see line 747)\n\nThus, remove the redundant NULL check and also use the epc_features::\n{msix_capable/msi_capable} flags directly to avoid local variables.\n\n[kwilczynski: commit log]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43824', 'https://git.kernel.org/linus/5a5095a8bd1bd349cce1c879e5e44407a34dda8a (6.11-rc1)', 'https://git.kernel.org/stable/c/5a5095a8bd1bd349cce1c879e5e44407a34dda8a', 'https://git.kernel.org/stable/c/af4ad016abb1632ff7ee598a6037952b495e5b80', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43824-fc04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43824', 'https://www.cve.org/CVERecord?id=CVE-2024-43824'], 'PublishedDate': '2024-08-17T10:15:08.477Z', 'LastModifiedDate': '2024-09-03T17:48:39.16Z'}, {'VulnerabilityID': 'CVE-2024-43825', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43825', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iio: Fix the sorting functionality in iio_gts_build_avail_time_table', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: Fix the sorting functionality in iio_gts_build_avail_time_table\n\nThe sorting in iio_gts_build_avail_time_table is not working as intended.\nIt could result in an out-of-bounds access when the time is zero.\n\nHere are more details:\n\n1. When the gts->itime_table[i].time_us is zero, e.g., the time\nsequence is `3, 0, 1`, the inner for-loop will not terminate and do\nout-of-bound writes. This is because once `times[j] > new`, the value\n`new` will be added in the current position and the `times[j]` will be\nmoved to `j+1` position, which makes the if-condition always hold.\nMeanwhile, idx will be added one, making the loop keep running without\ntermination and out-of-bound write.\n2. If none of the gts->itime_table[i].time_us is zero, the elements\nwill just be copied without being sorted as described in the comment\n"Sort times from all tables to one and remove duplicates".\n\nFor more details, please refer to\nhttps://lore.kernel.org/all/6dd0d822-046c-4dd2-9532-79d7ab96ec05@gmail.com.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 5.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43825', 'https://git.kernel.org/linus/5acc3f971a01be48d5ff4252d8f9cdb87998cdfb (6.11-rc1)', 'https://git.kernel.org/stable/c/31ff8464ef540785344994986a010031410f9ff3', 'https://git.kernel.org/stable/c/5acc3f971a01be48d5ff4252d8f9cdb87998cdfb', 'https://git.kernel.org/stable/c/b5046de32fd1532c3f67065197fc1da82f0b5193', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43825-20fc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43825', 'https://www.cve.org/CVERecord?id=CVE-2024-43825'], 'PublishedDate': '2024-08-17T10:15:08.533Z', 'LastModifiedDate': '2024-09-30T13:53:21.44Z'}, {'VulnerabilityID': 'CVE-2024-43826', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43826', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfs: pass explicit offset/count to trace events', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: pass explicit offset/count to trace events\n\nnfs_folio_length is unsafe to use without having the folio locked and a\ncheck for a NULL ->f_mapping that protects against truncations and can\nlead to kernel crashes. E.g. when running xfstests generic/065 with\nall nfs trace points enabled.\n\nFollow the model of the XFS trace points and pass in an explіcit offset\nand length. This has the additional benefit that these values can\nbe more accurate as some of the users touch partial folio ranges.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43826', 'https://git.kernel.org/linus/fada32ed6dbc748f447c8d050a961b75d946055a (6.11-rc1)', 'https://git.kernel.org/stable/c/387e6e9d110250946df4d4ebef9c2def5c7a4722', 'https://git.kernel.org/stable/c/fada32ed6dbc748f447c8d050a961b75d946055a', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43826-2a5f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43826', 'https://www.cve.org/CVERecord?id=CVE-2024-43826'], 'PublishedDate': '2024-08-17T10:15:08.593Z', 'LastModifiedDate': '2024-09-12T18:15:09.137Z'}, {'VulnerabilityID': 'CVE-2024-43827', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43827', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null check before access structs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check before access structs\n\nIn enable_phantom_plane, we should better check null pointer before\naccessing various structs.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43827', 'https://git.kernel.org/linus/c96140000915b610d86f941450e15ca552de154a (6.11-rc1)', 'https://git.kernel.org/stable/c/081ff4c0ef1884ae55f7adb8944efd22e22d8724', 'https://git.kernel.org/stable/c/c96140000915b610d86f941450e15ca552de154a', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43827-6486@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43827', 'https://www.cve.org/CVERecord?id=CVE-2024-43827'], 'PublishedDate': '2024-08-17T10:15:08.653Z', 'LastModifiedDate': '2024-09-30T12:51:34.97Z'}, {'VulnerabilityID': 'CVE-2024-43828', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43828', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: fix infinite loop when replaying fast_commit', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix infinite loop when replaying fast_commit\n\nWhen doing fast_commit replay an infinite loop may occur due to an\nuninitialized extent_status struct. ext4_ext_determine_insert_hole() does\nnot detect the replay and calls ext4_es_find_extent_range(), which will\nreturn immediately without initializing the 'es' variable.\n\nBecause 'es' contains garbage, an integer overflow may happen causing an\ninfinite loop in this function, easily reproducible using fstest generic/039.\n\nThis commit fixes this issue by unconditionally initializing the structure\nin function ext4_es_find_extent_range().\n\nThanks to Zhang Yi, for figuring out the real problem!", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43828', 'https://git.kernel.org/linus/907c3fe532253a6ef4eb9c4d67efb71fab58c706 (6.11-rc1)', 'https://git.kernel.org/stable/c/0619f7750f2b178a1309808832ab20d85e0ad121', 'https://git.kernel.org/stable/c/181e63cd595c688194e07332f9944b3a63193de2', 'https://git.kernel.org/stable/c/5ed0496e383cb6de120e56991385dce70bbb87c1', 'https://git.kernel.org/stable/c/81f819c537d29932e4b9267f02411cbc8b355178', 'https://git.kernel.org/stable/c/907c3fe532253a6ef4eb9c4d67efb71fab58c706', 'https://git.kernel.org/stable/c/c6e67df64783e99a657ef2b8c834ba2bf54c539c', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43828-6bcb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43828', 'https://www.cve.org/CVERecord?id=CVE-2024-43828'], 'PublishedDate': '2024-08-17T10:15:08.72Z', 'LastModifiedDate': '2024-08-22T15:41:50.87Z'}, {'VulnerabilityID': 'CVE-2024-43829', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43829', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/qxl: Add check for drm_cvt_mode', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/qxl: Add check for drm_cvt_mode\n\nAdd check for the return value of drm_cvt_mode() and return the error if\nit fails in order to avoid NULL pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43829', 'https://git.kernel.org/linus/7bd09a2db0f617377027a2bb0b9179e6959edff3 (6.11-rc1)', 'https://git.kernel.org/stable/c/3efe34f95b1ac8c138a46b14ce75956db0d6ee7c', 'https://git.kernel.org/stable/c/4b1f303bdeceac049e56e4b20eb5280bd9e02f4f', 'https://git.kernel.org/stable/c/4e87f592a46bb804d8f833da6ce702ae4b55053f', 'https://git.kernel.org/stable/c/62ef8d7816c8e4a6088275553818b9afc0ffaa03', 'https://git.kernel.org/stable/c/7bd09a2db0f617377027a2bb0b9179e6959edff3', 'https://git.kernel.org/stable/c/d4c57354a06cb4a77998ff8aa40af89eee30e07b', 'https://git.kernel.org/stable/c/f28b353c0c6c7831a70ccca881bf2db5e6785cdd', 'https://linux.oracle.com/cve/CVE-2024-43829.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43829-72cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43829', 'https://www.cve.org/CVERecord?id=CVE-2024-43829'], 'PublishedDate': '2024-08-17T10:15:08.787Z', 'LastModifiedDate': '2024-09-30T12:51:56.77Z'}, {'VulnerabilityID': 'CVE-2024-43830', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43830', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: leds: trigger: Unregister sysfs attributes before calling deactivate()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nleds: trigger: Unregister sysfs attributes before calling deactivate()\n\nTriggers which have trigger specific sysfs attributes typically store\nrelated data in trigger-data allocated by the activate() callback and\nfreed by the deactivate() callback.\n\nCalling device_remove_groups() after calling deactivate() leaves a window\nwhere the sysfs attributes show/store functions could be called after\ndeactivation and then operate on the just freed trigger-data.\n\nMove the device_remove_groups() call to before deactivate() to close\nthis race window.\n\nThis also makes the deactivation path properly do things in reverse order\nof the activation path which calls the activate() callback before calling\ndevice_add_groups().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7000', 'https://access.redhat.com/security/cve/CVE-2024-43830', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2265838', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2270103', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275558', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282648', 'https://bugzilla.redhat.com/2282669', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282764', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284511', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284630', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293414', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300381', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300439', 'https://bugzilla.redhat.com/2300440', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300709', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301543', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305410', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2305488', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7000.html', 'https://git.kernel.org/linus/c0dc9adf9474ecb7106e60e5472577375aedaed3 (6.11-rc1)', 'https://git.kernel.org/stable/c/0788a6f3523d3686a9eed5ea1e6fcce6841277b2', 'https://git.kernel.org/stable/c/09c1583f0e10c918855d6e7540a79461a353e5d6', 'https://git.kernel.org/stable/c/3fb6a9d67cfd812a547ac73ec02e1077c26c640d', 'https://git.kernel.org/stable/c/734ba6437e80dfc780e9ee9d95f912392d12b5ea', 'https://git.kernel.org/stable/c/c0dc9adf9474ecb7106e60e5472577375aedaed3', 'https://git.kernel.org/stable/c/c3b7a650c8717aa89df318364609c86cbc040156', 'https://git.kernel.org/stable/c/cb8aa9d2a4c8a15d6a43ccf901ef3d094aa60374', 'https://git.kernel.org/stable/c/d1415125b701ef13370e2761f691ec632a5eb93a', 'https://linux.oracle.com/cve/CVE-2024-43830.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43830-3b85@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43830', 'https://www.cve.org/CVERecord?id=CVE-2024-43830'], 'PublishedDate': '2024-08-17T10:15:08.857Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43831', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43831', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: mediatek: vcodec: Handle invalid decoder vsi', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: Handle invalid decoder vsi\n\nHandle an invalid decoder vsi in vpu_dec_init to ensure the decoder vsi\nis valid for future use.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43831', 'https://git.kernel.org/linus/59d438f8e02ca641c58d77e1feffa000ff809e9f (6.11-rc1)', 'https://git.kernel.org/stable/c/1c109f23b271a02b9bb195c173fab41e3285a8db', 'https://git.kernel.org/stable/c/59d438f8e02ca641c58d77e1feffa000ff809e9f', 'https://git.kernel.org/stable/c/cdf05ae76198c513836bde4eb55f099c44773280', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43831-b13e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43831', 'https://www.cve.org/CVERecord?id=CVE-2024-43831'], 'PublishedDate': '2024-08-17T10:15:08.917Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43832', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43832', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: s390/uv: Don't call folio_wait_writeback() without a folio reference", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/uv: Don't call folio_wait_writeback() without a folio reference\n\nfolio_wait_writeback() requires that no spinlocks are held and that\na folio reference is held, as documented. After we dropped the PTL, the\nfolio could get freed concurrently. So grab a temporary reference.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43832', 'https://git.kernel.org/linus/3f29f6537f54d74e64bac0a390fb2e26da25800d (6.11-rc1)', 'https://git.kernel.org/stable/c/1a1eb2f3fc453dcd52726d13e863938561489cb7', 'https://git.kernel.org/stable/c/3f29f6537f54d74e64bac0a390fb2e26da25800d', 'https://git.kernel.org/stable/c/8736604ef53359a718c246087cd21dcec232d2fb', 'https://git.kernel.org/stable/c/b21aba72aadd94bdac275deab021fc84d6c72b16', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43832-7746@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43832', 'https://www.cve.org/CVERecord?id=CVE-2024-43832'], 'PublishedDate': '2024-08-17T10:15:08.98Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43833', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43833', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: v4l: async: Fix NULL pointer dereference in adding ancillary links', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l: async: Fix NULL pointer dereference in adding ancillary links\n\nIn v4l2_async_create_ancillary_links(), ancillary links are created for\nlens and flash sub-devices. These are sub-device to sub-device links and\nif the async notifier is related to a V4L2 device, the source sub-device\nof the ancillary link is NULL, leading to a NULL pointer dereference.\nCheck the notifier's sd field is non-NULL in\nv4l2_async_create_ancillary_links().\n\n[Sakari Ailus: Reword the subject and commit messages slightly.]", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43833', 'https://git.kernel.org/linus/9b4667ea67854f0b116fe22ad11ef5628c5b5b5f (6.11-rc1)', 'https://git.kernel.org/stable/c/249212ceb4187783af3801c57b92a5a25d410621', 'https://git.kernel.org/stable/c/9b4667ea67854f0b116fe22ad11ef5628c5b5b5f', 'https://git.kernel.org/stable/c/b87e28050d9b0959de24574d587825cfab2f13fb', 'https://git.kernel.org/stable/c/fe0f92fd5320b393e44ca210805e653ea90cc982', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43833-4e73@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43833', 'https://www.cve.org/CVERecord?id=CVE-2024-43833'], 'PublishedDate': '2024-08-17T10:15:09.04Z', 'LastModifiedDate': '2024-08-22T15:42:46.827Z'}, {'VulnerabilityID': 'CVE-2024-43834', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43834', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xdp: fix invalid wait context of page_pool_destroy()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix invalid wait context of page_pool_destroy()\n\nIf the driver uses a page pool, it creates a page pool with\npage_pool_create().\nThe reference count of page pool is 1 as default.\nA page pool will be destroyed only when a reference count reaches 0.\npage_pool_destroy() is used to destroy page pool, it decreases a\nreference count.\nWhen a page pool is destroyed, ->disconnect() is called, which is\nmem_allocator_disconnect().\nThis function internally acquires mutex_lock().\n\nIf the driver uses XDP, it registers a memory model with\nxdp_rxq_info_reg_mem_model().\nThe xdp_rxq_info_reg_mem_model() internally increases a page pool\nreference count if a memory model is a page pool.\nNow the reference count is 2.\n\nTo destroy a page pool, the driver should call both page_pool_destroy()\nand xdp_unreg_mem_model().\nThe xdp_unreg_mem_model() internally calls page_pool_destroy().\nOnly page_pool_destroy() decreases a reference count.\n\nIf a driver calls page_pool_destroy() then xdp_unreg_mem_model(), we\nwill face an invalid wait context warning.\nBecause xdp_unreg_mem_model() calls page_pool_destroy() with\nrcu_read_lock().\nThe page_pool_destroy() internally acquires mutex_lock().\n\nSplat looks like:\n=============================\n[ BUG: Invalid wait context ]\n6.10.0-rc6+ #4 Tainted: G W\n-----------------------------\nethtool/1806 is trying to lock:\nffffffff90387b90 (mem_id_lock){+.+.}-{4:4}, at: mem_allocator_disconnect+0x73/0x150\nother info that might help us debug this:\ncontext-{5:5}\n3 locks held by ethtool/1806:\nstack backtrace:\nCPU: 0 PID: 1806 Comm: ethtool Tainted: G W 6.10.0-rc6+ #4 f916f41f172891c800f2fed\nHardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021\nCall Trace:\n\ndump_stack_lvl+0x7e/0xc0\n__lock_acquire+0x1681/0x4de0\n? _printk+0x64/0xe0\n? __pfx_mark_lock.part.0+0x10/0x10\n? __pfx___lock_acquire+0x10/0x10\nlock_acquire+0x1b3/0x580\n? mem_allocator_disconnect+0x73/0x150\n? __wake_up_klogd.part.0+0x16/0xc0\n? __pfx_lock_acquire+0x10/0x10\n? dump_stack_lvl+0x91/0xc0\n__mutex_lock+0x15c/0x1690\n? mem_allocator_disconnect+0x73/0x150\n? __pfx_prb_read_valid+0x10/0x10\n? mem_allocator_disconnect+0x73/0x150\n? __pfx_llist_add_batch+0x10/0x10\n? console_unlock+0x193/0x1b0\n? lockdep_hardirqs_on+0xbe/0x140\n? __pfx___mutex_lock+0x10/0x10\n? tick_nohz_tick_stopped+0x16/0x90\n? __irq_work_queue_local+0x1e5/0x330\n? irq_work_queue+0x39/0x50\n? __wake_up_klogd.part.0+0x79/0xc0\n? mem_allocator_disconnect+0x73/0x150\nmem_allocator_disconnect+0x73/0x150\n? __pfx_mem_allocator_disconnect+0x10/0x10\n? mark_held_locks+0xa5/0xf0\n? rcu_is_watching+0x11/0xb0\npage_pool_release+0x36e/0x6d0\npage_pool_destroy+0xd7/0x440\nxdp_unreg_mem_model+0x1a7/0x2a0\n? __pfx_xdp_unreg_mem_model+0x10/0x10\n? kfree+0x125/0x370\n? bnxt_free_ring.isra.0+0x2eb/0x500\n? bnxt_free_mem+0x5ac/0x2500\nxdp_rxq_info_unreg+0x4a/0xd0\nbnxt_free_mem+0x1356/0x2500\nbnxt_close_nic+0xf0/0x3b0\n? __pfx_bnxt_close_nic+0x10/0x10\n? ethnl_parse_bit+0x2c6/0x6d0\n? __pfx___nla_validate_parse+0x10/0x10\n? __pfx_ethnl_parse_bit+0x10/0x10\nbnxt_set_features+0x2a8/0x3e0\n__netdev_update_features+0x4dc/0x1370\n? ethnl_parse_bitset+0x4ff/0x750\n? __pfx_ethnl_parse_bitset+0x10/0x10\n? __pfx___netdev_update_features+0x10/0x10\n? mark_held_locks+0xa5/0xf0\n? _raw_spin_unlock_irqrestore+0x42/0x70\n? __pm_runtime_resume+0x7d/0x110\nethnl_set_features+0x32d/0xa20\n\nTo fix this problem, it uses rhashtable_lookup_fast() instead of\nrhashtable_lookup() with rcu_read_lock().\nUsing xa without rcu_read_lock() here is safe.\nxa is freed by __xdp_mem_allocator_rcu_free() and this is called by\ncall_rcu() of mem_xa_remove().\nThe mem_xa_remove() is called by page_pool_destroy() if a reference\ncount reaches 0.\nThe xa is already protected by the reference count mechanism well in the\ncontrol plane.\nSo removing rcu_read_lock() for page_pool_destroy() is safe.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43834', 'https://git.kernel.org/linus/59a931c5b732ca5fc2ca727f5a72aeabaafa85ec (6.11-rc1)', 'https://git.kernel.org/stable/c/12144069209eec7f2090ce9afa15acdcc2c2a537', 'https://git.kernel.org/stable/c/3fc1be360b99baeea15cdee3cf94252cd3a72d26', 'https://git.kernel.org/stable/c/59a931c5b732ca5fc2ca727f5a72aeabaafa85ec', 'https://git.kernel.org/stable/c/6c390ef198aa69795427a5cb5fd7cb4bc7e6cd7a', 'https://git.kernel.org/stable/c/be9d08ff102df3ac4f66e826ea935cf3af63a4bd', 'https://git.kernel.org/stable/c/bf0ce5aa5f2525ed1b921ba36de96e458e77f482', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43834-0140@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43834', 'https://www.cve.org/CVERecord?id=CVE-2024-43834'], 'PublishedDate': '2024-08-17T10:15:09.113Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43835', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43835', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: virtio_net: Fix napi_skb_cache_put warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Fix napi_skb_cache_put warning\n\nAfter the commit bdacf3e34945 ("net: Use nested-BH locking for\nnapi_alloc_cache.") was merged, the following warning began to appear:\n\n\t WARNING: CPU: 5 PID: 1 at net/core/skbuff.c:1451 napi_skb_cache_put+0x82/0x4b0\n\n\t __warn+0x12f/0x340\n\t napi_skb_cache_put+0x82/0x4b0\n\t napi_skb_cache_put+0x82/0x4b0\n\t report_bug+0x165/0x370\n\t handle_bug+0x3d/0x80\n\t exc_invalid_op+0x1a/0x50\n\t asm_exc_invalid_op+0x1a/0x20\n\t __free_old_xmit+0x1c8/0x510\n\t napi_skb_cache_put+0x82/0x4b0\n\t __free_old_xmit+0x1c8/0x510\n\t __free_old_xmit+0x1c8/0x510\n\t __pfx___free_old_xmit+0x10/0x10\n\nThe issue arises because virtio is assuming it\'s running in NAPI context\neven when it\'s not, such as in the netpoll case.\n\nTo resolve this, modify virtnet_poll_tx() to only set NAPI when budget\nis available. Same for virtnet_poll_cleantx(), which always assumed that\nit was in a NAPI context.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43835', 'https://git.kernel.org/linus/f8321fa75102246d7415a6af441872f6637c93ab (6.11-rc1)', 'https://git.kernel.org/stable/c/19ac6f29bf64304ef04630c8ab56ecd2059d7aa1', 'https://git.kernel.org/stable/c/468a729b78895893d0e580ceea49bed8ada2a2bd', 'https://git.kernel.org/stable/c/6b5325f2457521bbece29499970c0117a648c620', 'https://git.kernel.org/stable/c/842a97b5e44f0c8a9fc356fe976e0e13ddcf7783', 'https://git.kernel.org/stable/c/cc7340f18e45886121c131227985d64ef666012f', 'https://git.kernel.org/stable/c/d3af435e8ace119e58d8e21d3d2d6a4e7c4a4baa', 'https://git.kernel.org/stable/c/f5e9a22d19bb98a7e86034db85eb295e94187caa', 'https://git.kernel.org/stable/c/f8321fa75102246d7415a6af441872f6637c93ab', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43835-5f11@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43835', 'https://www.cve.org/CVERecord?id=CVE-2024-43835'], 'PublishedDate': '2024-08-17T10:15:09.183Z', 'LastModifiedDate': '2024-09-12T12:15:48.653Z'}, {'VulnerabilityID': 'CVE-2024-43837', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43837', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT\n\nWhen loading a EXT program without specifying `attr->attach_prog_fd`,\nthe `prog->aux->dst_prog` will be null. At this time, calling\nresolve_prog_type() anywhere will result in a null pointer dereference.\n\nExample stack trace:\n\n[ 8.107863] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004\n[ 8.108262] Mem abort info:\n[ 8.108384] ESR = 0x0000000096000004\n[ 8.108547] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 8.108722] SET = 0, FnV = 0\n[ 8.108827] EA = 0, S1PTW = 0\n[ 8.108939] FSC = 0x04: level 0 translation fault\n[ 8.109102] Data abort info:\n[ 8.109203] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 8.109399] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 8.109614] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 8.109836] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101354000\n[ 8.110011] [0000000000000004] pgd=0000000000000000, p4d=0000000000000000\n[ 8.112624] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 8.112783] Modules linked in:\n[ 8.113120] CPU: 0 PID: 99 Comm: may_access_dire Not tainted 6.10.0-rc3-next-20240613-dirty #1\n[ 8.113230] Hardware name: linux,dummy-virt (DT)\n[ 8.113390] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 8.113429] pc : may_access_direct_pkt_data+0x24/0xa0\n[ 8.113746] lr : add_subprog_and_kfunc+0x634/0x8e8\n[ 8.113798] sp : ffff80008283b9f0\n[ 8.113813] x29: ffff80008283b9f0 x28: ffff800082795048 x27: 0000000000000001\n[ 8.113881] x26: ffff0000c0bb2600 x25: 0000000000000000 x24: 0000000000000000\n[ 8.113897] x23: ffff0000c1134000 x22: 000000000001864f x21: ffff0000c1138000\n[ 8.113912] x20: 0000000000000001 x19: ffff0000c12b8000 x18: ffffffffffffffff\n[ 8.113929] x17: 0000000000000000 x16: 0000000000000000 x15: 0720072007200720\n[ 8.113944] x14: 0720072007200720 x13: 0720072007200720 x12: 0720072007200720\n[ 8.113958] x11: 0720072007200720 x10: 0000000000f9fca4 x9 : ffff80008021f4e4\n[ 8.113991] x8 : 0101010101010101 x7 : 746f72705f6d656d x6 : 000000001e0e0f5f\n[ 8.114006] x5 : 000000000001864f x4 : ffff0000c12b8000 x3 : 000000000000001c\n[ 8.114020] x2 : 0000000000000002 x1 : 0000000000000000 x0 : 0000000000000000\n[ 8.114126] Call trace:\n[ 8.114159] may_access_direct_pkt_data+0x24/0xa0\n[ 8.114202] bpf_check+0x3bc/0x28c0\n[ 8.114214] bpf_prog_load+0x658/0xa58\n[ 8.114227] __sys_bpf+0xc50/0x2250\n[ 8.114240] __arm64_sys_bpf+0x28/0x40\n[ 8.114254] invoke_syscall.constprop.0+0x54/0xf0\n[ 8.114273] do_el0_svc+0x4c/0xd8\n[ 8.114289] el0_svc+0x3c/0x140\n[ 8.114305] el0t_64_sync_handler+0x134/0x150\n[ 8.114331] el0t_64_sync+0x168/0x170\n[ 8.114477] Code: 7100707f 54000081 f9401c00 f9403800 (b9400403)\n[ 8.118672] ---[ end trace 0000000000000000 ]---\n\nOne way to fix it is by forcing `attach_prog_fd` non-empty when\nbpf_prog_load(). But this will lead to `libbpf_probe_bpf_prog_type`\nAPI broken which use verifier log to probe prog type and will log\nnothing if we reject invalid EXT prog before bpf_check().\n\nAnother way is by adding null check in resolve_prog_type().\n\nThe issue was introduced by commit 4a9c7bbe2ed4 ("bpf: Resolve to\nprog->aux->dst_prog->type only for BPF_PROG_TYPE_EXT") which wanted\nto correct type resolution for BPF_PROG_TYPE_TRACING programs. Before\nthat, the type resolution of BPF_PROG_TYPE_EXT prog actually follows\nthe logic below:\n\n prog->aux->dst_prog ? prog->aux->dst_prog->type : prog->type;\n\nIt implies that when EXT program is not yet attached to `dst_prog`,\nthe prog type should be EXT itself. This code worked fine in the past.\nSo just keep using it.\n\nFix this by returning `prog->type` for BPF_PROG_TYPE_EXT if `dst_prog`\nis not present in resolve_prog_type().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43837', 'https://git.kernel.org/linus/f7866c35873377313ff94398f17d425b28b71de1 (6.11-rc1)', 'https://git.kernel.org/stable/c/9d40fd516aeae6779e3c84c6b96700ca76285847', 'https://git.kernel.org/stable/c/b29a880bb145e1f1c1df5ab88ed26b1495ff9f09', 'https://git.kernel.org/stable/c/f7866c35873377313ff94398f17d425b28b71de1', 'https://git.kernel.org/stable/c/fcac5feb06f31ee4c88bca9bf98d8bc3ca7d2615', 'https://lore.kernel.org/linux-cve-announce/2024081729-CVE-2024-43837-63d2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43837', 'https://www.cve.org/CVERecord?id=CVE-2024-43837'], 'PublishedDate': '2024-08-17T10:15:09.32Z', 'LastModifiedDate': '2024-08-22T15:44:03.417Z'}, {'VulnerabilityID': 'CVE-2024-43839', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43839', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: bna: adjust 'name' buf size of bna_tcb and bna_ccb structures", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbna: adjust 'name' buf size of bna_tcb and bna_ccb structures\n\nTo have enough space to write all possible sprintf() args. Currently\n'name' size is 16, but the first '%s' specifier may already need at\nleast 16 characters, since 'bnad->netdev->name' is used there.\n\nFor '%d' specifiers, assume that they require:\n * 1 char for 'tx_id + tx_info->tcb[i]->id' sum, BNAD_MAX_TXQ_PER_TX is 8\n * 2 chars for 'rx_id + rx_info->rx_ctrl[i].ccb->id', BNAD_MAX_RXP_PER_RX\n is 16\n\nAnd replace sprintf with snprintf.\n\nDetected using the static analysis tool - Svace.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43839', 'https://git.kernel.org/linus/c9741a03dc8e491e57b95fba0058ab46b7e506da (6.11-rc1)', 'https://git.kernel.org/stable/c/6ce46045f9b90d952602e2c0b8886cfadf860bf1', 'https://git.kernel.org/stable/c/6d20c4044ab4d0e6a99aa35853e66f0aed5589e3', 'https://git.kernel.org/stable/c/ab748dd10d8742561f2980fea08ffb4f0cacfdef', 'https://git.kernel.org/stable/c/b0ff0cd0847b03c0a0abe20cfa900eabcfcb9e43', 'https://git.kernel.org/stable/c/c90b1cd7758fd4839909e838ae195d19f8065d76', 'https://git.kernel.org/stable/c/c9741a03dc8e491e57b95fba0058ab46b7e506da', 'https://git.kernel.org/stable/c/e0f48f51d55fb187400e9787192eda09fa200ff5', 'https://git.kernel.org/stable/c/f121740f69eda4da2de9a20a6687a13593e72540', 'https://linux.oracle.com/cve/CVE-2024-43839.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081729-CVE-2024-43839-ea03@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43839', 'https://www.cve.org/CVERecord?id=CVE-2024-43839'], 'PublishedDate': '2024-08-17T10:15:09.447Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43840', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43840', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG\n\nWhen BPF_TRAMP_F_CALL_ORIG is set, the trampoline calls\n__bpf_tramp_enter() and __bpf_tramp_exit() functions, passing them\nthe struct bpf_tramp_image *im pointer as an argument in R0.\n\nThe trampoline generation code uses emit_addr_mov_i64() to emit\ninstructions for moving the bpf_tramp_image address into R0, but\nemit_addr_mov_i64() assumes the address to be in the vmalloc() space\nand uses only 48 bits. Because bpf_tramp_image is allocated using\nkzalloc(), its address can use more than 48-bits, in this case the\ntrampoline will pass an invalid address to __bpf_tramp_enter/exit()\ncausing a kernel crash.\n\nFix this by using emit_a64_mov_i64() in place of emit_addr_mov_i64()\nas it can work with addresses that are greater than 48-bits.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43840', 'https://git.kernel.org/linus/19d3c179a37730caf600a97fed3794feac2b197b (6.11-rc1)', 'https://git.kernel.org/stable/c/19d3c179a37730caf600a97fed3794feac2b197b', 'https://git.kernel.org/stable/c/6d218fcc707d6b2c3616b6cd24b948fd4825cfec', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43840-69cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43840', 'https://www.cve.org/CVERecord?id=CVE-2024-43840'], 'PublishedDate': '2024-08-17T10:15:09.517Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43841', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43841', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: virt_wifi: avoid reporting connection success with wrong SSID', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: avoid reporting connection success with wrong SSID\n\nWhen user issues a connection with a different SSID than the one\nvirt_wifi has advertised, the __cfg80211_connect_result() will\ntrigger the warning: WARN_ON(bss_not_found).\n\nThe issue is because the connection code in virt_wifi does not\ncheck the SSID from user space (it only checks the BSSID), and\nvirt_wifi will call cfg80211_connect_result() with WLAN_STATUS_SUCCESS\neven if the SSID is different from the one virt_wifi has advertised.\nEventually cfg80211 won't be able to find the cfg80211_bss and generate\nthe warning.\n\nFixed it by checking the SSID (from user space) in the connection code.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43841', 'https://git.kernel.org/linus/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7 (6.11-rc1)', 'https://git.kernel.org/stable/c/05c4488a0e446c6ccde9f22b573950665e1cd414', 'https://git.kernel.org/stable/c/36e92b5edc8e0daa18e9325674313802ce3fbc29', 'https://git.kernel.org/stable/c/416d3c1538df005195721a200b0371d39636e05d', 'https://git.kernel.org/stable/c/93e898a264b4e0a475552ba9f99a016eb43ef942', 'https://git.kernel.org/stable/c/994fc2164a03200c3bf42fb45b3d49d9d6d33a4d', 'https://git.kernel.org/stable/c/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7', 'https://git.kernel.org/stable/c/d3cc85a10abc8eae48988336cdd3689ab92581b3', 'https://linux.oracle.com/cve/CVE-2024-43841.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43841-8143@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43841', 'https://www.cve.org/CVERecord?id=CVE-2024-43841'], 'PublishedDate': '2024-08-17T10:15:09.58Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43842', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43842', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()\n\nIn rtw89_sta_info_get_iter() \'status->he_gi\' is compared to array size.\nBut then \'rate->he_gi\' is used as array index instead of \'status->he_gi\'.\nThis can lead to go beyond array boundaries in case of \'rate->he_gi\' is\nnot equal to \'status->he_gi\' and is bigger than array size. Looks like\n"copy-paste" mistake.\n\nFix this mistake by replacing \'rate->he_gi\' with \'status->he_gi\'.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43842', 'https://git.kernel.org/linus/85099c7ce4f9e64c66aa397cd9a37473637ab891 (6.11-rc1)', 'https://git.kernel.org/stable/c/7a0edc3d83aff3a48813d78c9cad9daf38decc74', 'https://git.kernel.org/stable/c/85099c7ce4f9e64c66aa397cd9a37473637ab891', 'https://git.kernel.org/stable/c/96ae4de5bc4c8ba39fd072369398f59495b73f58', 'https://git.kernel.org/stable/c/a2a095c08b95372d6d0c5819b77f071af5e75366', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43842-31e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43842', 'https://www.cve.org/CVERecord?id=CVE-2024-43842'], 'PublishedDate': '2024-08-17T10:15:09.647Z', 'LastModifiedDate': '2024-09-30T13:55:17.007Z'}, {'VulnerabilityID': 'CVE-2024-43843', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43843', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv, bpf: Fix out-of-bounds issue when preparing trampoline image', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix out-of-bounds issue when preparing trampoline image\n\nWe get the size of the trampoline image during the dry run phase and\nallocate memory based on that size. The allocated image will then be\npopulated with instructions during the real patch phase. But after\ncommit 26ef208c209a ("bpf: Use arch_bpf_trampoline_size"), the `im`\nargument is inconsistent in the dry run and real patch phase. This may\ncause emit_imm in RV64 to generate a different number of instructions\nwhen generating the \'im\' address, potentially causing out-of-bounds\nissues. Let\'s emit the maximum number of instructions for the "im"\naddress during dry run to fix this problem.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43843', 'https://git.kernel.org/linus/9f1e16fb1fc9826001c69e0551d51fbbcd2d74e9 (6.11-rc1)', 'https://git.kernel.org/stable/c/3e6a1b1b179abb643ec3560c02bc3082bc92285f', 'https://git.kernel.org/stable/c/9f1e16fb1fc9826001c69e0551d51fbbcd2d74e9', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43843-e436@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43843', 'https://www.cve.org/CVERecord?id=CVE-2024-43843'], 'PublishedDate': '2024-08-17T10:15:09.707Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43844', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43844', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi rtw89 wow: fix GTK offload H2C skbuff issue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: wow: fix GTK offload H2C skbuff issue\n\nWe mistakenly put skb too large and that may exceed skb->end.\nTherefore, we fix it.\n\nskbuff: skb_over_panic: text:ffffffffc09e9a9d len:416 put:204 head:ffff8fba04eca780 data:ffff8fba04eca7e0 tail:0x200 end:0x140 dev:\n------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:192!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 4747 Comm: kworker/u4:44 Tainted: G O 6.6.30-02659-gc18865c4dfbd #1 86547039b47e46935493f615ee31d0b2d711d35e\nHardware name: HP Meep/Meep, BIOS Google_Meep.11297.262.0 03/18/2021\nWorkqueue: events_unbound async_run_entry_fn\nRIP: 0010:skb_panic+0x5d/0x60\nCode: c6 63 8b 8f bb 4c 0f 45 f6 48 c7 c7 4d 89 8b bb 48 89 ce 44 89 d1 41 56 53 41 53 ff b0 c8 00 00 00 e8 27 5f 23 00 48 83 c4 20 <0f> 0b 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44\nRSP: 0018:ffffaa700144bad0 EFLAGS: 00010282\nRAX: 0000000000000089 RBX: 0000000000000140 RCX: 14432c5aad26c900\nRDX: 0000000000000000 RSI: 00000000ffffdfff RDI: 0000000000000001\nRBP: ffffaa700144bae0 R08: 0000000000000000 R09: ffffaa700144b920\nR10: 00000000ffffdfff R11: ffffffffbc28fbc0 R12: ffff8fba4e57a010\nR13: 0000000000000000 R14: ffffffffbb8f8b63 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff8fba7bd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007999c4ad1000 CR3: 000000015503a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? __die_body+0x1f/0x70\n ? die+0x3d/0x60\n ? do_trap+0xa4/0x110\n ? skb_panic+0x5d/0x60\n ? do_error_trap+0x6d/0x90\n ? skb_panic+0x5d/0x60\n ? handle_invalid_op+0x30/0x40\n ? skb_panic+0x5d/0x60\n ? exc_invalid_op+0x3c/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_panic+0x5d/0x60\n skb_put+0x49/0x50\n rtw89_fw_h2c_wow_gtk_ofld+0xbd/0x220 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_wow_resume+0x31f/0x540 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_ops_resume+0x2b/0xa0 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n ieee80211_reconfig+0x84/0x13e0 [mac80211 818a894e3b77da6298269c59ed7cdff065a4ed52]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? dev_printk_emit+0x51/0x70\n ? _dev_info+0x6e/0x90\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n wiphy_resume+0x89/0x180 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n dpm_run_callback+0x3c/0x140\n device_resume+0x1f9/0x3c0\n ? __pfx_dpm_watchdog_handler+0x10/0x10\n async_resume+0x1d/0x30\n async_run_entry_fn+0x29/0xd0\n process_scheduled_works+0x1d8/0x3d0\n worker_thread+0x1fc/0x2f0\n kthread+0xed/0x110\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x38/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \nModules linked in: ccm 8021q r8153_ecm cdc_ether usbnet r8152 mii dm_integrity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmalloc uinput rfcomm cmac algif_hash rtw89_8922ae(O) algif_skcipher rtw89_8922a(O) af_alg rtw89_pci(O) rtw89_core(O) btusb(O) snd_soc_sst_bxt_da7219_max98357a btbcm(O) snd_soc_hdac_hdmi btintel(O) snd_soc_intel_hda_dsp_common snd_sof_probes btrtl(O) btmtk(O) snd_hda_codec_hdmi snd_soc_dmic uvcvideo videobuf2_vmalloc uvc videobuf2_memops videobuf2_v4l2 videobuf2_common snd_sof_pci_intel_apl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda soundwire_intel soundwire_generic_allocation snd_sof_intel_hda_mlink soundwire_cadence snd_sof_pci snd_sof_xtensa_dsp mac80211 snd_soc_acpi_intel_match snd_soc_acpi snd_sof snd_sof_utils soundwire_bus snd_soc_max98357a snd_soc_avs snd_soc_hda_codec snd_hda_ext_core snd_intel_dspcfg snd_intel_sdw_acpi snd_soc_da7219 snd_hda_codec snd_hwdep snd_hda_core veth ip6table_nat xt_MASQUERADE xt_cgroup fuse bluetooth ecdh_generic\n cfg80211 ecc\ngsmi: Log Shutdown \n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43844', 'https://git.kernel.org/linus/dda364c345913fe03ddbe4d5ae14a2754c100296 (6.11-rc1)', 'https://git.kernel.org/stable/c/dda364c345913fe03ddbe4d5ae14a2754c100296', 'https://git.kernel.org/stable/c/ef0d9d2f0dc1133db3d3a1c5167190c6627146b2', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43844-97ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43844', 'https://www.cve.org/CVERecord?id=CVE-2024-43844'], 'PublishedDate': '2024-08-17T10:15:09.763Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43845', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43845', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Fix bogus checksum computation in udf_rename()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix bogus checksum computation in udf_rename()\n\nSyzbot reports uninitialized memory access in udf_rename() when updating\nchecksum of '..' directory entry of a moved directory. This is indeed\ntrue as we pass on-stack diriter.fi to the udf_update_tag() and because\nthat has only struct fileIdentDesc included in it and not the impUse or\nname fields, the checksumming function is going to checksum random stack\ncontents beyond the end of the structure. This is actually harmless\nbecause the following udf_fiiter_write_fi() will recompute the checksum\nfrom on-disk buffers where everything is properly included. So all that\nis needed is just removing the bogus calculation.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43845', 'https://git.kernel.org/linus/27ab33854873e6fb958cb074681a0107cc2ecc4c (6.11-rc1)', 'https://git.kernel.org/stable/c/27ab33854873e6fb958cb074681a0107cc2ecc4c', 'https://git.kernel.org/stable/c/40d7b3ed52449d36143bab8d3e70926aa61a60f4', 'https://git.kernel.org/stable/c/c996b570305e7a6910c2ce4cdcd4c22757ffe241', 'https://git.kernel.org/stable/c/fe2ead240c31e8d158713beca9d0681a6e6a53ab', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43845-a85d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43845', 'https://www.cve.org/CVERecord?id=CVE-2024-43845'], 'PublishedDate': '2024-08-17T10:15:09.837Z', 'LastModifiedDate': '2024-08-29T17:15:08.397Z'}, {'VulnerabilityID': 'CVE-2024-43846', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: lib: objagg: Fix general protection fault', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlib: objagg: Fix general protection fault\n\nThe library supports aggregation of objects into other objects only if\nthe parent object does not have a parent itself. That is, nesting is not\nsupported.\n\nAggregation happens in two cases: Without and with hints, where hints\nare a pre-computed recommendation on how to aggregate the provided\nobjects.\n\nNesting is not possible in the first case due to a check that prevents\nit, but in the second case there is no check because the assumption is\nthat nesting cannot happen when creating objects based on hints. The\nviolation of this assumption leads to various warnings and eventually to\na general protection fault [1].\n\nBefore fixing the root cause, error out when nesting happens and warn.\n\n[1]\ngeneral protection fault, probably for non-canonical address 0xdead000000000d90: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 1083 Comm: kworker/1:9 Tainted: G W 6.9.0-rc6-custom-gd9b4f1cca7fb #7\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:mlxsw_sp_acl_erp_bf_insert+0x25/0x80\n[...]\nCall Trace:\n \n mlxsw_sp_acl_atcam_entry_add+0x256/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370\n worker_thread+0x2cb/0x3e0\n kthread+0xd0/0x100\n ret_from_fork+0x34/0x50\n ret_from_fork_asm+0x1a/0x30\n ', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43846', 'https://git.kernel.org/linus/b4a3a89fffcdf09702b1f161b914e52abca1894d (6.11-rc1)', 'https://git.kernel.org/stable/c/1936fa05a180834c3b52e0439a6bddc07814d3eb', 'https://git.kernel.org/stable/c/22ae17a267f4812861f0c644186c3421ff97dbfc', 'https://git.kernel.org/stable/c/499f742fed42e74f1321f4b12ca196a66a2b49fc', 'https://git.kernel.org/stable/c/565213e005557eb6cc4e42189d26eb300e02f170', 'https://git.kernel.org/stable/c/5adc61d29bbb461d7f7c2b48dceaa90ecd182eb7', 'https://git.kernel.org/stable/c/8161263362154cbebfbf4808097b956a6a8cb98a', 'https://git.kernel.org/stable/c/b4a3a89fffcdf09702b1f161b914e52abca1894d', 'https://linux.oracle.com/cve/CVE-2024-43846.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43846-2bd0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43846', 'https://www.cve.org/CVERecord?id=CVE-2024-43846'], 'PublishedDate': '2024-08-17T10:15:09.9Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43847', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43847', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: fix invalid memory access while processing fragmented packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix invalid memory access while processing fragmented packets\n\nThe monitor ring and the reo reinject ring share the same ring mask index.\nWhen the driver receives an interrupt for the reo reinject ring, the\nmonitor ring is also processed, leading to invalid memory access. Since\nmonitor support is not yet enabled in ath12k, the ring mask for the monitor\nring should be removed.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 2.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43847', 'https://git.kernel.org/linus/073f9f249eecd64ab9d59c91c4a23cfdcc02afe4 (6.11-rc1)', 'https://git.kernel.org/stable/c/073f9f249eecd64ab9d59c91c4a23cfdcc02afe4', 'https://git.kernel.org/stable/c/36fc66a7d9ca3e5c6eac25362cac63f83df8bed6', 'https://git.kernel.org/stable/c/8126f82dab7bd8b2e04799342b19fff0a1fd8575', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43847-6828@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43847', 'https://www.cve.org/CVERecord?id=CVE-2024-43847'], 'PublishedDate': '2024-08-17T10:15:09.963Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43849', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43849', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: pdr: protect locator_addr with the main mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pdr: protect locator_addr with the main mutex\n\nIf the service locator server is restarted fast enough, the PDR can\nrewrite locator_addr fields concurrently. Protect them by placing\nmodification of those fields under the main pdr->lock.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43849', 'https://git.kernel.org/linus/107924c14e3ddd85119ca43c26a4ee1056fa9b84 (6.11-rc1)', 'https://git.kernel.org/stable/c/107924c14e3ddd85119ca43c26a4ee1056fa9b84', 'https://git.kernel.org/stable/c/3e815626d73e05152a8142f6e44aecc4133e6e08', 'https://git.kernel.org/stable/c/475a77fb3f0e1d527f56c60b79f5879661df5b80', 'https://git.kernel.org/stable/c/8543269567e2fb3d976a8255c5e348aed14f98bc', 'https://git.kernel.org/stable/c/d0870c4847e77a49c2f91bb2a8e0fa3c1f8dea5c', 'https://git.kernel.org/stable/c/eab05737ee22216250fe20d27f5a596da5ea6eb7', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43849-fef0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43849', 'https://www.cve.org/CVERecord?id=CVE-2024-43849'], 'PublishedDate': '2024-08-17T10:15:10.093Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43850', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43850', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove\n\nThe following warning is seen during bwmon_remove due to refcount\nimbalance, fix this by releasing the OPPs after use.\n\nLogs:\nWARNING: at drivers/opp/core.c:1640 _opp_table_kref_release+0x150/0x158\nHardware name: Qualcomm Technologies, Inc. X1E80100 CRD (DT)\n...\nCall trace:\n_opp_table_kref_release+0x150/0x158\ndev_pm_opp_remove_table+0x100/0x1b4\ndevm_pm_opp_of_table_release+0x10/0x1c\ndevm_action_release+0x14/0x20\ndevres_release_all+0xa4/0x104\ndevice_unbind_cleanup+0x18/0x60\ndevice_release_driver_internal+0x1ec/0x228\ndriver_detach+0x50/0x98\nbus_remove_driver+0x6c/0xbc\ndriver_unregister+0x30/0x60\nplatform_driver_unregister+0x14/0x20\nbwmon_driver_exit+0x18/0x524 [icc_bwmon]\n__arm64_sys_delete_module+0x184/0x264\ninvoke_syscall+0x48/0x118\nel0_svc_common.constprop.0+0xc8/0xe8\ndo_el0_svc+0x20/0x2c\nel0_svc+0x34/0xdc\nel0t_64_sync_handler+0x13c/0x158\nel0t_64_sync+0x190/0x194\n--[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43850', 'https://git.kernel.org/linus/24086640ab39396eb1a92d1cb1cd2f31b2677c52 (6.11-rc1)', 'https://git.kernel.org/stable/c/24086640ab39396eb1a92d1cb1cd2f31b2677c52', 'https://git.kernel.org/stable/c/4100d4d019f8e140be1d4d3a9d8d93c1285f5d1c', 'https://git.kernel.org/stable/c/aad41f4c169bcb800ae88123799bdf8cdec3d366', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43850-4eec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43850', 'https://www.cve.org/CVERecord?id=CVE-2024-43850'], 'PublishedDate': '2024-08-17T10:15:10.157Z', 'LastModifiedDate': '2024-09-30T13:57:33.4Z'}, {'VulnerabilityID': 'CVE-2024-43852', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43852', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (ltc2991) re-order conditions to fix off by one bug', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ltc2991) re-order conditions to fix off by one bug\n\nLTC2991_T_INT_CH_NR is 4. The st->temp_en[] array has LTC2991_MAX_CHANNEL\n(4) elements. Thus if "channel" is equal to LTC2991_T_INT_CH_NR then we\nhave read one element beyond the end of the array. Flip the conditions\naround so that we check if "channel" is valid before using it as an array\nindex.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-193'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43852', 'https://git.kernel.org/linus/99bf7c2eccff82760fa23ce967cc67c8c219c6a6 (6.11-rc1)', 'https://git.kernel.org/stable/c/99bf7c2eccff82760fa23ce967cc67c8c219c6a6', 'https://git.kernel.org/stable/c/c180311c0a520692e2d0e9ca44dcd6c2ff1b41c4', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43852-61e2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43852', 'https://www.cve.org/CVERecord?id=CVE-2024-43852'], 'PublishedDate': '2024-08-17T10:15:10.31Z', 'LastModifiedDate': '2024-08-20T19:32:55.747Z'}, {'VulnerabilityID': 'CVE-2024-43853', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43853', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cgroup/cpuset: Prevent UAF in proc_cpuset_show()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: Prevent UAF in proc_cpuset_show()\n\nAn UAF can happen when /proc/cpuset is read as reported in [1].\n\nThis can be reproduced by the following methods:\n1.add an mdelay(1000) before acquiring the cgroup_lock In the\n cgroup_path_ns function.\n2.$cat /proc//cpuset repeatly.\n3.$mount -t cgroup -o cpuset cpuset /sys/fs/cgroup/cpuset/\n$umount /sys/fs/cgroup/cpuset/ repeatly.\n\nThe race that cause this bug can be shown as below:\n\n(umount)\t\t|\t(cat /proc//cpuset)\ncss_release\t\t|\tproc_cpuset_show\ncss_release_work_fn\t|\tcss = task_get_css(tsk, cpuset_cgrp_id);\ncss_free_rwork_fn\t|\tcgroup_path_ns(css->cgroup, ...);\ncgroup_destroy_root\t|\tmutex_lock(&cgroup_mutex);\nrebind_subsystems\t|\ncgroup_free_root \t|\n\t\t\t|\t// cgrp was freed, UAF\n\t\t\t|\tcgroup_path_ns_locked(cgrp,..);\n\nWhen the cpuset is initialized, the root node top_cpuset.css.cgrp\nwill point to &cgrp_dfl_root.cgrp. In cgroup v1, the mount operation will\nallocate cgroup_root, and top_cpuset.css.cgrp will point to the allocated\n&cgroup_root.cgrp. When the umount operation is executed,\ntop_cpuset.css.cgrp will be rebound to &cgrp_dfl_root.cgrp.\n\nThe problem is that when rebinding to cgrp_dfl_root, there are cases\nwhere the cgroup_root allocated by setting up the root for cgroup v1\nis cached. This could lead to a Use-After-Free (UAF) if it is\nsubsequently freed. The descendant cgroups of cgroup v1 can only be\nfreed after the css is released. However, the css of the root will never\nbe released, yet the cgroup_root should be freed when it is unmounted.\nThis means that obtaining a reference to the css of the root does\nnot guarantee that css.cgrp->root will not be freed.\n\nFix this problem by using rcu_read_lock in proc_cpuset_show().\nAs cgroup_root is kfree_rcu after commit d23b5c577715\n("cgroup: Make operations on the cgroup root_list RCU safe"),\ncss->cgroup won\'t be freed during the critical section.\nTo call cgroup_path_ns_locked, css_set_lock is needed, so it is safe to\nreplace task_get_css with task_css.\n\n[1] https://syzkaller.appspot.com/bug?extid=9b1ff7be974a403aa4cd', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43853', 'https://git.kernel.org/linus/1be59c97c83ccd67a519d8a49486b3a8a73ca28a (6.11-rc1)', 'https://git.kernel.org/stable/c/10aeaa47e4aa2432f29b3e5376df96d7dac5537a', 'https://git.kernel.org/stable/c/1be59c97c83ccd67a519d8a49486b3a8a73ca28a', 'https://git.kernel.org/stable/c/27d6dbdc6485d68075a0ebf8544d6425c1ed84bb', 'https://git.kernel.org/stable/c/29a8d4e02fd4840028c38ceb1536cc8f82a257d4', 'https://git.kernel.org/stable/c/29ac1d238b3bf126af36037df80d7ecc4822341e', 'https://git.kernel.org/stable/c/4e8d6ac8fc9f843e940ab7389db8136634e07989', 'https://git.kernel.org/stable/c/688325078a8b5badd6e07ae22b27cd04e9947aec', 'https://git.kernel.org/stable/c/96226fbed566f3f686f53a489a29846f2d538080', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43853-da5b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43853', 'https://www.cve.org/CVERecord?id=CVE-2024-43853'], 'PublishedDate': '2024-08-17T10:15:10.383Z', 'LastModifiedDate': '2024-09-04T12:15:04.827Z'}, {'VulnerabilityID': 'CVE-2024-43854', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43854', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: initialize integrity buffer to zero before writing it to media', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: initialize integrity buffer to zero before writing it to media\n\nMetadata added by bio_integrity_prep is using plain kmalloc, which leads\nto random kernel memory being written media. For PI metadata this is\nlimited to the app tag that isn't used by kernel generated metadata,\nbut for non-PI metadata the entire buffer leaks kernel memory.\n\nFix this by adding the __GFP_ZERO flag to allocations for writes.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43854', 'https://git.kernel.org/linus/899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f (6.11-rc1)', 'https://git.kernel.org/stable/c/129f95948a96105c1fad8e612c9097763e88ac5f', 'https://git.kernel.org/stable/c/23a19655fb56f241e592041156dfb1c6d04da644', 'https://git.kernel.org/stable/c/3fd11fe4f20756b4c0847f755a64cd96f8c6a005', 'https://git.kernel.org/stable/c/899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f', 'https://git.kernel.org/stable/c/9f4af4cf08f9a0329ade3d938f55d2220c40d0a6', 'https://git.kernel.org/stable/c/cf6b45ea7a8df0f61bded1dc4a8561ac6ad143d2', 'https://git.kernel.org/stable/c/d418313bd8f55c079a7da12651951b489a638ac1', 'https://git.kernel.org/stable/c/ebc0e91ba76dc6544fff9f5b66408b1982806a00', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43854-5586@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43854', 'https://www.cve.org/CVERecord?id=CVE-2024-43854'], 'PublishedDate': '2024-08-17T10:15:10.447Z', 'LastModifiedDate': '2024-09-12T12:15:49.423Z'}, {'VulnerabilityID': 'CVE-2024-43856', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43856', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dma: fix call order in dmam_free_coherent', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndma: fix call order in dmam_free_coherent\n\ndmam_free_coherent() frees a DMA allocation, which makes the\nfreed vaddr available for reuse, then calls devres_destroy()\nto remove and free the data structure used to track the DMA\nallocation. Between the two calls, it is possible for a\nconcurrent task to make an allocation with the same vaddr\nand add it to the devres list.\n\nIf this happens, there will be two entries in the devres list\nwith the same vaddr and devres_destroy() can free the wrong\nentry, triggering the WARN_ON() in dmam_match.\n\nFix by destroying the devres entry before freeing the DMA\nallocation.\n\n kokonut //net/encryption\n http://sponge2/b9145fe6-0f72-4325-ac2f-a84d81075b03', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43856', 'https://git.kernel.org/linus/28e8b7406d3a1f5329a03aa25a43aa28e087cb20 (6.11-rc1)', 'https://git.kernel.org/stable/c/1fe97f68fce1ba24bf823bfb0eb0956003473130', 'https://git.kernel.org/stable/c/22094f5f52e7bc16c5bf9613365049383650b02e', 'https://git.kernel.org/stable/c/257193083e8f43907e99ea633820fc2b3bcd24c7', 'https://git.kernel.org/stable/c/28e8b7406d3a1f5329a03aa25a43aa28e087cb20', 'https://git.kernel.org/stable/c/2f7bbdc744f2e7051d1cb47c8e082162df1923c9', 'https://git.kernel.org/stable/c/87b34c8c94e29fa01d744e5147697f592998d954', 'https://git.kernel.org/stable/c/f993a4baf6b622232e4c190d34c220179e5d61eb', 'https://git.kernel.org/stable/c/fe2d246080f035e0af5793cb79067ba125e4fb63', 'https://linux.oracle.com/cve/CVE-2024-43856.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43856-9087@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43856', 'https://www.cve.org/CVERecord?id=CVE-2024-43856'], 'PublishedDate': '2024-08-17T10:15:10.613Z', 'LastModifiedDate': '2024-08-22T17:57:08.64Z'}, {'VulnerabilityID': 'CVE-2024-43857', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43857', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix null reference error when checking end of zone', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix null reference error when checking end of zone\n\nThis patch fixes a potentially null pointer being accessed by\nis_end_zone_blkaddr() that checks the last block of a zone\nwhen f2fs is mounted as a single device.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43857', 'https://git.kernel.org/linus/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38 (6.11-rc1)', 'https://git.kernel.org/stable/c/381cbe85592c78fbaeb3e770e3e9f3bfa3e67efb', 'https://git.kernel.org/stable/c/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43857-b71b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43857', 'https://www.cve.org/CVERecord?id=CVE-2024-43857'], 'PublishedDate': '2024-08-17T10:15:10.687Z', 'LastModifiedDate': '2024-08-22T17:38:21.003Z'}, {'VulnerabilityID': 'CVE-2024-43859', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43859', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to truncate preallocated blocks in f2fs_file_open()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to truncate preallocated blocks in f2fs_file_open()\n\nchenyuwen reports a f2fs bug as below:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000011\n fscrypt_set_bio_crypt_ctx+0x78/0x1e8\n f2fs_grab_read_bio+0x78/0x208\n f2fs_submit_page_read+0x44/0x154\n f2fs_get_read_data_page+0x288/0x5f4\n f2fs_get_lock_data_page+0x60/0x190\n truncate_partial_data_page+0x108/0x4fc\n f2fs_do_truncate_blocks+0x344/0x5f0\n f2fs_truncate_blocks+0x6c/0x134\n f2fs_truncate+0xd8/0x200\n f2fs_iget+0x20c/0x5ac\n do_garbage_collect+0x5d0/0xf6c\n f2fs_gc+0x22c/0x6a4\n f2fs_disable_checkpoint+0xc8/0x310\n f2fs_fill_super+0x14bc/0x1764\n mount_bdev+0x1b4/0x21c\n f2fs_mount+0x20/0x30\n legacy_get_tree+0x50/0xbc\n vfs_get_tree+0x5c/0x1b0\n do_new_mount+0x298/0x4cc\n path_mount+0x33c/0x5fc\n __arm64_sys_mount+0xcc/0x15c\n invoke_syscall+0x60/0x150\n el0_svc_common+0xb8/0xf8\n do_el0_svc+0x28/0xa0\n el0_svc+0x24/0x84\n el0t_64_sync_handler+0x88/0xec\n\nIt is because inode.i_crypt_info is not initialized during below path:\n- mount\n - f2fs_fill_super\n - f2fs_disable_checkpoint\n - f2fs_gc\n - f2fs_iget\n - f2fs_truncate\n\nSo, let's relocate truncation of preallocated blocks to f2fs_file_open(),\nafter fscrypt_file_open().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43859', 'https://git.kernel.org/linus/298b1e4182d657c3e388adcc29477904e9600ed5 (6.11-rc1)', 'https://git.kernel.org/stable/c/298b1e4182d657c3e388adcc29477904e9600ed5', 'https://git.kernel.org/stable/c/3ba0ae885215b325605ff7ebf6de12ac2adf204d', 'https://git.kernel.org/stable/c/5f04969136db674f133781626e0b692c5f2bf2f0', 'https://git.kernel.org/stable/c/f44a25a8bfe0c15d33244539696cd9119cf44d18', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43859-62b4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43859', 'https://www.cve.org/CVERecord?id=CVE-2024-43859'], 'PublishedDate': '2024-08-17T10:15:10.817Z', 'LastModifiedDate': '2024-09-08T08:15:12.96Z'}, {'VulnerabilityID': 'CVE-2024-43860', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43860', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: remoteproc: imx_rproc: Skip over memory region when node value is NULL', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: imx_rproc: Skip over memory region when node value is NULL\n\nIn imx_rproc_addr_init() "nph = of_count_phandle_with_args()" just counts\nnumber of phandles. But phandles may be empty. So of_parse_phandle() in\nthe parsing loop (0 < a < nph) may return NULL which is later dereferenced.\nAdjust this issue by adding NULL-return check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[Fixed title to fit within the prescribed 70-75 charcters]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43860', 'https://git.kernel.org/linus/2fa26ca8b786888673689ccc9da6094150939982 (6.11-rc1)', 'https://git.kernel.org/stable/c/2fa26ca8b786888673689ccc9da6094150939982', 'https://git.kernel.org/stable/c/4e13b7c23988c0a13fdca92e94296a3bc2ff9f21', 'https://git.kernel.org/stable/c/6884fd0283e0831be153fb8d82d9eda8a55acaaa', 'https://git.kernel.org/stable/c/6b50462b473fdccdc0dfad73001147e40ff19a66', 'https://git.kernel.org/stable/c/6c9ea3547fad252fe9ae5d3ed7e066e2085bf3a2', 'https://git.kernel.org/stable/c/84beb7738459cac0ff9f8a7c4654b8ff82a702c0', 'https://git.kernel.org/stable/c/9a17cf8b2ce483fa75258bc2cdcf628f24bcf5f8', 'https://git.kernel.org/stable/c/c877a5f5268d4ab8224b9c9fbce3d746e4e72bc9', 'https://linux.oracle.com/cve/CVE-2024-43860.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43860-d72f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43860', 'https://www.cve.org/CVERecord?id=CVE-2024-43860'], 'PublishedDate': '2024-08-17T10:15:10.887Z', 'LastModifiedDate': '2024-08-22T17:08:15.097Z'}, {'VulnerabilityID': 'CVE-2024-43861', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43861', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: usb: qmi_wwan: fix memory leak for not ip packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: qmi_wwan: fix memory leak for not ip packets\n\nFree the unused skb when not ip packets arrive.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43861', 'https://git.kernel.org/linus/7ab107544b777c3bd7feb9fe447367d8edd5b202 (6.11-rc3)', 'https://git.kernel.org/stable/c/37c093449704017870604994ba9b813cdb9475a4', 'https://git.kernel.org/stable/c/3c90a69533b5bba73401ef884d033ea49ee99662', 'https://git.kernel.org/stable/c/7ab107544b777c3bd7feb9fe447367d8edd5b202', 'https://git.kernel.org/stable/c/c4251a3deccad852b27e60625f31fba6cc14372f', 'https://git.kernel.org/stable/c/c6c5b91424fafc0f83852d961c10c7e43a001882', 'https://git.kernel.org/stable/c/da518cc9b64df391795d9952aed551e0f782e446', 'https://git.kernel.org/stable/c/e87f52225e04a7001bf55bbd7a330fa4252327b5', 'https://git.kernel.org/stable/c/f2c353227de14b0289298ffc3ba92058c4768384', 'https://linux.oracle.com/cve/CVE-2024-43861.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43861-1958@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43861', 'https://www.cve.org/CVERecord?id=CVE-2024-43861'], 'PublishedDate': '2024-08-20T22:15:04.917Z', 'LastModifiedDate': '2024-09-03T13:45:12.667Z'}, {'VulnerabilityID': 'CVE-2024-43863', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43863', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Fix a deadlock in dma buf fence polling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix a deadlock in dma buf fence polling\n\nIntroduce a version of the fence ops that on release doesn't remove\nthe fence from the pending list, and thus doesn't require a lock to\nfix poll->fence wait->fence unref deadlocks.\n\nvmwgfx overwrites the wait callback to iterate over the list of all\nfences and update their status, to do that it holds a lock to prevent\nthe list modifcations from other threads. The fence destroy callback\nboth deletes the fence and removes it from the list of pending\nfences, for which it holds a lock.\n\ndma buf polling cb unrefs a fence after it's been signaled: so the poll\ncalls the wait, which signals the fences, which are being destroyed.\nThe destruction tries to acquire the lock on the pending fences list\nwhich it can never get because it's held by the wait from which it\nwas called.\n\nOld bug, but not a lot of userspace apps were using dma-buf polling\ninterfaces. Fix those, in particular this fixes KDE stalls/deadlock.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43863', 'https://git.kernel.org/linus/e58337100721f3cc0c7424a18730e4f39844934f (6.11-rc2)', 'https://git.kernel.org/stable/c/3b933b16c996af8adb6bc1b5748a63dfb41a82bc', 'https://git.kernel.org/stable/c/9e20d028d8d1deb1e7fed18f22ffc01669cf3237', 'https://git.kernel.org/stable/c/a8943969f9ead2fd3044fc826140a21622ef830e', 'https://git.kernel.org/stable/c/c98ab18b9f315ff977c2c65d7c71298ef98be8e3', 'https://git.kernel.org/stable/c/e58337100721f3cc0c7424a18730e4f39844934f', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43863-9124@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43863', 'https://www.cve.org/CVERecord?id=CVE-2024-43863'], 'PublishedDate': '2024-08-21T00:15:04.847Z', 'LastModifiedDate': '2024-09-03T13:42:44.727Z'}, {'VulnerabilityID': 'CVE-2024-43864', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43864', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Fix CT entry update leaks of modify header context', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix CT entry update leaks of modify header context\n\nThe cited commit allocates a new modify header to replace the old\none when updating CT entry. But if failed to allocate a new one, eg.\nexceed the max number firmware can support, modify header will be\nan error pointer that will trigger a panic when deallocating it. And\nthe old modify header point is copied to old attr. When the old\nattr is freed, the old modify header is lost.\n\nFix it by restoring the old attr to attr when failed to allocate a\nnew modify header context. So when the CT entry is freed, the right\nmodify header context will be freed. And the panic of accessing\nerror pointer is also fixed.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43864', 'https://git.kernel.org/linus/025f2b85a5e5a46df14ecf162c3c80a957a36d0b (6.11-rc2)', 'https://git.kernel.org/stable/c/025f2b85a5e5a46df14ecf162c3c80a957a36d0b', 'https://git.kernel.org/stable/c/89064d09c56b44c668509bf793c410484f63f5ad', 'https://git.kernel.org/stable/c/daab2cc17b6b6ab158566bba037e9551fd432b59', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43864-81ad@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43864', 'https://www.cve.org/CVERecord?id=CVE-2024-43864'], 'PublishedDate': '2024-08-21T00:15:04.91Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43866', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43866', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Always drain health in shutdown callback', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Always drain health in shutdown callback\n\nThere is no point in recovery during device shutdown. if health\nwork started need to wait for it to avoid races and NULL pointer\naccess.\n\nHence, drain health WQ on shutdown callback.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43866', 'https://git.kernel.org/linus/1b75da22ed1e6171e261bc9265370162553d5393 (6.11-rc2)', 'https://git.kernel.org/stable/c/1b75da22ed1e6171e261bc9265370162553d5393', 'https://git.kernel.org/stable/c/5005e2e159b300c1b8c6820a1e13a62eb0127b9b', 'https://git.kernel.org/stable/c/6048dec754554a1303d632be6042d3feb3295285', 'https://git.kernel.org/stable/c/6b6c2ebd83f2bf97e8f221479372aaca97a4a9b2', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43866-66ed@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43866', 'https://www.cve.org/CVERecord?id=CVE-2024-43866'], 'PublishedDate': '2024-08-21T00:15:05.023Z', 'LastModifiedDate': '2024-10-17T14:15:07.297Z'}, {'VulnerabilityID': 'CVE-2024-43867', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43867', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/nouveau: prime: fix refcount underflow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: prime: fix refcount underflow\n\nCalling nouveau_bo_ref() on a nouveau_bo without initializing it (and\nhence the backing ttm_bo) leads to a refcount underflow.\n\nInstead of calling nouveau_bo_ref() in the unwind path of\ndrm_gem_object_init(), clean things up manually.\n\n(cherry picked from commit 1b93f3e89d03cfc576636e195466a0d728ad8de5)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43867', 'https://git.kernel.org/linus/a9bf3efc33f1fbf88787a277f7349459283c9b95 (6.11-rc2)', 'https://git.kernel.org/stable/c/16998763c62bb465ebc409d0373b9cdcef1a61a6', 'https://git.kernel.org/stable/c/2a1b327d57a8ac080977633a18999f032d7e9e3f', 'https://git.kernel.org/stable/c/3bcb8bba72ce89667fa863054956267c450c47ef', 'https://git.kernel.org/stable/c/906372e753c5027a1dc88743843b6aa2ad1aaecf', 'https://git.kernel.org/stable/c/a9bf3efc33f1fbf88787a277f7349459283c9b95', 'https://git.kernel.org/stable/c/ebebba4d357b6c67f96776a48ddbaf0060fa4c10', 'https://git.kernel.org/stable/c/f23cd66933fe76b84d8e282e5606b4d99068c320', 'https://linux.oracle.com/cve/CVE-2024-43867.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43867-0620@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43867', 'https://www.cve.org/CVERecord?id=CVE-2024-43867'], 'PublishedDate': '2024-08-21T00:15:05.087Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43868', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43868', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv/purgatory: align riscv_kernel_entry', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/purgatory: align riscv_kernel_entry\n\nWhen alignment handling is delegated to the kernel, everything must be\nword-aligned in purgatory, since the trap handler is then set to the\nkexec one. Without the alignment, hitting the exception would\nultimately crash. On other occasions, the kernel's handler would take\ncare of exceptions.\nThis has been tested on a JH7110 SoC with oreboot and its SBI delegating\nunaligned access exceptions and the kernel configured to handle them.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43868', 'https://git.kernel.org/linus/fb197c5d2fd24b9af3d4697d0cf778645846d6d5 (6.11-rc2)', 'https://git.kernel.org/stable/c/5d4aaf16a8255f7c71790e211724ba029609c5ff', 'https://git.kernel.org/stable/c/fb197c5d2fd24b9af3d4697d0cf778645846d6d5', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43868-9a44@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43868', 'https://www.cve.org/CVERecord?id=CVE-2024-43868'], 'PublishedDate': '2024-08-21T00:15:05.15Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43869', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43869', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf: Fix event leak upon exec and file release', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix event leak upon exec and file release\n\nThe perf pending task work is never waited upon the matching event\nrelease. In the case of a child event, released via free_event()\ndirectly, this can potentially result in a leaked event, such as in the\nfollowing scenario that doesn't even require a weak IRQ work\nimplementation to trigger:\n\nschedule()\n prepare_task_switch()\n=======> \n perf_event_overflow()\n event->pending_sigtrap = ...\n irq_work_queue(&event->pending_irq)\n<======= \n perf_event_task_sched_out()\n event_sched_out()\n event->pending_sigtrap = 0;\n atomic_long_inc_not_zero(&event->refcount)\n task_work_add(&event->pending_task)\n finish_lock_switch()\n=======> \n perf_pending_irq()\n //do nothing, rely on pending task work\n<======= \n\nbegin_new_exec()\n perf_event_exit_task()\n perf_event_exit_event()\n // If is child event\n free_event()\n WARN(atomic_long_cmpxchg(&event->refcount, 1, 0) != 1)\n // event is leaked\n\nSimilar scenarios can also happen with perf_event_remove_on_exec() or\nsimply against concurrent perf_event_release().\n\nFix this with synchonizing against the possibly remaining pending task\nwork while freeing the event, just like is done with remaining pending\nIRQ work. This means that the pending task callback neither need nor\nshould hold a reference to the event, preventing it from ever beeing\nfreed.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43869', 'https://git.kernel.org/linus/3a5465418f5fd970e86a86c7f4075be262682840 (6.11-rc1)', 'https://git.kernel.org/stable/c/104e258a004037bc7dba9f6085c71dad6af57ad4', 'https://git.kernel.org/stable/c/3a5465418f5fd970e86a86c7f4075be262682840', 'https://git.kernel.org/stable/c/9ad46f1fef421d43cdab3a7d1744b2f43b54dae0', 'https://git.kernel.org/stable/c/ed2c202dac55423a52d7e2290f2888bf08b8ee99', 'https://git.kernel.org/stable/c/f34d8307a73a18de5320fcc6f40403146d061891', 'https://lore.kernel.org/linux-cve-announce/2024082133-CVE-2024-43869-26aa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43869', 'https://www.cve.org/CVERecord?id=CVE-2024-43869'], 'PublishedDate': '2024-08-21T01:15:11.55Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43870', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43870', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf: Fix event leak upon exit', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix event leak upon exit\n\nWhen a task is scheduled out, pending sigtrap deliveries are deferred\nto the target task upon resume to userspace via task_work.\n\nHowever failures while adding an event's callback to the task_work\nengine are ignored. And since the last call for events exit happen\nafter task work is eventually closed, there is a small window during\nwhich pending sigtrap can be queued though ignored, leaking the event\nrefcount addition such as in the following scenario:\n\n TASK A\n -----\n\n do_exit()\n exit_task_work(tsk);\n\n \n perf_event_overflow()\n event->pending_sigtrap = pending_id;\n irq_work_queue(&event->pending_irq);\n \n =========> PREEMPTION: TASK A -> TASK B\n event_sched_out()\n event->pending_sigtrap = 0;\n atomic_long_inc_not_zero(&event->refcount)\n // FAILS: task work has exited\n task_work_add(&event->pending_task)\n [...]\n \n perf_pending_irq()\n // early return: event->oncpu = -1\n \n [...]\n =========> TASK B -> TASK A\n perf_event_exit_task(tsk)\n perf_event_exit_event()\n free_event()\n WARN(atomic_long_cmpxchg(&event->refcount, 1, 0) != 1)\n // leak event due to unexpected refcount == 2\n\nAs a result the event is never released while the task exits.\n\nFix this with appropriate task_work_add()'s error handling.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43870', 'https://git.kernel.org/linus/2fd5ad3f310de22836cdacae919dd99d758a1f1b (6.11-rc1)', 'https://git.kernel.org/stable/c/05d3fd599594abf79aad4484bccb2b26e1cb0b51', 'https://git.kernel.org/stable/c/2fd5ad3f310de22836cdacae919dd99d758a1f1b', 'https://git.kernel.org/stable/c/3d7a63352a93bdb8a1cdf29606bf617d3ac1c22a', 'https://git.kernel.org/stable/c/67fad724f1b568b356c1065d50df46e6b30eb2f7', 'https://git.kernel.org/stable/c/70882d7fa74f0731492a0d493e8515a4f7131831', 'https://lore.kernel.org/linux-cve-announce/2024082135-CVE-2024-43870-2b6f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43870', 'https://www.cve.org/CVERecord?id=CVE-2024-43870'], 'PublishedDate': '2024-08-21T01:15:11.62Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43871', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43871', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: devres: Fix memory leakage caused by driver API devm_free_percpu()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndevres: Fix memory leakage caused by driver API devm_free_percpu()\n\nIt will cause memory leakage when use driver API devm_free_percpu()\nto free memory allocated by devm_alloc_percpu(), fixed by using\ndevres_release() instead of devres_destroy() within devm_free_percpu().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-43871', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/bd50a974097bb82d52a458bd3ee39fb723129a0c (6.11-rc1)', 'https://git.kernel.org/stable/c/3047f99caec240a88ccd06197af2868da1af6a96', 'https://git.kernel.org/stable/c/3dcd0673e47664bc6c719ad47dadac6d55d5950d', 'https://git.kernel.org/stable/c/700e8abd65b10792b2f179ce4e858f2ca2880f85', 'https://git.kernel.org/stable/c/95065edb8ebb27771d5f1e898eef6ab43dc6c87c', 'https://git.kernel.org/stable/c/b044588a16a978cd891cb3d665dd7ae06850d5bf', 'https://git.kernel.org/stable/c/b67552d7c61f52f1271031adfa7834545ae99701', 'https://git.kernel.org/stable/c/bd50a974097bb82d52a458bd3ee39fb723129a0c', 'https://git.kernel.org/stable/c/ef56dcdca8f2a53abc3a83d388b8336447533d85', 'https://linux.oracle.com/cve/CVE-2024-43871.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43871-c2cd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43871', 'https://www.cve.org/CVERecord?id=CVE-2024-43871'], 'PublishedDate': '2024-08-21T01:15:11.68Z', 'LastModifiedDate': '2024-09-03T13:39:19.553Z'}, {'VulnerabilityID': 'CVE-2024-43872', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43872', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/hns: Fix soft lockup under heavy CEQE load', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix soft lockup under heavy CEQE load\n\nCEQEs are handled in interrupt handler currently. This may cause the\nCPU core staying in interrupt context too long and lead to soft lockup\nunder heavy load.\n\nHandle CEQEs in BH workqueue and set an upper limit for the number of\nCEQE handled by a single call of work handler.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43872', 'https://git.kernel.org/linus/2fdf34038369c0a27811e7b4680662a14ada1d6b (6.11-rc1)', 'https://git.kernel.org/stable/c/06580b33c183c9f98e2a2ca96a86137179032c08', 'https://git.kernel.org/stable/c/2fdf34038369c0a27811e7b4680662a14ada1d6b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43872-c87e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43872', 'https://www.cve.org/CVERecord?id=CVE-2024-43872'], 'PublishedDate': '2024-08-21T01:15:11.74Z', 'LastModifiedDate': '2024-09-03T13:38:34.867Z'}, {'VulnerabilityID': 'CVE-2024-43873', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43873', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: vhost/vsock: always initialize seqpacket_allow', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/vsock: always initialize seqpacket_allow\n\nThere are two issues around seqpacket_allow:\n1. seqpacket_allow is not initialized when socket is\n created. Thus if features are never set, it will be\n read uninitialized.\n2. if VIRTIO_VSOCK_F_SEQPACKET is set and then cleared,\n then seqpacket_allow will not be cleared appropriately\n (existing apps I know about don't usually do this but\n it's legal and there's no way to be sure no one relies\n on this).\n\nTo fix:\n\t- initialize seqpacket_allow after allocation\n\t- set it unconditionally in set_features", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-909'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43873', 'https://git.kernel.org/linus/1e1fdcbdde3b7663e5d8faeb2245b9b151417d22 (6.11-rc1)', 'https://git.kernel.org/stable/c/1e1fdcbdde3b7663e5d8faeb2245b9b151417d22', 'https://git.kernel.org/stable/c/3062cb100787a9ddf45de30004b962035cd497fb', 'https://git.kernel.org/stable/c/30bd4593669443ac58515e23557dc8cef70d8582', 'https://git.kernel.org/stable/c/ea558f10fb05a6503c6e655a1b7d81fdf8e5924c', 'https://git.kernel.org/stable/c/eab96e8716cbfc2834b54f71cc9501ad4eec963b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43873-c547@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43873', 'https://www.cve.org/CVERecord?id=CVE-2024-43873'], 'PublishedDate': '2024-08-21T01:15:11.79Z', 'LastModifiedDate': '2024-09-03T13:35:44.897Z'}, {'VulnerabilityID': 'CVE-2024-43875', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43875', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: endpoint: Clean up error handling in vpci_scan_bus()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: Clean up error handling in vpci_scan_bus()\n\nSmatch complains about inconsistent NULL checking in vpci_scan_bus():\n\n drivers/pci/endpoint/functions/pci-epf-vntb.c:1024 vpci_scan_bus() error: we previously assumed 'vpci_bus' could be null (see line 1021)\n\nInstead of printing an error message and then crashing we should return\nan error code and clean up.\n\nAlso the NULL check is reversed so it prints an error for success\ninstead of failure.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43875', 'https://git.kernel.org/linus/8e0f5a96c534f781e8c57ca30459448b3bfe5429 (6.11-rc1)', 'https://git.kernel.org/stable/c/0e27e2e8697b8ce96cdef43f135426525d9d1f8f', 'https://git.kernel.org/stable/c/24414c842a24d0fd498f9db6d2a762a8dddf1832', 'https://git.kernel.org/stable/c/7d368de78b60088ec9031c60c88976c0063ea4c0', 'https://git.kernel.org/stable/c/8e0f5a96c534f781e8c57ca30459448b3bfe5429', 'https://git.kernel.org/stable/c/b9e8695246bcfc028341470cbf92630cdc1ba36b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43875-1257@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43875', 'https://www.cve.org/CVERecord?id=CVE-2024-43875'], 'PublishedDate': '2024-08-21T01:15:11.91Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43876', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43876', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()\n\nAvoid large backtrace, it is sufficient to warn the user that there has\nbeen a link problem. Either the link has failed and the system is in need\nof maintenance, or the link continues to work and user has been informed.\nThe message from the warning can be looked up in the sources.\n\nThis makes an actual link issue less verbose.\n\nFirst of all, this controller has a limitation in that the controller\ndriver has to assist the hardware with transition to L1 link state by\nwriting L1IATN to PMCTRL register, the L1 and L0 link state switching\nis not fully automatic on this controller.\n\nIn case of an ASMedia ASM1062 PCIe SATA controller which does not support\nASPM, on entry to suspend or during platform pm_test, the SATA controller\nenters D3hot state and the link enters L1 state. If the SATA controller\nwakes up before rcar_pcie_wakeup() was called and returns to D0, the link\nreturns to L0 before the controller driver even started its transition to\nL1 link state. At this point, the SATA controller did send an PM_ENTER_L1\nDLLP to the PCIe controller and the PCIe controller received it, and the\nPCIe controller did set PMSR PMEL1RX bit.\n\nOnce rcar_pcie_wakeup() is called, if the link is already back in L0 state\nand PMEL1RX bit is set, the controller driver has no way to determine if\nit should perform the link transition to L1 state, or treat the link as if\nit is in L0 state. Currently the driver attempts to perform the transition\nto L1 link state unconditionally, which in this specific case fails with a\nPMSR L1FAEG poll timeout, however the link still works as it is already\nback in L0 state.\n\nReduce this warning verbosity. In case the link is really broken, the\nrcar_pcie_config_access() would fail, otherwise it will succeed and any\nsystem with this controller and ASM1062 can suspend without generating\na backtrace.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 2.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43876', 'https://git.kernel.org/linus/c93637e6a4c4e1d0e85ef7efac78d066bbb24d96 (6.11-rc1)', 'https://git.kernel.org/stable/c/2ae4769332dfdb97f4b6f5dc9ac8f46d02aaa3df', 'https://git.kernel.org/stable/c/3ff3bdde950f1840df4030726cef156758a244d7', 'https://git.kernel.org/stable/c/526a877c6273d4cd0d0aede84c1d620479764b1c', 'https://git.kernel.org/stable/c/c93637e6a4c4e1d0e85ef7efac78d066bbb24d96', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43876-793b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43876', 'https://www.cve.org/CVERecord?id=CVE-2024-43876'], 'PublishedDate': '2024-08-21T01:15:11.973Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43877', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43877', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: pci: ivtv: Add check for DMA map result', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: ivtv: Add check for DMA map result\n\nIn case DMA fails, 'dma->SG_length' is 0. This value is later used to\naccess 'dma->SGarray[dma->SG_length - 1]', which will cause out of\nbounds access.\n\nAdd check to return early on invalid value. Adjust warnings accordingly.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43877', 'https://git.kernel.org/linus/629913d6d79508b166c66e07e4857e20233d85a9 (6.11-rc1)', 'https://git.kernel.org/stable/c/24062aa7407091dee3e45a8e8037df437e848718', 'https://git.kernel.org/stable/c/3d8fd92939e21ff0d45100ab208f8124af79402a', 'https://git.kernel.org/stable/c/629913d6d79508b166c66e07e4857e20233d85a9', 'https://git.kernel.org/stable/c/c766065e8272085ea9c436414b7ddf1f12e7787b', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43877-e8e4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43877', 'https://www.cve.org/CVERecord?id=CVE-2024-43877'], 'PublishedDate': '2024-08-21T01:15:12.033Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43879', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43879', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()\n\nCurrently NL80211_RATE_INFO_HE_RU_ALLOC_2x996 is not handled in\ncfg80211_calculate_bitrate_he(), leading to below warning:\n\nkernel: invalid HE MCS: bw:6, ru:6\nkernel: WARNING: CPU: 0 PID: 2312 at net/wireless/util.c:1501 cfg80211_calculate_bitrate_he+0x22b/0x270 [cfg80211]\n\nFix it by handling 2x996 RU allocation in the same way as 160 MHz bandwidth.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43879', 'https://git.kernel.org/linus/bcbd771cd5d68c0c52567556097d75f9fc4e7cd6 (6.11-rc1)', 'https://git.kernel.org/stable/c/16ad67e73309db0c20cc2a651992bd01c05e6b27', 'https://git.kernel.org/stable/c/19eaf4f2f5a981f55a265242ada2bf92b0c742dd', 'https://git.kernel.org/stable/c/2e201b3d162c6c49417c438ffb30b58c9f85769f', 'https://git.kernel.org/stable/c/45d20a1c54be4f3173862c7b950d4468447814c9', 'https://git.kernel.org/stable/c/576c64622649f3ec07e97bac8fec8b8a2ef4d086', 'https://git.kernel.org/stable/c/67b5f1054197e4f5553047759c15c1d67d4c8142', 'https://git.kernel.org/stable/c/b289ebb0516526cb4abae081b7ec29fd4fa1209d', 'https://git.kernel.org/stable/c/bcbd771cd5d68c0c52567556097d75f9fc4e7cd6', 'https://linux.oracle.com/cve/CVE-2024-43879.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43879-95cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43879', 'https://www.cve.org/CVERecord?id=CVE-2024-43879'], 'PublishedDate': '2024-08-21T01:15:12.153Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43880', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43880', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mlxsw: spectrum_acl_erp: Fix object nesting warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_erp: Fix object nesting warning\n\nACLs in Spectrum-2 and newer ASICs can reside in the algorithmic TCAM\n(A-TCAM) or in the ordinary circuit TCAM (C-TCAM). The former can\ncontain more ACLs (i.e., tc filters), but the number of masks in each\nregion (i.e., tc chain) is limited.\n\nIn order to mitigate the effects of the above limitation, the device\nallows filters to share a single mask if their masks only differ in up\nto 8 consecutive bits. For example, dst_ip/25 can be represented using\ndst_ip/24 with a delta of 1 bit. The C-TCAM does not have a limit on the\nnumber of masks being used (and therefore does not support mask\naggregation), but can contain a limited number of filters.\n\nThe driver uses the "objagg" library to perform the mask aggregation by\npassing it objects that consist of the filter\'s mask and whether the\nfilter is to be inserted into the A-TCAM or the C-TCAM since filters in\ndifferent TCAMs cannot share a mask.\n\nThe set of created objects is dependent on the insertion order of the\nfilters and is not necessarily optimal. Therefore, the driver will\nperiodically ask the library to compute a more optimal set ("hints") by\nlooking at all the existing objects.\n\nWhen the library asks the driver whether two objects can be aggregated\nthe driver only compares the provided masks and ignores the A-TCAM /\nC-TCAM indication. This is the right thing to do since the goal is to\nmove as many filters as possible to the A-TCAM. The driver also forbids\ntwo identical masks from being aggregated since this can only happen if\none was intentionally put in the C-TCAM to avoid a conflict in the\nA-TCAM.\n\nThe above can result in the following set of hints:\n\nH1: {mask X, A-TCAM} -> H2: {mask Y, A-TCAM} // X is Y + delta\nH3: {mask Y, C-TCAM} -> H4: {mask Z, A-TCAM} // Y is Z + delta\n\nAfter getting the hints from the library the driver will start migrating\nfilters from one region to another while consulting the computed hints\nand instructing the device to perform a lookup in both regions during\nthe transition.\n\nAssuming a filter with mask X is being migrated into the A-TCAM in the\nnew region, the hints lookup will return H1. Since H2 is the parent of\nH1, the library will try to find the object associated with it and\ncreate it if necessary in which case another hints lookup (recursive)\nwill be performed. This hints lookup for {mask Y, A-TCAM} will either\nreturn H2 or H3 since the driver passes the library an object comparison\nfunction that ignores the A-TCAM / C-TCAM indication.\n\nThis can eventually lead to nested objects which are not supported by\nthe library [1].\n\nFix by removing the object comparison function from both the driver and\nthe library as the driver was the only user. That way the lookup will\nonly return exact matches.\n\nI do not have a reliable reproducer that can reproduce the issue in a\ntimely manner, but before the fix the issue would reproduce in several\nminutes and with the fix it does not reproduce in over an hour.\n\nNote that the current usefulness of the hints is limited because they\ninclude the C-TCAM indication and represent aggregation that cannot\nactually happen. This will be addressed in net-next.\n\n[1]\nWARNING: CPU: 0 PID: 153 at lib/objagg.c:170 objagg_obj_parent_assign+0xb5/0xd0\nModules linked in:\nCPU: 0 PID: 153 Comm: kworker/0:18 Not tainted 6.9.0-rc6-custom-g70fbc2c1c38b #42\nHardware name: Mellanox Technologies Ltd. MSN3700C/VMOD0008, BIOS 5.11 10/10/2018\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:objagg_obj_parent_assign+0xb5/0xd0\n[...]\nCall Trace:\n \n __objagg_obj_get+0x2bb/0x580\n objagg_obj_get+0xe/0x80\n mlxsw_sp_acl_erp_mask_get+0xb5/0xf0\n mlxsw_sp_acl_atcam_entry_add+0xe8/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43880', 'https://git.kernel.org/linus/97d833ceb27dc19f8777d63f90be4a27b5daeedf (6.11-rc1)', 'https://git.kernel.org/stable/c/0e59c2d22853266704e127915653598f7f104037', 'https://git.kernel.org/stable/c/25c6fd9648ad05da493a5d30881896a78a08b624', 'https://git.kernel.org/stable/c/36a9996e020dd5aa325e0ecc55eb2328288ea6bb', 'https://git.kernel.org/stable/c/4dc09f6f260db3c4565a4ec52ba369393598f2fb', 'https://git.kernel.org/stable/c/97d833ceb27dc19f8777d63f90be4a27b5daeedf', 'https://git.kernel.org/stable/c/9a5261a984bba4f583d966c550fa72c33ff3714e', 'https://git.kernel.org/stable/c/fb5d4fc578e655d113f09565f6f047e15f7ab578', 'https://linux.oracle.com/cve/CVE-2024-43880.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43880-78ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43880', 'https://www.cve.org/CVERecord?id=CVE-2024-43880'], 'PublishedDate': '2024-08-21T01:15:12.213Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43881', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43881', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: change DMA direction while mapping reinjected packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: change DMA direction while mapping reinjected packets\n\nFor fragmented packets, ath12k reassembles each fragment as a normal\npacket and then reinjects it into HW ring. In this case, the DMA\ndirection should be DMA_TO_DEVICE, not DMA_FROM_DEVICE. Otherwise,\nan invalid payload may be reinjected into the HW and\nsubsequently delivered to the host.\n\nGiven that arbitrary memory can be allocated to the skb buffer,\nknowledge about the data contained in the reinjected buffer is lacking.\nConsequently, there’s a risk of private information being leaked.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43881', 'https://git.kernel.org/linus/33322e3ef07409278a18c6919c448e369d66a18e (6.11-rc1)', 'https://git.kernel.org/stable/c/33322e3ef07409278a18c6919c448e369d66a18e', 'https://git.kernel.org/stable/c/6925320fcd40d8042d32bf4ede8248e7a5315c3b', 'https://git.kernel.org/stable/c/e99d9b16ff153de9540073239d24adc3b0a3a997', 'https://lore.kernel.org/linux-cve-announce/2024082138-CVE-2024-43881-ead4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43881', 'https://www.cve.org/CVERecord?id=CVE-2024-43881'], 'PublishedDate': '2024-08-21T01:15:12.28Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43883', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43883', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: vhci-hcd: Do not drop references before new references are gained', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: vhci-hcd: Do not drop references before new references are gained\n\nAt a few places the driver carries stale pointers\nto references that can still be used. Make sure that does not happen.\nThis strictly speaking closes ZDI-CAN-22273, though there may be\nsimilar races in the driver.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43883', 'https://git.kernel.org/stable/c/128e82e41cf7d74a562726c1587d9d2ede1a0a37', 'https://git.kernel.org/stable/c/4dacdb9720aaab10b6be121eae55820174d97174', 'https://git.kernel.org/stable/c/585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14', 'https://git.kernel.org/stable/c/5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89', 'https://git.kernel.org/stable/c/9c3746ce8d8fcb3a2405644fc0eec7fc5312de80', 'https://git.kernel.org/stable/c/afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a', 'https://git.kernel.org/stable/c/c3d0857b7fc2c49f68f89128a5440176089a8f54', 'https://git.kernel.org/stable/c/e8c1e606dab8c56cf074b43b98d0805de7322ba2', 'https://linux.oracle.com/cve/CVE-2024-43883.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082313-CVE-2024-43883-a594@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43883', 'https://www.cve.org/CVERecord?id=CVE-2024-43883'], 'PublishedDate': '2024-08-23T13:15:03.873Z', 'LastModifiedDate': '2024-08-23T16:18:28.547Z'}, {'VulnerabilityID': 'CVE-2024-43884', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43884', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: MGMT: Add error handling to pair_device()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Add error handling to pair_device()\n\nhci_conn_params_add() never checks for a NULL value and could lead to a NULL\npointer dereference causing a crash.\n\nFixed by adding error handling in the function.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43884', 'https://git.kernel.org/linus/538fd3921afac97158d4177139a0ad39f056dbb2 (6.11-rc5)', 'https://git.kernel.org/stable/c/064dd929c76532359d2905d90a7c12348043cfd4', 'https://git.kernel.org/stable/c/11b4b0e63f2621b33b2e107407a7d67a65994ca1', 'https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2', 'https://git.kernel.org/stable/c/5da2884292329bc9be32a7778e0e119f06abe503', 'https://git.kernel.org/stable/c/90e1ff1c15e5a8f3023ca8266e3a85869ed03ee9', 'https://git.kernel.org/stable/c/951d6cb5eaac5130d076c728f2a6db420621afdb', 'https://git.kernel.org/stable/c/9df9783bd85610d3d6e126a1aca221531f6f6dcb', 'https://git.kernel.org/stable/c/ee0799103b1ae4bcfd80dc11a15df085f6ee1b61', 'https://lore.kernel.org/linux-cve-announce/2024082621-CVE-2024-43884-43fa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43884', 'https://www.cve.org/CVERecord?id=CVE-2024-43884'], 'PublishedDate': '2024-08-26T08:15:03.827Z', 'LastModifiedDate': '2024-09-04T12:15:04.927Z'}, {'VulnerabilityID': 'CVE-2024-43886', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43886', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null check in resource_log_pipe_topology_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check in resource_log_pipe_topology_update\n\n[WHY]\nWhen switching from "Extend" to "Second Display Only" we sometimes\ncall resource_get_otg_master_for_stream on a stream for the eDP,\nwhich is disconnected. This leads to a null pointer dereference.\n\n[HOW]\nAdded a null check in dc_resource.c/resource_log_pipe_topology_update.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43886', 'https://git.kernel.org/linus/899d92fd26fe780aad711322aa671f68058207a6 (6.11-rc1)', 'https://git.kernel.org/stable/c/899d92fd26fe780aad711322aa671f68058207a6', 'https://git.kernel.org/stable/c/c36e922a36bdf69765c340a0857ca74092003bee', 'https://lore.kernel.org/linux-cve-announce/2024082657-CVE-2024-43886-0726@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43886', 'https://www.cve.org/CVERecord?id=CVE-2024-43886'], 'PublishedDate': '2024-08-26T11:15:03.83Z', 'LastModifiedDate': '2024-08-27T14:37:45.377Z'}, {'VulnerabilityID': 'CVE-2024-43887', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43887', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/tcp: Disable TCP-AO static key after RCU grace period', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp: Disable TCP-AO static key after RCU grace period\n\nThe lifetime of TCP-AO static_key is the same as the last\ntcp_ao_info. On the socket destruction tcp_ao_info ceases to be\nwith RCU grace period, while tcp-ao static branch is currently deferred\ndestructed. The static key definition is\n: DEFINE_STATIC_KEY_DEFERRED_FALSE(tcp_ao_needed, HZ);\n\nwhich means that if RCU grace period is delayed by more than a second\nand tcp_ao_needed is in the process of disablement, other CPUs may\nyet see tcp_ao_info which atent dead, but soon-to-be.\nAnd that breaks the assumption of static_key_fast_inc_not_disabled().\n\nSee the comment near the definition:\n> * The caller must make sure that the static key can\'t get disabled while\n> * in this function. It doesn\'t patch jump labels, only adds a user to\n> * an already enabled static key.\n\nOriginally it was introduced in commit eb8c507296f6 ("jump_label:\nPrevent key->enabled int overflow"), which is needed for the atomic\ncontexts, one of which would be the creation of a full socket from a\nrequest socket. In that atomic context, it\'s known by the presence\nof the key (md5/ao) that the static branch is already enabled.\nSo, the ref counter for that static branch is just incremented\ninstead of holding the proper mutex.\nstatic_key_fast_inc_not_disabled() is just a helper for such usage\ncase. But it must not be used if the static branch could get disabled\nin parallel as it\'s not protected by jump_label_mutex and as a result,\nraces with jump_label_update() implementation details.\n\nHappened on netdev test-bot[1], so not a theoretical issue:\n\n[] jump_label: Fatal kernel bug, unexpected op at tcp_inbound_hash+0x1a7/0x870 [ffffffffa8c4e9b7] (eb 50 0f 1f 44 != 66 90 0f 1f 00)) size:2 type:1\n[] ------------[ cut here ]------------\n[] kernel BUG at arch/x86/kernel/jump_label.c:73!\n[] Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[] CPU: 3 PID: 243 Comm: kworker/3:3 Not tainted 6.10.0-virtme #1\n[] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[] Workqueue: events jump_label_update_timeout\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n...\n[] Call Trace:\n[] \n[] arch_jump_label_transform_queue+0x6c/0x110\n[] __jump_label_update+0xef/0x350\n[] __static_key_slow_dec_cpuslocked.part.0+0x3c/0x60\n[] jump_label_update_timeout+0x2c/0x40\n[] process_one_work+0xe3b/0x1670\n[] worker_thread+0x587/0xce0\n[] kthread+0x28a/0x350\n[] ret_from_fork+0x31/0x70\n[] ret_from_fork_asm+0x1a/0x30\n[] \n[] Modules linked in: veth\n[] ---[ end trace 0000000000000000 ]---\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n\n[1]: https://netdev-3.bots.linux.dev/vmksft-tcp-ao-dbg/results/696681/5-connect-deny-ipv6/stderr', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43887', 'https://git.kernel.org/linus/14ab4792ee120c022f276a7e4768f4dcb08f0cdd (6.11-rc3)', 'https://git.kernel.org/stable/c/14ab4792ee120c022f276a7e4768f4dcb08f0cdd', 'https://git.kernel.org/stable/c/954d55a59b2501f4a9bd693b40ce45a1c46cb2b3', 'https://lore.kernel.org/linux-cve-announce/2024082658-CVE-2024-43887-93bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43887', 'https://www.cve.org/CVERecord?id=CVE-2024-43887'], 'PublishedDate': '2024-08-26T11:15:03.877Z', 'LastModifiedDate': '2024-09-05T19:43:44.197Z'}, {'VulnerabilityID': 'CVE-2024-43888', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43888', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: list_lru: fix UAF for memory cgroup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: list_lru: fix UAF for memory cgroup\n\nThe mem_cgroup_from_slab_obj() is supposed to be called under rcu lock or\ncgroup_mutex or others which could prevent returned memcg from being\nfreed. Fix it by adding missing rcu read lock.\n\nFound by code inspection.\n\n[songmuchun@bytedance.com: only grab rcu lock when necessary, per Vlastimil]\n Link: https://lkml.kernel.org/r/20240801024603.1865-1-songmuchun@bytedance.com', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43888', 'https://git.kernel.org/linus/5161b48712dcd08ec427c450399d4d1483e21dea (6.11-rc3)', 'https://git.kernel.org/stable/c/4589f77c18dd98b65f45617b6d1e95313cf6fcab', 'https://git.kernel.org/stable/c/5161b48712dcd08ec427c450399d4d1483e21dea', 'https://lore.kernel.org/linux-cve-announce/2024082659-CVE-2024-43888-5beb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43888', 'https://www.cve.org/CVERecord?id=CVE-2024-43888'], 'PublishedDate': '2024-08-26T11:15:03.93Z', 'LastModifiedDate': '2024-08-27T14:37:52.61Z'}, {'VulnerabilityID': 'CVE-2024-43889', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43889', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npadata: Fix possible divide-by-0 panic in padata_mt_helper()\n\nWe are hit with a not easily reproducible divide-by-0 panic in padata.c at\nbootup time.\n\n [ 10.017908] Oops: divide error: 0000 1 PREEMPT SMP NOPTI\n [ 10.017908] CPU: 26 PID: 2627 Comm: kworker/u1666:1 Not tainted 6.10.0-15.el10.x86_64 #1\n [ 10.017908] Hardware name: Lenovo ThinkSystem SR950 [7X12CTO1WW]/[7X12CTO1WW], BIOS [PSE140J-2.30] 07/20/2021\n [ 10.017908] Workqueue: events_unbound padata_mt_helper\n [ 10.017908] RIP: 0010:padata_mt_helper+0x39/0xb0\n :\n [ 10.017963] Call Trace:\n [ 10.017968] \n [ 10.018004] ? padata_mt_helper+0x39/0xb0\n [ 10.018084] process_one_work+0x174/0x330\n [ 10.018093] worker_thread+0x266/0x3a0\n [ 10.018111] kthread+0xcf/0x100\n [ 10.018124] ret_from_fork+0x31/0x50\n [ 10.018138] ret_from_fork_asm+0x1a/0x30\n [ 10.018147] \n\nLooking at the padata_mt_helper() function, the only way a divide-by-0\npanic can happen is when ps->chunk_size is 0. The way that chunk_size is\ninitialized in padata_do_multithreaded(), chunk_size can be 0 when the\nmin_chunk in the passed-in padata_mt_job structure is 0.\n\nFix this divide-by-0 panic by making sure that chunk_size will be at least\n1 no matter what the input parameters are.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43889', 'https://git.kernel.org/linus/6d45e1c948a8b7ed6ceddb14319af69424db730c (6.11-rc3)', 'https://git.kernel.org/stable/c/6d45e1c948a8b7ed6ceddb14319af69424db730c', 'https://git.kernel.org/stable/c/8f5ffd2af7274853ff91d6cd62541191d9fbd10d', 'https://git.kernel.org/stable/c/924f788c906dccaca30acab86c7124371e1d6f2c', 'https://git.kernel.org/stable/c/a29cfcb848c31f22b4de6a531c3e1d68c9bfe09f', 'https://git.kernel.org/stable/c/ab8b397d5997d8c37610252528edc54bebf9f6d3', 'https://git.kernel.org/stable/c/da0ffe84fcc1627a7dff82c80b823b94236af905', 'https://lore.kernel.org/linux-cve-announce/2024082600-CVE-2024-43889-4d0b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43889', 'https://www.cve.org/CVERecord?id=CVE-2024-43889'], 'PublishedDate': '2024-08-26T11:15:03.98Z', 'LastModifiedDate': '2024-08-27T14:38:09.34Z'}, {'VulnerabilityID': 'CVE-2024-43890', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43890', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Fix overflow in get_free_elt()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix overflow in get_free_elt()\n\n"tracing_map->next_elt" in get_free_elt() is at risk of overflowing.\n\nOnce it overflows, new elements can still be inserted into the tracing_map\neven though the maximum number of elements (`max_elts`) has been reached.\nContinuing to insert elements after the overflow could result in the\ntracing_map containing "tracing_map->max_size" elements, leaving no empty\nentries.\nIf any attempt is made to insert an element into a full tracing_map using\n`__tracing_map_insert()`, it will cause an infinite loop with preemption\ndisabled, leading to a CPU hang problem.\n\nFix this by preventing any further increments to "tracing_map->next_elt"\nonce it reaches "tracing_map->max_elt".', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43890', 'https://git.kernel.org/linus/bcf86c01ca4676316557dd482c8416ece8c2e143 (6.11-rc3)', 'https://git.kernel.org/stable/c/236bb4690773ab6869b40bedc7bc8d889e36f9d6', 'https://git.kernel.org/stable/c/302ceb625d7b990db205a15e371f9a71238de91c', 'https://git.kernel.org/stable/c/788ea62499b3c18541fd6d621964d8fafbc4aec5', 'https://git.kernel.org/stable/c/a172c7b22bc2feaf489cfc6d6865f7237134fdf8', 'https://git.kernel.org/stable/c/bcf86c01ca4676316557dd482c8416ece8c2e143', 'https://git.kernel.org/stable/c/cd10d186a5409a1fe6e976df82858e9773a698da', 'https://git.kernel.org/stable/c/d3e4dbc2858fe85d1dbd2e72a9fc5dea988b5c18', 'https://git.kernel.org/stable/c/eb223bf01e688dfe37e813c8988ee11c8c9f8d0a', 'https://linux.oracle.com/cve/CVE-2024-43890.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082601-CVE-2024-43890-1c3a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43890', 'https://www.cve.org/CVERecord?id=CVE-2024-43890'], 'PublishedDate': '2024-08-26T11:15:04.04Z', 'LastModifiedDate': '2024-09-05T18:48:30.32Z'}, {'VulnerabilityID': 'CVE-2024-43891', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43891', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Have format file honor EVENT_FILE_FL_FREED', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have format file honor EVENT_FILE_FL_FREED\n\nWhen eventfs was introduced, special care had to be done to coordinate the\nfreeing of the file meta data with the files that are exposed to user\nspace. The file meta data would have a ref count that is set when the file\nis created and would be decremented and freed after the last user that\nopened the file closed it. When the file meta data was to be freed, it\nwould set a flag (EVENT_FILE_FL_FREED) to denote that the file is freed,\nand any new references made (like new opens or reads) would fail as it is\nmarked freed. This allowed other meta data to be freed after this flag was\nset (under the event_mutex).\n\nAll the files that were dynamically created in the events directory had a\npointer to the file meta data and would call event_release() when the last\nreference to the user space file was closed. This would be the time that it\nis safe to free the file meta data.\n\nA shortcut was made for the "format" file. It\'s i_private would point to\nthe "call" entry directly and not point to the file\'s meta data. This is\nbecause all format files are the same for the same "call", so it was\nthought there was no reason to differentiate them. The other files\nmaintain state (like the "enable", "trigger", etc). But this meant if the\nfile were to disappear, the "format" file would be unaware of it.\n\nThis caused a race that could be trigger via the user_events test (that\nwould create dynamic events and free them), and running a loop that would\nread the user_events format files:\n\nIn one console run:\n\n # cd tools/testing/selftests/user_events\n # while true; do ./ftrace_test; done\n\nAnd in another console run:\n\n # cd /sys/kernel/tracing/\n # while true; do cat events/user_events/__test_event/format; done 2>/dev/null\n\nWith KASAN memory checking, it would trigger a use-after-free bug report\n(which was a real bug). This was because the format file was not checking\nthe file\'s meta data flag "EVENT_FILE_FL_FREED", so it would access the\nevent that the file meta data pointed to after the event was freed.\n\nAfter inspection, there are other locations that were found to not check\nthe EVENT_FILE_FL_FREED flag when accessing the trace_event_file. Add a\nnew helper function: event_file_file() that will make sure that the\nevent_mutex is held, and will return NULL if the trace_event_file has the\nEVENT_FILE_FL_FREED flag set. Have the first reference of the struct file\npointer use event_file_file() and check for NULL. Later uses can still use\nthe event_file_data() helper function if the event_mutex is still held and\nwas not released since the event_file_file() call.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43891', 'https://git.kernel.org/linus/b1560408692cd0ab0370cfbe9deb03ce97ab3f6d (6.11-rc3)', 'https://git.kernel.org/stable/c/4ed03758ddf0b19d69eed69386d65a92d0091e0c', 'https://git.kernel.org/stable/c/531dc6780d94245af037c25c2371c8caf652f0f9', 'https://git.kernel.org/stable/c/b1560408692cd0ab0370cfbe9deb03ce97ab3f6d', 'https://lore.kernel.org/linux-cve-announce/2024082603-CVE-2024-43891-a69d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43891', 'https://www.cve.org/CVERecord?id=CVE-2024-43891'], 'PublishedDate': '2024-08-26T11:15:04.103Z', 'LastModifiedDate': '2024-09-05T18:46:18.44Z'}, {'VulnerabilityID': 'CVE-2024-43892', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43892', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg: protect concurrent access to mem_cgroup_idr', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: protect concurrent access to mem_cgroup_idr\n\nCommit 73f576c04b94 ("mm: memcontrol: fix cgroup creation failure after\nmany small jobs") decoupled the memcg IDs from the CSS ID space to fix the\ncgroup creation failures. It introduced IDR to maintain the memcg ID\nspace. The IDR depends on external synchronization mechanisms for\nmodifications. For the mem_cgroup_idr, the idr_alloc() and idr_replace()\nhappen within css callback and thus are protected through cgroup_mutex\nfrom concurrent modifications. However idr_remove() for mem_cgroup_idr\nwas not protected against concurrency and can be run concurrently for\ndifferent memcgs when they hit their refcnt to zero. Fix that.\n\nWe have been seeing list_lru based kernel crashes at a low frequency in\nour fleet for a long time. These crashes were in different part of\nlist_lru code including list_lru_add(), list_lru_del() and reparenting\ncode. Upon further inspection, it looked like for a given object (dentry\nand inode), the super_block\'s list_lru didn\'t have list_lru_one for the\nmemcg of that object. The initial suspicions were either the object is\nnot allocated through kmem_cache_alloc_lru() or somehow\nmemcg_list_lru_alloc() failed to allocate list_lru_one() for a memcg but\nreturned success. No evidence were found for these cases.\n\nLooking more deeply, we started seeing situations where valid memcg\'s id\nis not present in mem_cgroup_idr and in some cases multiple valid memcgs\nhave same id and mem_cgroup_idr is pointing to one of them. So, the most\nreasonable explanation is that these situations can happen due to race\nbetween multiple idr_remove() calls or race between\nidr_alloc()/idr_replace() and idr_remove(). These races are causing\nmultiple memcgs to acquire the same ID and then offlining of one of them\nwould cleanup list_lrus on the system for all of them. Later access from\nother memcgs to the list_lru cause crashes due to missing list_lru_one.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43892', 'https://git.kernel.org/linus/9972605a238339b85bd16b084eed5f18414d22db (6.11-rc3)', 'https://git.kernel.org/stable/c/37a060b64ae83b76600d187d76591ce488ab836b', 'https://git.kernel.org/stable/c/51c0b1bb7541f8893ec1accba59eb04361a70946', 'https://git.kernel.org/stable/c/56fd70f4aa8b82199dbe7e99366b1fd7a04d86fb', 'https://git.kernel.org/stable/c/912736a0435ef40e6a4ae78197ccb5553cb80b05', 'https://git.kernel.org/stable/c/9972605a238339b85bd16b084eed5f18414d22db', 'https://git.kernel.org/stable/c/e6cc9ff2ac0b5df9f25eb790934c3104f6710278', 'https://lore.kernel.org/linux-cve-announce/2024082604-CVE-2024-43892-584a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43892', 'https://www.cve.org/CVERecord?id=CVE-2024-43892'], 'PublishedDate': '2024-08-26T11:15:04.157Z', 'LastModifiedDate': '2024-09-12T12:15:49.593Z'}, {'VulnerabilityID': 'CVE-2024-43893', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43893', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: core: check uartclk for zero to avoid divide by zero', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: check uartclk for zero to avoid divide by zero\n\nCalling ioctl TIOCSSERIAL with an invalid baud_base can\nresult in uartclk being zero, which will result in a\ndivide by zero error in uart_get_divisor(). The check for\nuartclk being zero in uart_set_info() needs to be done\nbefore other settings are made as subsequent calls to\nioctl TIOCSSERIAL for the same port would be impacted if\nthe uartclk check was done where uartclk gets set.\n\nOops: divide error: 0000 PREEMPT SMP KASAN PTI\nRIP: 0010:uart_get_divisor (drivers/tty/serial/serial_core.c:580)\nCall Trace:\n \nserial8250_get_divisor (drivers/tty/serial/8250/8250_port.c:2576\n drivers/tty/serial/8250/8250_port.c:2589)\nserial8250_do_set_termios (drivers/tty/serial/8250/8250_port.c:502\n drivers/tty/serial/8250/8250_port.c:2741)\nserial8250_set_termios (drivers/tty/serial/8250/8250_port.c:2862)\nuart_change_line_settings (./include/linux/spinlock.h:376\n ./include/linux/serial_core.h:608 drivers/tty/serial/serial_core.c:222)\nuart_port_startup (drivers/tty/serial/serial_core.c:342)\nuart_startup (drivers/tty/serial/serial_core.c:368)\nuart_set_info (drivers/tty/serial/serial_core.c:1034)\nuart_set_info_user (drivers/tty/serial/serial_core.c:1059)\ntty_set_serial (drivers/tty/tty_io.c:2637)\ntty_ioctl (drivers/tty/tty_io.c:2647 drivers/tty/tty_io.c:2791)\n__x64_sys_ioctl (fs/ioctl.c:52 fs/ioctl.c:907\n fs/ioctl.c:893 fs/ioctl.c:893)\ndo_syscall_64 (arch/x86/entry/common.c:52\n (discriminator 1) arch/x86/entry/common.c:83 (discriminator 1))\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nRule: add', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43893', 'https://git.kernel.org/linus/6eabce6608d6f3440f4c03aa3d3ef50a47a3d193 (6.11-rc3)', 'https://git.kernel.org/stable/c/3bbd90fca824e6fd61fb20f6dd2b0fa5f8b14bba', 'https://git.kernel.org/stable/c/52b138f1021113e593ee6ad258ce08fe90693a9e', 'https://git.kernel.org/stable/c/55b2a5d331a6ceb1c4372945fdb77181265ba24f', 'https://git.kernel.org/stable/c/68dc02f319b9ee54dc23caba742a5c754d1cccc8', 'https://git.kernel.org/stable/c/6eabce6608d6f3440f4c03aa3d3ef50a47a3d193', 'https://git.kernel.org/stable/c/9196e42a3b8eeff1707e6ef769112b4b6096be49', 'https://git.kernel.org/stable/c/e13ba3fe5ee070f8a9dab60029d52b1f61da5051', 'https://git.kernel.org/stable/c/e3ad503876283ac3fcca922a1bf243ef9eb0b0e2', 'https://linux.oracle.com/cve/CVE-2024-43893.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082605-CVE-2024-43893-25dd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43893', 'https://www.cve.org/CVERecord?id=CVE-2024-43893'], 'PublishedDate': '2024-08-26T11:15:04.213Z', 'LastModifiedDate': '2024-09-10T18:13:21.92Z'}, {'VulnerabilityID': 'CVE-2024-43894', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43894', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/client: fix null pointer dereference in drm_client_modeset_probe', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/client: fix null pointer dereference in drm_client_modeset_probe\n\nIn drm_client_modeset_probe(), the return value of drm_mode_duplicate() is\nassigned to modeset->mode, which will lead to a possible NULL pointer\ndereference on failure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43894', 'https://git.kernel.org/linus/113fd6372a5bb3689aba8ef5b8a265ed1529a78f (6.11-rc3)', 'https://git.kernel.org/stable/c/113fd6372a5bb3689aba8ef5b8a265ed1529a78f', 'https://git.kernel.org/stable/c/24ddda932c43ffe156c7f3c568bed85131c63ae6', 'https://git.kernel.org/stable/c/5291d4f73452c91e8a11f71207617e3e234d418e', 'https://git.kernel.org/stable/c/612cae53e99ce32a58cb821b3b67199eb6e92dff', 'https://git.kernel.org/stable/c/c763dfe09425152b6bb0e348900a637c62c2ce52', 'https://git.kernel.org/stable/c/d64847c383100423aecb6ac5f18be5f4316d9d62', 'https://git.kernel.org/stable/c/d64fc94f7bb24fc2be0d6bd5df8df926da461a6d', 'https://linux.oracle.com/cve/CVE-2024-43894.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082607-CVE-2024-43894-aeee@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43894', 'https://www.cve.org/CVERecord?id=CVE-2024-43894'], 'PublishedDate': '2024-08-26T11:15:04.28Z', 'LastModifiedDate': '2024-09-10T18:09:41.23Z'}, {'VulnerabilityID': 'CVE-2024-43895', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43895', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip Recompute DSC Params if no Stream on Link', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip Recompute DSC Params if no Stream on Link\n\n[why]\nEncounter NULL pointer dereference uner mst + dsc setup.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 4 PID: 917 Comm: sway Not tainted 6.3.9-arch1-1 #1 124dc55df4f5272ccb409f39ef4872fc2b3376a2\n Hardware name: LENOVO 20NKS01Y00/20NKS01Y00, BIOS R12ET61W(1.31 ) 07/28/2022\n RIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\n Code: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\n RSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\n RAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\n RDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\n RBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\n R10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\n R13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\n FS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000010ddc6000 CR4: 00000000003506e0\n Call Trace:\n\n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? plist_add+0xbe/0x100\n ? exc_page_fault+0x7c/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n ? drm_dp_atomic_find_time_slots+0x28/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n compute_mst_dsc_configs_for_link+0x2ff/0xa40 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n ? fill_plane_buffer_attributes+0x419/0x510 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n compute_mst_dsc_configs_for_state+0x1e1/0x250 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n amdgpu_dm_atomic_check+0xecd/0x1190 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n drm_atomic_check_only+0x5c5/0xa40\n drm_mode_atomic_ioctl+0x76e/0xbc0\n\n[how]\ndsc recompute should be skipped if no mode change detected on the new\nrequest. If detected, keep checking whether the stream is already on\ncurrent state or not.\n\n(cherry picked from commit 8151a6c13111b465dbabe07c19f572f7cbd16fef)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43895', 'https://git.kernel.org/linus/50e376f1fe3bf571d0645ddf48ad37eb58323919 (6.11-rc3)', 'https://git.kernel.org/stable/c/282f0a482ee61d5e863512f3c4fcec90216c20d9', 'https://git.kernel.org/stable/c/50e376f1fe3bf571d0645ddf48ad37eb58323919', 'https://git.kernel.org/stable/c/5357141b4c2e2b332b6f11607ba8c5fbc2669a10', 'https://git.kernel.org/stable/c/70275bb960c71d313254473d38c14e7101cee5ad', 'https://git.kernel.org/stable/c/718d83f66fb07b2cab89a1fc984613a00e3db18f', 'https://lore.kernel.org/linux-cve-announce/2024082608-CVE-2024-43895-d3c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43895', 'https://www.cve.org/CVERecord?id=CVE-2024-43895'], 'PublishedDate': '2024-08-26T11:15:04.333Z', 'LastModifiedDate': '2024-10-10T12:15:04.35Z'}, {'VulnerabilityID': 'CVE-2024-43898', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43898', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: sanity check for NULL pointer after ext4_force_shutdown', 'Description': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43898', 'https://git.kernel.org/linus/83f4414b8f84249d538905825b088ff3ae555652 (6.11-rc1)', 'https://git.kernel.org/stable/c/3f6bbe6e07e5239294ecc3d2efa70d1f98aed52e', 'https://git.kernel.org/stable/c/83f4414b8f84249d538905825b088ff3ae555652', 'https://git.kernel.org/stable/c/f619876ccbfd329ae785fe5d3289b9dcd6eb5901', 'https://lore.kernel.org/linux-cve-announce/2024082613-CVE-2024-43898-52c2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43898', 'https://www.cve.org/CVERecord?id=CVE-2024-43898'], 'PublishedDate': '2024-08-26T11:15:04.493Z', 'LastModifiedDate': '2024-09-10T08:15:02.96Z'}, {'VulnerabilityID': 'CVE-2024-43899', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43899', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix null pointer deref in dcn20_resource.c', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null pointer deref in dcn20_resource.c\n\nFixes a hang thats triggered when MPV is run on a DCN401 dGPU:\n\nmpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all\n\nand then enabling fullscreen playback (double click on the video)\n\nThe following calltrace will be seen:\n\n[ 181.843989] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 181.843997] #PF: supervisor instruction fetch in kernel mode\n[ 181.844003] #PF: error_code(0x0010) - not-present page\n[ 181.844009] PGD 0 P4D 0\n[ 181.844020] Oops: 0010 [#1] PREEMPT SMP NOPTI\n[ 181.844028] CPU: 6 PID: 1892 Comm: gnome-shell Tainted: G W OE 6.5.0-41-generic #41~22.04.2-Ubuntu\n[ 181.844038] Hardware name: System manufacturer System Product Name/CROSSHAIR VI HERO, BIOS 6302 10/23/2018\n[ 181.844044] RIP: 0010:0x0\n[ 181.844079] Code: Unable to access opcode bytes at 0xffffffffffffffd6.\n[ 181.844084] RSP: 0018:ffffb593c2b8f7b0 EFLAGS: 00010246\n[ 181.844093] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004\n[ 181.844099] RDX: ffffb593c2b8f804 RSI: ffffb593c2b8f7e0 RDI: ffff9e3c8e758400\n[ 181.844105] RBP: ffffb593c2b8f7b8 R08: ffffb593c2b8f9c8 R09: ffffb593c2b8f96c\n[ 181.844110] R10: 0000000000000000 R11: 0000000000000000 R12: ffffb593c2b8f9c8\n[ 181.844115] R13: 0000000000000001 R14: ffff9e3c88000000 R15: 0000000000000005\n[ 181.844121] FS: 00007c6e323bb5c0(0000) GS:ffff9e3f85f80000(0000) knlGS:0000000000000000\n[ 181.844128] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 181.844134] CR2: ffffffffffffffd6 CR3: 0000000140fbe000 CR4: 00000000003506e0\n[ 181.844141] Call Trace:\n[ 181.844146] \n[ 181.844153] ? show_regs+0x6d/0x80\n[ 181.844167] ? __die+0x24/0x80\n[ 181.844179] ? page_fault_oops+0x99/0x1b0\n[ 181.844192] ? do_user_addr_fault+0x31d/0x6b0\n[ 181.844204] ? exc_page_fault+0x83/0x1b0\n[ 181.844216] ? asm_exc_page_fault+0x27/0x30\n[ 181.844237] dcn20_get_dcc_compression_cap+0x23/0x30 [amdgpu]\n[ 181.845115] amdgpu_dm_plane_validate_dcc.constprop.0+0xe5/0x180 [amdgpu]\n[ 181.845985] amdgpu_dm_plane_fill_plane_buffer_attributes+0x300/0x580 [amdgpu]\n[ 181.846848] fill_dc_plane_info_and_addr+0x258/0x350 [amdgpu]\n[ 181.847734] fill_dc_plane_attributes+0x162/0x350 [amdgpu]\n[ 181.848748] dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[ 181.849791] ? dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[ 181.850840] amdgpu_dm_atomic_check+0xdfe/0x1760 [amdgpu]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43899', 'https://git.kernel.org/linus/ecbf60782662f0a388493685b85a645a0ba1613c (6.11-rc1)', 'https://git.kernel.org/stable/c/974fccd61758599a9716c4b909d9226749efe37e', 'https://git.kernel.org/stable/c/ecbf60782662f0a388493685b85a645a0ba1613c', 'https://lore.kernel.org/linux-cve-announce/2024082614-CVE-2024-43899-2339@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43899', 'https://www.cve.org/CVERecord?id=CVE-2024-43899'], 'PublishedDate': '2024-08-26T11:15:04.557Z', 'LastModifiedDate': '2024-08-27T14:38:19.74Z'}, {'VulnerabilityID': 'CVE-2024-43900', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43900', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: xc2028: avoid use-after-free in load_firmware_cb()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: xc2028: avoid use-after-free in load_firmware_cb()\n\nsyzkaller reported use-after-free in load_firmware_cb() [1].\nThe reason is because the module allocated a struct tuner in tuner_probe(),\nand then the module initialization failed, the struct tuner was released.\nA worker which created during module initialization accesses this struct\ntuner later, it caused use-after-free.\n\nThe process is as follows:\n\ntask-6504 worker_thread\ntuner_probe <= alloc dvb_frontend [2]\n...\nrequest_firmware_nowait <= create a worker\n...\ntuner_remove <= free dvb_frontend\n...\n request_firmware_work_func <= the firmware is ready\n load_firmware_cb <= but now the dvb_frontend has been freed\n\nTo fix the issue, check the dvd_frontend in load_firmware_cb(), if it is\nnull, report a warning and just return.\n\n[1]:\n ==================================================================\n BUG: KASAN: use-after-free in load_firmware_cb+0x1310/0x17a0\n Read of size 8 at addr ffff8000d7ca2308 by task kworker/2:3/6504\n\n Call trace:\n load_firmware_cb+0x1310/0x17a0\n request_firmware_work_func+0x128/0x220\n process_one_work+0x770/0x1824\n worker_thread+0x488/0xea0\n kthread+0x300/0x430\n ret_from_fork+0x10/0x20\n\n Allocated by task 6504:\n kzalloc\n tuner_probe+0xb0/0x1430\n i2c_device_probe+0x92c/0xaf0\n really_probe+0x678/0xcd0\n driver_probe_device+0x280/0x370\n __device_attach_driver+0x220/0x330\n bus_for_each_drv+0x134/0x1c0\n __device_attach+0x1f4/0x410\n device_initial_probe+0x20/0x30\n bus_probe_device+0x184/0x200\n device_add+0x924/0x12c0\n device_register+0x24/0x30\n i2c_new_device+0x4e0/0xc44\n v4l2_i2c_new_subdev_board+0xbc/0x290\n v4l2_i2c_new_subdev+0xc8/0x104\n em28xx_v4l2_init+0x1dd0/0x3770\n\n Freed by task 6504:\n kfree+0x238/0x4e4\n tuner_remove+0x144/0x1c0\n i2c_device_remove+0xc8/0x290\n __device_release_driver+0x314/0x5fc\n device_release_driver+0x30/0x44\n bus_remove_device+0x244/0x490\n device_del+0x350/0x900\n device_unregister+0x28/0xd0\n i2c_unregister_device+0x174/0x1d0\n v4l2_device_unregister+0x224/0x380\n em28xx_v4l2_init+0x1d90/0x3770\n\n The buggy address belongs to the object at ffff8000d7ca2000\n which belongs to the cache kmalloc-2k of size 2048\n The buggy address is located 776 bytes inside of\n 2048-byte region [ffff8000d7ca2000, ffff8000d7ca2800)\n The buggy address belongs to the page:\n page:ffff7fe00035f280 count:1 mapcount:0 mapping:ffff8000c001f000 index:0x0\n flags: 0x7ff800000000100(slab)\n raw: 07ff800000000100 ffff7fe00049d880 0000000300000003 ffff8000c001f000\n raw: 0000000000000000 0000000080100010 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8000d7ca2200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8000d7ca2280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8000d7ca2300: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8000d7ca2380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8000d7ca2400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\n[2]\n Actually, it is allocated for struct tuner, and dvb_frontend is inside.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43900', 'https://git.kernel.org/linus/68594cec291ff9523b9feb3f43fd853dcddd1f60 (6.11-rc1)', 'https://git.kernel.org/stable/c/208deb6d8c3cb8c3acb1f41eb31cf68ea08726d5', 'https://git.kernel.org/stable/c/68594cec291ff9523b9feb3f43fd853dcddd1f60', 'https://git.kernel.org/stable/c/850304152d367f104d21c77cfbcc05806504218b', 'https://git.kernel.org/stable/c/ef517bdfc01818419f7bd426969a0c86b14f3e0e', 'https://lore.kernel.org/linux-cve-announce/2024082616-CVE-2024-43900-029c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43900', 'https://www.cve.org/CVERecord?id=CVE-2024-43900'], 'PublishedDate': '2024-08-26T11:15:04.613Z', 'LastModifiedDate': '2024-08-27T14:38:32.967Z'}, {'VulnerabilityID': 'CVE-2024-43902', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43902', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null checker before passing variables', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null checker before passing variables\n\nChecks null pointer before passing variables to functions.\n\nThis fixes 3 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43902', 'https://git.kernel.org/linus/8092aa3ab8f7b737a34b71f91492c676a843043a (6.11-rc1)', 'https://git.kernel.org/stable/c/1686675405d07f35eae7ff3d13a530034b899df2', 'https://git.kernel.org/stable/c/4cc2a94d96caeb3c975acdae7351c2f997c32175', 'https://git.kernel.org/stable/c/8092aa3ab8f7b737a34b71f91492c676a843043a', 'https://git.kernel.org/stable/c/83c7f509ef087041604e9572938f82e18b724c9d', 'https://git.kernel.org/stable/c/d0b8b23b9c2ebec693a36fea518d8f13493ad655', 'https://lore.kernel.org/linux-cve-announce/2024082618-CVE-2024-43902-eb6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43902', 'https://www.cve.org/CVERecord?id=CVE-2024-43902'], 'PublishedDate': '2024-08-26T11:15:04.733Z', 'LastModifiedDate': '2024-08-27T14:38:51.73Z'}, {'VulnerabilityID': 'CVE-2024-43903', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43903', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update\n\nThis commit adds a null check for the 'afb' variable in the\namdgpu_dm_plane_handle_cursor_update function. Previously, 'afb' was\nassumed to be null, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed 'afb' could be null (see line 1252)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43903', 'https://git.kernel.org/linus/38e6f715b02b572f74677eb2f29d3b4bc6f1ddff (6.11-rc1)', 'https://git.kernel.org/stable/c/31a679a880102dee6e10985a7b1789af8dc328cc', 'https://git.kernel.org/stable/c/38e6f715b02b572f74677eb2f29d3b4bc6f1ddff', 'https://git.kernel.org/stable/c/94220b35aeba2b68da81deeefbb784d94eeb5c04', 'https://git.kernel.org/stable/c/ce5d090af683137cb779ed7e3683839f9c778b35', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-43903-3644@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43903', 'https://www.cve.org/CVERecord?id=CVE-2024-43903'], 'PublishedDate': '2024-08-26T11:15:04.793Z', 'LastModifiedDate': '2024-08-27T13:39:48.683Z'}, {'VulnerabilityID': 'CVE-2024-43904', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43904', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing\n\nThis commit adds null checks for the 'stream' and 'plane' variables in\nthe dcn30_apply_idle_power_optimizations function. These variables were\npreviously assumed to be null at line 922, but they were used later in\nthe code without checking if they were null. This could potentially lead\nto a null pointer dereference, which would cause a crash.\n\nThe null checks ensure that 'stream' and 'plane' are not null before\nthey are used, preventing potential crashes.\n\nFixes the below static smatch checker:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:938 dcn30_apply_idle_power_optimizations() error: we previously assumed 'stream' could be null (see line 922)\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:940 dcn30_apply_idle_power_optimizations() error: we previously assumed 'plane' could be null (see line 922)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43904', 'https://git.kernel.org/linus/15c2990e0f0108b9c3752d7072a97d45d4283aea (6.11-rc1)', 'https://git.kernel.org/stable/c/15c2990e0f0108b9c3752d7072a97d45d4283aea', 'https://git.kernel.org/stable/c/16a8a2a839d19c4cf7253642b493ffb8eee1d857', 'https://lore.kernel.org/linux-cve-announce/2024082621-CVE-2024-43904-63a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43904', 'https://www.cve.org/CVERecord?id=CVE-2024-43904'], 'PublishedDate': '2024-08-26T11:15:04.847Z', 'LastModifiedDate': '2024-08-27T13:40:50.577Z'}, {'VulnerabilityID': 'CVE-2024-43905', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43905', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: Fix the null pointer dereference for vega10_hwmgr', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Fix the null pointer dereference for vega10_hwmgr\n\nCheck return value and conduct null pointer handling to avoid null pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43905', 'https://git.kernel.org/linus/50151b7f1c79a09117837eb95b76c2de76841dab (6.11-rc1)', 'https://git.kernel.org/stable/c/0fa11f9df96217c2785b040629ff1a16900fb51c', 'https://git.kernel.org/stable/c/2ac9deb7e087f0b461c3559d9eaa6b9cf19d3fa8', 'https://git.kernel.org/stable/c/2e538944996d0dd497faf8ee81f8bfcd3aca7d80', 'https://git.kernel.org/stable/c/50151b7f1c79a09117837eb95b76c2de76841dab', 'https://git.kernel.org/stable/c/69a441473fec2fc2aa2cf56122d6c42c4266a239', 'https://git.kernel.org/stable/c/c2629daf218a325f4d69754452cd42fe8451c15b', 'https://lore.kernel.org/linux-cve-announce/2024082623-CVE-2024-43905-008f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43905', 'https://www.cve.org/CVERecord?id=CVE-2024-43905'], 'PublishedDate': '2024-08-26T11:15:04.897Z', 'LastModifiedDate': '2024-09-12T12:15:51.26Z'}, {'VulnerabilityID': 'CVE-2024-43906', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43906', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/admgpu: fix dereferencing null pointer context', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/admgpu: fix dereferencing null pointer context\n\nWhen user space sets an invalid ta type, the pointer context will be empty.\nSo it need to check the pointer context before using it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43906', 'https://git.kernel.org/linus/030ffd4d43b433bc6671d9ec34fc12c59220b95d (6.11-rc1)', 'https://git.kernel.org/stable/c/030ffd4d43b433bc6671d9ec34fc12c59220b95d', 'https://git.kernel.org/stable/c/4fd52f7c2c11d330571c6bde06e5ea508ec25c9d', 'https://git.kernel.org/stable/c/641dac64178ccdb9e45c92b67120316896294d05', 'https://lore.kernel.org/linux-cve-announce/2024082624-CVE-2024-43906-27ab@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43906', 'https://www.cve.org/CVERecord?id=CVE-2024-43906'], 'PublishedDate': '2024-08-26T11:15:04.947Z', 'LastModifiedDate': '2024-08-27T13:41:30.093Z'}, {'VulnerabilityID': 'CVE-2024-43907', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43907', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/pm: Fix the null pointer dereference in apply_state_adjust_rules', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm: Fix the null pointer dereference in apply_state_adjust_rules\n\nCheck the pointer value to fix potential null pointer\ndereference', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43907', 'https://git.kernel.org/linus/d19fb10085a49b77578314f69fff21562f7cd054 (6.11-rc1)', 'https://git.kernel.org/stable/c/0c065e50445aea2e0a1815f12e97ee49e02cbaac', 'https://git.kernel.org/stable/c/13937a40aae4efe64592ba48c057ac3c72f7fe82', 'https://git.kernel.org/stable/c/3a01bf2ca9f860fdc88c358567b8fa3033efcf30', 'https://git.kernel.org/stable/c/c1749313f35b98e2e655479f037db37f19756622', 'https://git.kernel.org/stable/c/d19fb10085a49b77578314f69fff21562f7cd054', 'https://git.kernel.org/stable/c/e04d18c29954441aa1054af649f957ffad90a201', 'https://lore.kernel.org/linux-cve-announce/2024082626-CVE-2024-43907-91a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43907', 'https://www.cve.org/CVERecord?id=CVE-2024-43907'], 'PublishedDate': '2024-08-26T11:15:05Z', 'LastModifiedDate': '2024-08-27T13:41:40.497Z'}, {'VulnerabilityID': 'CVE-2024-43908', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43908', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix the null pointer dereference to ras_manager', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the null pointer dereference to ras_manager\n\nCheck ras_manager before using it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43908', 'https://git.kernel.org/linus/4c11d30c95576937c6c35e6f29884761f2dddb43 (6.11-rc1)', 'https://git.kernel.org/stable/c/033187a70ba9743c73a810a006816e5553d1e7d4', 'https://git.kernel.org/stable/c/48cada0ac79e4775236d642e9ec5998a7c7fb7a4', 'https://git.kernel.org/stable/c/4c11d30c95576937c6c35e6f29884761f2dddb43', 'https://git.kernel.org/stable/c/56e848034ccabe44e8f22ffcf49db771c17b0d0a', 'https://git.kernel.org/stable/c/b89616333979114bb0da5fa40fb6e4a2f5294ca2', 'https://git.kernel.org/stable/c/d81c1eeb333d84b3012a91c0500189dc1d71e46c', 'https://git.kernel.org/stable/c/ff5c4eb71ee8951c789b079f6e948f86708b04ed', 'https://linux.oracle.com/cve/CVE-2024-43908.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082627-CVE-2024-43908-4406@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43908', 'https://www.cve.org/CVERecord?id=CVE-2024-43908'], 'PublishedDate': '2024-08-26T11:15:05.057Z', 'LastModifiedDate': '2024-08-27T13:41:55.26Z'}, {'VulnerabilityID': 'CVE-2024-43909', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43909', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/pm: Fix the null pointer dereference for smu7', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm: Fix the null pointer dereference for smu7\n\noptimize the code to avoid pass a null pointer (hwmgr->backend)\nto function smu7_update_edc_leakage_table.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43909', 'https://git.kernel.org/linus/c02c1960c93eede587576625a1221205a68a904f (6.11-rc1)', 'https://git.kernel.org/stable/c/09544cd95c688d3041328a4253bd7514972399bb', 'https://git.kernel.org/stable/c/1b8aa82b80bd947b68a8ab051d960a0c7935e22d', 'https://git.kernel.org/stable/c/37b9df457cbcf095963d18f17d6cb7dfa0a03fce', 'https://git.kernel.org/stable/c/7f56f050f02c27ed89cce1ea0c04b34abce32751', 'https://git.kernel.org/stable/c/c02c1960c93eede587576625a1221205a68a904f', 'https://lore.kernel.org/linux-cve-announce/2024082628-CVE-2024-43909-acb8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43909', 'https://www.cve.org/CVERecord?id=CVE-2024-43909'], 'PublishedDate': '2024-08-26T11:15:05.117Z', 'LastModifiedDate': '2024-08-27T13:41:48.467Z'}, {'VulnerabilityID': 'CVE-2024-43910', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43910', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses\n\nCurrently, it's possible to pass in a modified CONST_PTR_TO_DYNPTR to\na global function as an argument. The adverse effects of this is that\nBPF helpers can continue to make use of this modified\nCONST_PTR_TO_DYNPTR from within the context of the global function,\nwhich can unintentionally result in out-of-bounds memory accesses and\ntherefore compromise overall system stability i.e.\n\n[ 244.157771] BUG: KASAN: slab-out-of-bounds in bpf_dynptr_data+0x137/0x140\n[ 244.161345] Read of size 8 at addr ffff88810914be68 by task test_progs/302\n[ 244.167151] CPU: 0 PID: 302 Comm: test_progs Tainted: G O E 6.10.0-rc3-00131-g66b586715063 #533\n[ 244.174318] Call Trace:\n[ 244.175787] \n[ 244.177356] dump_stack_lvl+0x66/0xa0\n[ 244.179531] print_report+0xce/0x670\n[ 244.182314] ? __virt_addr_valid+0x200/0x3e0\n[ 244.184908] kasan_report+0xd7/0x110\n[ 244.187408] ? bpf_dynptr_data+0x137/0x140\n[ 244.189714] ? bpf_dynptr_data+0x137/0x140\n[ 244.192020] bpf_dynptr_data+0x137/0x140\n[ 244.194264] bpf_prog_b02a02fdd2bdc5fa_global_call_bpf_dynptr_data+0x22/0x26\n[ 244.198044] bpf_prog_b0fe7b9d7dc3abde_callback_adjust_bpf_dynptr_reg_off+0x1f/0x23\n[ 244.202136] bpf_user_ringbuf_drain+0x2c7/0x570\n[ 244.204744] ? 0xffffffffc0009e58\n[ 244.206593] ? __pfx_bpf_user_ringbuf_drain+0x10/0x10\n[ 244.209795] bpf_prog_33ab33f6a804ba2d_user_ringbuf_callback_const_ptr_to_dynptr_reg_off+0x47/0x4b\n[ 244.215922] bpf_trampoline_6442502480+0x43/0xe3\n[ 244.218691] __x64_sys_prlimit64+0x9/0xf0\n[ 244.220912] do_syscall_64+0xc1/0x1d0\n[ 244.223043] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 244.226458] RIP: 0033:0x7ffa3eb8f059\n[ 244.228582] Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8f 1d 0d 00 f7 d8 64 89 01 48\n[ 244.241307] RSP: 002b:00007ffa3e9c6eb8 EFLAGS: 00000206 ORIG_RAX: 000000000000012e\n[ 244.246474] RAX: ffffffffffffffda RBX: 00007ffa3e9c7cdc RCX: 00007ffa3eb8f059\n[ 244.250478] RDX: 00007ffa3eb162b4 RSI: 0000000000000000 RDI: 00007ffa3e9c7fb0\n[ 244.255396] RBP: 00007ffa3e9c6ed0 R08: 00007ffa3e9c76c0 R09: 0000000000000000\n[ 244.260195] R10: 0000000000000000 R11: 0000000000000206 R12: ffffffffffffff80\n[ 244.264201] R13: 000000000000001c R14: 00007ffc5d6b4260 R15: 00007ffa3e1c7000\n[ 244.268303] \n\nAdd a check_func_arg_reg_off() to the path in which the BPF verifier\nverifies the arguments of global function arguments, specifically\nthose which take an argument of type ARG_PTR_TO_DYNPTR |\nMEM_RDONLY. Also, process_dynptr_func() doesn't appear to perform any\nexplicit and strict type matching on the supplied register type, so\nlet's also enforce that a register either type PTR_TO_STACK or\nCONST_PTR_TO_DYNPTR is by the caller.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43910', 'https://git.kernel.org/linus/ec2b9a5e11e51fea1bb04c1e7e471952e887e874 (6.11-rc1)', 'https://git.kernel.org/stable/c/13663a7c644bf1dedaf461d07252db5d76c8759a', 'https://git.kernel.org/stable/c/ec2b9a5e11e51fea1bb04c1e7e471952e887e874', 'https://lore.kernel.org/linux-cve-announce/2024082630-CVE-2024-43910-c6ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43910', 'https://www.cve.org/CVERecord?id=CVE-2024-43910'], 'PublishedDate': '2024-08-26T11:15:05.177Z', 'LastModifiedDate': '2024-09-05T18:30:23.437Z'}, {'VulnerabilityID': 'CVE-2024-43911', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43911', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mac80211: fix NULL dereference at band check in starting tx ba session', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix NULL dereference at band check in starting tx ba session\n\nIn MLD connection, link_data/link_conf are dynamically allocated. They\ndon't point to vif->bss_conf. So, there will be no chanreq assigned to\nvif->bss_conf and then the chan will be NULL. Tweak the code to check\nht_supported/vht_supported/has_he/has_eht on sta deflink.\n\nCrash log (with rtw89 version under MLO development):\n[ 9890.526087] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 9890.526102] #PF: supervisor read access in kernel mode\n[ 9890.526105] #PF: error_code(0x0000) - not-present page\n[ 9890.526109] PGD 0 P4D 0\n[ 9890.526114] Oops: 0000 [#1] PREEMPT SMP PTI\n[ 9890.526119] CPU: 2 PID: 6367 Comm: kworker/u16:2 Kdump: loaded Tainted: G OE 6.9.0 #1\n[ 9890.526123] Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB3WW (2.73 ) 11/28/2018\n[ 9890.526126] Workqueue: phy2 rtw89_core_ba_work [rtw89_core]\n[ 9890.526203] RIP: 0010:ieee80211_start_tx_ba_session (net/mac80211/agg-tx.c:618 (discriminator 1)) mac80211\n[ 9890.526279] Code: f7 e8 d5 93 3e ea 48 83 c4 28 89 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 49 8b 84 24 e0 f1 ff ff 48 8b 80 90 1b 00 00 <83> 38 03 0f 84 37 fe ff ff bb ea ff ff ff eb cc 49 8b 84 24 10 f3\nAll code\n========\n 0:\tf7 e8 \timul %eax\n 2:\td5 \t(bad)\n 3:\t93 \txchg %eax,%ebx\n 4:\t3e ea \tds (bad)\n 6:\t48 83 c4 28 \tadd $0x28,%rsp\n a:\t89 d8 \tmov %ebx,%eax\n c:\t5b \tpop %rbx\n d:\t41 5c \tpop %r12\n f:\t41 5d \tpop %r13\n 11:\t41 5e \tpop %r14\n 13:\t41 5f \tpop %r15\n 15:\t5d \tpop %rbp\n 16:\tc3 \tretq\n 17:\tcc \tint3\n 18:\tcc \tint3\n 19:\tcc \tint3\n 1a:\tcc \tint3\n 1b:\t49 8b 84 24 e0 f1 ff \tmov -0xe20(%r12),%rax\n 22:\tff\n 23:\t48 8b 80 90 1b 00 00 \tmov 0x1b90(%rax),%rax\n 2a:*\t83 38 03 \tcmpl $0x3,(%rax)\t\t<-- trapping instruction\n 2d:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe6a\n 33:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n 38:\teb cc \tjmp 0x6\n 3a:\t49 \trex.WB\n 3b:\t8b \t.byte 0x8b\n 3c:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 3f:\tf3 \trepz\n\nCode starting with the faulting instruction\n===========================================\n 0:\t83 38 03 \tcmpl $0x3,(%rax)\n 3:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe40\n 9:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n e:\teb cc \tjmp 0xffffffffffffffdc\n 10:\t49 \trex.WB\n 11:\t8b \t.byte 0x8b\n 12:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 15:\tf3 \trepz\n[ 9890.526285] RSP: 0018:ffffb8db09013d68 EFLAGS: 00010246\n[ 9890.526291] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff9308e0d656c8\n[ 9890.526295] RDX: 0000000000000000 RSI: ffffffffab99460b RDI: ffffffffab9a7685\n[ 9890.526300] RBP: ffffb8db09013db8 R08: 0000000000000000 R09: 0000000000000873\n[ 9890.526304] R10: ffff9308e0d64800 R11: 0000000000000002 R12: ffff9308e5ff6e70\n[ 9890.526308] R13: ffff930952500e20 R14: ffff9309192a8c00 R15: 0000000000000000\n[ 9890.526313] FS: 0000000000000000(0000) GS:ffff930b4e700000(0000) knlGS:0000000000000000\n[ 9890.526316] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9890.526318] CR2: 0000000000000000 CR3: 0000000391c58005 CR4: 00000000001706f0\n[ 9890.526321] Call Trace:\n[ 9890.526324] \n[ 9890.526327] ? show_regs (arch/x86/kernel/dumpstack.c:479)\n[ 9890.526335] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n[ 9890.526340] ? page_fault_oops (arch/x86/mm/fault.c:713)\n[ 9890.526347] ? search_module_extables (kernel/module/main.c:3256 (discriminator\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43911', 'https://git.kernel.org/linus/021d53a3d87eeb9dbba524ac515651242a2a7e3b (6.11-rc1)', 'https://git.kernel.org/stable/c/021d53a3d87eeb9dbba524ac515651242a2a7e3b', 'https://git.kernel.org/stable/c/a5594c1e03b0df3908b1e1202a1ba34422eed0f6', 'https://lore.kernel.org/linux-cve-announce/2024082631-CVE-2024-43911-96bb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43911', 'https://www.cve.org/CVERecord?id=CVE-2024-43911'], 'PublishedDate': '2024-08-26T11:15:05.227Z', 'LastModifiedDate': '2024-08-27T16:08:52.493Z'}, {'VulnerabilityID': 'CVE-2024-43912', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43912', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: nl80211: disallow setting special AP channel widths', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: disallow setting special AP channel widths\n\nSetting the AP channel width is meant for use with the normal\n20/40/... MHz channel width progression, and switching around\nin S1G or narrow channels isn't supported. Disallow that.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'V3Score': 4.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43912', 'https://git.kernel.org/linus/23daf1b4c91db9b26f8425cc7039cf96d22ccbfe (6.11-rc1)', 'https://git.kernel.org/stable/c/23daf1b4c91db9b26f8425cc7039cf96d22ccbfe', 'https://git.kernel.org/stable/c/3d42f2125f6c89e1e71c87b9f23412afddbba45e', 'https://git.kernel.org/stable/c/ac3bf6e47fd8da9bfe8027e1acfe0282a91584fc', 'https://git.kernel.org/stable/c/c6ea738e3feb407a3283197d9a25d0788f4f3cee', 'https://lore.kernel.org/linux-cve-announce/2024082632-CVE-2024-43912-801f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43912', 'https://www.cve.org/CVERecord?id=CVE-2024-43912'], 'PublishedDate': '2024-08-26T11:15:05.28Z', 'LastModifiedDate': '2024-09-05T18:19:17.067Z'}, {'VulnerabilityID': 'CVE-2024-43913', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43913', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: apple: fix device reference counting', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: apple: fix device reference counting\n\nDrivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.\nSplit the allocation side out to make the error handling boundary easier\nto navigate. The apple driver had been doing this wrong, leaking the\ncontroller device memory on a tagset failure.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43913', 'https://git.kernel.org/linus/b9ecbfa45516182cd062fecd286db7907ba84210 (6.11-rc1)', 'https://git.kernel.org/stable/c/b9ecbfa45516182cd062fecd286db7907ba84210', 'https://git.kernel.org/stable/c/d59c4d0eb6adc24c2201f153ccb7fd0a335b0d3d', 'https://lore.kernel.org/linux-cve-announce/2024082633-CVE-2024-43913-6ec7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43913', 'https://www.cve.org/CVERecord?id=CVE-2024-43913'], 'PublishedDate': '2024-08-26T11:15:05.33Z', 'LastModifiedDate': '2024-09-05T18:12:55.68Z'}, {'VulnerabilityID': 'CVE-2024-43914', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43914', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: md/raid5: avoid BUG_ON() while continue reshape after reassembling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid BUG_ON() while continue reshape after reassembling\n\nCurrently, mdadm support --revert-reshape to abort the reshape while\nreassembling, as the test 07revert-grow. However, following BUG_ON()\ncan be triggerred by the test:\n\nkernel BUG at drivers/md/raid5.c:6278!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nirq event stamp: 158985\nCPU: 6 PID: 891 Comm: md0_reshape Not tainted 6.9.0-03335-g7592a0b0049a #94\nRIP: 0010:reshape_request+0x3f1/0xe60\nCall Trace:\n \n raid5_sync_request+0x43d/0x550\n md_do_sync+0xb7a/0x2110\n md_thread+0x294/0x2b0\n kthread+0x147/0x1c0\n ret_from_fork+0x59/0x70\n ret_from_fork_asm+0x1a/0x30\n \n\nRoot cause is that --revert-reshape update the raid_disks from 5 to 4,\nwhile reshape position is still set, and after reassembling the array,\nreshape position will be read from super block, then during reshape the\nchecking of 'writepos' that is caculated by old reshape position will\nfail.\n\nFix this panic the easy way first, by converting the BUG_ON() to\nWARN_ON(), and stop the reshape if checkings fail.\n\nNoted that mdadm must fix --revert-shape as well, and probably md/raid\nshould enhance metadata validation as well, however this means\nreassemble will fail and there must be user tools to fix the wrong\nmetadata.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43914', 'https://git.kernel.org/linus/305a5170dc5cf3d395bb4c4e9239bca6d0b54b49 (6.11-rc1)', 'https://git.kernel.org/stable/c/2c92f8c1c456d556f15cbf51667b385026b2e6a0', 'https://git.kernel.org/stable/c/305a5170dc5cf3d395bb4c4e9239bca6d0b54b49', 'https://git.kernel.org/stable/c/3b33740c1750a39e046339ff9240e954f0156707', 'https://git.kernel.org/stable/c/4811d6e5d9f4090c3e0ff9890eb24077108046ab', 'https://git.kernel.org/stable/c/6b33c468d543f6a83de2d61f09fec74b27e19fd2', 'https://git.kernel.org/stable/c/775a9ba16c9ffe98fe54ebf14e55d5660f2bf600', 'https://git.kernel.org/stable/c/bf0ff69a42a3d2d46876d0514ecf13dffc516666', 'https://git.kernel.org/stable/c/c384dd4f1fb3b14a2fd199360701cc163ea88705', 'https://linux.oracle.com/cve/CVE-2024-43914.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082635-CVE-2024-43914-a664@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43914', 'https://www.cve.org/CVERecord?id=CVE-2024-43914'], 'PublishedDate': '2024-08-26T11:15:05.38Z', 'LastModifiedDate': '2024-09-05T18:03:49.997Z'}, {'VulnerabilityID': 'CVE-2024-44931', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44931', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gpio: prevent potential speculation leaks in gpio_device_get_desc()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: prevent potential speculation leaks in gpio_device_get_desc()\n\nUserspace may trigger a speculative read of an address outside the gpio\ndescriptor array.\nUsers can do that by calling gpio_ioctl() with an offset out of range.\nOffset is copied from user and then used as an array index to get\nthe gpio descriptor without sanitization in gpio_device_get_desc().\n\nThis change ensures that the offset is sanitized by using\narray_index_nospec() to mitigate any possibility of speculative\ninformation leaks.\n\nThis bug was discovered and resolved using Coverity Static Analysis\nSecurity Testing (SAST) by Synopsys, Inc.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44931', 'https://git.kernel.org/linus/d795848ecce24a75dfd46481aee066ae6fe39775 (6.11-rc1)', 'https://git.kernel.org/stable/c/1b955f786a4bcde8c0ccb2b7d519def2acb6f3cc', 'https://git.kernel.org/stable/c/672c19165fc96dfad531a5458e0b3cdab414aae4', 'https://git.kernel.org/stable/c/9d682e89c44bd5819b01f3fbb45a8e3681a4b6d0', 'https://git.kernel.org/stable/c/c65ab97efcd438cb4e9f299400f2ea55251f3a67', 'https://git.kernel.org/stable/c/d776c0486b03a5c4afca65b8ff44573592bf93bb', 'https://git.kernel.org/stable/c/d795848ecce24a75dfd46481aee066ae6fe39775', 'https://lore.kernel.org/linux-cve-announce/2024082636-CVE-2024-44931-8212@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44931', 'https://www.cve.org/CVERecord?id=CVE-2024-44931'], 'PublishedDate': '2024-08-26T11:15:05.447Z', 'LastModifiedDate': '2024-10-17T14:15:07.39Z'}, {'VulnerabilityID': 'CVE-2024-44932', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44932', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: idpf: fix UAFs when destroying the queues', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix UAFs when destroying the queues\n\nThe second tagged commit started sometimes (very rarely, but possible)\nthrowing WARNs from\nnet/core/page_pool.c:page_pool_disable_direct_recycling().\nTurned out idpf frees interrupt vectors with embedded NAPIs *before*\nfreeing the queues making page_pools' NAPI pointers lead to freed\nmemory before these pools are destroyed by libeth.\nIt's not clear whether there are other accesses to the freed vectors\nwhen destroying the queues, but anyway, we usually free queue/interrupt\nvectors only when the queues are destroyed and the NAPIs are guaranteed\nto not be referenced anywhere.\n\nInvert the allocation and freeing logic making queue/interrupt vectors\nbe allocated first and freed last. Vectors don't require queues to be\npresent, so this is safe. Additionally, this change allows to remove\nthat useless queue->q_vector pointer cleanup, as vectors are still\nvalid when freeing the queues (+ both are freed within one function,\nso it's not clear why nullify the pointers at all).", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44932', 'https://git.kernel.org/linus/290f1c033281c1a502a3cd1c53c3a549259c491f (6.11-rc3)', 'https://git.kernel.org/stable/c/290f1c033281c1a502a3cd1c53c3a549259c491f', 'https://git.kernel.org/stable/c/3cde714b0e77206ed1b5cf31f28c18ba9ae946fd', 'https://lore.kernel.org/linux-cve-announce/2024082638-CVE-2024-44932-2659@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44932', 'https://www.cve.org/CVERecord?id=CVE-2024-44932'], 'PublishedDate': '2024-08-26T11:15:05.5Z', 'LastModifiedDate': '2024-08-27T16:08:45.02Z'}, {'VulnerabilityID': 'CVE-2024-44934', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44934', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: bridge: mcast: wait for previous gc cycles when removing port', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: wait for previous gc cycles when removing port\n\nsyzbot hit a use-after-free[1] which is caused because the bridge doesn't\nmake sure that all previous garbage has been collected when removing a\nport. What happens is:\n CPU 1 CPU 2\n start gc cycle remove port\n acquire gc lock first\n wait for lock\n call br_multicasg_gc() directly\n acquire lock now but free port\n the port can be freed\n while grp timers still\n running\n\nMake sure all previous gc cycles have finished by using flush_work before\nfreeing the port.\n\n[1]\n BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699\n\n CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024\n Call Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n call_timer_fn+0x1a3/0x610 kernel/time/timer.c:1792\n expire_timers kernel/time/timer.c:1843 [inline]\n __run_timers+0x74b/0xaf0 kernel/time/timer.c:2417\n __run_timer_base kernel/time/timer.c:2428 [inline]\n __run_timer_base kernel/time/timer.c:2421 [inline]\n run_timer_base+0x111/0x190 kernel/time/timer.c:2437", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44934', 'https://git.kernel.org/linus/92c4ee25208d0f35dafc3213cdf355fbe449e078 (6.11-rc3)', 'https://git.kernel.org/stable/c/0d8b26e10e680c01522d7cc14abe04c3265a928f', 'https://git.kernel.org/stable/c/1e16828020c674b3be85f52685e8b80f9008f50f', 'https://git.kernel.org/stable/c/92c4ee25208d0f35dafc3213cdf355fbe449e078', 'https://git.kernel.org/stable/c/b2f794b168cf560682ff976b255aa6d29d14a658', 'https://git.kernel.org/stable/c/e3145ca904fa8dbfd1a5bf0187905bc117b0efce', 'https://lore.kernel.org/linux-cve-announce/2024082641-CVE-2024-44934-a7fe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44934', 'https://www.cve.org/CVERecord?id=CVE-2024-44934'], 'PublishedDate': '2024-08-26T11:15:05.593Z', 'LastModifiedDate': '2024-08-27T16:07:58.727Z'}, {'VulnerabilityID': 'CVE-2024-44935', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44935', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sctp: Fix null-ptr-deref in reuseport_add_sock().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Fix null-ptr-deref in reuseport_add_sock().\n\nsyzbot reported a null-ptr-deref while accessing sk2->sk_reuseport_cb in\nreuseport_add_sock(). [0]\n\nThe repro first creates a listener with SO_REUSEPORT. Then, it creates\nanother listener on the same port and concurrently closes the first\nlistener.\n\nThe second listen() calls reuseport_add_sock() with the first listener as\nsk2, where sk2->sk_reuseport_cb is not expected to be cleared concurrently,\nbut the close() does clear it by reuseport_detach_sock().\n\nThe problem is SCTP does not properly synchronise reuseport_alloc(),\nreuseport_add_sock(), and reuseport_detach_sock().\n\nThe caller of reuseport_alloc() and reuseport_{add,detach}_sock() must\nprovide synchronisation for sockets that are classified into the same\nreuseport group.\n\nOtherwise, such sockets form multiple identical reuseport groups, and\nall groups except one would be silently dead.\n\n 1. Two sockets call listen() concurrently\n 2. No socket in the same group found in sctp_ep_hashtable[]\n 3. Two sockets call reuseport_alloc() and form two reuseport groups\n 4. Only one group hit first in __sctp_rcv_lookup_endpoint() receives\n incoming packets\n\nAlso, the reported null-ptr-deref could occur.\n\nTCP/UDP guarantees that would not happen by holding the hash bucket lock.\n\nLet's apply the locking strategy to __sctp_hash_endpoint() and\n__sctp_unhash_endpoint().\n\n[0]:\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nCPU: 1 UID: 0 PID: 10230 Comm: syz-executor119 Not tainted 6.10.0-syzkaller-12585-g301927d2d2eb #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024\nRIP: 0010:reuseport_add_sock+0x27e/0x5e0 net/core/sock_reuseport.c:350\nCode: 00 0f b7 5d 00 bf 01 00 00 00 89 de e8 1b a4 ff f7 83 fb 01 0f 85 a3 01 00 00 e8 6d a0 ff f7 49 8d 7e 12 48 89 f8 48 c1 e8 03 <42> 0f b6 04 28 84 c0 0f 85 4b 02 00 00 41 0f b7 5e 12 49 8d 7e 14\nRSP: 0018:ffffc9000b947c98 EFLAGS: 00010202\nRAX: 0000000000000002 RBX: ffff8880252ddf98 RCX: ffff888079478000\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000012\nRBP: 0000000000000001 R08: ffffffff8993e18d R09: 1ffffffff1fef385\nR10: dffffc0000000000 R11: fffffbfff1fef386 R12: ffff8880252ddac0\nR13: dffffc0000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f24e45b96c0(0000) GS:ffff8880b9300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffcced5f7b8 CR3: 00000000241be000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __sctp_hash_endpoint net/sctp/input.c:762 [inline]\n sctp_hash_endpoint+0x52a/0x600 net/sctp/input.c:790\n sctp_listen_start net/sctp/socket.c:8570 [inline]\n sctp_inet_listen+0x767/0xa20 net/sctp/socket.c:8625\n __sys_listen_socket net/socket.c:1883 [inline]\n __sys_listen+0x1b7/0x230 net/socket.c:1894\n __do_sys_listen net/socket.c:1902 [inline]\n __se_sys_listen net/socket.c:1900 [inline]\n __x64_sys_listen+0x5a/0x70 net/socket.c:1900\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f24e46039b9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 91 1a 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f24e45b9228 EFLAGS: 00000246 ORIG_RAX: 0000000000000032\nRAX: ffffffffffffffda RBX: 00007f24e468e428 RCX: 00007f24e46039b9\nRDX: 00007f24e46039b9 RSI: 0000000000000003 RDI: 0000000000000004\nRBP: 00007f24e468e420 R08: 00007f24e45b96c0 R09: 00007f24e45b96c0\nR10: 00007f24e45b96c0 R11: 0000000000000246 R12: 00007f24e468e42c\nR13:\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44935', 'https://git.kernel.org/linus/9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18 (6.11-rc3)', 'https://git.kernel.org/stable/c/05e4a0fa248240efd99a539853e844f0f0a9e6a5', 'https://git.kernel.org/stable/c/1407be30fc17eff918a98e0a990c0e988f11dc84', 'https://git.kernel.org/stable/c/52319d9d2f522ed939af31af70f8c3a0f0f67e6c', 'https://git.kernel.org/stable/c/54b303d8f9702b8ab618c5032fae886b16356928', 'https://git.kernel.org/stable/c/9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18', 'https://git.kernel.org/stable/c/c9b3fc4f157867e858734e31022ebee8a24f0de7', 'https://git.kernel.org/stable/c/e809a84c802377ef61525a298a1ec1728759b913', 'https://linux.oracle.com/cve/CVE-2024-44935.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082642-CVE-2024-44935-3452@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44935', 'https://www.cve.org/CVERecord?id=CVE-2024-44935'], 'PublishedDate': '2024-08-26T11:15:05.643Z', 'LastModifiedDate': '2024-08-27T16:09:01.633Z'}, {'VulnerabilityID': 'CVE-2024-44937', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44937', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: platform/x86: intel-vbtn: Protect ACPI notify handler against recursion', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: intel-vbtn: Protect ACPI notify handler against recursion\n\nSince commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on\nall CPUs") ACPI notify handlers like the intel-vbtn notify_handler() may\nrun on multiple CPU cores racing with themselves.\n\nThis race gets hit on Dell Venue 7140 tablets when undocking from\nthe keyboard, causing the handler to try and register priv->switches_dev\ntwice, as can be seen from the dev_info() message getting logged twice:\n\n[ 83.861800] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n[ 83.861858] input: Intel Virtual Switches as /devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\n[ 83.861865] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n\nAfter which things go seriously wrong:\n[ 83.861872] sysfs: cannot create duplicate filename \'/devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\'\n...\n[ 83.861967] kobject: kobject_add_internal failed for input17 with -EEXIST, don\'t try to register things with the same name in the same directory.\n[ 83.877338] BUG: kernel NULL pointer dereference, address: 0000000000000018\n...\n\nProtect intel-vbtn notify_handler() from racing with itself with a mutex\nto fix this.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44937', 'https://git.kernel.org/linus/e075c3b13a0a142dcd3151b25d29a24f31b7b640 (6.11-rc3)', 'https://git.kernel.org/stable/c/5c9618a3b6ea94cf7bdff7702aca8bf2d777d97b', 'https://git.kernel.org/stable/c/e075c3b13a0a142dcd3151b25d29a24f31b7b640', 'https://lore.kernel.org/linux-cve-announce/2024082645-CVE-2024-44937-5c1d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44937', 'https://www.cve.org/CVERecord?id=CVE-2024-44937'], 'PublishedDate': '2024-08-26T11:15:05.753Z', 'LastModifiedDate': '2024-08-27T16:10:11.423Z'}, {'VulnerabilityID': 'CVE-2024-44938', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44938', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: jfs: Fix shift-out-of-bounds in dbDiscardAG', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix shift-out-of-bounds in dbDiscardAG\n\nWhen searching for the next smaller log2 block, BLKSTOL2() returned 0,\ncausing shift exponent -1 to be negative.\n\nThis patch fixes the issue by exiting the loop directly when negative\nshift is found.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44938', 'https://git.kernel.org/linus/7063b80268e2593e58bee8a8d709c2f3ff93e2f2 (6.11-rc1)', 'https://git.kernel.org/stable/c/234e6ea0855cdb5673d54ecaf7dc5c78f3e84630', 'https://git.kernel.org/stable/c/7063b80268e2593e58bee8a8d709c2f3ff93e2f2', 'https://git.kernel.org/stable/c/bd04a149e3a29e7f71b7956ed41dba34e42d539e', 'https://git.kernel.org/stable/c/f650148b43949ca9e37e820804bb6026fff404f3', 'https://lore.kernel.org/linux-cve-announce/2024082616-CVE-2024-44938-fc08@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44938', 'https://www.cve.org/CVERecord?id=CVE-2024-44938'], 'PublishedDate': '2024-08-26T12:15:05.96Z', 'LastModifiedDate': '2024-09-12T14:05:44.31Z'}, {'VulnerabilityID': 'CVE-2024-44939', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44939', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: jfs: fix null ptr deref in dtInsertEntry', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix null ptr deref in dtInsertEntry\n\n[syzbot reported]\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nRIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713\n...\n[Analyze]\nIn dtInsertEntry(), when the pointer h has the same value as p, after writing\nname in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the\npreviously true judgment "p->header.flag & BT-LEAF" to change to no after writing\nthe name operation, this leads to entering an incorrect branch and accessing the\nuninitialized object ih when judging this condition for the second time.\n\n[Fix]\nAfter got the page, check freelist first, if freelist == 0 then exit dtInsert()\nand return -EINVAL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44939', 'https://git.kernel.org/linus/ce6dede912f064a855acf6f04a04cbb2c25b8c8c (6.11-rc1)', 'https://git.kernel.org/stable/c/53023ab11836ac56fd75f7a71ec1356e50920fa9', 'https://git.kernel.org/stable/c/6ea10dbb1e6c58384136e9adfd75f81951e423f6', 'https://git.kernel.org/stable/c/9c2ac38530d1a3ee558834dfa16c85a40fd0e702', 'https://git.kernel.org/stable/c/ce6dede912f064a855acf6f04a04cbb2c25b8c8c', 'https://lore.kernel.org/linux-cve-announce/2024082619-CVE-2024-44939-cf96@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44939', 'https://www.cve.org/CVERecord?id=CVE-2024-44939'], 'PublishedDate': '2024-08-26T12:15:06.007Z', 'LastModifiedDate': '2024-09-12T20:58:03.783Z'}, {'VulnerabilityID': 'CVE-2024-44940', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44940', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fou: remove warn in gue_gro_receive on unsupported protocol', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfou: remove warn in gue_gro_receive on unsupported protocol\n\nDrop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is\nnot known or does not have a GRO handler.\n\nSuch a packet is easily constructed. Syzbot generates them and sets\noff this warning.\n\nRemove the warning as it is expected and not actionable.\n\nThe warning was previously reduced from WARN_ON to WARN_ON_ONCE in\ncommit 270136613bf7 ("fou: Do WARN_ON_ONCE in gue_gro_receive for bad\nproto callbacks").', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44940', 'https://git.kernel.org/linus/dd89a81d850fa9a65f67b4527c0e420d15bf836c (6.11-rc1)', 'https://git.kernel.org/stable/c/3db4395332e7050ef9ddeb3052e6b5019f2a2a59', 'https://git.kernel.org/stable/c/440ab7f97261bc28501636a13998e1b1946d2e79', 'https://git.kernel.org/stable/c/5a2e37bc648a2503bf6d687aed27b9f4455d82eb', 'https://git.kernel.org/stable/c/dd89a81d850fa9a65f67b4527c0e420d15bf836c', 'https://lore.kernel.org/linux-cve-announce/2024082619-CVE-2024-44940-249f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44940', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-44940'], 'PublishedDate': '2024-08-26T12:15:06.053Z', 'LastModifiedDate': '2024-09-12T14:10:00.857Z'}, {'VulnerabilityID': 'CVE-2024-44941', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44941', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to cover read extent cache access with lock', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to cover read extent cache access with lock\n\nsyzbot reports a f2fs bug as below:\n\nBUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\nRead of size 4 at addr ffff8880739ab220 by task syz-executor200/5097\n\nCPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\n do_read_inode fs/f2fs/inode.c:509 [inline]\n f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560\n f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237\n generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413\n exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444\n exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584\n do_handle_to_path fs/fhandle.c:155 [inline]\n handle_to_path fs/fhandle.c:210 [inline]\n do_handle_open+0x495/0x650 fs/fhandle.c:226\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWe missed to cover sanity_check_extent_cache() w/ extent cache lock,\nso, below race case may happen, result in use after free issue.\n\n- f2fs_iget\n - do_read_inode\n - f2fs_init_read_extent_tree\n : add largest extent entry in to cache\n\t\t\t\t\t- shrink\n\t\t\t\t\t - f2fs_shrink_read_extent_tree\n\t\t\t\t\t - __shrink_extent_tree\n\t\t\t\t\t - __detach_extent_node\n\t\t\t\t\t : drop largest extent entry\n - sanity_check_extent_cache\n : access et->largest w/o lock\n\nlet's refactor sanity_check_extent_cache() to avoid extent cache access\nand call it before f2fs_init_read_extent_tree() to fix this issue.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44941', 'https://git.kernel.org/linus/d7409b05a64f212735f0d33f5f1602051a886eab (6.11-rc1)', 'https://git.kernel.org/stable/c/263df78166d3a9609b97d28c34029bd01874cbb8', 'https://git.kernel.org/stable/c/323ef20b5558b9d9fd10c1224327af6f11a8177d', 'https://git.kernel.org/stable/c/d7409b05a64f212735f0d33f5f1602051a886eab', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-44941-143e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44941', 'https://www.cve.org/CVERecord?id=CVE-2024-44941'], 'PublishedDate': '2024-08-26T12:15:06.107Z', 'LastModifiedDate': '2024-09-12T20:57:26.143Z'}, {'VulnerabilityID': 'CVE-2024-44942', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44942', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/inline.c:258!\nCPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0\nRIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258\nCall Trace:\n f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834\n f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315\n do_writepages+0x35b/0x870 mm/page-writeback.c:2612\n __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650\n writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941\n wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117\n wb_do_writeback fs/fs-writeback.c:2264 [inline]\n wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335\n worker_thread+0x86d/0xd70 kernel/workqueue.c:3416\n kthread+0x2f2/0x390 kernel/kthread.c:388\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nThe root cause is: inline_data inode can be fuzzed, so that there may\nbe valid blkaddr in its direct node, once f2fs triggers background GC\nto migrate the block, it will hit f2fs_bug_on() during dirty page\nwriteback.\n\nLet's add sanity check on F2FS_INLINE_DATA flag in inode during GC,\nso that, it can forbid migrating inline_data inode's data block for\nfixing.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44942', 'https://git.kernel.org/linus/fc01008c92f40015aeeced94750855a7111b6929 (6.11-rc1)', 'https://git.kernel.org/stable/c/26c07775fb5dc74351d1c3a2bc3cdf609b03e49f', 'https://git.kernel.org/stable/c/ae00e6536a2dd54b64b39e9a39548870cf835745', 'https://git.kernel.org/stable/c/fc01008c92f40015aeeced94750855a7111b6929', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-44942-651a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44942', 'https://www.cve.org/CVERecord?id=CVE-2024-44942'], 'PublishedDate': '2024-08-26T12:15:06.157Z', 'LastModifiedDate': '2024-08-27T16:09:10.01Z'}, {'VulnerabilityID': 'CVE-2024-44943', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'In the Linux kernel, the following vulnerability has been resolved: m ...', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: gup: stop abusing try_grab_folio\n\nA kernel warning was reported when pinning folio in CMA memory when\nlaunching SEV virtual machine. The splat looks like:\n\n[ 464.325306] WARNING: CPU: 13 PID: 6734 at mm/gup.c:1313 __get_user_pages+0x423/0x520\n[ 464.325464] CPU: 13 PID: 6734 Comm: qemu-kvm Kdump: loaded Not tainted 6.6.33+ #6\n[ 464.325477] RIP: 0010:__get_user_pages+0x423/0x520\n[ 464.325515] Call Trace:\n[ 464.325520] \n[ 464.325523] ? __get_user_pages+0x423/0x520\n[ 464.325528] ? __warn+0x81/0x130\n[ 464.325536] ? __get_user_pages+0x423/0x520\n[ 464.325541] ? report_bug+0x171/0x1a0\n[ 464.325549] ? handle_bug+0x3c/0x70\n[ 464.325554] ? exc_invalid_op+0x17/0x70\n[ 464.325558] ? asm_exc_invalid_op+0x1a/0x20\n[ 464.325567] ? __get_user_pages+0x423/0x520\n[ 464.325575] __gup_longterm_locked+0x212/0x7a0\n[ 464.325583] internal_get_user_pages_fast+0xfb/0x190\n[ 464.325590] pin_user_pages_fast+0x47/0x60\n[ 464.325598] sev_pin_memory+0xca/0x170 [kvm_amd]\n[ 464.325616] sev_mem_enc_register_region+0x81/0x130 [kvm_amd]\n\nPer the analysis done by yangge, when starting the SEV virtual machine, it\nwill call pin_user_pages_fast(..., FOLL_LONGTERM, ...) to pin the memory. \nBut the page is in CMA area, so fast GUP will fail then fallback to the\nslow path due to the longterm pinnalbe check in try_grab_folio().\n\nThe slow path will try to pin the pages then migrate them out of CMA area.\nBut the slow path also uses try_grab_folio() to pin the page, it will\nalso fail due to the same check then the above warning is triggered.\n\nIn addition, the try_grab_folio() is supposed to be used in fast path and\nit elevates folio refcount by using add ref unless zero. We are guaranteed\nto have at least one stable reference in slow path, so the simple atomic add\ncould be used. The performance difference should be trivial, but the\nmisuse may be confusing and misleading.\n\nRedefined try_grab_folio() to try_grab_folio_fast(), and try_grab_page()\nto try_grab_folio(), and use them in the proper paths. This solves both\nthe abuse and the kernel warning.\n\nThe proper naming makes their usecase more clear and should prevent from\nabusing in the future.\n\npeterx said:\n\n: The user will see the pin fails, for gpu-slow it further triggers the WARN\n: right below that failure (as in the original report):\n: \n: folio = try_grab_folio(page, page_increm - 1,\n: foll_flags);\n: if (WARN_ON_ONCE(!folio)) { <------------------------ here\n: /*\n: * Release the 1st page ref if the\n: * folio is problematic, fail hard.\n: */\n: gup_put_folio(page_folio(page), 1,\n: foll_flags);\n: ret = -EFAULT;\n: goto out;\n: }\n\n[1] https://lore.kernel.org/linux-mm/1719478388-31917-1-git-send-email-yangge1116@126.com/\n\n[shy828301@gmail.com: fix implicit declaration of function try_grab_folio_fast]\n Link: https://lkml.kernel.org/r/CAHbLzkowMSso-4Nufc9hcMehQsK9PNz3OSu-+eniU-2Mm-xjhA@mail.gmail.com', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44943', 'https://git.kernel.org/linus/f442fa6141379a20b48ae3efabee827a3d260787 (6.10)', 'https://git.kernel.org/stable/c/26273f5f4cf68b29414e403837093408a9c98e1f', 'https://git.kernel.org/stable/c/f442fa6141379a20b48ae3efabee827a3d260787', 'https://lore.kernel.org/linux-cve-announce/2024082853-CVE-2024-44943-234f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44943', 'https://www.cve.org/CVERecord?id=CVE-2024-44943'], 'PublishedDate': '2024-08-28T08:15:06.963Z', 'LastModifiedDate': '2024-09-10T18:12:43.38Z'}, {'VulnerabilityID': 'CVE-2024-44944', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44944', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: ctnetlink: use helper function to calculate expect ID', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: use helper function to calculate expect ID\n\nDelete expectation path is missing a call to the nf_expect_get_id()\nhelper function to calculate the expectation ID, otherwise LSB of the\nexpectation object address is leaked to userspace.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44944', 'https://git.kernel.org/linus/782161895eb4ac45cf7cfa8db375bd4766cb8299 (6.11-rc1)', 'https://git.kernel.org/stable/c/24f407042cf90b0872de667460230d8d50c06c39', 'https://git.kernel.org/stable/c/27662b46f2adaa52c1665a82af4b21c42c4337fd', 'https://git.kernel.org/stable/c/5e2c24f7b0911b15c29aefce760bcf770542fb61', 'https://git.kernel.org/stable/c/64c0b8e64be8368617ef08dfc59a3160563a1435', 'https://git.kernel.org/stable/c/66e7650dbbb8e236e781c670b167edc81e771450', 'https://git.kernel.org/stable/c/74de442b8e12a207c07953ee068009a7701aff8f', 'https://git.kernel.org/stable/c/782161895eb4ac45cf7cfa8db375bd4766cb8299', 'https://git.kernel.org/stable/c/eb4ca1a97e08ff5b920664ba292e576257e2d184', 'https://linux.oracle.com/cve/CVE-2024-44944.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024083044-CVE-2024-44944-56c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44944', 'https://www.cve.org/CVERecord?id=CVE-2024-44944', 'https://www.zerodayinitiative.com/advisories/ZDI-24-1182/'], 'PublishedDate': '2024-08-30T08:15:04.58Z', 'LastModifiedDate': '2024-09-10T08:15:03.23Z'}, {'VulnerabilityID': 'CVE-2024-44946', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44946', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kcm: Serialise kcm_sendmsg() for the same socket.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: Serialise kcm_sendmsg() for the same socket.\n\nsyzkaller reported UAF in kcm_release(). [0]\n\nThe scenario is\n\n 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb.\n\n 2. Thread A resumes building skb from kcm->seq_skb but is blocked\n by sk_stream_wait_memory()\n\n 3. Thread B calls sendmsg() concurrently, finishes building kcm->seq_skb\n and puts the skb to the write queue\n\n 4. Thread A faces an error and finally frees skb that is already in the\n write queue\n\n 5. kcm_release() does double-free the skb in the write queue\n\nWhen a thread is building a MSG_MORE skb, another thread must not touch it.\n\nLet's add a per-sk mutex and serialise kcm_sendmsg().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __skb_unlink include/linux/skbuff.h:2366 [inline]\nBUG: KASAN: slab-use-after-free in __skb_dequeue include/linux/skbuff.h:2385 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge include/linux/skbuff.h:3181 [inline]\nBUG: KASAN: slab-use-after-free in kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\nRead of size 8 at addr ffff0000ced0fc80 by task syz-executor329/6167\n\nCPU: 1 PID: 6167 Comm: syz-executor329 Tainted: G B 6.8.0-rc5-syzkaller-g9abbc24128bc #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nCall trace:\n dump_backtrace+0x1b8/0x1e4 arch/arm64/kernel/stacktrace.c:291\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:298\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd0/0x124 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x178/0x518 mm/kasan/report.c:488\n kasan_report+0xd8/0x138 mm/kasan/report.c:601\n __asan_report_load8_noabort+0x20/0x2c mm/kasan/report_generic.c:381\n __skb_unlink include/linux/skbuff.h:2366 [inline]\n __skb_dequeue include/linux/skbuff.h:2385 [inline]\n __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\n __skb_queue_purge include/linux/skbuff.h:3181 [inline]\n kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\n __sock_release net/socket.c:659 [inline]\n sock_close+0xa4/0x1e8 net/socket.c:1421\n __fput+0x30c/0x738 fs/file_table.c:376\n ____fput+0x20/0x30 fs/file_table.c:404\n task_work_run+0x230/0x2e0 kernel/task_work.c:180\n exit_task_work include/linux/task_work.h:38 [inline]\n do_exit+0x618/0x1f64 kernel/exit.c:871\n do_group_exit+0x194/0x22c kernel/exit.c:1020\n get_signal+0x1500/0x15ec kernel/signal.c:2893\n do_signal+0x23c/0x3b44 arch/arm64/kernel/signal.c:1249\n do_notify_resume+0x74/0x1f4 arch/arm64/kernel/entry-common.c:148\n exit_to_user_mode_prepare arch/arm64/kernel/entry-common.c:169 [inline]\n exit_to_user_mode arch/arm64/kernel/entry-common.c:178 [inline]\n el0_svc+0xac/0x168 arch/arm64/kernel/entry-common.c:713\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\n\nAllocated by task 6166:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x70/0x84 mm/kasan/generic.c:626\n unpoison_slab_object mm/kasan/common.c:314 [inline]\n __kasan_slab_alloc+0x74/0x8c mm/kasan/common.c:340\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3813 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_node+0x204/0x4c0 mm/slub.c:3903\n __alloc_skb+0x19c/0x3d8 net/core/skbuff.c:641\n alloc_skb include/linux/skbuff.h:1296 [inline]\n kcm_sendmsg+0x1d3c/0x2124 net/kcm/kcmsock.c:783\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n sock_sendmsg+0x220/0x2c0 net/socket.c:768\n splice_to_socket+0x7cc/0xd58 fs/splice.c:889\n do_splice_from fs/splice.c:941 [inline]\n direct_splice_actor+0xec/0x1d8 fs/splice.c:1164\n splice_direct_to_actor+0x438/0xa0c fs/splice.c:1108\n do_splice_direct_actor \n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44946', 'https://git.kernel.org/linus/807067bf014d4a3ae2cc55bd3de16f22a01eb580 (6.11-rc5)', 'https://git.kernel.org/stable/c/00425508f30baa5ab6449a1f478480ca7cffa6da', 'https://git.kernel.org/stable/c/6633b17840bf828921254d788ccd15602843fe9b', 'https://git.kernel.org/stable/c/72da240aafb142630cf16adc803ccdacb3780849', 'https://git.kernel.org/stable/c/807067bf014d4a3ae2cc55bd3de16f22a01eb580', 'https://git.kernel.org/stable/c/8c9cdbf600143bd6835c8b8351e5ac956da79aec', 'https://git.kernel.org/stable/c/9c8d544ed619f704e2b70e63e08ab75630c2ea23', 'https://git.kernel.org/stable/c/eb06c8d3022ce6738711191c89f9b3e9cfb91914', 'https://git.kernel.org/stable/c/fa6c23fe6dcac8c8bd63920ee8681292a2bd544e', 'https://lore.kernel.org/linux-cve-announce/2024083150-CVE-2024-44946-9cf1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44946', 'https://www.cve.org/CVERecord?id=CVE-2024-44946'], 'PublishedDate': '2024-08-31T14:15:04.32Z', 'LastModifiedDate': '2024-09-04T12:15:05.15Z'}, {'VulnerabilityID': 'CVE-2024-44947', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44947', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fuse: Initialize beyond-EOF page contents before setting uptodate', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: Initialize beyond-EOF page contents before setting uptodate\n\nfuse_notify_store(), unlike fuse_do_readpage(), does not enable page\nzeroing (because it can be used to change partial page contents).\n\nSo fuse_notify_store() must be more careful to fully initialize page\ncontents (including parts of the page that are beyond end-of-file)\nbefore marking the page uptodate.\n\nThe current code can leave beyond-EOF page contents uninitialized, which\nmakes these uninitialized page contents visible to userspace via mmap().\n\nThis is an information leak, but only affects systems which do not\nenable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the\ncorresponding kernel command line parameter).', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44947', 'https://git.kernel.org/stable/c/18a067240817bee8a9360539af5d79a4bf5398a5', 'https://git.kernel.org/stable/c/33168db352c7b56ae18aa55c2cae1a1c5905d30e', 'https://git.kernel.org/stable/c/3c0da3d163eb32f1f91891efaade027fa9b245b9', 'https://git.kernel.org/stable/c/4690e2171f651e2b415e3941ce17f2f7b813aff6', 'https://git.kernel.org/stable/c/49934861514d36d0995be8e81bb3312a499d8d9a', 'https://git.kernel.org/stable/c/831433527773e665bdb635ab5783d0b95d1246f4', 'https://git.kernel.org/stable/c/8c78303eafbf85a728dd84d1750e89240c677dd9', 'https://git.kernel.org/stable/c/ac42e0f0eb66af966015ee33fd355bc6f5d80cd6', 'https://lore.kernel.org/linux-cve-announce/2024090219-CVE-2024-44947-f49c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44947', 'https://www.cve.org/CVERecord?id=CVE-2024-44947'], 'PublishedDate': '2024-09-02T18:15:36.577Z', 'LastModifiedDate': '2024-09-16T17:52:37.563Z'}, {'VulnerabilityID': 'CVE-2024-44948', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44948', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/mtrr: Check if fixed MTRRs exist before saving them', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mtrr: Check if fixed MTRRs exist before saving them\n\nMTRRs have an obsolete fixed variant for fine grained caching control\nof the 640K-1MB region that uses separate MSRs. This fixed variant has\na separate capability bit in the MTRR capability MSR.\n\nSo far all x86 CPUs which support MTRR have this separate bit set, so it\nwent unnoticed that mtrr_save_state() does not check the capability bit\nbefore accessing the fixed MTRR MSRs.\n\nThough on a CPU that does not support the fixed MTRR capability this\nresults in a #GP. The #GP itself is harmless because the RDMSR fault is\nhandled gracefully, but results in a WARN_ON().\n\nAdd the missing capability check to prevent this.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44948', 'https://git.kernel.org/linus/919f18f961c03d6694aa726c514184f2311a4614 (6.11-rc3)', 'https://git.kernel.org/stable/c/06c1de44d378ec5439db17bf476507d68589bfe9', 'https://git.kernel.org/stable/c/34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e', 'https://git.kernel.org/stable/c/388f1c954019f253a8383f7eb733f38d541e10b6', 'https://git.kernel.org/stable/c/450b6b22acdaac67a18eaf5ed498421ffcf10051', 'https://git.kernel.org/stable/c/8a90d3fc7c24608548d3a750671f9dac21d1a462', 'https://git.kernel.org/stable/c/8aa79dfb216b865e96ff890bc4ea71650f9bc8d7', 'https://git.kernel.org/stable/c/919f18f961c03d6694aa726c514184f2311a4614', 'https://git.kernel.org/stable/c/ca7d00c5656d1791e28369919e3e10febe9c3b16', 'https://linux.oracle.com/cve/CVE-2024-44948.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090407-CVE-2024-44948-5554@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44948', 'https://www.cve.org/CVERecord?id=CVE-2024-44948'], 'PublishedDate': '2024-09-04T19:15:29.95Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-44949', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44949', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: parisc: fix a possible DMA corruption', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: fix a possible DMA corruption\n\nARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be\npossible that two unrelated 16-byte allocations share a cache line. If\none of these allocations is written using DMA and the other is written\nusing cached write, the value that was written with DMA may be\ncorrupted.\n\nThis commit changes ARCH_DMA_MINALIGN to be 128 on PA20 and 32 on PA1.1 -\nthat's the largest possible cache line size.\n\nAs different parisc microarchitectures have different cache line size, we\ndefine arch_slab_minalign(), cache_line_size() and\ndma_get_cache_alignment() so that the kernel may tune slab cache\nparameters dynamically, based on the detected cache line size.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44949', 'https://git.kernel.org/linus/7ae04ba36b381bffe2471eff3a93edced843240f (6.11-rc2)', 'https://git.kernel.org/stable/c/533de2f470baac40d3bf622fe631f15231a03c9f', 'https://git.kernel.org/stable/c/642a0b7453daff0295310774016fcb56d1f5bc7f', 'https://git.kernel.org/stable/c/7ae04ba36b381bffe2471eff3a93edced843240f', 'https://lore.kernel.org/linux-cve-announce/2024090410-CVE-2024-44949-8f05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44949', 'https://www.cve.org/CVERecord?id=CVE-2024-44949'], 'PublishedDate': '2024-09-04T19:15:30.04Z', 'LastModifiedDate': '2024-10-09T13:53:32.513Z'}, {'VulnerabilityID': 'CVE-2024-44950', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44950', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: sc16is7xx: fix invalid FIFO access with special register set', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix invalid FIFO access with special register set\n\nWhen enabling access to the special register set, Receiver time-out and\nRHR interrupts can happen. In this case, the IRQ handler will try to read\nfrom the FIFO thru the RHR register at address 0x00, but address 0x00 is\nmapped to DLL register, resulting in erroneous FIFO reading.\n\nCall graph example:\n sc16is7xx_startup(): entry\n sc16is7xx_ms_proc(): entry\n sc16is7xx_set_termios(): entry\n sc16is7xx_set_baud(): DLH/DLL = $009C --> access special register set\n sc16is7xx_port_irq() entry --> IIR is 0x0C\n sc16is7xx_handle_rx() entry\n sc16is7xx_fifo_read(): --> unable to access FIFO (RHR) because it is\n mapped to DLL (LCR=LCR_CONF_MODE_A)\n sc16is7xx_set_baud(): exit --> Restore access to general register set\n\nFix the problem by claiming the efr_lock mutex when accessing the Special\nregister set.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 5.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44950', 'https://git.kernel.org/linus/7d3b793faaab1305994ce568b59d61927235f57b (6.11-rc3)', 'https://git.kernel.org/stable/c/6a6730812220a9a5ce4003eb347da1ee5abd06b0', 'https://git.kernel.org/stable/c/7d3b793faaab1305994ce568b59d61927235f57b', 'https://lore.kernel.org/linux-cve-announce/2024090410-CVE-2024-44950-67fb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44950', 'https://www.cve.org/CVERecord?id=CVE-2024-44950'], 'PublishedDate': '2024-09-04T19:15:30.1Z', 'LastModifiedDate': '2024-10-09T14:21:16.773Z'}, {'VulnerabilityID': 'CVE-2024-44951', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44951', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: sc16is7xx: fix TX fifo corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix TX fifo corruption\n\nSometimes, when a packet is received on channel A at almost the same time\nas a packet is about to be transmitted on channel B, we observe with a\nlogic analyzer that the received packet on channel A is transmitted on\nchannel B. In other words, the Tx buffer data on channel B is corrupted\nwith data from channel A.\n\nThe problem appeared since commit 4409df5866b7 ("serial: sc16is7xx: change\nEFR lock to operate on each channels"), which changed the EFR locking to\noperate on each channel instead of chip-wise.\n\nThis commit has introduced a regression, because the EFR lock is used not\nonly to protect the EFR registers access, but also, in a very obscure and\nundocumented way, to protect access to the data buffer, which is shared by\nthe Tx and Rx handlers, but also by each channel of the IC.\n\nFix this regression first by switching to kfifo_out_linear_ptr() in\nsc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer.\n\nSecondly, replace the chip-wise Rx buffer with a separate Rx buffer for\neach channel.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44951', 'https://git.kernel.org/linus/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4 (6.11-rc3)', 'https://git.kernel.org/stable/c/09cfe05e9907f3276887a20e267cc40e202f4fdd', 'https://git.kernel.org/stable/c/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44951-9121@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44951', 'https://www.cve.org/CVERecord?id=CVE-2024-44951'], 'PublishedDate': '2024-09-04T19:15:30.153Z', 'LastModifiedDate': '2024-10-09T14:27:43.973Z'}, {'VulnerabilityID': 'CVE-2024-44952', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44952', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: driver core: Fix uevent_show() vs driver detach race', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: Fix uevent_show() vs driver detach race\n\nuevent_show() wants to de-reference dev->driver->name. There is no clean\nway for a device attribute to de-reference dev->driver unless that\nattribute is defined via (struct device_driver).dev_groups. Instead, the\nanti-pattern of taking the device_lock() in the attribute handler risks\ndeadlocks with code paths that remove device attributes while holding\nthe lock.\n\nThis deadlock is typically invisible to lockdep given the device_lock()\nis marked lockdep_set_novalidate_class(), but some subsystems allocate a\nlocal lockdep key for @dev->mutex to reveal reports of the form:\n\n ======================================================\n WARNING: possible circular locking dependency detected\n 6.10.0-rc7+ #275 Tainted: G OE N\n ------------------------------------------------------\n modprobe/2374 is trying to acquire lock:\n ffff8c2270070de0 (kn->active#6){++++}-{0:0}, at: __kernfs_remove+0xde/0x220\n\n but task is already holding lock:\n ffff8c22016e88f8 (&cxl_root_key){+.+.}-{3:3}, at: device_release_driver_internal+0x39/0x210\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #1 (&cxl_root_key){+.+.}-{3:3}:\n __mutex_lock+0x99/0xc30\n uevent_show+0xac/0x130\n dev_attr_show+0x18/0x40\n sysfs_kf_seq_show+0xac/0xf0\n seq_read_iter+0x110/0x450\n vfs_read+0x25b/0x340\n ksys_read+0x67/0xf0\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n -> #0 (kn->active#6){++++}-{0:0}:\n __lock_acquire+0x121a/0x1fa0\n lock_acquire+0xd6/0x2e0\n kernfs_drain+0x1e9/0x200\n __kernfs_remove+0xde/0x220\n kernfs_remove_by_name_ns+0x5e/0xa0\n device_del+0x168/0x410\n device_unregister+0x13/0x60\n devres_release_all+0xb8/0x110\n device_unbind_cleanup+0xe/0x70\n device_release_driver_internal+0x1c7/0x210\n driver_detach+0x47/0x90\n bus_remove_driver+0x6c/0xf0\n cxl_acpi_exit+0xc/0x11 [cxl_acpi]\n __do_sys_delete_module.isra.0+0x181/0x260\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe observation though is that driver objects are typically much longer\nlived than device objects. It is reasonable to perform lockless\nde-reference of a @driver pointer even if it is racing detach from a\ndevice. Given the infrequency of driver unregistration, use\nsynchronize_rcu() in module_remove_driver() to close any potential\nraces. It is potentially overkill to suffer synchronize_rcu() just to\nhandle the rare module removal racing uevent_show() event.\n\nThanks to Tetsuo Handa for the debug analysis of the syzbot report [1].', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44952', 'https://git.kernel.org/linus/15fffc6a5624b13b428bb1c6e9088e32a55eb82c (6.11-rc3)', 'https://git.kernel.org/stable/c/15fffc6a5624b13b428bb1c6e9088e32a55eb82c', 'https://git.kernel.org/stable/c/49ea4e0d862632d51667da5e7a9c88a560e9c5a1', 'https://git.kernel.org/stable/c/4a7c2a8387524942171037e70b80e969c3b5c05b', 'https://git.kernel.org/stable/c/4d035c743c3e391728a6f81cbf0f7f9ca700cf62', 'https://git.kernel.org/stable/c/9c23fc327d6ec67629b4ad323bd64d3834c0417d', 'https://git.kernel.org/stable/c/cd490a247ddf325325fd0de8898659400c9237ef', 'https://git.kernel.org/stable/c/dd98c9630b7ee273da87e9a244f94ddf947161e2', 'https://git.kernel.org/stable/c/f098e8fc7227166206256c18d56ab622039108b1', 'https://linux.oracle.com/cve/CVE-2024-44952.html', 'https://linux.oracle.com/errata/ELSA-2024-12779.html', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44952-6290@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44952', 'https://www.cve.org/CVERecord?id=CVE-2024-44952'], 'PublishedDate': '2024-09-04T19:15:30.213Z', 'LastModifiedDate': '2024-09-06T16:37:38.37Z'}, {'VulnerabilityID': 'CVE-2024-44953', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44953', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: ufs: core: Fix deadlock during RTC update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix deadlock during RTC update\n\nThere is a deadlock when runtime suspend waits for the flush of RTC work,\nand the RTC work calls ufshcd_rpm_get_sync() to wait for runtime resume.\n\nHere is deadlock backtrace:\n\nkworker/0:1 D 4892.876354 10 10971 4859 0x4208060 0x8 10 0 120 670730152367\nptr f0ffff80c2e40000 0 1 0x00000001 0x000000ff 0x000000ff 0x000000ff\n __switch_to+0x1a8/0x2d4\n __schedule+0x684/0xa98\n schedule+0x48/0xc8\n schedule_timeout+0x48/0x170\n do_wait_for_common+0x108/0x1b0\n wait_for_completion+0x44/0x60\n __flush_work+0x39c/0x424\n __cancel_work_sync+0xd8/0x208\n cancel_delayed_work_sync+0x14/0x28\n __ufshcd_wl_suspend+0x19c/0x480\n ufshcd_wl_runtime_suspend+0x3c/0x1d4\n scsi_runtime_suspend+0x78/0xc8\n __rpm_callback+0x94/0x3e0\n rpm_suspend+0x2d4/0x65c\n __pm_runtime_suspend+0x80/0x114\n scsi_runtime_idle+0x38/0x6c\n rpm_idle+0x264/0x338\n __pm_runtime_idle+0x80/0x110\n ufshcd_rtc_work+0x128/0x1e4\n process_one_work+0x26c/0x650\n worker_thread+0x260/0x3d8\n kthread+0x110/0x134\n ret_from_fork+0x10/0x20\n\nSkip updating RTC if RPM state is not RPM_ACTIVE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44953', 'https://git.kernel.org/linus/3911af778f208e5f49d43ce739332b91e26bc48e (6.11-rc2)', 'https://git.kernel.org/stable/c/3911af778f208e5f49d43ce739332b91e26bc48e', 'https://git.kernel.org/stable/c/f13f1858a28c68b7fc0d72c2008d5c1f80d2e8d5', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44953-1a10@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44953', 'https://www.cve.org/CVERecord?id=CVE-2024-44953'], 'PublishedDate': '2024-09-04T19:15:30.297Z', 'LastModifiedDate': '2024-09-06T16:37:33.65Z'}, {'VulnerabilityID': 'CVE-2024-44954', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44954', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ALSA: line6: Fix racy access to midibuf', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: line6: Fix racy access to midibuf\n\nThere can be concurrent accesses to line6 midibuf from both the URB\ncompletion callback and the rawmidi API access. This could be a cause\nof KMSAN warning triggered by syzkaller below (so put as reported-by\nhere).\n\nThis patch protects the midibuf call of the former code path with a\nspinlock for avoiding the possible races.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-362'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44954', 'https://git.kernel.org/linus/15b7a03205b31bc5623378c190d22b7ff60026f1 (6.11-rc3)', 'https://git.kernel.org/stable/c/15b7a03205b31bc5623378c190d22b7ff60026f1', 'https://git.kernel.org/stable/c/40f3d5cb0e0cbf7fa697913a27d5d361373bdcf5', 'https://git.kernel.org/stable/c/51d87f11dd199bbc6a85982b088ff27bde53b48a', 'https://git.kernel.org/stable/c/535df7f896a568a8a1564114eaea49d002cb1747', 'https://git.kernel.org/stable/c/643293b68fbb6c03f5e907736498da17d43f0d81', 'https://git.kernel.org/stable/c/a54da4b787dcac60b598da69c9c0072812b8282d', 'https://git.kernel.org/stable/c/c80f454a805443c274394b1db0d1ebf477abd94e', 'https://git.kernel.org/stable/c/e7e7d2b180d8f297cea6db43ea72402fd33e1a29', 'https://linux.oracle.com/cve/CVE-2024-44954.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44954-6838@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44954', 'https://www.cve.org/CVERecord?id=CVE-2024-44954'], 'PublishedDate': '2024-09-04T19:15:30.353Z', 'LastModifiedDate': '2024-10-10T18:02:42.307Z'}, {'VulnerabilityID': 'CVE-2024-44955', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44955', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute\n\n[Why]\nWhen unplug one of monitors connected after mst hub, encounter null pointer dereference.\n\nIt's due to dc_sink get released immediately in early_unregister() or detect_ctx(). When\ncommit new state which directly referring to info stored in dc_sink will cause null pointer\ndereference.\n\n[how]\nRemove redundant checking condition. Relevant condition should already be covered by checking\nif dsc_aux is null or not. Also reset dsc_aux to NULL when the connector is disconnected.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44955', 'https://git.kernel.org/linus/fcf6a49d79923a234844b8efe830a61f3f0584e4 (6.11-rc1)', 'https://git.kernel.org/stable/c/39b217193729aa45eded8de24d9245468a0c0263', 'https://git.kernel.org/stable/c/fcf6a49d79923a234844b8efe830a61f3f0584e4', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44955-20e8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44955', 'https://www.cve.org/CVERecord?id=CVE-2024-44955'], 'PublishedDate': '2024-09-04T19:15:30.423Z', 'LastModifiedDate': '2024-10-10T17:57:00.267Z'}, {'VulnerabilityID': 'CVE-2024-44956', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44956', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/preempt_fence: enlarge the fence critical section', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/preempt_fence: enlarge the fence critical section\n\nIt is really easy to introduce subtle deadlocks in\npreempt_fence_work_func() since we operate on single global ordered-wq\nfor signalling our preempt fences behind the scenes, so even though we\nsignal a particular fence, everything in the callback should be in the\nfence critical section, since blocking in the callback will prevent\nother published fences from signalling. If we enlarge the fence critical\nsection to cover the entire callback, then lockdep should be able to\nunderstand this better, and complain if we grab a sensitive lock like\nvm->lock, which is also held when waiting on preempt fences.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44956', 'https://git.kernel.org/linus/3cd1585e57908b6efcd967465ef7685f40b2a294 (6.11-rc1)', 'https://git.kernel.org/stable/c/3cd1585e57908b6efcd967465ef7685f40b2a294', 'https://git.kernel.org/stable/c/458bb83119dfee5d14c677f7846dd9363817006f', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44956-8bcf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44956', 'https://www.cve.org/CVERecord?id=CVE-2024-44956'], 'PublishedDate': '2024-09-04T19:15:30.48Z', 'LastModifiedDate': '2024-09-06T16:37:11.777Z'}, {'VulnerabilityID': 'CVE-2024-44957', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44957', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xen: privcmd: Switch from mutex to spinlock for irqfds', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Switch from mutex to spinlock for irqfds\n\nirqfd_wakeup() gets EPOLLHUP, when it is called by\neventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which\ngets called under spin_lock_irqsave(). We can't use a mutex here as it\nwill lead to a deadlock.\n\nFix it by switching over to a spin lock.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44957', 'https://git.kernel.org/linus/1c682593096a487fd9aebc079a307ff7a6d054a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/1c682593096a487fd9aebc079a307ff7a6d054a3', 'https://git.kernel.org/stable/c/49f2a5da6785b2dbde93e291cae037662440346e', 'https://git.kernel.org/stable/c/c2775ae4d9227729f8ca9ee2a068f62a00d5ea9c', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44957-5c8e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44957', 'https://www.cve.org/CVERecord?id=CVE-2024-44957'], 'PublishedDate': '2024-09-04T19:15:30.523Z', 'LastModifiedDate': '2024-09-06T16:37:00.077Z'}, {'VulnerabilityID': 'CVE-2024-44958', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44958', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched/smt: Fix unbalance sched_smt_present dec/inc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched/smt: Fix unbalance sched_smt_present dec/inc\n\nI got the following warn report while doing stress test:\n\njump label: negative count!\nWARNING: CPU: 3 PID: 38 at kernel/jump_label.c:263 static_key_slow_try_dec+0x9d/0xb0\nCall Trace:\n \n __static_key_slow_dec_cpuslocked+0x16/0x70\n sched_cpu_deactivate+0x26e/0x2a0\n cpuhp_invoke_callback+0x3ad/0x10d0\n cpuhp_thread_fun+0x3f5/0x680\n smpboot_thread_fn+0x56d/0x8d0\n kthread+0x309/0x400\n ret_from_fork+0x41/0x70\n ret_from_fork_asm+0x1b/0x30\n \n\nBecause when cpuset_cpu_inactive() fails in sched_cpu_deactivate(),\nthe cpu offline failed, but sched_smt_present is decremented before\ncalling sched_cpu_deactivate(), it leads to unbalanced dec/inc, so\nfix it by incrementing sched_smt_present in the error path.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44958', 'https://git.kernel.org/linus/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117 (6.11-rc2)', 'https://git.kernel.org/stable/c/2a3548c7ef2e135aee40e7e5e44e7d11b893e7c4', 'https://git.kernel.org/stable/c/2cf7665efe451e48d27953e6b5bc627d518c902b', 'https://git.kernel.org/stable/c/65727331b60197b742089855ac09464c22b96f66', 'https://git.kernel.org/stable/c/d0c87a3c6be10a57aa3463c32c3fc6b2a47c3dab', 'https://git.kernel.org/stable/c/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44958-80e9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44958', 'https://www.cve.org/CVERecord?id=CVE-2024-44958'], 'PublishedDate': '2024-09-04T19:15:30.58Z', 'LastModifiedDate': '2024-10-10T17:56:24.467Z'}, {'VulnerabilityID': 'CVE-2024-44959', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44959', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracefs: Use generic inode RCU for synchronizing freeing', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntracefs: Use generic inode RCU for synchronizing freeing\n\nWith structure layout randomization enabled for 'struct inode' we need to\navoid overlapping any of the RCU-used / initialized-only-once members,\ne.g. i_lru or i_sb_list to not corrupt related list traversals when making\nuse of the rcu_head.\n\nFor an unlucky structure layout of 'struct inode' we may end up with the\nfollowing splat when running the ftrace selftests:\n\n[<...>] list_del corruption, ffff888103ee2cb0->next (tracefs_inode_cache+0x0/0x4e0 [slab object]) is NULL (prev is tracefs_inode_cache+0x78/0x4e0 [slab object])\n[<...>] ------------[ cut here ]------------\n[<...>] kernel BUG at lib/list_debug.c:54!\n[<...>] invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[<...>] CPU: 3 PID: 2550 Comm: mount Tainted: G N 6.8.12-grsec+ #122 ed2f536ca62f28b087b90e3cc906a8d25b3ddc65\n[<...>] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\n[<...>] RIP: 0010:[] __list_del_entry_valid_or_report+0x138/0x3e0\n[<...>] Code: 48 b8 99 fb 65 f2 ff ff ff ff e9 03 5c d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff e9 33 5a d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff <0f> 0b 4c 89 e9 48 89 ea 48 89 ee 48 c7 c7 60 8f dd 89 31 c0 e8 2f\n[<...>] RSP: 0018:fffffe80416afaf0 EFLAGS: 00010283\n[<...>] RAX: 0000000000000098 RBX: ffff888103ee2cb0 RCX: 0000000000000000\n[<...>] RDX: ffffffff84655fe8 RSI: ffffffff89dd8b60 RDI: 0000000000000001\n[<...>] RBP: ffff888103ee2cb0 R08: 0000000000000001 R09: fffffbd0082d5f25\n[<...>] R10: fffffe80416af92f R11: 0000000000000001 R12: fdf99c16731d9b6d\n[<...>] R13: 0000000000000000 R14: ffff88819ad4b8b8 R15: 0000000000000000\n[<...>] RBX: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RDX: __list_del_entry_valid_or_report+0x108/0x3e0\n[<...>] RSI: __func__.47+0x4340/0x4400\n[<...>] RBP: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RSP: process kstack fffffe80416afaf0+0x7af0/0x8000 [mount 2550 2550]\n[<...>] R09: kasan shadow of process kstack fffffe80416af928+0x7928/0x8000 [mount 2550 2550]\n[<...>] R10: process kstack fffffe80416af92f+0x792f/0x8000 [mount 2550 2550]\n[<...>] R14: tracefs_inode_cache+0x78/0x4e0 [slab object]\n[<...>] FS: 00006dcb380c1840(0000) GS:ffff8881e0600000(0000) knlGS:0000000000000000\n[<...>] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[<...>] CR2: 000076ab72b30e84 CR3: 000000000b088004 CR4: 0000000000360ef0 shadow CR4: 0000000000360ef0\n[<...>] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[<...>] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[<...>] ASID: 0003\n[<...>] Stack:\n[<...>] ffffffff818a2315 00000000f5c856ee ffffffff896f1840 ffff888103ee2cb0\n[<...>] ffff88812b6b9750 0000000079d714b6 fffffbfff1e9280b ffffffff8f49405f\n[<...>] 0000000000000001 0000000000000000 ffff888104457280 ffffffff8248b392\n[<...>] Call Trace:\n[<...>] \n[<...>] [] ? lock_release+0x175/0x380 fffffe80416afaf0\n[<...>] [] list_lru_del+0x152/0x740 fffffe80416afb48\n[<...>] [] list_lru_del_obj+0x113/0x280 fffffe80416afb88\n[<...>] [] ? _atomic_dec_and_lock+0x119/0x200 fffffe80416afb90\n[<...>] [] iput_final+0x1c4/0x9a0 fffffe80416afbb8\n[<...>] [] dentry_unlink_inode+0x44b/0xaa0 fffffe80416afbf8\n[<...>] [] __dentry_kill+0x23c/0xf00 fffffe80416afc40\n[<...>] [] ? __this_cpu_preempt_check+0x1f/0xa0 fffffe80416afc48\n[<...>] [] ? shrink_dentry_list+0x1c5/0x760 fffffe80416afc70\n[<...>] [] ? shrink_dentry_list+0x51/0x760 fffffe80416afc78\n[<...>] [] shrink_dentry_list+0x288/0x760 fffffe80416afc80\n[<...>] [] shrink_dcache_sb+0x155/0x420 fffffe80416afcc8\n[<...>] [] ? debug_smp_processor_id+0x23/0xa0 fffffe80416afce0\n[<...>] [] ? do_one_tre\n---truncated---", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44959', 'https://git.kernel.org/linus/0b6743bd60a56a701070b89fb80c327a44b7b3e2 (6.11-rc3)', 'https://git.kernel.org/stable/c/061da60716ce0cde99f62f31937b81e1c03acef6', 'https://git.kernel.org/stable/c/0b6743bd60a56a701070b89fb80c327a44b7b3e2', 'https://git.kernel.org/stable/c/726f4c241e17be75a9cf6870d80cd7479dc89e8f', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44959-61a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44959', 'https://www.cve.org/CVERecord?id=CVE-2024-44959'], 'PublishedDate': '2024-09-04T19:15:30.637Z', 'LastModifiedDate': '2024-10-10T17:54:07.96Z'}, {'VulnerabilityID': 'CVE-2024-44960', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44960', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: gadget: core: Check for unset descriptor', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: core: Check for unset descriptor\n\nMake sure the descriptor has been set before looking at maxpacket.\nThis fixes a null pointer panic in this case.\n\nThis may happen if the gadget doesn't properly set up the endpoint\nfor the current speed, or the gadget descriptors are malformed and\nthe descriptor for the speed/endpoint are not found.\n\nNo current gadget driver is known to have this problem, but this\nmay cause a hard-to-find bug during development of new gadgets.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44960', 'https://git.kernel.org/linus/973a57891608a98e894db2887f278777f564de18 (6.11-rc3)', 'https://git.kernel.org/stable/c/1a9df57d57452b104c46c918569143cf21d7ebf1', 'https://git.kernel.org/stable/c/50c5248b0ea8aae0529fdf28dac42a41312d3b62', 'https://git.kernel.org/stable/c/716cba46f73a92645cf13eded8d257ed48afc2a4', 'https://git.kernel.org/stable/c/7cc9ebcfe58be22f18056ad8bc6272d120bdcb3e', 'https://git.kernel.org/stable/c/973a57891608a98e894db2887f278777f564de18', 'https://git.kernel.org/stable/c/a0362cd6e503278add954123957fd47990e8d9bf', 'https://git.kernel.org/stable/c/ba15815dd24cc5ec0d23e2170dc58c7db1e03b4a', 'https://git.kernel.org/stable/c/df8e734ae5e605348aa0ca2498aedb73e815f244', 'https://linux.oracle.com/cve/CVE-2024-44960.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44960-039b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44960', 'https://www.cve.org/CVERecord?id=CVE-2024-44960'], 'PublishedDate': '2024-09-04T19:15:30.7Z', 'LastModifiedDate': '2024-10-04T16:44:05.497Z'}, {'VulnerabilityID': 'CVE-2024-44961', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44961', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Forward soft recovery errors to userspace', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Forward soft recovery errors to userspace\n\nAs we discussed before[1], soft recovery should be\nforwarded to userspace, or we can get into a really\nbad state where apps will keep submitting hanging\ncommand buffers cascading us to a hard reset.\n\n1: https://lore.kernel.org/all/bf23d5ed-9a6b-43e7-84ee-8cbfd0d60f18@froggi.es/\n(cherry picked from commit 434967aadbbbe3ad9103cc29e9a327de20fdba01)', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44961', 'https://git.kernel.org/linus/829798c789f567ef6ba4b084c15b7b5f3bd98d51 (6.11-rc3)', 'https://git.kernel.org/stable/c/0da0b06165d83a8ecbb6582d9d5a135f9d38a52a', 'https://git.kernel.org/stable/c/829798c789f567ef6ba4b084c15b7b5f3bd98d51', 'https://git.kernel.org/stable/c/c28d207edfc5679585f4e96acb67000076ce90be', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44961-8666@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44961', 'https://www.cve.org/CVERecord?id=CVE-2024-44961'], 'PublishedDate': '2024-09-04T19:15:30.77Z', 'LastModifiedDate': '2024-10-04T16:39:39.3Z'}, {'VulnerabilityID': 'CVE-2024-44962', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44962', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: btnxpuart: Shutdown timer and prevent rearming when driver unloading', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Shutdown timer and prevent rearming when driver unloading\n\nWhen unload the btnxpuart driver, its associated timer will be deleted.\nIf the timer happens to be modified at this moment, it leads to the\nkernel call this timer even after the driver unloaded, resulting in\nkernel panic.\nUse timer_shutdown_sync() instead of del_timer_sync() to prevent rearming.\n\npanic log:\n Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n Modules linked in: algif_hash algif_skcipher af_alg moal(O) mlan(O) crct10dif_ce polyval_ce polyval_generic snd_soc_imx_card snd_soc_fsl_asoc_card snd_soc_imx_audmux mxc_jpeg_encdec v4l2_jpeg snd_soc_wm8962 snd_soc_fsl_micfil snd_soc_fsl_sai flexcan snd_soc_fsl_utils ap130x rpmsg_ctrl imx_pcm_dma can_dev rpmsg_char pwm_fan fuse [last unloaded: btnxpuart]\n CPU: 5 PID: 723 Comm: memtester Tainted: G O 6.6.23-lts-next-06207-g4aef2658ac28 #1\n Hardware name: NXP i.MX95 19X19 board (DT)\n pstate: 20400009 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : 0xffff80007a2cf464\n lr : call_timer_fn.isra.0+0x24/0x80\n...\n Call trace:\n 0xffff80007a2cf464\n __run_timers+0x234/0x280\n run_timer_softirq+0x20/0x40\n __do_softirq+0x100/0x26c\n ____do_softirq+0x10/0x1c\n call_on_irq_stack+0x24/0x4c\n do_softirq_own_stack+0x1c/0x2c\n irq_exit_rcu+0xc0/0xdc\n el0_interrupt+0x54/0xd8\n __el0_irq_handler_common+0x18/0x24\n el0t_64_irq_handler+0x10/0x1c\n el0t_64_irq+0x190/0x194\n Code: ???????? ???????? ???????? ???????? (????????)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Oops: Fatal exception in interrupt\n SMP: stopping secondary CPUs\n Kernel Offset: disabled\n CPU features: 0x0,c0000000,40028143,1000721b\n Memory Limit: none\n ---[ end Kernel panic - not syncing: Oops: Fatal exception in interrupt ]---', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44962', 'https://git.kernel.org/linus/0d0df1e750bac0fdaa77940e711c1625cff08d33 (6.11-rc1)', 'https://git.kernel.org/stable/c/0d0df1e750bac0fdaa77940e711c1625cff08d33', 'https://git.kernel.org/stable/c/28bbb5011a9723700006da67bdb57ab6a914452b', 'https://git.kernel.org/stable/c/4d9adcb94d55e9be8a3e464d9f2ff7d27e2ed016', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44962-c329@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44962', 'https://www.cve.org/CVERecord?id=CVE-2024-44962'], 'PublishedDate': '2024-09-04T19:15:30.827Z', 'LastModifiedDate': '2024-10-04T16:20:34.55Z'}, {'VulnerabilityID': 'CVE-2024-44963', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44963', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: do not BUG_ON() when freeing tree block after error', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not BUG_ON() when freeing tree block after error\n\nWhen freeing a tree block, at btrfs_free_tree_block(), if we fail to\ncreate a delayed reference we don't deal with the error and just do a\nBUG_ON(). The error most likely to happen is -ENOMEM, and we have a\ncomment mentioning that only -ENOMEM can happen, but that is not true,\nbecause in case qgroups are enabled any error returned from\nbtrfs_qgroup_trace_extent_post() (can be -EUCLEAN or anything returned\nfrom btrfs_search_slot() for example) can be propagated back to\nbtrfs_free_tree_block().\n\nSo stop doing a BUG_ON() and return the error to the callers and make\nthem abort the transaction to prevent leaking space. Syzbot was\ntriggering this, likely due to memory allocation failure injection.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44963', 'https://git.kernel.org/linus/bb3868033a4cccff7be57e9145f2117cbdc91c11 (6.11-rc1)', 'https://git.kernel.org/stable/c/98251cd60b4d702a8a81de442ab621e83a3fb24f', 'https://git.kernel.org/stable/c/bb3868033a4cccff7be57e9145f2117cbdc91c11', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44963-2e6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44963', 'https://www.cve.org/CVERecord?id=CVE-2024-44963'], 'PublishedDate': '2024-09-04T19:15:30.883Z', 'LastModifiedDate': '2024-10-04T16:19:20.77Z'}, {'VulnerabilityID': 'CVE-2024-44964', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44964', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: idpf: fix memory leaks and crashes while performing a soft reset', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix memory leaks and crashes while performing a soft reset\n\nThe second tagged commit introduced a UAF, as it removed restoring\nq_vector->vport pointers after reinitializating the structures.\nThis is due to that all queue allocation functions are performed here\nwith the new temporary vport structure and those functions rewrite\nthe backpointers to the vport. Then, this new struct is freed and\nthe pointers start leading to nowhere.\n\nBut generally speaking, the current logic is very fragile. It claims\nto be more reliable when the system is low on memory, but in fact, it\nconsumes two times more memory as at the moment of running this\nfunction, there are two vports allocated with their queues and vectors.\nMoreover, it claims to prevent the driver from running into "bad state",\nbut in fact, any error during the rebuild leaves the old vport in the\npartially allocated state.\nFinally, if the interface is down when the function is called, it always\nallocates a new queue set, but when the user decides to enable the\ninterface later on, vport_open() allocates them once again, IOW there\'s\na clear memory leak here.\n\nJust don\'t allocate a new queue set when performing a reset, that solves\ncrashes and memory leaks. Readd the old queue number and reopen the\ninterface on rollback - that solves limbo states when the device is left\ndisabled and/or without HW queues enabled.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401', 'CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44964', 'https://git.kernel.org/linus/f01032a2ca099ec8d619aaa916c3762aa62495df (6.11-rc3)', 'https://git.kernel.org/stable/c/6b289f8d91537ec1e4f9c7b38b31b90d93b1419b', 'https://git.kernel.org/stable/c/f01032a2ca099ec8d619aaa916c3762aa62495df', 'https://lore.kernel.org/linux-cve-announce/2024090414-CVE-2024-44964-ebb1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44964', 'https://www.cve.org/CVERecord?id=CVE-2024-44964'], 'PublishedDate': '2024-09-04T19:15:30.94Z', 'LastModifiedDate': '2024-09-06T16:36:45.137Z'}, {'VulnerabilityID': 'CVE-2024-44965', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44965', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/mm: Fix pti_clone_pgtable() alignment assumption', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Fix pti_clone_pgtable() alignment assumption\n\nGuenter reported dodgy crashes on an i386-nosmp build using GCC-11\nthat had the form of endless traps until entry stack exhaust and then\n#DF from the stack guard.\n\nIt turned out that pti_clone_pgtable() had alignment assumptions on\nthe start address, notably it hard assumes start is PMD aligned. This\nis true on x86_64, but very much not true on i386.\n\nThese assumptions can cause the end condition to malfunction, leading\nto a 'short' clone. Guess what happens when the user mapping has a\nshort copy of the entry text?\n\nUse the correct increment form for addr to avoid alignment\nassumptions.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44965', 'https://git.kernel.org/linus/41e71dbb0e0a0fe214545fe64af031303a08524c (6.11-rc2)', 'https://git.kernel.org/stable/c/18da1b27ce16a14a9b636af9232acb4fb24f4c9e', 'https://git.kernel.org/stable/c/25a727233a40a9b33370eec9f0cad67d8fd312f8', 'https://git.kernel.org/stable/c/41e71dbb0e0a0fe214545fe64af031303a08524c', 'https://git.kernel.org/stable/c/4d143ae782009b43b4f366402e5c37f59d4e4346', 'https://git.kernel.org/stable/c/5c580c1050bcbc15c3e78090859d798dcf8c9763', 'https://git.kernel.org/stable/c/ca07aab70dd3b5e7fddb62d7a6ecd7a7d6d0b2ed', 'https://git.kernel.org/stable/c/d00c9b4bbc442d99e1dafbdfdab848bc1ead73f6', 'https://git.kernel.org/stable/c/df3eecb5496f87263d171b254ca6e2758ab3c35c', 'https://linux.oracle.com/cve/CVE-2024-44965.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090415-CVE-2024-44965-d41d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44965', 'https://www.cve.org/CVERecord?id=CVE-2024-44965'], 'PublishedDate': '2024-09-04T19:15:30.99Z', 'LastModifiedDate': '2024-10-04T16:17:15.23Z'}, {'VulnerabilityID': 'CVE-2024-44966', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44966', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: binfmt_flat: Fix corruption when not offsetting data start', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_flat: Fix corruption when not offsetting data start\n\nCommit 04d82a6d0881 ("binfmt_flat: allow not offsetting data start")\nintroduced a RISC-V specific variant of the FLAT format which does\nnot allocate any space for the (obsolete) array of shared library\npointers. However, it did not disable the code which initializes the\narray, resulting in the corruption of sizeof(long) bytes before the DATA\nsegment, generally the end of the TEXT segment.\n\nIntroduce MAX_SHARED_LIBS_UPDATE which depends on the state of\nCONFIG_BINFMT_FLAT_NO_DATA_START_OFFSET to guard the initialization of\nthe shared library pointer region so that it will only be initialized\nif space is reserved for it.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44966', 'https://git.kernel.org/linus/3eb3cd5992f7a0c37edc8d05b4c38c98758d8671 (6.11-rc4)', 'https://git.kernel.org/stable/c/3a684499261d0f7ed5ee72793025c88c2276809c', 'https://git.kernel.org/stable/c/3eb3cd5992f7a0c37edc8d05b4c38c98758d8671', 'https://git.kernel.org/stable/c/49df34d2b7da9e57c839555a2f7877291ce45ad1', 'https://git.kernel.org/stable/c/9350ba06ee61db392c486716ac68ecc20e030f7c', 'https://git.kernel.org/stable/c/af65d5383854cc3f172a7d0843b628758bf462c8', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-44966-3aac@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44966', 'https://www.cve.org/CVERecord?id=CVE-2024-44966'], 'PublishedDate': '2024-09-04T19:15:31.06Z', 'LastModifiedDate': '2024-10-04T16:15:30.047Z'}, {'VulnerabilityID': 'CVE-2024-44967', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44967', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/mgag200: Bind I2C lifetime to DRM device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mgag200: Bind I2C lifetime to DRM device\n\nManaged cleanup with devm_add_action_or_reset() will release the I2C\nadapter when the underlying Linux device goes away. But the connector\nstill refers to it, so this cleanup leaves behind a stale pointer\nin struct drm_connector.ddc.\n\nBind the lifetime of the I2C adapter to the connector's lifetime by\nusing DRM's managed release. When the DRM device goes away (after\nthe Linux device) DRM will first clean up the connector and then\nclean up the I2C adapter.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44967', 'https://git.kernel.org/linus/eb1ae34e48a09b7a1179c579aed042b032e408f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/55a6916db77102765b22855d3a0add4751988b7c', 'https://git.kernel.org/stable/c/81d34df843620e902dd04aa9205c875833d61c17', 'https://git.kernel.org/stable/c/9d96b91e03cba9dfcb4ac370c93af4dbc47d5191', 'https://git.kernel.org/stable/c/eb1ae34e48a09b7a1179c579aed042b032e408f4', 'https://lore.kernel.org/linux-cve-announce/2024090453-CVE-2024-44967-dd14@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44967', 'https://www.cve.org/CVERecord?id=CVE-2024-44967'], 'PublishedDate': '2024-09-04T19:15:31.117Z', 'LastModifiedDate': '2024-10-03T18:21:17.23Z'}, {'VulnerabilityID': 'CVE-2024-44969', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44969', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/sclp: Prevent release of buffer in I/O', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/sclp: Prevent release of buffer in I/O\n\nWhen a task waiting for completion of a Store Data operation is\ninterrupted, an attempt is made to halt this operation. If this attempt\nfails due to a hardware or firmware problem, there is a chance that the\nSCLP facility might store data into buffers referenced by the original\noperation at a later time.\n\nHandle this situation by not releasing the referenced data buffers if\nthe halt attempt fails. For current use cases, this might result in a\nleak of few pages of memory in case of a rare hardware/firmware\nmalfunction.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44969', 'https://git.kernel.org/linus/bf365071ea92b9579d5a272679b74052a5643e35 (6.11-rc1)', 'https://git.kernel.org/stable/c/1e8b7fb427af6b2ddd54eff66a6b428a81c96633', 'https://git.kernel.org/stable/c/1ec5ea9e25f582fd6999393e2f2c3bf56f234e05', 'https://git.kernel.org/stable/c/2429ea3b4330e3653b72b210a0d5f2a717359506', 'https://git.kernel.org/stable/c/46f67233b011385d53cf14d272431755de3a7c79', 'https://git.kernel.org/stable/c/7a7e60ed23d471a07dbbe72565d2992ee8244bbe', 'https://git.kernel.org/stable/c/a3e52a4c22c846858a6875e1c280030a3849e148', 'https://git.kernel.org/stable/c/a88a49473c94ccfd8dce1e766aacf3c627278463', 'https://git.kernel.org/stable/c/bf365071ea92b9579d5a272679b74052a5643e35', 'https://linux.oracle.com/cve/CVE-2024-44969.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090456-CVE-2024-44969-48bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44969', 'https://www.cve.org/CVERecord?id=CVE-2024-44969'], 'PublishedDate': '2024-09-04T19:15:31.24Z', 'LastModifiedDate': '2024-10-03T17:38:41.333Z'}, {'VulnerabilityID': 'CVE-2024-44970', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44970', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink\n\nWhen all the strides in a WQE have been consumed, the WQE is unlinked\nfrom the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible\nto receive CQEs with 0 consumed strides for the same WQE even after the\nWQE is fully consumed and unlinked. This triggers an additional unlink\nfor the same wqe which corrupts the linked list.\n\nFix this scenario by accepting 0 sized consumed strides without\nunlinking the WQE again.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44970', 'https://git.kernel.org/linus/fba8334721e266f92079632598e46e5f89082f30 (6.11-rc1)', 'https://git.kernel.org/stable/c/50d8009a0ac02c3311b23a0066511f8337bd88d9', 'https://git.kernel.org/stable/c/650e24748e1e0a7ff91d5c72b72a2f2a452b5b76', 'https://git.kernel.org/stable/c/7b379353e9144e1f7460ff15f39862012c9d0d78', 'https://git.kernel.org/stable/c/fba8334721e266f92079632598e46e5f89082f30', 'https://lore.kernel.org/linux-cve-announce/2024090456-CVE-2024-44970-f687@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44970', 'https://www.cve.org/CVERecord?id=CVE-2024-44970'], 'PublishedDate': '2024-09-04T19:15:31.307Z', 'LastModifiedDate': '2024-10-03T14:22:06.003Z'}, {'VulnerabilityID': 'CVE-2024-44971', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44971', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()\n\nbcm_sf2_mdio_register() calls of_phy_find_device() and then\nphy_device_remove() in a loop to remove existing PHY devices.\nof_phy_find_device() eventually calls bus_find_device(), which calls\nget_device() on the returned struct device * to increment the refcount.\nThe current implementation does not decrement the refcount, which causes\nmemory leak.\n\nThis commit adds the missing phy_device_free() call to decrement the\nrefcount via put_device() to balance the refcount.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44971', 'https://git.kernel.org/linus/e3862093ee93fcfbdadcb7957f5f8974fffa806a (6.11-rc3)', 'https://git.kernel.org/stable/c/7feef10768ea71d468d9bbc1e0d14c461876768c', 'https://git.kernel.org/stable/c/a7d2808d67570e6acae45c2a96e0d59986888e4c', 'https://git.kernel.org/stable/c/b7b8d9f5e679af60c94251fd6728dde34be69a71', 'https://git.kernel.org/stable/c/c05516c072903f6fb9134b8e7e1ad4bffcdc4819', 'https://git.kernel.org/stable/c/e3862093ee93fcfbdadcb7957f5f8974fffa806a', 'https://git.kernel.org/stable/c/f3d5efe18a11f94150fee8b3fda9d62079af640a', 'https://lore.kernel.org/linux-cve-announce/2024090457-CVE-2024-44971-eb75@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44971', 'https://www.cve.org/CVERecord?id=CVE-2024-44971'], 'PublishedDate': '2024-09-04T19:15:31.367Z', 'LastModifiedDate': '2024-09-05T17:54:36.607Z'}, {'VulnerabilityID': 'CVE-2024-44972', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44972', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: do not clear page dirty inside extent_write_locked_range()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not clear page dirty inside extent_write_locked_range()\n\n[BUG]\nFor subpage + zoned case, the following workload can lead to rsv data\nleak at unmount time:\n\n # mkfs.btrfs -f -s 4k $dev\n # mount $dev $mnt\n # fsstress -w -n 8 -d $mnt -s 1709539240\n 0/0: fiemap - no filename\n 0/1: copyrange read - no filename\n 0/2: write - no filename\n 0/3: rename - no source filename\n 0/4: creat f0 x:0 0 0\n 0/4: creat add id=0,parent=-1\n 0/5: writev f0[259 1 0 0 0 0] [778052,113,965] 0\n 0/6: ioctl(FIEMAP) f0[259 1 0 0 224 887097] [1294220,2291618343991484791,0x10000] -1\n 0/7: dwrite - xfsctl(XFS_IOC_DIOINFO) f0[259 1 0 0 224 887097] return 25, fallback to stat()\n 0/7: dwrite f0[259 1 0 0 224 887097] [696320,102400] 0\n # umount $mnt\n\nThe dmesg includes the following rsv leak detection warning (all call\ntrace skipped):\n\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8653 btrfs_destroy_inode+0x1e0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8654 btrfs_destroy_inode+0x1a8/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8660 btrfs_destroy_inode+0x1a0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): last unmount of filesystem 1b4abba9-de34-4f07-9e7f-157cf12a18d6\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info DATA has 268218368 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=204800, pinned=0, reserved=0, may_use=12288, readonly=0 zone_unusable=0\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info METADATA has 267796480 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=131072, pinned=0, reserved=0, may_use=262144, readonly=0 zone_unusable=245760\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n\nAbove $dev is a tcmu-runner emulated zoned HDD, which has a max zone\nappend size of 64K, and the system has 64K page size.\n\n[CAUSE]\nI have added several trace_printk() to show the events (header skipped):\n\n > btrfs_dirty_pages: r/i=5/259 dirty start=774144 len=114688\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=720896 off_in_page=53248 len_in_page=12288\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=786432 off_in_page=0 len_in_page=65536\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=851968 off_in_page=0 len_in_page=36864\n\nThe above lines show our buffered write has dirtied 3 pages of inode\n259 of root 5:\n\n 704K 768K 832K 896K\n I |////I/////////////////I///////////| I\n 756K 868K\n\n |///| is the dirtied range using subpage bitmaps. and 'I' is the page\n boundary.\n\n Meanwhile all three pages (704K, 768K, 832K) have their PageDirty\n flag set.\n\n > btrfs_direct_write: r/i=5/259 start dio filepos=696320 len=102400\n\nThen direct IO writ\n---truncated---", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44972', 'https://git.kernel.org/linus/97713b1a2ced1e4a2a6c40045903797ebd44d7e0 (6.11-rc1)', 'https://git.kernel.org/stable/c/97713b1a2ced1e4a2a6c40045903797ebd44d7e0', 'https://git.kernel.org/stable/c/ba4dedb71356638d8284e34724daca944be70368', 'https://git.kernel.org/stable/c/d3b403209f767e5857c1b9fda66726e6e6ffc99f', 'https://lore.kernel.org/linux-cve-announce/2024090457-CVE-2024-44972-23b5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44972', 'https://www.cve.org/CVERecord?id=CVE-2024-44972'], 'PublishedDate': '2024-09-04T19:15:31.43Z', 'LastModifiedDate': '2024-10-03T16:10:12.077Z'}, {'VulnerabilityID': 'CVE-2024-44973', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44973', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm, slub: do not call do_slab_free for kfence object', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: do not call do_slab_free for kfence object\n\nIn 782f8906f805 the freeing of kfence objects was moved from deep\ninside do_slab_free to the wrapper functions outside. This is a nice\nchange, but unfortunately it missed one spot in __kmem_cache_free_bulk.\n\nThis results in a crash like this:\n\nBUG skbuff_head_cache (Tainted: G S B E ): Padding overwritten. 0xffff88907fea0f00-0xffff88907fea0fff @offset=3840\n\nslab_err (mm/slub.c:1129)\nfree_to_partial_list (mm/slub.c:? mm/slub.c:4036)\nslab_pad_check (mm/slub.c:864 mm/slub.c:1290)\ncheck_slab (mm/slub.c:?)\nfree_to_partial_list (mm/slub.c:3171 mm/slub.c:4036)\nkmem_cache_alloc_bulk (mm/slub.c:? mm/slub.c:4495 mm/slub.c:4586 mm/slub.c:4635)\nnapi_build_skb (net/core/skbuff.c:348 net/core/skbuff.c:527 net/core/skbuff.c:549)\n\nAll the other callers to do_slab_free appear to be ok.\n\nAdd a kfence_free check in __kmem_cache_free_bulk to avoid the crash.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44973', 'https://git.kernel.org/linus/a371d558e6f3aed977a8a7346350557de5d25190 (6.11-rc3)', 'https://git.kernel.org/stable/c/a371d558e6f3aed977a8a7346350557de5d25190', 'https://git.kernel.org/stable/c/b35cd7f1e969aaa63e6716d82480f6b8a3230949', 'https://lore.kernel.org/linux-cve-announce/2024090425-CVE-2024-44973-a92d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44973', 'https://www.cve.org/CVERecord?id=CVE-2024-44973'], 'PublishedDate': '2024-09-04T19:15:31.487Z', 'LastModifiedDate': '2024-10-03T14:23:09.147Z'}, {'VulnerabilityID': 'CVE-2024-44974', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44974', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: avoid possible UaF when selecting endp', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: avoid possible UaF when selecting endp\n\nselect_local_address() and select_signal_address() both select an\nendpoint entry from the list inside an RCU protected section, but return\na reference to it, to be read later on. If the entry is dereferenced\nafter the RCU unlock, reading info could cause a Use-after-Free.\n\nA simple solution is to copy the required info while inside the RCU\nprotected section to avoid any risk of UaF later. The address ID might\nneed to be modified later to handle the ID0 case later, so a copy seems\nOK to deal with.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44974', 'https://git.kernel.org/linus/48e50dcbcbaaf713d82bf2da5c16aeced94ad07d (6.11-rc5)', 'https://git.kernel.org/stable/c/0201d65d9806d287a00e0ba96f0321835631f63f', 'https://git.kernel.org/stable/c/2b4f46f9503633dade75cb796dd1949d0e6581a1', 'https://git.kernel.org/stable/c/48e50dcbcbaaf713d82bf2da5c16aeced94ad07d', 'https://git.kernel.org/stable/c/9a9afbbc3fbfca4975eea4aa5b18556db5a0c0b8', 'https://git.kernel.org/stable/c/ddee5b4b6a1cc03c1e9921cf34382e094c2009f1', 'https://git.kernel.org/stable/c/f2c865e9e3ca44fc06b5f73b29a954775e4dbb38', 'https://lore.kernel.org/linux-cve-announce/2024090440-CVE-2024-44974-dbe8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44974', 'https://www.cve.org/CVERecord?id=CVE-2024-44974'], 'PublishedDate': '2024-09-04T20:15:07.1Z', 'LastModifiedDate': '2024-09-12T12:15:51.397Z'}, {'VulnerabilityID': 'CVE-2024-44975', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44975', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cgroup/cpuset: fix panic caused by partcmd_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: fix panic caused by partcmd_update\n\nWe find a bug as below:\nBUG: unable to handle page fault for address: 00000003\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 3 PID: 358 Comm: bash Tainted: G W I 6.6.0-10893-g60d6\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/4\nRIP: 0010:partition_sched_domains_locked+0x483/0x600\nCode: 01 48 85 d2 74 0d 48 83 05 29 3f f8 03 01 f3 48 0f bc c2 89 c0 48 9\nRSP: 0018:ffffc90000fdbc58 EFLAGS: 00000202\nRAX: 0000000100000003 RBX: ffff888100b3dfa0 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000002fe80\nRBP: ffff888100b3dfb0 R08: 0000000000000001 R09: 0000000000000000\nR10: ffffc90000fdbcb0 R11: 0000000000000004 R12: 0000000000000002\nR13: ffff888100a92b48 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f44a5425740(0000) GS:ffff888237d80000(0000) knlGS:0000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000100030973 CR3: 000000010722c000 CR4: 00000000000006e0\nCall Trace:\n \n ? show_regs+0x8c/0xa0\n ? __die_body+0x23/0xa0\n ? __die+0x3a/0x50\n ? page_fault_oops+0x1d2/0x5c0\n ? partition_sched_domains_locked+0x483/0x600\n ? search_module_extables+0x2a/0xb0\n ? search_exception_tables+0x67/0x90\n ? kernelmode_fixup_or_oops+0x144/0x1b0\n ? __bad_area_nosemaphore+0x211/0x360\n ? up_read+0x3b/0x50\n ? bad_area_nosemaphore+0x1a/0x30\n ? exc_page_fault+0x890/0xd90\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? asm_exc_page_fault+0x26/0x30\n ? partition_sched_domains_locked+0x483/0x600\n ? partition_sched_domains_locked+0xf0/0x600\n rebuild_sched_domains_locked+0x806/0xdc0\n update_partition_sd_lb+0x118/0x130\n cpuset_write_resmask+0xffc/0x1420\n cgroup_file_write+0xb2/0x290\n kernfs_fop_write_iter+0x194/0x290\n new_sync_write+0xeb/0x160\n vfs_write+0x16f/0x1d0\n ksys_write+0x81/0x180\n __x64_sys_write+0x21/0x30\n x64_sys_call+0x2f25/0x4630\n do_syscall_64+0x44/0xb0\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\nRIP: 0033:0x7f44a553c887\n\nIt can be reproduced with cammands:\ncd /sys/fs/cgroup/\nmkdir test\ncd test/\necho +cpuset > ../cgroup.subtree_control\necho root > cpuset.cpus.partition\ncat /sys/fs/cgroup/cpuset.cpus.effective\n0-3\necho 0-3 > cpuset.cpus // taking away all cpus from root\n\nThis issue is caused by the incorrect rebuilding of scheduling domains.\nIn this scenario, test/cpuset.cpus.partition should be an invalid root\nand should not trigger the rebuilding of scheduling domains. When calling\nupdate_parent_effective_cpumask with partcmd_update, if newmask is not\nnull, it should recheck newmask whether there are cpus is available\nfor parect/cs that has tasks.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44975', 'https://git.kernel.org/linus/959ab6350add903e352890af53e86663739fcb9a (6.11-rc5)', 'https://git.kernel.org/stable/c/73d6c6cf8ef6a3c532aa159f5114077746a372d6', 'https://git.kernel.org/stable/c/959ab6350add903e352890af53e86663739fcb9a', 'https://lore.kernel.org/linux-cve-announce/2024090442-CVE-2024-44975-7c21@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44975', 'https://www.cve.org/CVERecord?id=CVE-2024-44975'], 'PublishedDate': '2024-09-04T20:15:07.16Z', 'LastModifiedDate': '2024-10-03T14:32:31.677Z'}, {'VulnerabilityID': 'CVE-2024-44977', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44977', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Validate TA binary size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Validate TA binary size\n\nAdd TA binary size validation to avoid OOB write.\n\n(cherry picked from commit c0a04e3570d72aaf090962156ad085e37c62e442)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44977', 'https://git.kernel.org/linus/c99769bceab4ecb6a067b9af11f9db281eea3e2a (6.11-rc5)', 'https://git.kernel.org/stable/c/50553ea7cbd3344fbf40afb065f6a2d38171c1ad', 'https://git.kernel.org/stable/c/5ab8793b9a6cc059f503cbe6fe596f80765e0f19', 'https://git.kernel.org/stable/c/c99769bceab4ecb6a067b9af11f9db281eea3e2a', 'https://git.kernel.org/stable/c/e562415248f402203e7fb6d8c38c1b32fa99220f', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44977-7f6b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44977', 'https://www.cve.org/CVERecord?id=CVE-2024-44977'], 'PublishedDate': '2024-09-04T20:15:07.29Z', 'LastModifiedDate': '2024-10-10T17:47:59.593Z'}, {'VulnerabilityID': 'CVE-2024-44978', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44978', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Free job before xe_exec_queue_put', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Free job before xe_exec_queue_put\n\nFree job depends on job->vm being valid, the last xe_exec_queue_put can\ndestroy the VM. Prevent UAF by freeing job before xe_exec_queue_put.\n\n(cherry picked from commit 32a42c93b74c8ca6d0915ea3eba21bceff53042f)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44978', 'https://git.kernel.org/linus/9e7f30563677fbeff62d368d5d2a5ac7aaa9746a (6.11-rc5)', 'https://git.kernel.org/stable/c/98aa0330f200b9b8fb9e1298e006eda57a13351c', 'https://git.kernel.org/stable/c/9e7f30563677fbeff62d368d5d2a5ac7aaa9746a', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44978-096b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44978', 'https://www.cve.org/CVERecord?id=CVE-2024-44978'], 'PublishedDate': '2024-09-04T20:15:07.343Z', 'LastModifiedDate': '2024-09-10T16:51:19.813Z'}, {'VulnerabilityID': 'CVE-2024-44979', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44979', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Fix missing workqueue destroy in xe_gt_pagefault', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix missing workqueue destroy in xe_gt_pagefault\n\nOn driver reload we never free up the memory for the pagefault and\naccess counter workqueues. Add those destroy calls here.\n\n(cherry picked from commit 7586fc52b14e0b8edd0d1f8a434e0de2078b7b2b)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44979', 'https://git.kernel.org/linus/a6f78359ac75f24cac3c1bdd753c49c1877bcd82 (6.11-rc5)', 'https://git.kernel.org/stable/c/a6f78359ac75f24cac3c1bdd753c49c1877bcd82', 'https://git.kernel.org/stable/c/b09ef3b762a7fc641fb2f89afd3ebdb65b8ba1b9', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44979-74c3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44979', 'https://www.cve.org/CVERecord?id=CVE-2024-44979'], 'PublishedDate': '2024-09-04T20:15:07.4Z', 'LastModifiedDate': '2024-10-10T17:44:36.417Z'}, {'VulnerabilityID': 'CVE-2024-44980', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44980', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Fix opregion leak', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix opregion leak\n\nBeing part o the display, ideally the setup and cleanup would be done by\ndisplay itself. However this is a bigger refactor that needs to be done\non both i915 and xe. For now, just fix the leak:\n\nunreferenced object 0xffff8881a0300008 (size 192):\n comm "modprobe", pid 4354, jiffies 4295647021\n hex dump (first 32 bytes):\n 00 00 87 27 81 88 ff ff 18 80 9b 00 00 c9 ff ff ...\'............\n 18 81 9b 00 00 c9 ff ff 00 00 00 00 00 00 00 00 ................\n backtrace (crc 99260e31):\n [] kmemleak_alloc+0x4b/0x80\n [] kmalloc_trace_noprof+0x312/0x3d0\n [] intel_opregion_setup+0x89/0x700 [xe]\n [] xe_display_init_noirq+0x2f/0x90 [xe]\n [] xe_device_probe+0x7a3/0xbf0 [xe]\n [] xe_pci_probe+0x333/0x5b0 [xe]\n [] local_pci_probe+0x48/0xb0\n [] pci_device_probe+0xc8/0x280\n [] really_probe+0xf8/0x390\n [] __driver_probe_device+0x8a/0x170\n [] driver_probe_device+0x23/0xb0\n [] __driver_attach+0xc7/0x190\n [] bus_for_each_dev+0x7d/0xd0\n [] driver_attach+0x1e/0x30\n [] bus_add_driver+0x117/0x250\n\n(cherry picked from commit 6f4e43a2f771b737d991142ec4f6d4b7ff31fbb4)', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44980', 'https://git.kernel.org/linus/f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f (6.11-rc5)', 'https://git.kernel.org/stable/c/f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f', 'https://git.kernel.org/stable/c/f7ecdd9853dd9f34e7cdfdadfb70b8f40644ebb4', 'https://lore.kernel.org/linux-cve-announce/2024090443-CVE-2024-44980-d1ba@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44980', 'https://www.cve.org/CVERecord?id=CVE-2024-44980'], 'PublishedDate': '2024-09-04T20:15:07.46Z', 'LastModifiedDate': '2024-10-10T17:42:53.433Z'}, {'VulnerabilityID': 'CVE-2024-44982', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44982', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: cleanup FB if dpu_format_populate_layout fails\n\nIf the dpu_format_populate_layout() fails, then FB is prepared, but not\ncleaned up. This ends up leaking the pin_count on the GEM object and\ncauses a splat during DRM file closure:\n\nmsm_obj->pin_count\nWARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc\n[...]\nCall trace:\n update_lru_locked+0xc4/0xcc\n put_pages+0xac/0x100\n msm_gem_free_object+0x138/0x180\n drm_gem_object_free+0x1c/0x30\n drm_gem_object_handle_put_unlocked+0x108/0x10c\n drm_gem_object_release_handle+0x58/0x70\n idr_for_each+0x68/0xec\n drm_gem_release+0x28/0x40\n drm_file_free+0x174/0x234\n drm_release+0xb0/0x160\n __fput+0xc0/0x2c8\n __fput_sync+0x50/0x5c\n __arm64_sys_close+0x38/0x7c\n invoke_syscall+0x48/0x118\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x4c/0x120\n el0t_64_sync_handler+0x100/0x12c\n el0t_64_sync+0x190/0x194\nirq event stamp: 129818\nhardirqs last enabled at (129817): [] console_unlock+0x118/0x124\nhardirqs last disabled at (129818): [] el1_dbg+0x24/0x8c\nsoftirqs last enabled at (129808): [] handle_softirqs+0x4c8/0x4e8\nsoftirqs last disabled at (129785): [] __do_softirq+0x14/0x20\n\nPatchwork: https://patchwork.freedesktop.org/patch/600714/', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44982', 'https://git.kernel.org/linus/bfa1a6283be390947d3649c482e5167186a37016 (6.11-rc5)', 'https://git.kernel.org/stable/c/02193c70723118889281f75b88722b26b58bf4ae', 'https://git.kernel.org/stable/c/7ecf85542169012765e4c2817cd3be6c2e009962', 'https://git.kernel.org/stable/c/9b8b65211a880af8fe8330a101e1e239a2d4008f', 'https://git.kernel.org/stable/c/a3c5815b07f4ee19d0b7e2ddf91ff9f03ecbf27d', 'https://git.kernel.org/stable/c/bfa1a6283be390947d3649c482e5167186a37016', 'https://lore.kernel.org/linux-cve-announce/2024090444-CVE-2024-44982-dd24@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44982', 'https://www.cve.org/CVERecord?id=CVE-2024-44982'], 'PublishedDate': '2024-09-04T20:15:07.593Z', 'LastModifiedDate': '2024-10-10T17:09:54.35Z'}, {'VulnerabilityID': 'CVE-2024-44983', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44983', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: flowtable: validate vlan header', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: validate vlan header\n\nEnsure there is sufficient room to access the protocol field of the\nVLAN header, validate it once before the flowtable lookup.\n\n=====================================================\nBUG: KMSAN: uninit-value in nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_ingress include/linux/netfilter_netdev.h:34 [inline]\n nf_ingress net/core/dev.c:5440 [inline]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44983', 'https://git.kernel.org/linus/6ea14ccb60c8ab829349979b22b58a941ec4a3ee (6.11-rc5)', 'https://git.kernel.org/stable/c/0279c35d242d037abeb73d60d06a6d1bb7f672d9', 'https://git.kernel.org/stable/c/043a18bb6cf16adaa2f8642acfde6e8956a9caaa', 'https://git.kernel.org/stable/c/6ea14ccb60c8ab829349979b22b58a941ec4a3ee', 'https://git.kernel.org/stable/c/c05155cc455785916164aa5e1b4605a2ae946537', 'https://git.kernel.org/stable/c/d9384ae7aec46036d248d1c2c2757e471ab486c3', 'https://lore.kernel.org/linux-cve-announce/2024090444-CVE-2024-44983-dcdd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44983', 'https://www.cve.org/CVERecord?id=CVE-2024-44983'], 'PublishedDate': '2024-09-04T20:15:07.657Z', 'LastModifiedDate': '2024-09-10T16:57:55.11Z'}, {'VulnerabilityID': 'CVE-2024-44984', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44984', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix double DMA unmapping for XDP_REDIRECT\n\nRemove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT\ncode path. This should have been removed when we let the page pool\nhandle the DMA mapping. This bug causes the warning:\n\nWARNING: CPU: 7 PID: 59 at drivers/iommu/dma-iommu.c:1198 iommu_dma_unmap_page+0xd5/0x100\nCPU: 7 PID: 59 Comm: ksoftirqd/7 Tainted: G W 6.8.0-1010-gcp #11-Ubuntu\nHardware name: Dell Inc. PowerEdge R7525/0PYVT1, BIOS 2.15.2 04/02/2024\nRIP: 0010:iommu_dma_unmap_page+0xd5/0x100\nCode: 89 ee 48 89 df e8 cb f2 69 ff 48 83 c4 08 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 c9 31 f6 31 ff 45 31 c0 e9 ab 17 71 00 <0f> 0b 48 83 c4 08 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 c9\nRSP: 0018:ffffab1fc0597a48 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff99ff838280c8 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffab1fc0597a78 R08: 0000000000000002 R09: ffffab1fc0597c1c\nR10: ffffab1fc0597cd3 R11: ffff99ffe375acd8 R12: 00000000e65b9000\nR13: 0000000000000050 R14: 0000000000001000 R15: 0000000000000002\nFS: 0000000000000000(0000) GS:ffff9a06efb80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000565c34c37210 CR3: 00000005c7e3e000 CR4: 0000000000350ef0\n? show_regs+0x6d/0x80\n? __warn+0x89/0x150\n? iommu_dma_unmap_page+0xd5/0x100\n? report_bug+0x16a/0x190\n? handle_bug+0x51/0xa0\n? exc_invalid_op+0x18/0x80\n? iommu_dma_unmap_page+0xd5/0x100\n? iommu_dma_unmap_page+0x35/0x100\ndma_unmap_page_attrs+0x55/0x220\n? bpf_prog_4d7e87c0d30db711_xdp_dispatcher+0x64/0x9f\nbnxt_rx_xdp+0x237/0x520 [bnxt_en]\nbnxt_rx_pkt+0x640/0xdd0 [bnxt_en]\n__bnxt_poll_work+0x1a1/0x3d0 [bnxt_en]\nbnxt_poll+0xaa/0x1e0 [bnxt_en]\n__napi_poll+0x33/0x1e0\nnet_rx_action+0x18a/0x2f0", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44984', 'https://git.kernel.org/linus/8baeef7616d5194045c5a6b97fd1246b87c55b13 (6.11-rc5)', 'https://git.kernel.org/stable/c/8baeef7616d5194045c5a6b97fd1246b87c55b13', 'https://git.kernel.org/stable/c/95a305ba259b685780ed62ea2295aa2feb2d6c0c', 'https://git.kernel.org/stable/c/fa4e6ae38574d0fc5596272bee64727d8ab7052b', 'https://lore.kernel.org/linux-cve-announce/2024090445-CVE-2024-44984-43ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44984', 'https://www.cve.org/CVERecord?id=CVE-2024-44984'], 'PublishedDate': '2024-09-04T20:15:07.717Z', 'LastModifiedDate': '2024-10-10T16:48:56.167Z'}, {'VulnerabilityID': 'CVE-2024-44985', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44985', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipv6: prevent possible UAF in ip6_xmit()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible UAF in ip6_xmit()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand the associated dst/idev could also have been freed.\n\nWe must use rcu_read_lock() to prevent a possible UAF.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44985', 'https://git.kernel.org/linus/2d5ff7e339d04622d8282661df36151906d0e1c7 (6.11-rc5)', 'https://git.kernel.org/stable/c/124b428fe28064c809e4237b0b38e97200a8a4a8', 'https://git.kernel.org/stable/c/2d5ff7e339d04622d8282661df36151906d0e1c7', 'https://git.kernel.org/stable/c/38a21c026ed2cc7232414cb166efc1923f34af17', 'https://git.kernel.org/stable/c/975f764e96f71616b530e300c1bb2ac0ce0c2596', 'https://git.kernel.org/stable/c/fc88d6c1f2895a5775795d82ec581afdff7661d1', 'https://lore.kernel.org/linux-cve-announce/2024090445-CVE-2024-44985-2dde@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44985', 'https://www.cve.org/CVERecord?id=CVE-2024-44985'], 'PublishedDate': '2024-09-04T20:15:07.777Z', 'LastModifiedDate': '2024-09-05T17:54:11.313Z'}, {'VulnerabilityID': 'CVE-2024-44986', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44986', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipv6: fix possible UAF in ip6_finish_output2()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in ip6_finish_output2()\n\nIf skb_expand_head() returns NULL, skb has been freed\nand associated dst/idev could also have been freed.\n\nWe need to hold rcu_read_lock() to make sure the dst and\nassociated idev are alive.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44986', 'https://git.kernel.org/linus/da273b377ae0d9bd255281ed3c2adb228321687b (6.11-rc5)', 'https://git.kernel.org/stable/c/3574d28caf9a09756ae87ad1ea096c6f47b6101e', 'https://git.kernel.org/stable/c/56efc253196751ece1fc535a5b582be127b0578a', 'https://git.kernel.org/stable/c/6ab6bf731354a6fdbaa617d1ec194960db61cf3b', 'https://git.kernel.org/stable/c/da273b377ae0d9bd255281ed3c2adb228321687b', 'https://git.kernel.org/stable/c/e891b36de161fcd96f12ff83667473e5067b9037', 'https://lore.kernel.org/linux-cve-announce/2024090445-CVE-2024-44986-1197@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44986', 'https://www.cve.org/CVERecord?id=CVE-2024-44986'], 'PublishedDate': '2024-09-04T20:15:07.833Z', 'LastModifiedDate': '2024-09-05T17:54:04.127Z'}, {'VulnerabilityID': 'CVE-2024-44987', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44987', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipv6: prevent UAF in ip6_send_skb()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent UAF in ip6_send_skb()\n\nsyzbot reported an UAF in ip6_send_skb() [1]\n\nAfter ip6_local_out() has returned, we no longer can safely\ndereference rt, unless we hold rcu_read_lock().\n\nA similar issue has been fixed in commit\na688caa34beb ("ipv6: take rcu lock in rawv6_send_hdrinc()")\n\nAnother potential issue in ip6_finish_output2() is handled in a\nseparate patch.\n\n[1]\n BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\nRead of size 8 at addr ffff88806dde4858 by task syz.1.380/6530\n\nCPU: 1 UID: 0 PID: 6530 Comm: syz.1.380 Not tainted 6.11.0-rc3-syzkaller-00306-gdf6cbc62cc9b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964\n rawv6_push_pending_frames+0x75c/0x9e0 net/ipv6/raw.c:588\n rawv6_sendmsg+0x19c7/0x23c0 net/ipv6/raw.c:926\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n sock_write_iter+0x2dd/0x400 net/socket.c:1160\n do_iter_readv_writev+0x60a/0x890\n vfs_writev+0x37c/0xbb0 fs/read_write.c:971\n do_writev+0x1b1/0x350 fs/read_write.c:1018\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f936bf79e79\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f936cd7f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000014\nRAX: ffffffffffffffda RBX: 00007f936c115f80 RCX: 00007f936bf79e79\nRDX: 0000000000000001 RSI: 0000000020000040 RDI: 0000000000000004\nRBP: 00007f936bfe7916 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f936c115f80 R15: 00007fff2860a7a8\n \n\nAllocated by task 6530:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:312 [inline]\n __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:338\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3988 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_noprof+0x135/0x2a0 mm/slub.c:4044\n dst_alloc+0x12b/0x190 net/core/dst.c:89\n ip6_blackhole_route+0x59/0x340 net/ipv6/route.c:2670\n make_blackhole net/xfrm/xfrm_policy.c:3120 [inline]\n xfrm_lookup_route+0xd1/0x1c0 net/xfrm/xfrm_policy.c:3313\n ip6_dst_lookup_flow+0x13e/0x180 net/ipv6/ip6_output.c:1257\n rawv6_sendmsg+0x1283/0x23c0 net/ipv6/raw.c:898\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597\n ___sys_sendmsg net/socket.c:2651 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2680\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 45:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2252 [inline]\n slab_free mm/slub.c:4473 [inline]\n kmem_cache_free+0x145/0x350 mm/slub.c:4548\n dst_destroy+0x2ac/0x460 net/core/dst.c:124\n rcu_do_batch kernel/rcu/tree.c:2569 [inline]\n rcu_core+0xafd/0x1830 kernel/rcu/tree.\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44987', 'https://git.kernel.org/linus/faa389b2fbaaec7fd27a390b4896139f9da662e3 (6.11-rc5)', 'https://git.kernel.org/stable/c/24e93695b1239fbe4c31e224372be77f82dab69a', 'https://git.kernel.org/stable/c/571567e0277008459750f0728f246086b2659429', 'https://git.kernel.org/stable/c/9a3e55afa95ed4ac9eda112d4f918af645d72f25', 'https://git.kernel.org/stable/c/af1dde074ee2ed7dd5bdca4e7e8ba17f44e7b011', 'https://git.kernel.org/stable/c/cb5880a0de12c7f618d2bdd84e2d985f1e06ed7e', 'https://git.kernel.org/stable/c/ce2f6cfab2c637d0bd9762104023a15d0ab7c0a8', 'https://git.kernel.org/stable/c/e44bd76dd072756e674f45c5be00153f4ded68b2', 'https://git.kernel.org/stable/c/faa389b2fbaaec7fd27a390b4896139f9da662e3', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44987-f916@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44987', 'https://www.cve.org/CVERecord?id=CVE-2024-44987'], 'PublishedDate': '2024-09-04T20:15:07.89Z', 'LastModifiedDate': '2024-09-05T17:53:54.687Z'}, {'VulnerabilityID': 'CVE-2024-44988', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44988', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: mv88e6xxx: Fix out-of-bound access', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Fix out-of-bound access\n\nIf an ATU violation was caused by a CPU Load operation, the SPID could\nbe larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44988', 'https://git.kernel.org/linus/528876d867a23b5198022baf2e388052ca67c952 (6.11-rc5)', 'https://git.kernel.org/stable/c/050e7274ab2150cd212b2372595720e7b83a15bd', 'https://git.kernel.org/stable/c/18b2e833daf049223ab3c2efdf8cdee08854c484', 'https://git.kernel.org/stable/c/528876d867a23b5198022baf2e388052ca67c952', 'https://git.kernel.org/stable/c/a10d0337115a6d223a1563d853d4455f05d0b2e3', 'https://git.kernel.org/stable/c/d39f5be62f098fe367d672b4dd4bc4b2b80e08e7', 'https://git.kernel.org/stable/c/f7d8c2fabd39250cf2333fbf8eef67e837f90a5d', 'https://git.kernel.org/stable/c/f87ce03c652dba199aef15ac18ade3991db5477e', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44988-516a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44988', 'https://www.cve.org/CVERecord?id=CVE-2024-44988'], 'PublishedDate': '2024-09-04T20:15:07.96Z', 'LastModifiedDate': '2024-10-10T16:44:14.767Z'}, {'VulnerabilityID': 'CVE-2024-44989', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44989', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bonding: fix xfrm real_dev null pointer dereference', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix xfrm real_dev null pointer dereference\n\nWe shouldn't set real_dev to NULL because packets can be in transit and\nxfrm might call xdo_dev_offload_ok() in parallel. All callbacks assume\nreal_dev is set.\n\n Example trace:\n kernel: BUG: unable to handle page fault for address: 0000000000001030\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: #PF: supervisor write access in kernel mode\n kernel: #PF: error_code(0x0002) - not-present page\n kernel: PGD 0 P4D 0\n kernel: Oops: 0002 [#1] PREEMPT SMP\n kernel: CPU: 4 PID: 2237 Comm: ping Not tainted 6.7.7+ #12\n kernel: Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\n kernel: RIP: 0010:nsim_ipsec_offload_ok+0xc/0x20 [netdevsim]\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: Code: e0 0f 0b 48 83 7f 38 00 74 de 0f 0b 48 8b 47 08 48 8b 37 48 8b 78 40 e9 b2 e5 9a d7 66 90 0f 1f 44 00 00 48 8b 86 80 02 00 00 <83> 80 30 10 00 00 01 b8 01 00 00 00 c3 0f 1f 80 00 00 00 00 0f 1f\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: RSP: 0018:ffffabde81553b98 EFLAGS: 00010246\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel:\n kernel: RAX: 0000000000000000 RBX: ffff9eb404e74900 RCX: ffff9eb403d97c60\n kernel: RDX: ffffffffc090de10 RSI: ffff9eb404e74900 RDI: ffff9eb3c5de9e00\n kernel: RBP: ffff9eb3c0a42000 R08: 0000000000000010 R09: 0000000000000014\n kernel: R10: 7974203030303030 R11: 3030303030303030 R12: 0000000000000000\n kernel: R13: ffff9eb3c5de9e00 R14: ffffabde81553cc8 R15: ffff9eb404c53000\n kernel: FS: 00007f2a77a3ad00(0000) GS:ffff9eb43bd00000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 0000000000001030 CR3: 00000001122ab000 CR4: 0000000000350ef0\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: Call Trace:\n kernel: \n kernel: ? __die+0x1f/0x60\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ? page_fault_oops+0x142/0x4c0\n kernel: ? do_user_addr_fault+0x65/0x670\n kernel: ? kvm_read_and_reset_apf_flags+0x3b/0x50\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: ? exc_page_fault+0x7b/0x180\n kernel: ? asm_exc_page_fault+0x22/0x30\n kernel: ? nsim_bpf_uninit+0x50/0x50 [netdevsim]\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ? nsim_ipsec_offload_ok+0xc/0x20 [netdevsim]\n kernel: bond0: (slave eni0np1): making interface the new active one\n kernel: bond_ipsec_offload_ok+0x7b/0x90 [bonding]\n kernel: xfrm_output+0x61/0x3b0\n kernel: bond0: (slave eni0np1): bond_ipsec_add_sa_all: failed to add SA\n kernel: ip_push_pending_frames+0x56/0x80", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44989', 'https://git.kernel.org/linus/f8cde9805981c50d0c029063dc7d82821806fc44 (6.11-rc5)', 'https://git.kernel.org/stable/c/21816b696c172c19d53a30d45ee005cce246ed21', 'https://git.kernel.org/stable/c/2f72c6a66bcd7e0187ec085237fee5db27145294', 'https://git.kernel.org/stable/c/4582d4ff413a07d4ed8a4823c652dc5207760548', 'https://git.kernel.org/stable/c/7fa9243391ad2afe798ef4ea2e2851947b95754f', 'https://git.kernel.org/stable/c/89fc1dca79db5c3e7a2d589ecbf8a3661c65f436', 'https://git.kernel.org/stable/c/f8cde9805981c50d0c029063dc7d82821806fc44', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44989-8a2d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44989', 'https://www.cve.org/CVERecord?id=CVE-2024-44989'], 'PublishedDate': '2024-09-04T20:15:08.02Z', 'LastModifiedDate': '2024-09-06T16:31:22.253Z'}, {'VulnerabilityID': 'CVE-2024-44990', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44990', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bonding: fix null pointer deref in bond_ipsec_offload_ok', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix null pointer deref in bond_ipsec_offload_ok\n\nWe must check if there is an active slave before dereferencing the pointer.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44990', 'https://git.kernel.org/linus/95c90e4ad89d493a7a14fa200082e466e2548f9d (6.11-rc5)', 'https://git.kernel.org/stable/c/0707260a18312bbcd2a5668584e3692d0a29e3f6', 'https://git.kernel.org/stable/c/2f5bdd68c1ce64bda6bef4d361a3de23b04ccd59', 'https://git.kernel.org/stable/c/32a0173600c63aadaf2103bf02f074982e8602ab', 'https://git.kernel.org/stable/c/81216b9352be43f8958092d379f6dec85443c309', 'https://git.kernel.org/stable/c/95c90e4ad89d493a7a14fa200082e466e2548f9d', 'https://git.kernel.org/stable/c/b70b0ddfed31fc92c8dc722d0afafc8e14cb550c', 'https://lore.kernel.org/linux-cve-announce/2024090446-CVE-2024-44990-6b62@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44990', 'https://www.cve.org/CVERecord?id=CVE-2024-44990'], 'PublishedDate': '2024-09-04T20:15:08.087Z', 'LastModifiedDate': '2024-09-06T16:31:12.87Z'}, {'VulnerabilityID': 'CVE-2024-44991', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44991', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp: prevent concurrent execution of tcp_sk_exit_batch', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: prevent concurrent execution of tcp_sk_exit_batch\n\nIts possible that two threads call tcp_sk_exit_batch() concurrently,\nonce from the cleanup_net workqueue, once from a task that failed to clone\na new netns. In the latter case, error unwinding calls the exit handlers\nin reverse order for the \'failed\' netns.\n\ntcp_sk_exit_batch() calls tcp_twsk_purge().\nProblem is that since commit b099ce2602d8 ("net: Batch inet_twsk_purge"),\nthis function picks up twsk in any dying netns, not just the one passed\nin via exit_batch list.\n\nThis means that the error unwind of setup_net() can "steal" and destroy\ntimewait sockets belonging to the exiting netns.\n\nThis allows the netns exit worker to proceed to call\n\nWARN_ON_ONCE(!refcount_dec_and_test(&net->ipv4.tcp_death_row.tw_refcount));\n\nwithout the expected 1 -> 0 transition, which then splats.\n\nAt same time, error unwind path that is also running inet_twsk_purge()\nwill splat as well:\n\nWARNING: .. at lib/refcount.c:31 refcount_warn_saturate+0x1ed/0x210\n...\n refcount_dec include/linux/refcount.h:351 [inline]\n inet_twsk_kill+0x758/0x9c0 net/ipv4/inet_timewait_sock.c:70\n inet_twsk_deschedule_put net/ipv4/inet_timewait_sock.c:221\n inet_twsk_purge+0x725/0x890 net/ipv4/inet_timewait_sock.c:304\n tcp_sk_exit_batch+0x1c/0x170 net/ipv4/tcp_ipv4.c:3522\n ops_exit_list+0x128/0x180 net/core/net_namespace.c:178\n setup_net+0x714/0xb40 net/core/net_namespace.c:375\n copy_net_ns+0x2f0/0x670 net/core/net_namespace.c:508\n create_new_namespaces+0x3ea/0xb10 kernel/nsproxy.c:110\n\n... because refcount_dec() of tw_refcount unexpectedly dropped to 0.\n\nThis doesn\'t seem like an actual bug (no tw sockets got lost and I don\'t\nsee a use-after-free) but as erroneous trigger of debug check.\n\nAdd a mutex to force strict ordering: the task that calls tcp_twsk_purge()\nblocks other task from doing final _dec_and_test before mutex-owner has\nremoved all tw sockets of dying netns.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44991', 'https://git.kernel.org/linus/565d121b69980637f040eb4d84289869cdaabedf (6.11-rc5)', 'https://git.kernel.org/stable/c/565d121b69980637f040eb4d84289869cdaabedf', 'https://git.kernel.org/stable/c/99580ae890ec8bd98b21a2a9c6668f8f1555b62e', 'https://git.kernel.org/stable/c/e3d9de3742f4d5c47ae35f888d3023a5b54fcd2f', 'https://git.kernel.org/stable/c/f6fd2dbf584a4047ba88d1369ff91c9851261ec1', 'https://lore.kernel.org/linux-cve-announce/2024090447-CVE-2024-44991-2437@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44991', 'https://www.cve.org/CVERecord?id=CVE-2024-44991'], 'PublishedDate': '2024-09-04T20:15:08.15Z', 'LastModifiedDate': '2024-10-09T14:36:15.79Z'}, {'VulnerabilityID': 'CVE-2024-44993', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44993', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()`', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()`\n\nWhen enabling UBSAN on Raspberry Pi 5, we get the following warning:\n\n[ 387.894977] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/v3d/v3d_sched.c:320:3\n[ 387.903868] index 7 is out of range for type '__u32 [7]'\n[ 387.909692] CPU: 0 PID: 1207 Comm: kworker/u16:2 Tainted: G WC 6.10.3-v8-16k-numa #151\n[ 387.919166] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT)\n[ 387.925961] Workqueue: v3d_csd drm_sched_run_job_work [gpu_sched]\n[ 387.932525] Call trace:\n[ 387.935296] dump_backtrace+0x170/0x1b8\n[ 387.939403] show_stack+0x20/0x38\n[ 387.942907] dump_stack_lvl+0x90/0xd0\n[ 387.946785] dump_stack+0x18/0x28\n[ 387.950301] __ubsan_handle_out_of_bounds+0x98/0xd0\n[ 387.955383] v3d_csd_job_run+0x3a8/0x438 [v3d]\n[ 387.960707] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched]\n[ 387.966862] process_one_work+0x62c/0xb48\n[ 387.971296] worker_thread+0x468/0x5b0\n[ 387.975317] kthread+0x1c4/0x1e0\n[ 387.978818] ret_from_fork+0x10/0x20\n[ 387.983014] ---[ end trace ]---\n\nThis happens because the UAPI provides only seven configuration\nregisters and we are reading the eighth position of this u32 array.\n\nTherefore, fix the out-of-bounds read in `v3d_csd_job_run()` by\naccessing only seven positions on the '__u32 [7]' array. The eighth\nregister exists indeed on V3D 7.1, but it isn't currently used. That\nbeing so, let's guarantee that it remains unused and add a note that it\ncould be set in a future patch.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44993', 'https://git.kernel.org/linus/497d370a644d95a9f04271aa92cb96d32e84c770 (6.11-rc4)', 'https://git.kernel.org/stable/c/497d370a644d95a9f04271aa92cb96d32e84c770', 'https://git.kernel.org/stable/c/d656b82c4b30cf12715e6cd129d3df808fde24a7', 'https://lore.kernel.org/linux-cve-announce/2024090447-CVE-2024-44993-b6db@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44993', 'https://www.cve.org/CVERecord?id=CVE-2024-44993'], 'PublishedDate': '2024-09-04T20:15:08.257Z', 'LastModifiedDate': '2024-09-06T16:28:49.18Z'}, {'VulnerabilityID': 'CVE-2024-44995', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44995', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: hns3: fix a deadlock problem when config TC during resetting', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix a deadlock problem when config TC during resetting\n\nWhen config TC during the reset process, may cause a deadlock, the flow is\nas below:\n pf reset start\n │\n ▼\n ......\nsetup tc │\n │ ▼\n ▼ DOWN: napi_disable()\nnapi_disable()(skip) │\n │ │\n ▼ ▼\n ...... ......\n │ │\n ▼ │\nnapi_enable() │\n ▼\n UINIT: netif_napi_del()\n │\n ▼\n ......\n │\n ▼\n INIT: netif_napi_add()\n │\n ▼\n ...... global reset start\n │ │\n ▼ ▼\n UP: napi_enable()(skip) ......\n │ │\n ▼ ▼\n ...... napi_disable()\n\nIn reset process, the driver will DOWN the port and then UINIT, in this\ncase, the setup tc process will UP the port before UINIT, so cause the\nproblem. Adds a DOWN process in UINIT to fix it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44995', 'https://git.kernel.org/linus/be5e816d00a506719e9dbb1a9c861c5ced30a109 (6.11-rc4)', 'https://git.kernel.org/stable/c/195918217448a6bb7f929d6a2ffffce9f1ece1cc', 'https://git.kernel.org/stable/c/67492d4d105c0a6321b00c393eec96b9a7a97a16', 'https://git.kernel.org/stable/c/6ae2b7d63cd056f363045eb65409143e16f23ae8', 'https://git.kernel.org/stable/c/be5e816d00a506719e9dbb1a9c861c5ced30a109', 'https://git.kernel.org/stable/c/de37408d5c26fc4a296a28a0c96dcb814219bfa1', 'https://git.kernel.org/stable/c/fa1d4de7265c370e673583ac8d1bd17d21826cd9', 'https://git.kernel.org/stable/c/fc250eca15bde34c4c8f806b9d88f55bd56a992c', 'https://lore.kernel.org/linux-cve-announce/2024090448-CVE-2024-44995-16e5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44995', 'https://www.cve.org/CVERecord?id=CVE-2024-44995'], 'PublishedDate': '2024-09-04T20:15:08.353Z', 'LastModifiedDate': '2024-09-15T18:15:34.54Z'}, {'VulnerabilityID': 'CVE-2024-44996', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44996', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: vsock: fix recursive ->recvmsg calls', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: fix recursive ->recvmsg calls\n\nAfter a vsock socket has been added to a BPF sockmap, its prot->recvmsg\nhas been replaced with vsock_bpf_recvmsg(). Thus the following\nrecursiion could happen:\n\nvsock_bpf_recvmsg()\n -> __vsock_recvmsg()\n -> vsock_connectible_recvmsg()\n -> prot->recvmsg()\n -> vsock_bpf_recvmsg() again\n\nWe need to fix it by calling the original ->recvmsg() without any BPF\nsockmap logic in __vsock_recvmsg().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-674'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44996', 'https://git.kernel.org/linus/69139d2919dd4aa9a553c8245e7c63e82613e3fc (6.11-rc4)', 'https://git.kernel.org/stable/c/69139d2919dd4aa9a553c8245e7c63e82613e3fc', 'https://git.kernel.org/stable/c/921f1acf0c3cf6b1260ab57a8a6e8b3d5f3023d5', 'https://git.kernel.org/stable/c/b4ee8cf1acc5018ed1369150d7bb3e0d0f79e135', 'https://lore.kernel.org/linux-cve-announce/2024090448-CVE-2024-44996-8b26@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44996', 'https://www.cve.org/CVERecord?id=CVE-2024-44996'], 'PublishedDate': '2024-09-04T20:15:08.413Z', 'LastModifiedDate': '2024-09-16T12:21:47.37Z'}, {'VulnerabilityID': 'CVE-2024-44998', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44998', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: atm: idt77252: prevent use after free in dequeue_rx()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\natm: idt77252: prevent use after free in dequeue_rx()\n\nWe can\'t dereference "skb" after calling vcc->push() because the skb\nis released.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44998', 'https://git.kernel.org/linus/a9a18e8f770c9b0703dab93580d0b02e199a4c79 (6.11-rc4)', 'https://git.kernel.org/stable/c/09e086a5f72ea27c758b3f3b419a69000c32adc1', 'https://git.kernel.org/stable/c/1cece837e387c039225f19028df255df87a97c0d', 'https://git.kernel.org/stable/c/24cf390a5426aac9255205e9533cdd7b4235d518', 'https://git.kernel.org/stable/c/379a6a326514a3e2f71b674091dfb0e0e7522b55', 'https://git.kernel.org/stable/c/628ea82190a678a56d2ec38cda3addf3b3a6248d', 'https://git.kernel.org/stable/c/91b4850e7165a4b7180ef1e227733bcb41ccdf10', 'https://git.kernel.org/stable/c/a9a18e8f770c9b0703dab93580d0b02e199a4c79', 'https://git.kernel.org/stable/c/ef23c18ab88e33ce000d06a5c6aad0620f219bfd', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-44998-6505@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44998', 'https://www.cve.org/CVERecord?id=CVE-2024-44998'], 'PublishedDate': '2024-09-04T20:15:08.52Z', 'LastModifiedDate': '2024-09-06T16:28:16Z'}, {'VulnerabilityID': 'CVE-2024-44999', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44999', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gtp: pull network headers in gtp_dev_xmit()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: pull network headers in gtp_dev_xmit()\n\nsyzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1]\n\nWe must make sure the IPv4 or Ipv6 header is pulled in skb->head\nbefore accessing fields in them.\n\nUse pskb_inet_may_pull() to fix this issue.\n\n[1]\nBUG: KMSAN: uninit-value in ipv6_pdp_find drivers/net/gtp.c:220 [inline]\n BUG: KMSAN: uninit-value in gtp_build_skb_ip6 drivers/net/gtp.c:1229 [inline]\n BUG: KMSAN: uninit-value in gtp_dev_xmit+0x1424/0x2540 drivers/net/gtp.c:1281\n ipv6_pdp_find drivers/net/gtp.c:220 [inline]\n gtp_build_skb_ip6 drivers/net/gtp.c:1229 [inline]\n gtp_dev_xmit+0x1424/0x2540 drivers/net/gtp.c:1281\n __netdev_start_xmit include/linux/netdevice.h:4913 [inline]\n netdev_start_xmit include/linux/netdevice.h:4922 [inline]\n xmit_one net/core/dev.c:3580 [inline]\n dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3596\n __dev_queue_xmit+0x358c/0x5610 net/core/dev.c:4423\n dev_queue_xmit include/linux/netdevice.h:3105 [inline]\n packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3145 [inline]\n packet_sendmsg+0x90e3/0xa3a0 net/packet/af_packet.c:3177\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n __sys_sendto+0x685/0x830 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2212\n x64_sys_call+0x3799/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3994 [inline]\n slab_alloc_node mm/slub.c:4037 [inline]\n kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4080\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:583\n __alloc_skb+0x363/0x7b0 net/core/skbuff.c:674\n alloc_skb include/linux/skbuff.h:1320 [inline]\n alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6526\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2815\n packet_alloc_skb net/packet/af_packet.c:2994 [inline]\n packet_snd net/packet/af_packet.c:3088 [inline]\n packet_sendmsg+0x749c/0xa3a0 net/packet/af_packet.c:3177\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n __sys_sendto+0x685/0x830 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2212\n x64_sys_call+0x3799/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCPU: 0 UID: 0 PID: 7115 Comm: syz.1.515 Not tainted 6.11.0-rc1-syzkaller-00043-g94ede2a3e913 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44999', 'https://git.kernel.org/linus/3a3be7ff9224f424e485287b54be00d2c6bd9c40 (6.11-rc4)', 'https://git.kernel.org/stable/c/137d565ab89ce3584503b443bc9e00d44f482593', 'https://git.kernel.org/stable/c/1f6b62392453d8f36685d19b761307a8c5617ac1', 'https://git.kernel.org/stable/c/34ba4f29f3d9eb52dee37512059efb2afd7e966f', 'https://git.kernel.org/stable/c/3939d787139e359b77aaf9485d1e145d6713d7b9', 'https://git.kernel.org/stable/c/3a3be7ff9224f424e485287b54be00d2c6bd9c40', 'https://git.kernel.org/stable/c/3d89d0c4a1c6d4d2a755e826351b0a101dbc86f3', 'https://git.kernel.org/stable/c/cbb9a969fc190e85195d1b0f08038e7f6199044e', 'https://git.kernel.org/stable/c/f5dda8db382c5751c4e572afc7c99df7da1f83ca', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-44999-187d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44999', 'https://www.cve.org/CVERecord?id=CVE-2024-44999'], 'PublishedDate': '2024-09-04T20:15:08.59Z', 'LastModifiedDate': '2024-09-06T16:27:51.89Z'}, {'VulnerabilityID': 'CVE-2024-45000', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45000', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fs/netfs/fscache_cookie: add missing "n_accesses" check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/netfs/fscache_cookie: add missing "n_accesses" check\n\nThis fixes a NULL pointer dereference bug due to a data race which\nlooks like this:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000008\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP PTI\n CPU: 33 PID: 16573 Comm: kworker/u97:799 Not tainted 6.8.7-cm4all1-hp+ #43\n Hardware name: HP ProLiant DL380 Gen9/ProLiant DL380 Gen9, BIOS P89 10/17/2018\n Workqueue: events_unbound netfs_rreq_write_to_cache_work\n RIP: 0010:cachefiles_prepare_write+0x30/0xa0\n Code: 57 41 56 45 89 ce 41 55 49 89 cd 41 54 49 89 d4 55 53 48 89 fb 48 83 ec 08 48 8b 47 08 48 83 7f 10 00 48 89 34 24 48 8b 68 20 <48> 8b 45 08 4c 8b 38 74 45 49 8b 7f 50 e8 4e a9 b0 ff 48 8b 73 10\n RSP: 0018:ffffb4e78113bde0 EFLAGS: 00010286\n RAX: ffff976126be6d10 RBX: ffff97615cdb8438 RCX: 0000000000020000\n RDX: ffff97605e6c4c68 RSI: ffff97605e6c4c60 RDI: ffff97615cdb8438\n RBP: 0000000000000000 R08: 0000000000278333 R09: 0000000000000001\n R10: ffff97605e6c4600 R11: 0000000000000001 R12: ffff97605e6c4c68\n R13: 0000000000020000 R14: 0000000000000001 R15: ffff976064fe2c00\n FS: 0000000000000000(0000) GS:ffff9776dfd40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000005942c002 CR4: 00000000001706f0\n Call Trace:\n \n ? __die+0x1f/0x70\n ? page_fault_oops+0x15d/0x440\n ? search_module_extables+0xe/0x40\n ? fixup_exception+0x22/0x2f0\n ? exc_page_fault+0x5f/0x100\n ? asm_exc_page_fault+0x22/0x30\n ? cachefiles_prepare_write+0x30/0xa0\n netfs_rreq_write_to_cache_work+0x135/0x2e0\n process_one_work+0x137/0x2c0\n worker_thread+0x2e9/0x400\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xcc/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x30/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n Modules linked in:\n CR2: 0000000000000008\n ---[ end trace 0000000000000000 ]---\n\nThis happened because fscache_cookie_state_machine() was slow and was\nstill running while another process invoked fscache_unuse_cookie();\nthis led to a fscache_cookie_lru_do_one() call, setting the\nFSCACHE_COOKIE_DO_LRU_DISCARD flag, which was picked up by\nfscache_cookie_state_machine(), withdrawing the cookie via\ncachefiles_withdraw_cookie(), clearing cookie->cache_priv.\n\nAt the same time, yet another process invoked\ncachefiles_prepare_write(), which found a NULL pointer in this code\nline:\n\n struct cachefiles_object *object = cachefiles_cres_object(cres);\n\nThe next line crashes, obviously:\n\n struct cachefiles_cache *cache = object->volume->cache;\n\nDuring cachefiles_prepare_write(), the "n_accesses" counter is\nnon-zero (via fscache_begin_operation()). The cookie must not be\nwithdrawn until it drops to zero.\n\nThe counter is checked by fscache_cookie_state_machine() before\nswitching to FSCACHE_COOKIE_STATE_RELINQUISHING and\nFSCACHE_COOKIE_STATE_WITHDRAWING (in "case\nFSCACHE_COOKIE_STATE_FAILED"), but not for\nFSCACHE_COOKIE_STATE_LRU_DISCARDING ("case\nFSCACHE_COOKIE_STATE_ACTIVE").\n\nThis patch adds the missing check. With a non-zero access counter,\nthe function returns and the next fscache_end_cookie_access() call\nwill queue another fscache_cookie_state_machine() call to handle the\nstill-pending FSCACHE_COOKIE_DO_LRU_DISCARD.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45000', 'https://git.kernel.org/linus/f71aa06398aabc2e3eaac25acdf3d62e0094ba70 (6.11-rc4)', 'https://git.kernel.org/stable/c/0a4d41fa14b2a0efd40e350cfe8ec6a4c998ac1d', 'https://git.kernel.org/stable/c/b8a50877f68efdcc0be3fcc5116e00c31b90e45b', 'https://git.kernel.org/stable/c/dfaa39b05a6cf34a16c525a2759ee6ab26b5fef6', 'https://git.kernel.org/stable/c/f71aa06398aabc2e3eaac25acdf3d62e0094ba70', 'https://lore.kernel.org/linux-cve-announce/2024090449-CVE-2024-45000-fd6f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45000', 'https://www.cve.org/CVERecord?id=CVE-2024-45000'], 'PublishedDate': '2024-09-04T20:15:08.657Z', 'LastModifiedDate': '2024-09-06T16:27:31.003Z'}, {'VulnerabilityID': 'CVE-2024-45001', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45001', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: mana: Fix RX buf alloc_size alignment and atomic op panic', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix RX buf alloc_size alignment and atomic op panic\n\nThe MANA driver's RX buffer alloc_size is passed into napi_build_skb() to\ncreate SKB. skb_shinfo(skb) is located at the end of skb, and its alignment\nis affected by the alloc_size passed into napi_build_skb(). The size needs\nto be aligned properly for better performance and atomic operations.\nOtherwise, on ARM64 CPU, for certain MTU settings like 4000, atomic\noperations may panic on the skb_shinfo(skb)->dataref due to alignment fault.\n\nTo fix this bug, add proper alignment to the alloc_size calculation.\n\nSample panic info:\n[ 253.298819] Unable to handle kernel paging request at virtual address ffff000129ba5cce\n[ 253.300900] Mem abort info:\n[ 253.301760] ESR = 0x0000000096000021\n[ 253.302825] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 253.304268] SET = 0, FnV = 0\n[ 253.305172] EA = 0, S1PTW = 0\n[ 253.306103] FSC = 0x21: alignment fault\nCall trace:\n __skb_clone+0xfc/0x198\n skb_clone+0x78/0xe0\n raw6_local_deliver+0xfc/0x228\n ip6_protocol_deliver_rcu+0x80/0x500\n ip6_input_finish+0x48/0x80\n ip6_input+0x48/0xc0\n ip6_sublist_rcv_finish+0x50/0x78\n ip6_sublist_rcv+0x1cc/0x2b8\n ipv6_list_rcv+0x100/0x150\n __netif_receive_skb_list_core+0x180/0x220\n netif_receive_skb_list_internal+0x198/0x2a8\n __napi_poll+0x138/0x250\n net_rx_action+0x148/0x330\n handle_softirqs+0x12c/0x3a0", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45001', 'https://git.kernel.org/linus/32316f676b4ee87c0404d333d248ccf777f739bc (6.11-rc4)', 'https://git.kernel.org/stable/c/32316f676b4ee87c0404d333d248ccf777f739bc', 'https://git.kernel.org/stable/c/65f20b174ec0172f2d6bcfd8533ab9c9e7e347fa', 'https://git.kernel.org/stable/c/e6bea6a45f8a401f3d5a430bc81814f0cc8848cf', 'https://lore.kernel.org/linux-cve-announce/2024090450-CVE-2024-45001-50df@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45001', 'https://ubuntu.com/security/notices/USN-7074-1', 'https://ubuntu.com/security/notices/USN-7076-1', 'https://www.cve.org/CVERecord?id=CVE-2024-45001'], 'PublishedDate': '2024-09-04T20:15:08.71Z', 'LastModifiedDate': '2024-10-09T14:49:39.953Z'}, {'VulnerabilityID': 'CVE-2024-45002', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45002', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: rtla/osnoise: Prevent NULL dereference in error handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrtla/osnoise: Prevent NULL dereference in error handling\n\nIf the "tool->data" allocation fails then there is no need to call\nosnoise_free_top() and, in fact, doing so will lead to a NULL dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45002', 'https://git.kernel.org/linus/90574d2a675947858b47008df8d07f75ea50d0d0 (6.11-rc4)', 'https://git.kernel.org/stable/c/753f1745146e03abd17eec8eee95faffc96d743d', 'https://git.kernel.org/stable/c/90574d2a675947858b47008df8d07f75ea50d0d0', 'https://git.kernel.org/stable/c/abdb9ddaaab476e62805e36cce7b4ef8413ffd01', 'https://git.kernel.org/stable/c/fc575212c6b75d538e1a0a74f4c7e2ac73bc46ac', 'https://lore.kernel.org/linux-cve-announce/2024090450-CVE-2024-45002-c292@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45002', 'https://www.cve.org/CVERecord?id=CVE-2024-45002'], 'PublishedDate': '2024-09-04T20:15:08.763Z', 'LastModifiedDate': '2024-09-06T16:27:13.727Z'}, {'VulnerabilityID': 'CVE-2024-45003', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45003', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: vfs: Don't evict inode under the inode lru traversing context", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nvfs: Don't evict inode under the inode lru traversing context\n\nThe inode reclaiming process(See function prune_icache_sb) collects all\nreclaimable inodes and mark them with I_FREEING flag at first, at that\ntime, other processes will be stuck if they try getting these inodes\n(See function find_inode_fast), then the reclaiming process destroy the\ninodes by function dispose_list(). Some filesystems(eg. ext4 with\nea_inode feature, ubifs with xattr) may do inode lookup in the inode\nevicting callback function, if the inode lookup is operated under the\ninode lru traversing context, deadlock problems may happen.\n\nCase 1: In function ext4_evict_inode(), the ea inode lookup could happen\n if ea_inode feature is enabled, the lookup process will be stuck\n\tunder the evicting context like this:\n\n 1. File A has inode i_reg and an ea inode i_ea\n 2. getfattr(A, xattr_buf) // i_ea is added into lru // lru->i_ea\n 3. Then, following three processes running like this:\n\n PA PB\n echo 2 > /proc/sys/vm/drop_caches\n shrink_slab\n prune_dcache_sb\n // i_reg is added into lru, lru->i_ea->i_reg\n prune_icache_sb\n list_lru_walk_one\n inode_lru_isolate\n i_ea->i_state |= I_FREEING // set inode state\n inode_lru_isolate\n __iget(i_reg)\n spin_unlock(&i_reg->i_lock)\n spin_unlock(lru_lock)\n rm file A\n i_reg->nlink = 0\n iput(i_reg) // i_reg->nlink is 0, do evict\n ext4_evict_inode\n ext4_xattr_delete_inode\n ext4_xattr_inode_dec_ref_all\n ext4_xattr_inode_iget\n ext4_iget(i_ea->i_ino)\n iget_locked\n find_inode_fast\n __wait_on_freeing_inode(i_ea) ----? AA deadlock\n dispose_list // cannot be executed by prune_icache_sb\n wake_up_bit(&i_ea->i_state)\n\nCase 2: In deleted inode writing function ubifs_jnl_write_inode(), file\n deleting process holds BASEHD's wbuf->io_mutex while getting the\n\txattr inode, which could race with inode reclaiming process(The\n reclaiming process could try locking BASEHD's wbuf->io_mutex in\n\tinode evicting function), then an ABBA deadlock problem would\n\thappen as following:\n\n 1. File A has inode ia and a xattr(with inode ixa), regular file B has\n inode ib and a xattr.\n 2. getfattr(A, xattr_buf) // ixa is added into lru // lru->ixa\n 3. Then, following three processes running like this:\n\n PA PB PC\n echo 2 > /proc/sys/vm/drop_caches\n shrink_slab\n prune_dcache_sb\n // ib and ia are added into lru, lru->ixa->ib->ia\n prune_icache_sb\n list_lru_walk_one\n inode_lru_isolate\n ixa->i_state |= I_FREEING // set inode state\n inode_lru_isolate\n __iget(ib)\n spin_unlock(&ib->i_lock)\n spin_unlock(lru_lock)\n rm file B\n ib->nlink = 0\n rm file A\n iput(ia)\n ubifs_evict_inode(ia)\n ubifs_jnl_delete_inode(ia)\n ubifs_jnl_write_inode(ia)\n make_reservation(BASEHD) // Lock wbuf->io_mutex\n ubifs_iget(ixa->i_ino)\n iget_locked\n find_inode_fast\n __wait_on_freeing_inode(ixa)\n | iput(ib) // ib->nlink is 0, do evict\n | ubifs_evict_inode\n | ubifs_jnl_delete_inode(ib)\n ? ubifs_jnl_write_inode\n ABBA deadlock ?-----make_reservation(BASEHD)\n dispose_list // cannot be executed by prune_icache_sb\n wake_up_bit(&ixa->i_state)\n\nFix the possible deadlock by using new inode state flag I_LRU_ISOLATING\nto pin the inode in memory while inode_lru_isolate(\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45003', 'https://git.kernel.org/linus/2a0629834cd82f05d424bbc193374f9a43d1f87d (6.11-rc4)', 'https://git.kernel.org/stable/c/03880af02a78bc9a98b5a581f529cf709c88a9b8', 'https://git.kernel.org/stable/c/2a0629834cd82f05d424bbc193374f9a43d1f87d', 'https://git.kernel.org/stable/c/3525ad25240dfdd8c78f3470911ed10aa727aa72', 'https://git.kernel.org/stable/c/437741eba63bf4e437e2beb5583f8633556a2b98', 'https://git.kernel.org/stable/c/9063ab49c11e9518a3f2352434bb276cc8134c5f', 'https://git.kernel.org/stable/c/b9bda5f6012dd00372f3a06a82ed8971a4c57c32', 'https://git.kernel.org/stable/c/cda54ec82c0f9d05393242b20b13f69b083f7e88', 'https://lore.kernel.org/linux-cve-announce/2024090450-CVE-2024-45003-3bc2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45003', 'https://www.cve.org/CVERecord?id=CVE-2024-45003'], 'PublishedDate': '2024-09-04T20:15:08.823Z', 'LastModifiedDate': '2024-10-09T15:07:31.027Z'}, {'VulnerabilityID': 'CVE-2024-45005', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45005', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: KVM: s390: fix validity interception issue when gisa is switched off', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: fix validity interception issue when gisa is switched off\n\nWe might run into a SIE validity if gisa has been disabled either via using\nkernel parameter "kvm.use_gisa=0" or by setting the related sysfs\nattribute to N (echo N >/sys/module/kvm/parameters/use_gisa).\n\nThe validity is caused by an invalid value in the SIE control block\'s\ngisa designation. That happens because we pass the uninitialized gisa\norigin to virt_to_phys() before writing it to the gisa designation.\n\nTo fix this we return 0 in kvm_s390_get_gisa_desc() if the origin is 0.\nkvm_s390_get_gisa_desc() is used to determine which gisa designation to\nset in the SIE control block. A value of 0 in the gisa designation disables\ngisa usage.\n\nThe issue surfaces in the host kernel with the following kernel message as\nsoon a new kvm guest start is attemted.\n\nkvm: unhandled validity intercept 0x1011\nWARNING: CPU: 0 PID: 781237 at arch/s390/kvm/intercept.c:101 kvm_handle_sie_intercept+0x42e/0x4d0 [kvm]\nModules linked in: vhost_net tap tun xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT xt_tcpudp nft_compat x_tables nf_nat_tftp nf_conntrack_tftp vfio_pci_core irqbypass vhost_vsock vmw_vsock_virtio_transport_common vsock vhost vhost_iotlb kvm nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables sunrpc mlx5_ib ib_uverbs ib_core mlx5_core uvdevice s390_trng eadm_sch vfio_ccw zcrypt_cex4 mdev vfio_iommu_type1 vfio sch_fq_codel drm i2c_core loop drm_panel_orientation_quirks configfs nfnetlink lcs ctcm fsm dm_service_time ghash_s390 prng chacha_s390 libchacha aes_s390 des_s390 libdes sha3_512_s390 sha3_256_s390 sha512_s390 sha256_s390 sha1_s390 sha_common dm_mirror dm_region_hash dm_log zfcp scsi_transport_fc scsi_dh_rdac scsi_dh_emc scsi_dh_alua pkey zcrypt dm_multipath rng_core autofs4 [last unloaded: vfio_pci]\nCPU: 0 PID: 781237 Comm: CPU 0/KVM Not tainted 6.10.0-08682-gcad9f11498ea #6\nHardware name: IBM 3931 A01 701 (LPAR)\nKrnl PSW : 0704c00180000000 000003d93deb0122 (kvm_handle_sie_intercept+0x432/0x4d0 [kvm])\n R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:0 PM:0 RI:0 EA:3\nKrnl GPRS: 000003d900000027 000003d900000023 0000000000000028 000002cd00000000\n 000002d063a00900 00000359c6daf708 00000000000bebb5 0000000000001eff\n 000002cfd82e9000 000002cfd80bc000 0000000000001011 000003d93deda412\n 000003ff8962df98 000003d93de77ce0 000003d93deb011e 00000359c6daf960\nKrnl Code: 000003d93deb0112: c020fffe7259\tlarl\t%r2,000003d93de7e5c4\n 000003d93deb0118: c0e53fa8beac\tbrasl\t%r14,000003d9bd3c7e70\n #000003d93deb011e: af000000\t\tmc\t0,0\n >000003d93deb0122: a728ffea\t\tlhi\t%r2,-22\n 000003d93deb0126: a7f4fe24\t\tbrc\t15,000003d93deafd6e\n 000003d93deb012a: 9101f0b0\t\ttm\t176(%r15),1\n 000003d93deb012e: a774fe48\t\tbrc\t7,000003d93deafdbe\n 000003d93deb0132: 40a0f0ae\t\tsth\t%r10,174(%r15)\nCall Trace:\n [<000003d93deb0122>] kvm_handle_sie_intercept+0x432/0x4d0 [kvm]\n([<000003d93deb011e>] kvm_handle_sie_intercept+0x42e/0x4d0 [kvm])\n [<000003d93deacc10>] vcpu_post_run+0x1d0/0x3b0 [kvm]\n [<000003d93deaceda>] __vcpu_run+0xea/0x2d0 [kvm]\n [<000003d93dead9da>] kvm_arch_vcpu_ioctl_run+0x16a/0x430 [kvm]\n [<000003d93de93ee0>] kvm_vcpu_ioctl+0x190/0x7c0 [kvm]\n [<000003d9bd728b4e>] vfs_ioctl+0x2e/0x70\n [<000003d9bd72a092>] __s390x_sys_ioctl+0xc2/0xd0\n [<000003d9be0e9222>] __do_syscall+0x1f2/0x2e0\n [<000003d9be0f9a90>] system_call+0x70/0x98\nLast Breaking-Event-Address:\n [<000003d9bd3c7f58>] __warn_printk+0xe8/0xf0', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45005', 'https://git.kernel.org/linus/5a44bb061d04b0306f2aa8add761d86d152b9377 (6.11-rc4)', 'https://git.kernel.org/stable/c/027ac3c5092561bccce09b314a73a1c167117ef6', 'https://git.kernel.org/stable/c/051c0a558154174cfcea301a386e4c91ade83ce1', 'https://git.kernel.org/stable/c/5a44bb061d04b0306f2aa8add761d86d152b9377', 'https://lore.kernel.org/linux-cve-announce/2024090451-CVE-2024-45005-2297@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45005', 'https://www.cve.org/CVERecord?id=CVE-2024-45005'], 'PublishedDate': '2024-09-04T20:15:08.94Z', 'LastModifiedDate': '2024-10-09T15:30:03.767Z'}, {'VulnerabilityID': 'CVE-2024-45006', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45006', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: Fix Panther point NULL pointer deref at full-speed re-enumeration\n\nre-enumerating full-speed devices after a failed address device command\ncan trigger a NULL pointer dereference.\n\nFull-speed devices may need to reconfigure the endpoint 0 Max Packet Size\nvalue during enumeration. Usb core calls usb_ep0_reinit() in this case,\nwhich ends up calling xhci_configure_endpoint().\n\nOn Panther point xHC the xhci_configure_endpoint() function will\nadditionally check and reserve bandwidth in software. Other hosts do\nthis in hardware\n\nIf xHC address device command fails then a new xhci_virt_device structure\nis allocated as part of re-enabling the slot, but the bandwidth table\npointers are not set up properly here.\nThis triggers the NULL pointer dereference the next time usb_ep0_reinit()\nis called and xhci_configure_endpoint() tries to check and reserve\nbandwidth\n\n[46710.713538] usb 3-1: new full-speed USB device number 5 using xhci_hcd\n[46710.713699] usb 3-1: Device not responding to setup address.\n[46710.917684] usb 3-1: Device not responding to setup address.\n[46711.125536] usb 3-1: device not accepting address 5, error -71\n[46711.125594] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[46711.125600] #PF: supervisor read access in kernel mode\n[46711.125603] #PF: error_code(0x0000) - not-present page\n[46711.125606] PGD 0 P4D 0\n[46711.125610] Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n[46711.125615] CPU: 1 PID: 25760 Comm: kworker/1:2 Not tainted 6.10.3_2 #1\n[46711.125620] Hardware name: Gigabyte Technology Co., Ltd.\n[46711.125623] Workqueue: usb_hub_wq hub_event [usbcore]\n[46711.125668] RIP: 0010:xhci_reserve_bandwidth (drivers/usb/host/xhci.c\n\nFix this by making sure bandwidth table pointers are set up correctly\nafter a failed address device command, and additionally by avoiding\nchecking for bandwidth in cases like this where no actual endpoints are\nadded or removed, i.e. only context for default control endpoint 0 is\nevaluated.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45006', 'https://git.kernel.org/linus/af8e119f52e9c13e556be9e03f27957554a84656 (6.11-rc4)', 'https://git.kernel.org/stable/c/0f0654318e25b2c185e245ba4a591e42fabb5e59', 'https://git.kernel.org/stable/c/365ef7c4277fdd781a695c3553fa157d622d805d', 'https://git.kernel.org/stable/c/5ad898ae82412f8a689d59829804bff2999dd0ea', 'https://git.kernel.org/stable/c/6b99de301d78e1f5249e57ef2c32e1dec3df2bb1', 'https://git.kernel.org/stable/c/8fb9d412ebe2f245f13481e4624b40e651570cbd', 'https://git.kernel.org/stable/c/a57b0ebabe6862dce0a2e0f13e17941ad72fc56b', 'https://git.kernel.org/stable/c/af8e119f52e9c13e556be9e03f27957554a84656', 'https://git.kernel.org/stable/c/ef0a0e616b2789bb804a0ce5e161db03170a85b6', 'https://lore.kernel.org/linux-cve-announce/2024090451-CVE-2024-45006-6642@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45006', 'https://www.cve.org/CVERecord?id=CVE-2024-45006'], 'PublishedDate': '2024-09-04T20:15:08.997Z', 'LastModifiedDate': '2024-09-06T16:26:52.64Z'}, {'VulnerabilityID': 'CVE-2024-45007', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45007', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: char: xillybus: Don't destroy workqueue from work item running on it", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Don't destroy workqueue from work item running on it\n\nTriggered by a kref decrement, destroy_workqueue() may be called from\nwithin a work item for destroying its own workqueue. This illegal\nsituation is averted by adding a module-global workqueue for exclusive\nuse of the offending work item. Other work items continue to be queued\non per-device workqueues to ensure performance.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45007', 'https://git.kernel.org/linus/ccbde4b128ef9c73d14d0d7817d68ef795f6d131 (6.11-rc4)', 'https://git.kernel.org/stable/c/409b495f8e3300d5fba08bc817fa8825dae48cc9', 'https://git.kernel.org/stable/c/5d3567caff2a1d678aa40cc74a54e1318941fad3', 'https://git.kernel.org/stable/c/a7ad105b12256ec7fb6d6d1a0e2e60f00b7da157', 'https://git.kernel.org/stable/c/aa1a19724fa2c31e97a9be48baedd4692b265157', 'https://git.kernel.org/stable/c/ccbde4b128ef9c73d14d0d7817d68ef795f6d131', 'https://lore.kernel.org/linux-cve-announce/2024090452-CVE-2024-45007-74c8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45007', 'https://www.cve.org/CVERecord?id=CVE-2024-45007'], 'PublishedDate': '2024-09-04T20:15:09.053Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-45008', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Input: MT - limit max slots', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: MT - limit max slots\n\nsyzbot is reporting too large allocation at input_mt_init_slots(), for\nnum_slots is supplied from userspace using ioctl(UI_DEV_CREATE).\n\nSince nobody knows possible max slots, this patch chose 1024.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45008', 'https://git.kernel.org/linus/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb (6.11-rc2)', 'https://git.kernel.org/stable/c/05dd9aabd04f9b5eb04dab9bb83d8c3e982d7549', 'https://git.kernel.org/stable/c/2829c80614890624456337e47320289112785f3e', 'https://git.kernel.org/stable/c/87f610a1a7fbdb1f2e3d90b54c955bd3b8a0c322', 'https://git.kernel.org/stable/c/8f04edd554d191834e9e1349ef030318ea6b11ba', 'https://git.kernel.org/stable/c/94736334b8a25e4fae8daa6934e54a31f099be43', 'https://git.kernel.org/stable/c/95f73d01f547dfc67fda3022c51e377a0454b505', 'https://git.kernel.org/stable/c/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb', 'https://git.kernel.org/stable/c/cd19f1799c32ba7b874474b1b968815ce5364f73', 'https://lore.kernel.org/linux-cve-announce/2024090452-CVE-2024-45008-1d89@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45008', 'https://www.cve.org/CVERecord?id=CVE-2024-45008'], 'PublishedDate': '2024-09-04T20:15:09.107Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-45009', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45009', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: only decrement add_addr_accepted for MPJ req', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: only decrement add_addr_accepted for MPJ req\n\nAdding the following warning ...\n\n WARN_ON_ONCE(msk->pm.add_addr_accepted == 0)\n\n... before decrementing the add_addr_accepted counter helped to find a\nbug when running the "remove single subflow" subtest from the\nmptcp_join.sh selftest.\n\nRemoving a \'subflow\' endpoint will first trigger a RM_ADDR, then the\nsubflow closure. Before this patch, and upon the reception of the\nRM_ADDR, the other peer will then try to decrement this\nadd_addr_accepted. That\'s not correct because the attached subflows have\nnot been created upon the reception of an ADD_ADDR.\n\nA way to solve that is to decrement the counter only if the attached\nsubflow was an MP_JOIN to a remote id that was not 0, and initiated by\nthe host receiving the RM_ADDR.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45009', 'https://git.kernel.org/linus/1c1f721375989579e46741f59523e39ec9b2a9bd (6.11-rc5)', 'https://git.kernel.org/stable/c/1c1f721375989579e46741f59523e39ec9b2a9bd', 'https://git.kernel.org/stable/c/2060f1efab370b496c4903b840844ecaff324c3c', 'https://git.kernel.org/stable/c/35b31f5549ede4070566b949781e83495906b43d', 'https://git.kernel.org/stable/c/85b866e4c4e63a1d7afb58f1e24273caad03d0b7', 'https://git.kernel.org/stable/c/d20bf2c96d7ffd171299b32f562f70e5bf5dc608', 'https://lore.kernel.org/linux-cve-announce/2024091104-CVE-2024-45009-24ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45009', 'https://www.cve.org/CVERecord?id=CVE-2024-45009'], 'PublishedDate': '2024-09-11T16:15:06.427Z', 'LastModifiedDate': '2024-09-13T16:36:57.233Z'}, {'VulnerabilityID': 'CVE-2024-45010', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45010', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: mptcp: pm: only mark 'subflow' endp as available", 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: only mark \'subflow\' endp as available\n\nAdding the following warning ...\n\n WARN_ON_ONCE(msk->pm.local_addr_used == 0)\n\n... before decrementing the local_addr_used counter helped to find a bug\nwhen running the "remove single address" subtest from the mptcp_join.sh\nselftests.\n\nRemoving a \'signal\' endpoint will trigger the removal of all subflows\nlinked to this endpoint via mptcp_pm_nl_rm_addr_or_subflow() with\nrm_type == MPTCP_MIB_RMSUBFLOW. This will decrement the local_addr_used\ncounter, which is wrong in this case because this counter is linked to\n\'subflow\' endpoints, and here it is a \'signal\' endpoint that is being\nremoved.\n\nNow, the counter is decremented, only if the ID is being used outside\nof mptcp_pm_nl_rm_addr_or_subflow(), only for \'subflow\' endpoints, and\nif the ID is not 0 -- local_addr_used is not taking into account these\nones. This marking of the ID as being available, and the decrement is\ndone no matter if a subflow using this ID is currently available,\nbecause the subflow could have been closed before.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45010', 'https://git.kernel.org/linus/322ea3778965da72862cca2a0c50253aacf65fe6 (6.11-rc5)', 'https://git.kernel.org/stable/c/322ea3778965da72862cca2a0c50253aacf65fe6', 'https://git.kernel.org/stable/c/43cf912b0b0fc7b4fd12cbc735d1f5afb8e1322d', 'https://git.kernel.org/stable/c/7fdc870d08960961408a44c569f20f50940e7d4f', 'https://git.kernel.org/stable/c/9849cfc67383ceb167155186f8f8fe8a896b60b3', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45010-33ee@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45010', 'https://www.cve.org/CVERecord?id=CVE-2024-45010'], 'PublishedDate': '2024-09-11T16:15:06.483Z', 'LastModifiedDate': '2024-09-13T16:35:05.843Z'}, {'VulnerabilityID': 'CVE-2024-45011', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45011', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: char: xillybus: Check USB endpoints when probing device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Check USB endpoints when probing device\n\nEnsure, as the driver probes the device, that all endpoints that the\ndriver may attempt to access exist and are of the correct type.\n\nAll XillyUSB devices must have a Bulk IN and Bulk OUT endpoint at\naddress 1. This is verified in xillyusb_setup_base_eps().\n\nOn top of that, a XillyUSB device may have additional Bulk OUT\nendpoints. The information about these endpoints' addresses is deduced\nfrom a data structure (the IDT) that the driver fetches from the device\nwhile probing it. These endpoints are checked in setup_channels().\n\nA XillyUSB device never has more than one IN endpoint, as all data\ntowards the host is multiplexed in this single Bulk IN endpoint. This is\nwhy setup_channels() only checks OUT endpoints.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45011', 'https://git.kernel.org/linus/2374bf7558de915edc6ec8cb10ec3291dfab9594 (6.11-rc4)', 'https://git.kernel.org/stable/c/1371d32b95972d39c1e6e4bae8b6d0df1b573731', 'https://git.kernel.org/stable/c/2374bf7558de915edc6ec8cb10ec3291dfab9594', 'https://git.kernel.org/stable/c/25ee8b2908200fc862c0434e5ad483817d50ceda', 'https://git.kernel.org/stable/c/4267131278f5cc98f8db31d035d64bdbbfe18658', 'https://git.kernel.org/stable/c/5cff754692ad45d5086b75fef8cc3a99c30a1005', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45011-e729@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45011', 'https://www.cve.org/CVERecord?id=CVE-2024-45011'], 'PublishedDate': '2024-09-11T16:15:06.55Z', 'LastModifiedDate': '2024-09-13T16:36:55.757Z'}, {'VulnerabilityID': 'CVE-2024-45012', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45012', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nouveau/firmware: use dma non-coherent allocator', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/firmware: use dma non-coherent allocator\n\nCurrently, enabling SG_DEBUG in the kernel will cause nouveau to hit a\nBUG() on startup, when the iommu is enabled:\n\nkernel BUG at include/linux/scatterlist.h:187!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 7 PID: 930 Comm: (udev-worker) Not tainted 6.9.0-rc3Lyude-Test+ #30\nHardware name: MSI MS-7A39/A320M GAMING PRO (MS-7A39), BIOS 1.I0 01/22/2019\nRIP: 0010:sg_init_one+0x85/0xa0\nCode: 69 88 32 01 83 e1 03 f6 c3 03 75 20 a8 01 75 1e 48 09 cb 41 89 54\n24 08 49 89 1c 24 41 89 6c 24 0c 5b 5d 41 5c e9 7b b9 88 00 <0f> 0b 0f 0b\n0f 0b 48 8b 05 5e 46 9a 01 eb b2 66 66 2e 0f 1f 84 00\nRSP: 0018:ffffa776017bf6a0 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffffa77600d87000 RCX: 000000000000002b\nRDX: 0000000000000001 RSI: 0000000000000000 RDI: ffffa77680d87000\nRBP: 000000000000e000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffff98f4c46aa508 R11: 0000000000000000 R12: ffff98f4c46aa508\nR13: ffff98f4c46aa008 R14: ffffa77600d4a000 R15: ffffa77600d4a018\nFS: 00007feeb5aae980(0000) GS:ffff98f5c4dc0000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f22cb9a4520 CR3: 00000001043ba000 CR4: 00000000003506f0\nCall Trace:\n \n ? die+0x36/0x90\n ? do_trap+0xdd/0x100\n ? sg_init_one+0x85/0xa0\n ? do_error_trap+0x65/0x80\n ? sg_init_one+0x85/0xa0\n ? exc_invalid_op+0x50/0x70\n ? sg_init_one+0x85/0xa0\n ? asm_exc_invalid_op+0x1a/0x20\n ? sg_init_one+0x85/0xa0\n nvkm_firmware_ctor+0x14a/0x250 [nouveau]\n nvkm_falcon_fw_ctor+0x42/0x70 [nouveau]\n ga102_gsp_booter_ctor+0xb4/0x1a0 [nouveau]\n r535_gsp_oneinit+0xb3/0x15f0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? nvkm_udevice_new+0x95/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? ktime_get+0x47/0xb0\n\nFix this by using the non-coherent allocator instead, I think there\nmight be a better answer to this, but it involve ripping up some of\nAPIs using sg lists.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45012', 'https://git.kernel.org/linus/9b340aeb26d50e9a9ec99599e2a39b035fac978e (6.11-rc5)', 'https://git.kernel.org/stable/c/57ca481fca97ca4553e8c85d6a94baf4cb40c40e', 'https://git.kernel.org/stable/c/9b340aeb26d50e9a9ec99599e2a39b035fac978e', 'https://git.kernel.org/stable/c/cc29c5546c6a373648363ac49781f1d74b530707', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45012-9234@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45012', 'https://www.cve.org/CVERecord?id=CVE-2024-45012'], 'PublishedDate': '2024-09-11T16:15:06.607Z', 'LastModifiedDate': '2024-09-13T16:35:35.787Z'}, {'VulnerabilityID': 'CVE-2024-45013', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: move stopping keep-alive into nvme_uninit_ctrl()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: move stopping keep-alive into nvme_uninit_ctrl()\n\nCommit 4733b65d82bd ("nvme: start keep-alive after admin queue setup")\nmoves starting keep-alive from nvme_start_ctrl() into\nnvme_init_ctrl_finish(), but don\'t move stopping keep-alive into\nnvme_uninit_ctrl(), so keep-alive work can be started and keep pending\nafter failing to start controller, finally use-after-free is triggered if\nnvme host driver is unloaded.\n\nThis patch fixes kernel panic when running nvme/004 in case that connection\nfailure is triggered, by moving stopping keep-alive into nvme_uninit_ctrl().\n\nThis way is reasonable because keep-alive is now started in\nnvme_init_ctrl_finish().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45013', 'https://git.kernel.org/linus/a54a93d0e3599b05856971734e15418ac551a14c (6.11-rc5)', 'https://git.kernel.org/stable/c/4101af98ab573554c4225e328d506fec2a74bc54', 'https://git.kernel.org/stable/c/a54a93d0e3599b05856971734e15418ac551a14c', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45013-8efe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45013', 'https://www.cve.org/CVERecord?id=CVE-2024-45013'], 'PublishedDate': '2024-09-11T16:15:06.663Z', 'LastModifiedDate': '2024-09-13T16:35:42.49Z'}, {'VulnerabilityID': 'CVE-2024-45015', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45015', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()\n\nFor cases where the crtc's connectors_changed was set without enable/active\ngetting toggled , there is an atomic_enable() call followed by an\natomic_disable() but without an atomic_mode_set().\n\nThis results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in\nthe atomic_enable() as the dpu_encoder's connector was cleared in the\natomic_disable() but not re-assigned as there was no atomic_mode_set() call.\n\nFix the NULL ptr access by moving the assignment for atomic_enable() and also\nuse drm_atomic_get_new_connector_for_encoder() to get the connector from\nthe atomic_state.\n\nPatchwork: https://patchwork.freedesktop.org/patch/606729/", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45015', 'https://git.kernel.org/linus/aedf02e46eb549dac8db4821a6b9f0c6bf6e3990 (6.11-rc5)', 'https://git.kernel.org/stable/c/3bacf814b6a61cc683c68465f175ebd938f09c52', 'https://git.kernel.org/stable/c/3fb61718bcbe309279205d1cc275a6435611dc77', 'https://git.kernel.org/stable/c/aedf02e46eb549dac8db4821a6b9f0c6bf6e3990', 'https://lore.kernel.org/linux-cve-announce/2024091107-CVE-2024-45015-c139@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45015', 'https://www.cve.org/CVERecord?id=CVE-2024-45015'], 'PublishedDate': '2024-09-11T16:15:06.763Z', 'LastModifiedDate': '2024-09-13T16:35:58.617Z'}, {'VulnerabilityID': 'CVE-2024-45016', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1017.18~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45016', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netem: fix return value if duplicate enqueue fails', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetem: fix return value if duplicate enqueue fails\n\nThere is a bug in netem_enqueue() introduced by\ncommit 5845f706388a ("net: netem: fix skb length BUG_ON in __skb_to_sgvec")\nthat can lead to a use-after-free.\n\nThis commit made netem_enqueue() always return NET_XMIT_SUCCESS\nwhen a packet is duplicated, which can cause the parent qdisc\'s q.qlen\nto be mistakenly incremented. When this happens qlen_notify() may be\nskipped on the parent during destruction, leaving a dangling pointer\nfor some classful qdiscs like DRR.\n\nThere are two ways for the bug happen:\n\n- If the duplicated packet is dropped by rootq->enqueue() and then\n the original packet is also dropped.\n- If rootq->enqueue() sends the duplicated packet to a different qdisc\n and the original packet is dropped.\n\nIn both cases NET_XMIT_SUCCESS is returned even though no packets\nare enqueued at the netem qdisc.\n\nThe fix is to defer the enqueue of the duplicate packet until after\nthe original packet has been guaranteed to return NET_XMIT_SUCCESS.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45016', 'https://git.kernel.org/linus/c07ff8592d57ed258afee5a5e04991a48dbaf382 (6.11-rc5)', 'https://git.kernel.org/stable/c/0486d31dd8198e22b63a4730244b38fffce6d469', 'https://git.kernel.org/stable/c/52d99a69f3d556c6426048c9d481b912205919d8', 'https://git.kernel.org/stable/c/577d6c0619467fe90f7e8e57e45cb5bd9d936014', 'https://git.kernel.org/stable/c/759e3e8c4a6a6b4e52ebc4547123a457f0ce90d4', 'https://git.kernel.org/stable/c/c07ff8592d57ed258afee5a5e04991a48dbaf382', 'https://git.kernel.org/stable/c/c414000da1c2ea1ba9a5e5bb1a4ba774e51e202d', 'https://git.kernel.org/stable/c/e5bb2988a310667abed66c7d3ffa28880cf0f883', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45016-fd5a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45016', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://ubuntu.com/security/notices/USN-7071-1', 'https://ubuntu.com/security/notices/USN-7072-1', 'https://ubuntu.com/security/notices/USN-7073-1', 'https://ubuntu.com/security/notices/USN-7073-2', 'https://ubuntu.com/security/notices/USN-7074-1', 'https://ubuntu.com/security/notices/USN-7076-1', 'https://www.cve.org/CVERecord?id=CVE-2024-45016'], 'PublishedDate': '2024-09-11T16:15:06.817Z', 'LastModifiedDate': '2024-09-13T16:36:06.773Z'}, {'VulnerabilityID': 'CVE-2024-45017', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45017', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix IPsec RoCE MPV trace call', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix IPsec RoCE MPV trace call\n\nPrevent the call trace below from happening, by not allowing IPsec\ncreation over a slave, if master device doesn't support IPsec.\n\nWARNING: CPU: 44 PID: 16136 at kernel/locking/rwsem.c:240 down_read+0x75/0x94\nModules linked in: esp4_offload esp4 act_mirred act_vlan cls_flower sch_ingress mlx5_vdpa vringh vhost_iotlb vdpa mst_pciconf(OE) nfsv3 nfs_acl nfs lockd grace fscache netfs xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_reject_ipv4 nft_compat nft_counter nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill cuse fuse rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi rdma_cm ib_ipoib iw_cm ib_cm ipmi_ssif intel_rapl_msr intel_rapl_common amd64_edac edac_mce_amd kvm_amd kvm irqbypass crct10dif_pclmul crc32_pclmul mlx5_ib ghash_clmulni_intel sha1_ssse3 dell_smbios ib_uverbs aesni_intel crypto_simd dcdbas wmi_bmof dell_wmi_descriptor cryptd pcspkr ib_core acpi_ipmi sp5100_tco ccp i2c_piix4 ipmi_si ptdma k10temp ipmi_devintf ipmi_msghandler acpi_power_meter acpi_cpufreq ext4 mbcache jbd2 sd_mod t10_pi sg mgag200 drm_kms_helper syscopyarea sysfillrect mlx5_core sysimgblt fb_sys_fops cec\n ahci libahci mlxfw drm pci_hyperv_intf libata tg3 sha256_ssse3 tls megaraid_sas i2c_algo_bit psample wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: mst_pci]\nCPU: 44 PID: 16136 Comm: kworker/44:3 Kdump: loaded Tainted: GOE 5.15.0-20240509.el8uek.uek7_u3_update_v6.6_ipsec_bf.x86_64 #2\nHardware name: Dell Inc. PowerEdge R7525/074H08, BIOS 2.0.3 01/15/2021\nWorkqueue: events xfrm_state_gc_task\nRIP: 0010:down_read+0x75/0x94\nCode: 00 48 8b 45 08 65 48 8b 14 25 80 fc 01 00 83 e0 02 48 09 d0 48 83 c8 01 48 89 45 08 5d 31 c0 89 c2 89 c6 89 c7 e9 cb 88 3b 00 <0f> 0b 48 8b 45 08 a8 01 74 b2 a8 02 75 ae 48 89 c2 48 83 ca 02 f0\nRSP: 0018:ffffb26387773da8 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffffa08b658af900 RCX: 0000000000000001\nRDX: 0000000000000000 RSI: ff886bc5e1366f2f RDI: 0000000000000000\nRBP: ffffa08b658af940 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffa0a9bfb31540\nR13: ffffa0a9bfb37900 R14: 0000000000000000 R15: ffffa0a9bfb37905\nFS: 0000000000000000(0000) GS:ffffa0a9bfb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055a45ed814e8 CR3: 000000109038a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? show_trace_log_lvl+0x1d6/0x2f9\n ? show_trace_log_lvl+0x1d6/0x2f9\n ? mlx5_devcom_for_each_peer_begin+0x29/0x60 [mlx5_core]\n ? down_read+0x75/0x94\n ? __warn+0x80/0x113\n ? down_read+0x75/0x94\n ? report_bug+0xa4/0x11d\n ? handle_bug+0x35/0x8b\n ? exc_invalid_op+0x14/0x75\n ? asm_exc_invalid_op+0x16/0x1b\n ? down_read+0x75/0x94\n ? down_read+0xe/0x94\n mlx5_devcom_for_each_peer_begin+0x29/0x60 [mlx5_core]\n mlx5_ipsec_fs_roce_tx_destroy+0xb1/0x130 [mlx5_core]\n tx_destroy+0x1b/0xc0 [mlx5_core]\n tx_ft_put+0x53/0xc0 [mlx5_core]\n mlx5e_xfrm_free_state+0x45/0x90 [mlx5_core]\n ___xfrm_state_destroy+0x10f/0x1a2\n xfrm_state_gc_task+0x81/0xa9\n process_one_work+0x1f1/0x3c6\n worker_thread+0x53/0x3e4\n ? process_one_work.cold+0x46/0x3c\n kthread+0x127/0x144\n ? set_kthread_struct+0x60/0x52\n ret_from_fork+0x22/0x2d\n \n---[ end trace 5ef7896144d398e1 ]---", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45017', 'https://git.kernel.org/linus/607e1df7bd47fe91cab85a97f57870a26d066137 (6.11-rc5)', 'https://git.kernel.org/stable/c/2ae52a65a850ded75a94e8d7ec1e09737f4c6509', 'https://git.kernel.org/stable/c/607e1df7bd47fe91cab85a97f57870a26d066137', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45017-ee3e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45017', 'https://www.cve.org/CVERecord?id=CVE-2024-45017'], 'PublishedDate': '2024-09-11T16:15:06.877Z', 'LastModifiedDate': '2024-09-13T16:36:13.19Z'}, {'VulnerabilityID': 'CVE-2024-45018', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45018', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: flowtable: initialise extack before use', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: initialise extack before use\n\nFix missing initialisation of extack in flow offload.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45018', 'https://git.kernel.org/linus/e9767137308daf906496613fd879808a07f006a2 (6.11-rc4)', 'https://git.kernel.org/stable/c/119be227bc04f5035efa64cb823b8a5ca5e2d1c1', 'https://git.kernel.org/stable/c/356beb911b63a8cff34cb57f755c2a2d2ee9dec7', 'https://git.kernel.org/stable/c/7eafeec6be68ebd6140a830ce9ae68ad5b67ec78', 'https://git.kernel.org/stable/c/c7b760499f7791352b49b11667ed04b23d7f5b0f', 'https://git.kernel.org/stable/c/e5ceff2196dc633c995afb080f6f44a72cff6e1d', 'https://git.kernel.org/stable/c/e9767137308daf906496613fd879808a07f006a2', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45018-7e30@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45018', 'https://www.cve.org/CVERecord?id=CVE-2024-45018'], 'PublishedDate': '2024-09-11T16:15:06.933Z', 'LastModifiedDate': '2024-09-13T16:36:24.397Z'}, {'VulnerabilityID': 'CVE-2024-45019', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45019', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Take state lock during tx timeout reporter', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Take state lock during tx timeout reporter\n\nmlx5e_safe_reopen_channels() requires the state lock taken. The\nreferenced changed in the Fixes tag removed the lock to fix another\nissue. This patch adds it back but at a later point (when calling\nmlx5e_safe_reopen_channels()) to avoid the deadlock referenced in the\nFixes tag.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45019', 'https://git.kernel.org/linus/e6b5afd30b99b43682a7764e1a74a42fe4d5f4b3 (6.11-rc4)', 'https://git.kernel.org/stable/c/03d3734bd692affe4d0e9c9d638f491aaf37411b', 'https://git.kernel.org/stable/c/8e57e66ecbdd2fddc9fbf3e984b1c523b70e9809', 'https://git.kernel.org/stable/c/b3b9a87adee97854bcd71057901d46943076267e', 'https://git.kernel.org/stable/c/e6b5afd30b99b43682a7764e1a74a42fe4d5f4b3', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45019-5f8b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45019', 'https://www.cve.org/CVERecord?id=CVE-2024-45019'], 'PublishedDate': '2024-09-11T16:15:06.99Z', 'LastModifiedDate': '2024-09-13T16:36:19.36Z'}, {'VulnerabilityID': 'CVE-2024-45020', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45020', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix a kernel verifier crash in stacksafe()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a kernel verifier crash in stacksafe()\n\nDaniel Hodges reported a kernel verifier crash when playing with sched-ext.\nFurther investigation shows that the crash is due to invalid memory access\nin stacksafe(). More specifically, it is the following code:\n\n if (exact != NOT_EXACT &&\n old->stack[spi].slot_type[i % BPF_REG_SIZE] !=\n cur->stack[spi].slot_type[i % BPF_REG_SIZE])\n return false;\n\nThe 'i' iterates old->allocated_stack.\nIf cur->allocated_stack < old->allocated_stack the out-of-bound\naccess will happen.\n\nTo fix the issue add 'i >= cur->allocated_stack' check such that if\nthe condition is true, stacksafe() should fail. Otherwise,\ncur->stack[spi].slot_type[i % BPF_REG_SIZE] memory access is legal.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45020', 'https://git.kernel.org/linus/bed2eb964c70b780fb55925892a74f26cb590b25 (6.11-rc4)', 'https://git.kernel.org/stable/c/6e3987ac310c74bb4dd6a2fa8e46702fe505fb2b', 'https://git.kernel.org/stable/c/7cad3174cc79519bf5f6c4441780264416822c08', 'https://git.kernel.org/stable/c/bed2eb964c70b780fb55925892a74f26cb590b25', 'https://lore.kernel.org/linux-cve-announce/2024091108-CVE-2024-45020-afcc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45020', 'https://www.cve.org/CVERecord?id=CVE-2024-45020'], 'PublishedDate': '2024-09-11T16:15:07.05Z', 'LastModifiedDate': '2024-09-13T16:36:52.29Z'}, {'VulnerabilityID': 'CVE-2024-45021', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45021', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg_write_event_control(): fix a user-triggerable oops', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg_write_event_control(): fix a user-triggerable oops\n\nwe are *not* guaranteed that anything past the terminating NUL\nis mapped (let alone initialized with anything sane).', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45021', 'https://git.kernel.org/linus/046667c4d3196938e992fba0dfcde570aa85cd0e (6.11-rc4)', 'https://git.kernel.org/stable/c/046667c4d3196938e992fba0dfcde570aa85cd0e', 'https://git.kernel.org/stable/c/0fbe2a72e853a1052abe9bc2b7df8ddb102da227', 'https://git.kernel.org/stable/c/1b37ec85ad95b612307627758c6018cd9d92cca8', 'https://git.kernel.org/stable/c/21b578f1d599edb87462f11113c5b0fc7a04ac61', 'https://git.kernel.org/stable/c/43768fa80fd192558737e24ed6548f74554611d7', 'https://git.kernel.org/stable/c/ad149f5585345e383baa65f1539d816cd715fd3b', 'https://git.kernel.org/stable/c/f1aa7c509aa766080db7ab3aec2e31b1df09e57c', 'https://git.kernel.org/stable/c/fa5bfdf6cb5846a00e712d630a43e3cf55ccb411', 'https://lore.kernel.org/linux-cve-announce/2024091109-CVE-2024-45021-68c4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45021', 'https://www.cve.org/CVERecord?id=CVE-2024-45021'], 'PublishedDate': '2024-09-11T16:15:07.103Z', 'LastModifiedDate': '2024-09-13T16:36:31.583Z'}, {'VulnerabilityID': 'CVE-2024-45022', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45022', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0\n\nThe __vmap_pages_range_noflush() assumes its argument pages** contains\npages with the same page shift. However, since commit e9c3cda4d86e ("mm,\nvmalloc: fix high order __GFP_NOFAIL allocations"), if gfp_flags includes\n__GFP_NOFAIL with high order in vm_area_alloc_pages() and page allocation\nfailed for high order, the pages** may contain two different page shifts\n(high order and order-0). This could lead __vmap_pages_range_noflush() to\nperform incorrect mappings, potentially resulting in memory corruption.\n\nUsers might encounter this as follows (vmap_allow_huge = true, 2M is for\nPMD_SIZE):\n\nkvmalloc(2M, __GFP_NOFAIL|GFP_X)\n __vmalloc_node_range_noprof(vm_flags=VM_ALLOW_HUGE_VMAP)\n vm_area_alloc_pages(order=9) ---> order-9 allocation failed and fallback to order-0\n vmap_pages_range()\n vmap_pages_range_noflush()\n __vmap_pages_range_noflush(page_shift = 21) ----> wrong mapping happens\n\nWe can remove the fallback code because if a high-order allocation fails,\n__vmalloc_node_range_noprof() will retry with order-0. Therefore, it is\nunnecessary to fallback to order-0 here. Therefore, fix this by removing\nthe fallback code.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45022', 'https://git.kernel.org/linus/61ebe5a747da649057c37be1c37eb934b4af79ca (6.11-rc4)', 'https://git.kernel.org/stable/c/61ebe5a747da649057c37be1c37eb934b4af79ca', 'https://git.kernel.org/stable/c/c91618816f4d21fc574d7577a37722adcd4075b2', 'https://git.kernel.org/stable/c/de7bad86345c43cd040ed43e20d9fad78a3ee59f', 'https://git.kernel.org/stable/c/fd1ffbb50ef4da5e1378a46616b6d7407dc795da', 'https://lore.kernel.org/linux-cve-announce/2024091109-CVE-2024-45022-08f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45022', 'https://www.cve.org/CVERecord?id=CVE-2024-45022'], 'PublishedDate': '2024-09-11T16:15:07.163Z', 'LastModifiedDate': '2024-09-13T16:36:39.043Z'}, {'VulnerabilityID': 'CVE-2024-45025', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45025', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE\n\ncopy_fd_bitmaps(new, old, count) is expected to copy the first\ncount/BITS_PER_LONG bits from old->full_fds_bits[] and fill\nthe rest with zeroes. What it does is copying enough words\n(BITS_TO_LONGS(count/BITS_PER_LONG)), then memsets the rest.\nThat works fine, *if* all bits past the cutoff point are\nclear. Otherwise we are risking garbage from the last word\nwe'd copied.\n\nFor most of the callers that is true - expand_fdtable() has\ncount equal to old->max_fds, so there's no open descriptors\npast count, let alone fully occupied words in ->open_fds[],\nwhich is what bits in ->full_fds_bits[] correspond to.\n\nThe other caller (dup_fd()) passes sane_fdtable_size(old_fdt, max_fds),\nwhich is the smallest multiple of BITS_PER_LONG that covers all\nopened descriptors below max_fds. In the common case (copying on\nfork()) max_fds is ~0U, so all opened descriptors will be below\nit and we are fine, by the same reasons why the call in expand_fdtable()\nis safe.\n\nUnfortunately, there is a case where max_fds is less than that\nand where we might, indeed, end up with junk in ->full_fds_bits[] -\nclose_range(from, to, CLOSE_RANGE_UNSHARE) with\n\t* descriptor table being currently shared\n\t* 'to' being above the current capacity of descriptor table\n\t* 'from' being just under some chunk of opened descriptors.\nIn that case we end up with observably wrong behaviour - e.g. spawn\na child with CLONE_FILES, get all descriptors in range 0..127 open,\nthen close_range(64, ~0U, CLOSE_RANGE_UNSHARE) and watch dup(0) ending\nup with descriptor #128, despite #64 being observably not open.\n\nThe minimally invasive fix would be to deal with that in dup_fd().\nIf this proves to add measurable overhead, we can go that way, but\nlet's try to fix copy_fd_bitmaps() first.\n\n* new helper: bitmap_copy_and_expand(to, from, bits_to_copy, size).\n* make copy_fd_bitmaps() take the bitmap size in words, rather than\nbits; it's 'count' argument is always a multiple of BITS_PER_LONG,\nso we are not losing any information, and that way we can use the\nsame helper for all three bitmaps - compiler will see that count\nis a multiple of BITS_PER_LONG for the large ones, so it'll generate\nplain memcpy()+memset().\n\nReproducer added to tools/testing/selftests/core/close_range_test.c", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45025', 'https://git.kernel.org/linus/9a2fa1472083580b6c66bdaf291f591e1170123a (6.11-rc4)', 'https://git.kernel.org/stable/c/5053581fe5dfb09b58c65dd8462bf5dea71f41ff', 'https://git.kernel.org/stable/c/8cad3b2b3ab81ca55f37405ffd1315bcc2948058', 'https://git.kernel.org/stable/c/9a2fa1472083580b6c66bdaf291f591e1170123a', 'https://git.kernel.org/stable/c/c69d18f0ac7060de724511537810f10f29a27958', 'https://git.kernel.org/stable/c/dd72ae8b0fce9c0bbe9582b9b50820f0407f8d8a', 'https://git.kernel.org/stable/c/e807487a1d5fd5d941f26578ae826ca815dbfcd6', 'https://git.kernel.org/stable/c/ee501f827f3db02d4e599afbbc1a7f8b792d05d7', 'https://git.kernel.org/stable/c/fe5bf14881701119aeeda7cf685f3c226c7380df', 'https://lore.kernel.org/linux-cve-announce/2024091109-CVE-2024-45025-94f6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45025', 'https://www.cve.org/CVERecord?id=CVE-2024-45025'], 'PublishedDate': '2024-09-11T16:15:07.44Z', 'LastModifiedDate': '2024-09-13T16:30:07.073Z'}, {'VulnerabilityID': 'CVE-2024-45026', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45026', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/dasd: fix error recovery leading to data corruption on ESE devices', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix error recovery leading to data corruption on ESE devices\n\nExtent Space Efficient (ESE) or thin provisioned volumes need to be\nformatted on demand during usual IO processing.\n\nThe dasd_ese_needs_format function checks for error codes that signal\nthe non existence of a proper track format.\n\nThe check for incorrect length is to imprecise since other error cases\nleading to transport of insufficient data also have this flag set.\nThis might lead to data corruption in certain error cases for example\nduring a storage server warmstart.\n\nFix by removing the check for incorrect length and replacing by\nexplicitly checking for invalid track format in transport mode.\n\nAlso remove the check for file protected since this is not a valid\nESE handling case.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45026', 'https://git.kernel.org/linus/7db4042336580dfd75cb5faa82c12cd51098c90b (6.11-rc4)', 'https://git.kernel.org/stable/c/0a228896a1b3654cd461ff654f6a64e97a9c3246', 'https://git.kernel.org/stable/c/19f60a55b2fda49bc4f6134a5f6356ef62ee69d8', 'https://git.kernel.org/stable/c/5d4a304338daf83ace2887aaacafd66fe99ed5cc', 'https://git.kernel.org/stable/c/7db4042336580dfd75cb5faa82c12cd51098c90b', 'https://git.kernel.org/stable/c/93a7e2856951680cd7fe6ebd705ac10c8a8a5efd', 'https://git.kernel.org/stable/c/a665e3b7ac7d5cdc26e00e3d0fc8fd490e00316a', 'https://git.kernel.org/stable/c/e245a18281c252c8dbc467492e09bb5d4b012118', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45026-eaa8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45026', 'https://www.cve.org/CVERecord?id=CVE-2024-45026'], 'PublishedDate': '2024-09-11T16:15:07.507Z', 'LastModifiedDate': '2024-09-13T16:29:55.927Z'}, {'VulnerabilityID': 'CVE-2024-45027', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45027', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup()\n\nIf xhci_mem_init() fails, it calls into xhci_mem_cleanup() to mop\nup the damage. If it fails early enough, before xhci->interrupters\nis allocated but after xhci->max_interrupters has been set, which\nhappens in most (all?) cases, things get uglier, as xhci_mem_cleanup()\nunconditionally derefences xhci->interrupters. With prejudice.\n\nGate the interrupt freeing loop with a check on xhci->interrupters\nbeing non-NULL.\n\nFound while debugging a DMA allocation issue that led the XHCI driver\non this exact path.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45027', 'https://git.kernel.org/linus/dcdb52d948f3a17ccd3fce757d9bd981d7c32039 (6.11-rc4)', 'https://git.kernel.org/stable/c/770cacc75b0091ece17349195d72133912c1ca7c', 'https://git.kernel.org/stable/c/dcdb52d948f3a17ccd3fce757d9bd981d7c32039', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45027-95b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45027', 'https://www.cve.org/CVERecord?id=CVE-2024-45027'], 'PublishedDate': '2024-09-11T16:15:07.57Z', 'LastModifiedDate': '2024-09-13T16:29:44.213Z'}, {'VulnerabilityID': 'CVE-2024-45028', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45028', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mmc: mmc_test: Fix NULL dereference on allocation failure', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmc_test: Fix NULL dereference on allocation failure\n\nIf the "test->highmem = alloc_pages()" allocation fails then calling\n__free_pages(test->highmem) will result in a NULL dereference. Also\nchange the error code to -ENOMEM instead of returning success.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45028', 'https://git.kernel.org/linus/a1e627af32ed60713941cbfc8075d44cad07f6dd (6.11-rc5)', 'https://git.kernel.org/stable/c/2b507b03991f44dfb202fc2a82c9874d1b1f0c06', 'https://git.kernel.org/stable/c/3b4e76ceae5b5a46c968bd952f551ce173809f63', 'https://git.kernel.org/stable/c/9b9ba386d7bfdbc38445932c90fa9444c0524bea', 'https://git.kernel.org/stable/c/a1e627af32ed60713941cbfc8075d44cad07f6dd', 'https://git.kernel.org/stable/c/cac2815f49d343b2f0acc4973d2c14918ac3ab0c', 'https://git.kernel.org/stable/c/e40515582141a9e7c84b269be699c05236a499a6', 'https://git.kernel.org/stable/c/e97be13a9f51284da450dd2a592e3fa87b49cdc9', 'https://git.kernel.org/stable/c/ecb15b8ca12c0cbdab81e307e9795214d8b90890', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45028-34f7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45028', 'https://www.cve.org/CVERecord?id=CVE-2024-45028'], 'PublishedDate': '2024-09-11T16:15:07.647Z', 'LastModifiedDate': '2024-09-13T16:29:35.877Z'}, {'VulnerabilityID': 'CVE-2024-45029', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45029', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: i2c: tegra: Do not mark ACPI devices as irq safe', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: tegra: Do not mark ACPI devices as irq safe\n\nOn ACPI machines, the tegra i2c module encounters an issue due to a\nmutex being called inside a spinlock. This leads to the following bug:\n\n\tBUG: sleeping function called from invalid context at kernel/locking/mutex.c:585\n\t...\n\n\tCall trace:\n\t__might_sleep\n\t__mutex_lock_common\n\tmutex_lock_nested\n\tacpi_subsys_runtime_resume\n\trpm_resume\n\ttegra_i2c_xfer\n\nThe problem arises because during __pm_runtime_resume(), the spinlock\n&dev->power.lock is acquired before rpm_resume() is called. Later,\nrpm_resume() invokes acpi_subsys_runtime_resume(), which relies on\nmutexes, triggering the error.\n\nTo address this issue, devices on ACPI are now marked as not IRQ-safe,\nconsidering the dependency of acpi_subsys_runtime_resume() on mutexes.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45029', 'https://git.kernel.org/linus/14d069d92951a3e150c0a81f2ca3b93e54da913b (6.11-rc4)', 'https://git.kernel.org/stable/c/14d069d92951a3e150c0a81f2ca3b93e54da913b', 'https://git.kernel.org/stable/c/2853e1376d8161b04c9ff18ba82b43f08a049905', 'https://git.kernel.org/stable/c/6861faf4232e4b78878f2de1ed3ee324ddae2287', 'https://git.kernel.org/stable/c/a89aef1e6cc43fa019a58080ed05c839e6c77876', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45029-662e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45029', 'https://www.cve.org/CVERecord?id=CVE-2024-45029'], 'PublishedDate': '2024-09-11T16:15:07.717Z', 'LastModifiedDate': '2024-09-13T16:29:29.74Z'}, {'VulnerabilityID': 'CVE-2024-45030', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-45030', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: igb: cope with large MAX_SKB_FRAGS', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nigb: cope with large MAX_SKB_FRAGS\n\nSabrina reports that the igb driver does not cope well with large\nMAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload\ncorruption on TX.\n\nAn easy reproducer is to run ssh to connect to the machine. With\nMAX_SKB_FRAGS=17 it works, with MAX_SKB_FRAGS=45 it fails. This has\nbeen reported originally in\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2265320\n\nThe root cause of the issue is that the driver does not take into\naccount properly the (possibly large) shared info size when selecting\nthe ring layout, and will try to fit two packets inside the same 4K\npage even when the 1st fraglist will trump over the 2nd head.\n\nAddress the issue by checking if 2K buffers are insufficient.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-45030', 'https://git.kernel.org/linus/8aba27c4a5020abdf60149239198297f88338a8d (6.11-rc5)', 'https://git.kernel.org/stable/c/8aba27c4a5020abdf60149239198297f88338a8d', 'https://git.kernel.org/stable/c/8ea80ff5d8298356d28077bc30913ed37df65109', 'https://git.kernel.org/stable/c/b52bd8bcb9e8ff250c79b44f9af8b15cae8911ab', 'https://lore.kernel.org/linux-cve-announce/2024091110-CVE-2024-45030-c2eb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-45030', 'https://www.cve.org/CVERecord?id=CVE-2024-45030'], 'PublishedDate': '2024-09-11T16:15:07.77Z', 'LastModifiedDate': '2024-09-13T16:29:23.557Z'}, {'VulnerabilityID': 'CVE-2024-46672', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46672', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion\n\nwpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA flush in the\ndriver for SAE/OWE offload cases") SSID based PMKSA del commands.\nbrcmfmac is not prepared and tries to dereference the NULL bssid and\npmkid pointers in cfg80211_pmksa. PMKID_V3 operations support SSID based\nupdates so copy the SSID.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46672', 'https://git.kernel.org/linus/2ad4e1ada8eebafa2d75a4b75eeeca882de6ada1 (6.11-rc4)', 'https://git.kernel.org/stable/c/1f566eb912d192c83475a919331aea59619e1197', 'https://git.kernel.org/stable/c/2ad4e1ada8eebafa2d75a4b75eeeca882de6ada1', 'https://git.kernel.org/stable/c/4291f94f8c6b01505132c22ee27b59ed27c3584f', 'https://lore.kernel.org/linux-cve-announce/2024091111-CVE-2024-46672-7542@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46672', 'https://www.cve.org/CVERecord?id=CVE-2024-46672'], 'PublishedDate': '2024-09-11T16:15:07.84Z', 'LastModifiedDate': '2024-09-13T16:29:17.123Z'}, {'VulnerabilityID': 'CVE-2024-46673', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46673', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: aacraid: Fix double-free on probe failure', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: aacraid: Fix double-free on probe failure\n\naac_probe_one() calls hardware-specific init functions through the\naac_driver_ident::init pointer, all of which eventually call down to\naac_init_adapter().\n\nIf aac_init_adapter() fails after allocating memory for aac_dev::queues,\nit frees the memory but does not clear that member.\n\nAfter the hardware-specific init function returns an error,\naac_probe_one() goes down an error path that frees the memory pointed to\nby aac_dev::queues, resulting.in a double-free.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46673', 'https://git.kernel.org/linus/919ddf8336f0b84c0453bac583808c9f165a85c2 (6.11-rc6)', 'https://git.kernel.org/stable/c/4b540ec7c0045c2d01c4e479f34bbc8f147afa4c', 'https://git.kernel.org/stable/c/564e1986b00c5f05d75342f8407f75f0a17b94df', 'https://git.kernel.org/stable/c/60962c3d8e18e5d8dfa16df788974dd7f35bd87a', 'https://git.kernel.org/stable/c/85449b28ff6a89c4513115e43ddcad949b5890c9', 'https://git.kernel.org/stable/c/8a3995a3ffeca280a961b59f5c99843d81b15929', 'https://git.kernel.org/stable/c/919ddf8336f0b84c0453bac583808c9f165a85c2', 'https://git.kernel.org/stable/c/9e96dea7eff6f2bbcd0b42a098012fc66af9eb69', 'https://git.kernel.org/stable/c/d237c7d06ffddcdb5d36948c527dc01284388218', 'https://lore.kernel.org/linux-cve-announce/2024091333-CVE-2024-46673-c49c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46673', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-46673'], 'PublishedDate': '2024-09-13T06:15:11.917Z', 'LastModifiedDate': '2024-09-13T16:51:39.117Z'}, {'VulnerabilityID': 'CVE-2024-46675', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46675', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: dwc3: core: Prevent USB core invalid event buffer address access', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: core: Prevent USB core invalid event buffer address access\n\nThis commit addresses an issue where the USB core could access an\ninvalid event buffer address during runtime suspend, potentially causing\nSMMU faults and other memory issues in Exynos platforms. The problem\narises from the following sequence.\n 1. In dwc3_gadget_suspend, there is a chance of a timeout when\n moving the USB core to the halt state after clearing the\n run/stop bit by software.\n 2. In dwc3_core_exit, the event buffer is cleared regardless of\n the USB core's status, which may lead to an SMMU faults and\n other memory issues. if the USB core tries to access the event\n buffer address.\n\nTo prevent this hardware quirk on Exynos platforms, this commit ensures\nthat the event buffer address is not cleared by software when the USB\ncore is active during runtime suspend by checking its status before\nclearing the buffer address.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46675', 'https://git.kernel.org/linus/14e497183df28c006603cc67fd3797a537eef7b9 (6.11-rc6)', 'https://git.kernel.org/stable/c/111277b881def3153335acfe0d1f43e6cd83ac93', 'https://git.kernel.org/stable/c/14e497183df28c006603cc67fd3797a537eef7b9', 'https://git.kernel.org/stable/c/2189fd13c577d7881f94affc09c950a795064c4b', 'https://git.kernel.org/stable/c/7bb11a75dd4d3612378b90e2a4aa49bdccea28ab', 'https://git.kernel.org/stable/c/b72da4d89b97da71e056cc4d1429b2bc426a9c2f', 'https://git.kernel.org/stable/c/d2afc2bffec77316b90d530b07695e3f534df914', 'https://git.kernel.org/stable/c/e23f6ad8d110bf632f7471482e10b43dc174fb72', 'https://git.kernel.org/stable/c/eca3f543f817da87c00d1a5697b473efb548204f', 'https://lore.kernel.org/linux-cve-announce/2024091335-CVE-2024-46675-ba70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46675', 'https://www.cve.org/CVERecord?id=CVE-2024-46675'], 'PublishedDate': '2024-09-13T06:15:12.117Z', 'LastModifiedDate': '2024-09-20T17:18:48.753Z'}, {'VulnerabilityID': 'CVE-2024-46676', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46676', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfc: pn533: Add poll mod list filling check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: Add poll mod list filling check\n\nIn case of im_protocols value is 1 and tm_protocols value is 0 this\ncombination successfully passes the check\n\'if (!im_protocols && !tm_protocols)\' in the nfc_start_poll().\nBut then after pn533_poll_create_mod_list() call in pn533_start_poll()\npoll mod list will remain empty and dev->poll_mod_count will remain 0\nwhich lead to division by zero.\n\nNormally no im protocol has value 1 in the mask, so this combination is\nnot expected by driver. But these protocol values actually come from\nuserspace via Netlink interface (NFC_CMD_START_POLL operation). So a\nbroken or malicious program may pass a message containing a "bad"\ncombination of protocol parameter values so that dev->poll_mod_count\nis not incremented inside pn533_poll_create_mod_list(), thus leading\nto division by zero.\nCall trace looks like:\nnfc_genl_start_poll()\n nfc_start_poll()\n ->start_poll()\n pn533_start_poll()\n\nAdd poll mod list filling check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46676', 'https://git.kernel.org/linus/febccb39255f9df35527b88c953b2e0deae50e53 (6.11-rc6)', 'https://git.kernel.org/stable/c/56ad559cf6d87f250a8d203b555dfc3716afa946', 'https://git.kernel.org/stable/c/64513d0e546a1f19e390f7e5eba3872bfcbdacf5', 'https://git.kernel.org/stable/c/7535db0624a2dede374c42040808ad9a9101d723', 'https://git.kernel.org/stable/c/7ecd3dd4f8eecd3309432156ccfe24768e009ec4', 'https://git.kernel.org/stable/c/8ddaea033de051ed61b39f6b69ad54a411172b33', 'https://git.kernel.org/stable/c/c5e05237444f32f6cfe5d907603a232c77a08b31', 'https://git.kernel.org/stable/c/febccb39255f9df35527b88c953b2e0deae50e53', 'https://lore.kernel.org/linux-cve-announce/2024091335-CVE-2024-46676-0b05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46676', 'https://www.cve.org/CVERecord?id=CVE-2024-46676'], 'PublishedDate': '2024-09-13T06:15:12.223Z', 'LastModifiedDate': '2024-09-23T14:42:38.23Z'}, {'VulnerabilityID': 'CVE-2024-46677', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46677', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gtp: fix a potential NULL pointer dereference', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix a potential NULL pointer dereference\n\nWhen sockfd_lookup() fails, gtp_encap_enable_socket() returns a\nNULL pointer, but its callers only check for error pointers thus miss\nthe NULL pointer case.\n\nFix it by returning an error pointer with the error code carried from\nsockfd_lookup().\n\n(I found this bug during code inspection.)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46677', 'https://git.kernel.org/linus/defd8b3c37b0f9cb3e0f60f47d3d78d459d57fda (6.11-rc6)', 'https://git.kernel.org/stable/c/28c67f0f84f889fe9f4cbda8354132b20dc9212d', 'https://git.kernel.org/stable/c/4643b91691e969b1b9ad54bf552d7a990cfa3b87', 'https://git.kernel.org/stable/c/612edd35f2a3910ab1f61c1f2338889d4ba99fa2', 'https://git.kernel.org/stable/c/620fe9809752fae91b4190e897b81ed9976dfb39', 'https://git.kernel.org/stable/c/8bbb9e4e0e66a39282e582d0440724055404b38c', 'https://git.kernel.org/stable/c/bdd99e5f0ad5fa727b16f2101fe880aa2bff2f8e', 'https://git.kernel.org/stable/c/defd8b3c37b0f9cb3e0f60f47d3d78d459d57fda', 'https://git.kernel.org/stable/c/e8b9930b0eb045d19e883c65ff9676fc89320c70', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46677-b53c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46677', 'https://www.cve.org/CVERecord?id=CVE-2024-46677'], 'PublishedDate': '2024-09-13T06:15:12.36Z', 'LastModifiedDate': '2024-09-13T16:51:53.69Z'}, {'VulnerabilityID': 'CVE-2024-46678', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46678', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bonding: change ipsec_lock from spin lock to mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: change ipsec_lock from spin lock to mutex\n\nIn the cited commit, bond->ipsec_lock is added to protect ipsec_list,\nhence xdo_dev_state_add and xdo_dev_state_delete are called inside\nthis lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep,\n"scheduling while atomic" will be triggered when changing bond\'s\nactive slave.\n\n[ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200\n[ 101.055726] Modules linked in:\n[ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1\n[ 101.058760] Hardware name:\n[ 101.059434] Call Trace:\n[ 101.059436] \n[ 101.060873] dump_stack_lvl+0x51/0x60\n[ 101.061275] __schedule_bug+0x4e/0x60\n[ 101.061682] __schedule+0x612/0x7c0\n[ 101.062078] ? __mod_timer+0x25c/0x370\n[ 101.062486] schedule+0x25/0xd0\n[ 101.062845] schedule_timeout+0x77/0xf0\n[ 101.063265] ? asm_common_interrupt+0x22/0x40\n[ 101.063724] ? __bpf_trace_itimer_state+0x10/0x10\n[ 101.064215] __wait_for_common+0x87/0x190\n[ 101.064648] ? usleep_range_state+0x90/0x90\n[ 101.065091] cmd_exec+0x437/0xb20 [mlx5_core]\n[ 101.065569] mlx5_cmd_do+0x1e/0x40 [mlx5_core]\n[ 101.066051] mlx5_cmd_exec+0x18/0x30 [mlx5_core]\n[ 101.066552] mlx5_crypto_create_dek_key+0xea/0x120 [mlx5_core]\n[ 101.067163] ? bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[ 101.067738] ? kmalloc_trace+0x4d/0x350\n[ 101.068156] mlx5_ipsec_create_sa_ctx+0x33/0x100 [mlx5_core]\n[ 101.068747] mlx5e_xfrm_add_state+0x47b/0xaa0 [mlx5_core]\n[ 101.069312] bond_change_active_slave+0x392/0x900 [bonding]\n[ 101.069868] bond_option_active_slave_set+0x1c2/0x240 [bonding]\n[ 101.070454] __bond_opt_set+0xa6/0x430 [bonding]\n[ 101.070935] __bond_opt_set_notify+0x2f/0x90 [bonding]\n[ 101.071453] bond_opt_tryset_rtnl+0x72/0xb0 [bonding]\n[ 101.071965] bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[ 101.072567] kernfs_fop_write_iter+0x10c/0x1a0\n[ 101.073033] vfs_write+0x2d8/0x400\n[ 101.073416] ? alloc_fd+0x48/0x180\n[ 101.073798] ksys_write+0x5f/0xe0\n[ 101.074175] do_syscall_64+0x52/0x110\n[ 101.074576] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nAs bond_ipsec_add_sa_all and bond_ipsec_del_sa_all are only called\nfrom bond_change_active_slave, which requires holding the RTNL lock.\nAnd bond_ipsec_add_sa and bond_ipsec_del_sa are xfrm state\nxdo_dev_state_add and xdo_dev_state_delete APIs, which are in user\ncontext. So ipsec_lock doesn\'t have to be spin lock, change it to\nmutex, and thus the above issue can be resolved.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46678', 'https://git.kernel.org/linus/2aeeef906d5a526dc60cf4af92eda69836c39b1f (6.11-rc6)', 'https://git.kernel.org/stable/c/2aeeef906d5a526dc60cf4af92eda69836c39b1f', 'https://git.kernel.org/stable/c/56354b0a2c24a7828eeed7de4b4dc9652d9affa3', 'https://git.kernel.org/stable/c/6b598069164ac1bb60996d6ff94e7f9169dbd2d3', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46678-ca65@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46678', 'https://www.cve.org/CVERecord?id=CVE-2024-46678'], 'PublishedDate': '2024-09-13T06:15:12.45Z', 'LastModifiedDate': '2024-09-23T14:44:12.88Z'}, {'VulnerabilityID': 'CVE-2024-46679', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46679', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ethtool: check device is present when getting link settings', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: check device is present when getting link settings\n\nA sysfs reader can race with a device reset or removal, attempting to\nread device state when the device is not actually present. eg:\n\n [exception RIP: qed_get_current_link+17]\n #8 [ffffb9e4f2907c48] qede_get_link_ksettings at ffffffffc07a994a [qede]\n #9 [ffffb9e4f2907cd8] __rh_call_get_link_ksettings at ffffffff992b01a3\n #10 [ffffb9e4f2907d38] __ethtool_get_link_ksettings at ffffffff992b04e4\n #11 [ffffb9e4f2907d90] duplex_show at ffffffff99260300\n #12 [ffffb9e4f2907e38] dev_attr_show at ffffffff9905a01c\n #13 [ffffb9e4f2907e50] sysfs_kf_seq_show at ffffffff98e0145b\n #14 [ffffb9e4f2907e68] seq_read at ffffffff98d902e3\n #15 [ffffb9e4f2907ec8] vfs_read at ffffffff98d657d1\n #16 [ffffb9e4f2907f00] ksys_read at ffffffff98d65c3f\n #17 [ffffb9e4f2907f38] do_syscall_64 at ffffffff98a052fb\n\n crash> struct net_device.state ffff9a9d21336000\n state = 5,\n\nstate 5 is __LINK_STATE_START (0b1) and __LINK_STATE_NOCARRIER (0b100).\nThe device is not present, note lack of __LINK_STATE_PRESENT (0b10).\n\nThis is the same sort of panic as observed in commit 4224cfd7fb65\n("net-sysfs: add check for netdevice being present to speed_show").\n\nThere are many other callers of __ethtool_get_link_ksettings() which\ndon\'t have a device presence check.\n\nMove this check into ethtool to protect all callers.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46679', 'https://git.kernel.org/linus/a699781c79ecf6cfe67fb00a0331b4088c7c8466 (6.11-rc6)', 'https://git.kernel.org/stable/c/1d6d9b5b1b95bfeccb84386a51b7e6c510ec13b2', 'https://git.kernel.org/stable/c/7a8d98b6d6484d3ad358510366022da080c37cbc', 'https://git.kernel.org/stable/c/842a40c7273ba1c1cb30dda50405b328de1d860e', 'https://git.kernel.org/stable/c/94ab317024ba373d37340893d1c0358638935fbb', 'https://git.kernel.org/stable/c/9bba5955eed160102114d4cc00c3d399be9bdae4', 'https://git.kernel.org/stable/c/a699781c79ecf6cfe67fb00a0331b4088c7c8466', 'https://git.kernel.org/stable/c/ec7b4f7f644018ac293cb1b02528a40a32917e62', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46679-3527@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46679', 'https://www.cve.org/CVERecord?id=CVE-2024-46679'], 'PublishedDate': '2024-09-13T06:15:12.53Z', 'LastModifiedDate': '2024-09-23T14:47:23.287Z'}, {'VulnerabilityID': 'CVE-2024-46680', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46680', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: btnxpuart: Fix random crash seen while removing driver', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix random crash seen while removing driver\n\nThis fixes the random kernel crash seen while removing the driver, when\nrunning the load/unload test over multiple iterations.\n\n1) modprobe btnxpuart\n2) hciconfig hci0 reset\n3) hciconfig (check hci0 interface up with valid BD address)\n4) modprobe -r btnxpuart\nRepeat steps 1 to 4\n\nThe ps_wakeup() call in btnxpuart_close() schedules the psdata->work(),\nwhich gets scheduled after module is removed, causing a kernel crash.\n\nThis hidden issue got highlighted after enabling Power Save by default\nin 4183a7be7700 (Bluetooth: btnxpuart: Enable Power Save feature on\nstartup)\n\nThe new ps_cleanup() deasserts UART break immediately while closing\nserdev device, cancels any scheduled ps_work and destroys the ps_lock\nmutex.\n\n[ 85.884604] Unable to handle kernel paging request at virtual address ffffd4a61638f258\n[ 85.884624] Mem abort info:\n[ 85.884625] ESR = 0x0000000086000007\n[ 85.884628] EC = 0x21: IABT (current EL), IL = 32 bits\n[ 85.884633] SET = 0, FnV = 0\n[ 85.884636] EA = 0, S1PTW = 0\n[ 85.884638] FSC = 0x07: level 3 translation fault\n[ 85.884642] swapper pgtable: 4k pages, 48-bit VAs, pgdp=0000000041dd0000\n[ 85.884646] [ffffd4a61638f258] pgd=1000000095fff003, p4d=1000000095fff003, pud=100000004823d003, pmd=100000004823e003, pte=0000000000000000\n[ 85.884662] Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n[ 85.890932] Modules linked in: algif_hash algif_skcipher af_alg overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_spdif snd_soc_fsl_micfil snd_soc_fsl_sai snd_soc_fsl_utils gpio_ir_recv rc_core fuse [last unloaded: btnxpuart(O)]\n[ 85.927297] CPU: 1 PID: 67 Comm: kworker/1:3 Tainted: G O 6.1.36+g937b1be4345a #1\n[ 85.936176] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 85.936182] Workqueue: events 0xffffd4a61638f380\n[ 85.936198] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 85.952817] pc : 0xffffd4a61638f258\n[ 85.952823] lr : 0xffffd4a61638f258\n[ 85.952827] sp : ffff8000084fbd70\n[ 85.952829] x29: ffff8000084fbd70 x28: 0000000000000000 x27: 0000000000000000\n[ 85.963112] x26: ffffd4a69133f000 x25: ffff4bf1c8540990 x24: ffff4bf215b87305\n[ 85.963119] x23: ffff4bf215b87300 x22: ffff4bf1c85409d0 x21: ffff4bf1c8540970\n[ 85.977382] x20: 0000000000000000 x19: ffff4bf1c8540880 x18: 0000000000000000\n[ 85.977391] x17: 0000000000000000 x16: 0000000000000133 x15: 0000ffffe2217090\n[ 85.977399] x14: 0000000000000001 x13: 0000000000000133 x12: 0000000000000139\n[ 85.977407] x11: 0000000000000001 x10: 0000000000000a60 x9 : ffff8000084fbc50\n[ 85.977417] x8 : ffff4bf215b7d000 x7 : ffff4bf215b83b40 x6 : 00000000000003e8\n[ 85.977424] x5 : 00000000410fd030 x4 : 0000000000000000 x3 : 0000000000000000\n[ 85.977432] x2 : 0000000000000000 x1 : ffff4bf1c4265880 x0 : 0000000000000000\n[ 85.977443] Call trace:\n[ 85.977446] 0xffffd4a61638f258\n[ 85.977451] 0xffffd4a61638f3e8\n[ 85.977455] process_one_work+0x1d4/0x330\n[ 85.977464] worker_thread+0x6c/0x430\n[ 85.977471] kthread+0x108/0x10c\n[ 85.977476] ret_from_fork+0x10/0x20\n[ 85.977488] Code: bad PC value\n[ 85.977491] ---[ end trace 0000000000000000 ]---\n\nPreset since v6.9.11', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46680', 'https://git.kernel.org/linus/35237475384ab3622f63c3c09bdf6af6dacfe9c3 (6.11-rc6)', 'https://git.kernel.org/stable/c/29a1d9971e38f92c84b363ff50379dd434ddfe1c', 'https://git.kernel.org/stable/c/35237475384ab3622f63c3c09bdf6af6dacfe9c3', 'https://git.kernel.org/stable/c/662a55986b88807da4d112d838c8aaa05810e938', 'https://lore.kernel.org/linux-cve-announce/2024091336-CVE-2024-46680-f40d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46680', 'https://www.cve.org/CVERecord?id=CVE-2024-46680'], 'PublishedDate': '2024-09-13T06:15:12.617Z', 'LastModifiedDate': '2024-09-23T14:45:10.233Z'}, {'VulnerabilityID': 'CVE-2024-46681', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46681', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pktgen: use cpus_read_lock() in pg_net_init()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npktgen: use cpus_read_lock() in pg_net_init()\n\nI have seen the WARN_ON(smp_processor_id() != cpu) firing\nin pktgen_thread_worker() during tests.\n\nWe must use cpus_read_lock()/cpus_read_unlock()\naround the for_each_online_cpu(cpu) loop.\n\nWhile we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46681', 'https://git.kernel.org/linus/979b581e4c69257acab1af415ddad6b2d78a2fa5 (6.11-rc6)', 'https://git.kernel.org/stable/c/5f5f7366dda8ae870e8305d6e7b3c0c2686cd2cf', 'https://git.kernel.org/stable/c/979b581e4c69257acab1af415ddad6b2d78a2fa5', 'https://lore.kernel.org/linux-cve-announce/2024091337-CVE-2024-46681-6086@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46681', 'https://www.cve.org/CVERecord?id=CVE-2024-46681'], 'PublishedDate': '2024-09-13T06:15:12.71Z', 'LastModifiedDate': '2024-09-19T18:10:49.623Z'}, {'VulnerabilityID': 'CVE-2024-46683', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46683', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: prevent UAF around preempt fence', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: prevent UAF around preempt fence\n\nThe fence lock is part of the queue, therefore in the current design\nanything locking the fence should then also hold a ref to the queue to\nprevent the queue from being freed.\n\nHowever, currently it looks like we signal the fence and then drop the\nqueue ref, but if something is waiting on the fence, the waiter is\nkicked to wake up at some later point, where upon waking up it first\ngrabs the lock before checking the fence state. But if we have already\ndropped the queue ref, then the lock might already be freed as part of\nthe queue, leading to uaf.\n\nTo prevent this, move the fence lock into the fence itself so we don't\nrun into lifetime issues. Alternative might be to have device level\nlock, or only release the queue in the fence release callback, however\nthat might require pushing to another worker to avoid locking issues.\n\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2454\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2342\nReferences: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/2020\n(cherry picked from commit 7116c35aacedc38be6d15bd21b2fc936eed0008b)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46683', 'https://git.kernel.org/linus/730b72480e29f63fd644f5fa57c9d46109428953 (6.11-rc5)', 'https://git.kernel.org/stable/c/10081b0b0ed201f53e24bd92deb2e0f3c3e713d4', 'https://git.kernel.org/stable/c/730b72480e29f63fd644f5fa57c9d46109428953', 'https://lore.kernel.org/linux-cve-announce/2024091337-CVE-2024-46683-e513@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46683', 'https://www.cve.org/CVERecord?id=CVE-2024-46683'], 'PublishedDate': '2024-09-13T06:15:12.993Z', 'LastModifiedDate': '2024-09-13T16:52:14.373Z'}, {'VulnerabilityID': 'CVE-2024-46685', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46685', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pinctrl: single: fix potential NULL dereference in pcs_get_function()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: single: fix potential NULL dereference in pcs_get_function()\n\npinmux_generic_get_function() can return NULL and the pointer 'function'\nwas dereferenced without checking against NULL. Add checking of pointer\n'function' in pcs_get_function().\n\nFound by code review.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46685', 'https://git.kernel.org/linus/1c38a62f15e595346a1106025722869e87ffe044 (6.11-rc6)', 'https://git.kernel.org/stable/c/0a2bab5ed161318f57134716accba0a30f3af191', 'https://git.kernel.org/stable/c/1c38a62f15e595346a1106025722869e87ffe044', 'https://git.kernel.org/stable/c/292151af6add3e5ab11b2e9916cffa5f52859a1f', 'https://git.kernel.org/stable/c/2cea369a5c2e85ab14ae716da1d1cc6d25c85e11', 'https://git.kernel.org/stable/c/4e9436375fcc9bd2a60ee96aba6ed53f7a377d10', 'https://git.kernel.org/stable/c/4ed45fe99ec9e3c9478bd634624cd05a57d002f7', 'https://git.kernel.org/stable/c/6341c2856785dca7006820b127278058a180c075', 'https://git.kernel.org/stable/c/8f0bd526921b6867c2f10a83cd4fd14139adcd92', 'https://lore.kernel.org/linux-cve-announce/2024091338-CVE-2024-46685-6606@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46685', 'https://www.cve.org/CVERecord?id=CVE-2024-46685'], 'PublishedDate': '2024-09-13T06:15:13.2Z', 'LastModifiedDate': '2024-09-14T16:00:55.547Z'}, {'VulnerabilityID': 'CVE-2024-46686', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46686', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: avoid dereferencing rdata=NULL in smb2_new_read_req()\n\nThis happens when called from SMB2_read() while using rdma\nand reaching the rdma_readwrite_threshold.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46686', 'https://git.kernel.org/linus/c724b2ab6a46435b4e7d58ad2fbbdb7a318823cf (6.11-rc6)', 'https://git.kernel.org/stable/c/6df57c63c200cd05e085c3b695128260e21959b7', 'https://git.kernel.org/stable/c/a01859dd6aebf826576513850a3b05992809e9d2', 'https://git.kernel.org/stable/c/b902fb78ab21299e4dd1775e7e8d251d5c0735bc', 'https://git.kernel.org/stable/c/c724b2ab6a46435b4e7d58ad2fbbdb7a318823cf', 'https://lore.kernel.org/linux-cve-announce/2024091338-CVE-2024-46686-5b18@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46686', 'https://www.cve.org/CVERecord?id=CVE-2024-46686'], 'PublishedDate': '2024-09-13T06:15:13.28Z', 'LastModifiedDate': '2024-09-14T16:16:33.087Z'}, {'VulnerabilityID': 'CVE-2024-46687', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46687', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()\n\n[BUG]\nThere is an internal report that KASAN is reporting use-after-free, with\nthe following backtrace:\n\n BUG: KASAN: slab-use-after-free in btrfs_check_read_bio+0xa68/0xb70 [btrfs]\n Read of size 4 at addr ffff8881117cec28 by task kworker/u16:2/45\n CPU: 1 UID: 0 PID: 45 Comm: kworker/u16:2 Not tainted 6.11.0-rc2-next-20240805-default+ #76\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\n Workqueue: btrfs-endio btrfs_end_bio_work [btrfs]\n Call Trace:\n dump_stack_lvl+0x61/0x80\n print_address_description.constprop.0+0x5e/0x2f0\n print_report+0x118/0x216\n kasan_report+0x11d/0x1f0\n btrfs_check_read_bio+0xa68/0xb70 [btrfs]\n process_one_work+0xce0/0x12a0\n worker_thread+0x717/0x1250\n kthread+0x2e3/0x3c0\n ret_from_fork+0x2d/0x70\n ret_from_fork_asm+0x11/0x20\n\n Allocated by task 20917:\n kasan_save_stack+0x37/0x60\n kasan_save_track+0x10/0x30\n __kasan_slab_alloc+0x7d/0x80\n kmem_cache_alloc_noprof+0x16e/0x3e0\n mempool_alloc_noprof+0x12e/0x310\n bio_alloc_bioset+0x3f0/0x7a0\n btrfs_bio_alloc+0x2e/0x50 [btrfs]\n submit_extent_page+0x4d1/0xdb0 [btrfs]\n btrfs_do_readpage+0x8b4/0x12a0 [btrfs]\n btrfs_readahead+0x29a/0x430 [btrfs]\n read_pages+0x1a7/0xc60\n page_cache_ra_unbounded+0x2ad/0x560\n filemap_get_pages+0x629/0xa20\n filemap_read+0x335/0xbf0\n vfs_read+0x790/0xcb0\n ksys_read+0xfd/0x1d0\n do_syscall_64+0x6d/0x140\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n Freed by task 20917:\n kasan_save_stack+0x37/0x60\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x37/0x50\n __kasan_slab_free+0x4b/0x60\n kmem_cache_free+0x214/0x5d0\n bio_free+0xed/0x180\n end_bbio_data_read+0x1cc/0x580 [btrfs]\n btrfs_submit_chunk+0x98d/0x1880 [btrfs]\n btrfs_submit_bio+0x33/0x70 [btrfs]\n submit_one_bio+0xd4/0x130 [btrfs]\n submit_extent_page+0x3ea/0xdb0 [btrfs]\n btrfs_do_readpage+0x8b4/0x12a0 [btrfs]\n btrfs_readahead+0x29a/0x430 [btrfs]\n read_pages+0x1a7/0xc60\n page_cache_ra_unbounded+0x2ad/0x560\n filemap_get_pages+0x629/0xa20\n filemap_read+0x335/0xbf0\n vfs_read+0x790/0xcb0\n ksys_read+0xfd/0x1d0\n do_syscall_64+0x6d/0x140\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n[CAUSE]\nAlthough I cannot reproduce the error, the report itself is good enough\nto pin down the cause.\n\nThe call trace is the regular endio workqueue context, but the\nfree-by-task trace is showing that during btrfs_submit_chunk() we\nalready hit a critical error, and is calling btrfs_bio_end_io() to error\nout. And the original endio function called bio_put() to free the whole\nbio.\n\nThis means a double freeing thus causing use-after-free, e.g.:\n\n1. Enter btrfs_submit_bio() with a read bio\n The read bio length is 128K, crossing two 64K stripes.\n\n2. The first run of btrfs_submit_chunk()\n\n2.1 Call btrfs_map_block(), which returns 64K\n2.2 Call btrfs_split_bio()\n Now there are two bios, one referring to the first 64K, the other\n referring to the second 64K.\n2.3 The first half is submitted.\n\n3. The second run of btrfs_submit_chunk()\n\n3.1 Call btrfs_map_block(), which by somehow failed\n Now we call btrfs_bio_end_io() to handle the error\n\n3.2 btrfs_bio_end_io() calls the original endio function\n Which is end_bbio_data_read(), and it calls bio_put() for the\n original bio.\n\n Now the original bio is freed.\n\n4. The submitted first 64K bio finished\n Now we call into btrfs_check_read_bio() and tries to advance the bio\n iter.\n But since the original bio (thus its iter) is already freed, we\n trigger the above use-after free.\n\n And even if the memory is not poisoned/corrupted, we will later call\n the original endio function, causing a double freeing.\n\n[FIX]\nInstead of calling btrfs_bio_end_io(), call btrfs_orig_bbio_end_io(),\nwhich has the extra check on split bios and do the pr\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415', 'CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46687', 'https://git.kernel.org/linus/10d9d8c3512f16cad47b2ff81ec6fc4b27d8ee10 (6.11-rc6)', 'https://git.kernel.org/stable/c/10d9d8c3512f16cad47b2ff81ec6fc4b27d8ee10', 'https://git.kernel.org/stable/c/4a3b9e1a8e6cd1a8d427a905e159de58d38941cc', 'https://git.kernel.org/stable/c/51722b99f41f5e722ffa10b8f61e802a0e70b331', 'https://lore.kernel.org/linux-cve-announce/2024091338-CVE-2024-46687-5668@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46687', 'https://www.cve.org/CVERecord?id=CVE-2024-46687'], 'PublishedDate': '2024-09-13T06:15:13.377Z', 'LastModifiedDate': '2024-09-14T16:17:33.073Z'}, {'VulnerabilityID': 'CVE-2024-46689', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46689', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: cmd-db: Map shared memory as WC, not WB\n\nLinux does not write into cmd-db region. This region of memory is write\nprotected by XPU. XPU may sometime falsely detect clean cache eviction\nas "write" into the write protected region leading to secure interrupt\nwhich causes an endless loop somewhere in Trust Zone.\n\nThe only reason it is working right now is because Qualcomm Hypervisor\nmaps the same region as Non-Cacheable memory in Stage 2 translation\ntables. The issue manifests if we want to use another hypervisor (like\nXen or KVM), which does not know anything about those specific mappings.\n\nChanging the mapping of cmd-db memory from MEMREMAP_WB to MEMREMAP_WT/WC\nremoves dependency on correct mappings in Stage 2 tables. This patch\nfixes the issue by updating the mapping to MEMREMAP_WC.\n\nI tested this on SA8155P with Xen.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46689', 'https://git.kernel.org/linus/f9bb896eab221618927ae6a2f1d566567999839d (6.11-rc6)', 'https://git.kernel.org/stable/c/0ee9594c974368a17e85a431e9fe1c14fb65c278', 'https://git.kernel.org/stable/c/62c2d63605ca25b5db78a347ed303c0a0a77d5b4', 'https://git.kernel.org/stable/c/d9d48d70e922b272875cda60d2ada89291c840cf', 'https://git.kernel.org/stable/c/eaff392c1e34fb77cc61505a31b0191e5e46e271', 'https://git.kernel.org/stable/c/ef80520be0ff78ae5ed44cb6eee1525e65bebe70', 'https://git.kernel.org/stable/c/f5a5a5a0e95f36e2792d48e6e4b64e665eb01374', 'https://git.kernel.org/stable/c/f9bb896eab221618927ae6a2f1d566567999839d', 'https://lore.kernel.org/linux-cve-announce/2024091339-CVE-2024-46689-4c19@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46689', 'https://www.cve.org/CVERecord?id=CVE-2024-46689'], 'PublishedDate': '2024-09-13T06:15:13.653Z', 'LastModifiedDate': '2024-09-20T15:52:23.727Z'}, {'VulnerabilityID': 'CVE-2024-46691', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46691', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: typec: ucsi: Move unregister out of atomic section', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Move unregister out of atomic section\n\nCommit \'9329933699b3 ("soc: qcom: pmic_glink: Make client-lock\nnon-sleeping")\' moved the pmic_glink client list under a spinlock, as it\nis accessed by the rpmsg/glink callback, which in turn is invoked from\nIRQ context.\n\nThis means that ucsi_unregister() is now called from atomic context,\nwhich isn\'t feasible as it\'s expecting a sleepable context. An effort is\nunder way to get GLINK to invoke its callbacks in a sleepable context,\nbut until then lets schedule the unregistration.\n\nA side effect of this is that ucsi_unregister() can now happen\nafter the remote processor, and thereby the communication link with it, is\ngone. pmic_glink_send() is amended with a check to avoid the resulting NULL\npointer dereference.\nThis does however result in the user being informed about this error by\nthe following entry in the kernel log:\n\n ucsi_glink.pmic_glink_ucsi pmic_glink.ucsi.0: failed to send UCSI write request: -5', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46691', 'https://git.kernel.org/linus/11bb2ffb679399f99041540cf662409905179e3a (6.11-rc6)', 'https://git.kernel.org/stable/c/095b0001aefddcd9361097c971b7debc84e72714', 'https://git.kernel.org/stable/c/11bb2ffb679399f99041540cf662409905179e3a', 'https://lore.kernel.org/linux-cve-announce/2024091339-CVE-2024-46691-93e1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46691', 'https://www.cve.org/CVERecord?id=CVE-2024-46691'], 'PublishedDate': '2024-09-13T06:15:13.96Z', 'LastModifiedDate': '2024-09-13T16:52:21.057Z'}, {'VulnerabilityID': 'CVE-2024-46692', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46692', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: firmware: qcom: scm: Mark get_wq_ctx() as atomic call', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: scm: Mark get_wq_ctx() as atomic call\n\nCurrently get_wq_ctx() is wrongly configured as a standard call. When two\nSMC calls are in sleep and one SMC wakes up, it calls get_wq_ctx() to\nresume the corresponding sleeping thread. But if get_wq_ctx() is\ninterrupted, goes to sleep and another SMC call is waiting to be allocated\na waitq context, it leads to a deadlock.\n\nTo avoid this get_wq_ctx() must be an atomic call and can't be a standard\nSMC call. Hence mark get_wq_ctx() as a fast call.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46692', 'https://git.kernel.org/linus/9960085a3a82c58d3323c1c20b991db6045063b0 (6.11-rc6)', 'https://git.kernel.org/stable/c/9960085a3a82c58d3323c1c20b991db6045063b0', 'https://git.kernel.org/stable/c/cdf7efe4b02aa93813db0bf1ca596ad298ab6b06', 'https://git.kernel.org/stable/c/e40115c33c0d79c940545b6b12112aace7acd9f5', 'https://lore.kernel.org/linux-cve-announce/2024091339-CVE-2024-46692-f287@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46692', 'https://www.cve.org/CVERecord?id=CVE-2024-46692'], 'PublishedDate': '2024-09-13T06:15:14.047Z', 'LastModifiedDate': '2024-09-13T16:52:31.627Z'}, {'VulnerabilityID': 'CVE-2024-46693', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46693', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: pmic_glink: Fix race during initialization', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pmic_glink: Fix race during initialization\n\nAs pointed out by Stephen Boyd it is possible that during initialization\nof the pmic_glink child drivers, the protection-domain notifiers fires,\nand the associated work is scheduled, before the client registration\nreturns and as a result the local "client" pointer has been initialized.\n\nThe outcome of this is a NULL pointer dereference as the "client"\npointer is blindly dereferenced.\n\nTimeline provided by Stephen:\n CPU0 CPU1\n ---- ----\n ucsi->client = NULL;\n devm_pmic_glink_register_client()\n client->pdr_notify(client->priv, pg->client_state)\n pmic_glink_ucsi_pdr_notify()\n schedule_work(&ucsi->register_work)\n \n pmic_glink_ucsi_register()\n ucsi_register()\n pmic_glink_ucsi_read_version()\n pmic_glink_ucsi_read()\n pmic_glink_ucsi_read()\n pmic_glink_send(ucsi->client)\n \n ucsi->client = client // Too late!\n\nThis code is identical across the altmode, battery manager and usci\nchild drivers.\n\nResolve this by splitting the allocation of the "client" object and the\nregistration thereof into two operations.\n\nThis only happens if the protection domain registry is populated at the\ntime of registration, which by the introduction of commit \'1ebcde047c54\n("soc: qcom: add pd-mapper implementation")\' became much more likely.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46693', 'https://git.kernel.org/linus/3568affcddd68743e25aa3ec1647d9b82797757b (6.11-rc6)', 'https://git.kernel.org/stable/c/1efdbf5323c9360e05066049b97414405e94e087', 'https://git.kernel.org/stable/c/3568affcddd68743e25aa3ec1647d9b82797757b', 'https://git.kernel.org/stable/c/943b0e7cc646a624bb20a68080f8f1a4a55df41c', 'https://lore.kernel.org/linux-cve-announce/2024091340-CVE-2024-46693-cbe3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46693', 'https://www.cve.org/CVERecord?id=CVE-2024-46693'], 'PublishedDate': '2024-09-13T06:15:14.14Z', 'LastModifiedDate': '2024-09-13T16:52:41.27Z'}, {'VulnerabilityID': 'CVE-2024-46694', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46694', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: avoid using null object of framebuffer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: avoid using null object of framebuffer\n\nInstead of using state->fb->obj[0] directly, get object from framebuffer\nby calling drm_gem_fb_get_obj() and return error code when object is\nnull to avoid using null object of framebuffer.\n\n(cherry picked from commit 73dd0ad9e5dad53766ea3e631303430116f834b3)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46694', 'https://git.kernel.org/linus/3b9a33235c773c7a3768060cf1d2cf8a9153bc37 (6.11-rc6)', 'https://git.kernel.org/stable/c/093ee72ed35c2338c87c26b6ba6f0b7789c9e14e', 'https://git.kernel.org/stable/c/3b9a33235c773c7a3768060cf1d2cf8a9153bc37', 'https://git.kernel.org/stable/c/49e1b214f3239b78967c6ddb8f8ec47ae047b051', 'https://git.kernel.org/stable/c/f6f5e39a3fe7cbdba190f42b28b40bdff03c8cf0', 'https://lore.kernel.org/linux-cve-announce/2024091340-CVE-2024-46694-0706@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46694', 'https://www.cve.org/CVERecord?id=CVE-2024-46694'], 'PublishedDate': '2024-09-13T06:15:14.24Z', 'LastModifiedDate': '2024-09-19T18:16:22.247Z'}, {'VulnerabilityID': 'CVE-2024-46695', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46695', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: selinux,smack: don't bypass permissions check in inode_setsecctx hook', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux,smack: don't bypass permissions check in inode_setsecctx hook\n\nMarek Gresko reports that the root user on an NFS client is able to\nchange the security labels on files on an NFS filesystem that is\nexported with root squashing enabled.\n\nThe end of the kerneldoc comment for __vfs_setxattr_noperm() states:\n\n * This function requires the caller to lock the inode's i_mutex before it\n * is executed. It also assumes that the caller will make the appropriate\n * permission checks.\n\nnfsd_setattr() does do permissions checking via fh_verify() and\nnfsd_permission(), but those don't do all the same permissions checks\nthat are done by security_inode_setxattr() and its related LSM hooks do.\n\nSince nfsd_setattr() is the only consumer of security_inode_setsecctx(),\nsimplest solution appears to be to replace the call to\n__vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This\nfixes the above issue and has the added benefit of causing nfsd to\nrecall conflicting delegations on a file when a client tries to change\nits security label.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-276'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N', 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46695', 'https://git.kernel.org/linus/76a0e79bc84f466999fa501fce5bf7a07641b8a7 (6.11-rc6)', 'https://git.kernel.org/stable/c/2dbc4b7bac60b02cc6e70d05bf6a7dfd551f9dda', 'https://git.kernel.org/stable/c/459584258d47ec3cc6245a82e8a49c9d08eb8b57', 'https://git.kernel.org/stable/c/76a0e79bc84f466999fa501fce5bf7a07641b8a7', 'https://git.kernel.org/stable/c/eebec98791d0137e455cc006411bb92a54250924', 'https://git.kernel.org/stable/c/f71ec019257ba4f7ab198bd948c5902a207bad96', 'https://git.kernel.org/stable/c/fe0cd53791119f6287b6532af8ce41576d664930', 'https://lore.kernel.org/linux-cve-announce/2024091340-CVE-2024-46695-affc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46695', 'https://www.cve.org/CVERecord?id=CVE-2024-46695'], 'PublishedDate': '2024-09-13T06:15:14.32Z', 'LastModifiedDate': '2024-10-17T14:15:07.517Z'}, {'VulnerabilityID': 'CVE-2024-46697', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46697', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfsd: ensure that nfsd4_fattr_args.context is zeroed out', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: ensure that nfsd4_fattr_args.context is zeroed out\n\nIf nfsd4_encode_fattr4 ends up doing a "goto out" before we get to\nchecking for the security label, then args.context will be set to\nuninitialized junk on the stack, which we\'ll then try to free.\nInitialize it early.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46697', 'https://git.kernel.org/linus/f58bab6fd4063913bd8321e99874b8239e9ba726 (6.11-rc6)', 'https://git.kernel.org/stable/c/dd65b324174a64558a16ebbf4c3266e5701185d0', 'https://git.kernel.org/stable/c/f58bab6fd4063913bd8321e99874b8239e9ba726', 'https://lore.kernel.org/linux-cve-announce/2024091341-CVE-2024-46697-d166@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46697', 'https://www.cve.org/CVERecord?id=CVE-2024-46697'], 'PublishedDate': '2024-09-13T06:15:14.5Z', 'LastModifiedDate': '2024-09-19T17:53:43.173Z'}, {'VulnerabilityID': 'CVE-2024-46698', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46698', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: video/aperture: optionally match the device in sysfb_disable()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvideo/aperture: optionally match the device in sysfb_disable()\n\nIn aperture_remove_conflicting_pci_devices(), we currently only\ncall sysfb_disable() on vga class devices. This leads to the\nfollowing problem when the pimary device is not VGA compatible:\n\n1. A PCI device with a non-VGA class is the boot display\n2. That device is probed first and it is not a VGA device so\n sysfb_disable() is not called, but the device resources\n are freed by aperture_detach_platform_device()\n3. Non-primary GPU has a VGA class and it ends up calling sysfb_disable()\n4. NULL pointer dereference via sysfb_disable() since the resources\n have already been freed by aperture_detach_platform_device() when\n it was called by the other device.\n\nFix this by passing a device pointer to sysfb_disable() and checking\nthe device to determine if we should execute it or not.\n\nv2: Fix build when CONFIG_SCREEN_INFO is not set\nv3: Move device check into the mutex\n Drop primary variable in aperture_remove_conflicting_pci_devices()\n Drop __init on pci sysfb_pci_dev_is_enabled()', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46698', 'https://git.kernel.org/linus/b49420d6a1aeb399e5b107fc6eb8584d0860fbd7 (6.11-rc6)', 'https://git.kernel.org/stable/c/17e78f43de0c6da34204cc858b4cc05671ea9acf', 'https://git.kernel.org/stable/c/b49420d6a1aeb399e5b107fc6eb8584d0860fbd7', 'https://lore.kernel.org/linux-cve-announce/2024091341-CVE-2024-46698-357c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46698', 'https://www.cve.org/CVERecord?id=CVE-2024-46698'], 'PublishedDate': '2024-09-13T06:15:14.563Z', 'LastModifiedDate': '2024-09-13T16:53:03Z'}, {'VulnerabilityID': 'CVE-2024-46701', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46701', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: libfs: fix infinite directory reads for offset dir', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibfs: fix infinite directory reads for offset dir\n\nAfter we switch tmpfs dir operations from simple_dir_operations to\nsimple_offset_dir_operations, every rename happened will fill new dentry\nto dest dir\'s maple tree(&SHMEM_I(inode)->dir_offsets->mt) with a free\nkey starting with octx->newx_offset, and then set newx_offset equals to\nfree key + 1. This will lead to infinite readdir combine with rename\nhappened at the same time, which fail generic/736 in xfstests(detail show\nas below).\n\n1. create 5000 files(1 2 3...) under one dir\n2. call readdir(man 3 readdir) once, and get one entry\n3. rename(entry, "TEMPFILE"), then rename("TEMPFILE", entry)\n4. loop 2~3, until readdir return nothing or we loop too many\n times(tmpfs break test with the second condition)\n\nWe choose the same logic what commit 9b378f6ad48cf ("btrfs: fix infinite\ndirectory reads") to fix it, record the last_index when we open dir, and\ndo not emit the entry which index >= last_index. The file->private_data\nnow used in offset dir can use directly to do this, and we also update\nthe last_index when we llseek the dir file.\n\n[brauner: only update last_index after seek when offset is zero like Jan suggested]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46701', 'https://git.kernel.org/linus/64a7ce76fb901bf9f9c36cf5d681328fc0fd4b5a (6.11-rc4)', 'https://git.kernel.org/stable/c/308b4fc2403b335894592ee9dc212a5e58bb309f', 'https://git.kernel.org/stable/c/64a7ce76fb901bf9f9c36cf5d681328fc0fd4b5a', 'https://lore.kernel.org/linux-cve-announce/2024091326-CVE-2024-46701-ad65@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46701', 'https://www.cve.org/CVERecord?id=CVE-2024-46701'], 'PublishedDate': '2024-09-13T07:15:05.127Z', 'LastModifiedDate': '2024-09-19T13:40:27.817Z'}, {'VulnerabilityID': 'CVE-2024-46702', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46702', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: thunderbolt: Mark XDomain as unplugged when router is removed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Mark XDomain as unplugged when router is removed\n\nI noticed that when we do discrete host router NVM upgrade and it gets\nhot-removed from the PCIe side as a result of NVM firmware authentication,\nif there is another host connected with enabled paths we hang in tearing\nthem down. This is due to fact that the Thunderbolt networking driver\nalso tries to cleanup the paths and ends up blocking in\ntb_disconnect_xdomain_paths() waiting for the domain lock.\n\nHowever, at this point we already cleaned the paths in tb_stop() so\nthere is really no need for tb_disconnect_xdomain_paths() to do that\nanymore. Furthermore it already checks if the XDomain is unplugged and\nbails out early so take advantage of that and mark the XDomain as\nunplugged when we remove the parent router.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46702', 'https://git.kernel.org/linus/e2006140ad2e01a02ed0aff49cc2ae3ceeb11f8d (6.11-rc4)', 'https://git.kernel.org/stable/c/18b3ad2a3cc877dd4b16f48d84aa27b78d53bf1d', 'https://git.kernel.org/stable/c/23ce6ba3b95488a2b9e9f6d43b340da0c15395dc', 'https://git.kernel.org/stable/c/747bc154577de6e6af4bc99abfa859b8419bb4d8', 'https://git.kernel.org/stable/c/7ca24cf9163c112bb6b580c6fb57c04a1f8b76e1', 'https://git.kernel.org/stable/c/80ac8d194831eca0c2f4fd862f7925532fda320c', 'https://git.kernel.org/stable/c/e2006140ad2e01a02ed0aff49cc2ae3ceeb11f8d', 'https://lore.kernel.org/linux-cve-announce/2024091329-CVE-2024-46702-9b8e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46702', 'https://www.cve.org/CVERecord?id=CVE-2024-46702'], 'PublishedDate': '2024-09-13T07:15:05.217Z', 'LastModifiedDate': '2024-09-19T13:35:58.637Z'}, {'VulnerabilityID': 'CVE-2024-46703', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46703', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "serial: 8250_omap: Set the console genpd always on if no console suspend"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "serial: 8250_omap: Set the console genpd always on if no console suspend"\n\nThis reverts commit 68e6939ea9ec3d6579eadeab16060339cdeaf940.\n\nKevin reported that this causes a crash during suspend on platforms that\ndont use PM domains.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46703', 'https://git.kernel.org/linus/0863bffda1131fd2fa9c05b653ad9ee3d8db127e (6.11-rc4)', 'https://git.kernel.org/stable/c/0863bffda1131fd2fa9c05b653ad9ee3d8db127e', 'https://git.kernel.org/stable/c/321aecb079e9ca8b1af90778068a6fb40f2bf22d', 'https://lore.kernel.org/linux-cve-announce/2024091329-CVE-2024-46703-1f29@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46703', 'https://www.cve.org/CVERecord?id=CVE-2024-46703'], 'PublishedDate': '2024-09-13T07:15:05.317Z', 'LastModifiedDate': '2024-09-19T13:33:57.563Z'}, {'VulnerabilityID': 'CVE-2024-46705', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46705', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: reset mmio mappings with devm', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: reset mmio mappings with devm\n\nSet our various mmio mappings to NULL. This should make it easier to\ncatch something rogue trying to mess with mmio after device removal. For\nexample, we might unmap everything and then start hitting some mmio\naddress which has already been unmamped by us and then remapped by\nsomething else, causing all kinds of carnage.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46705', 'https://git.kernel.org/linus/c7117419784f612d59ee565145f722e8b5541fe6 (6.11-rc1)', 'https://git.kernel.org/stable/c/b1c9fbed3884d3883021d699c7cdf5253a65543a', 'https://git.kernel.org/stable/c/c7117419784f612d59ee565145f722e8b5541fe6', 'https://lore.kernel.org/linux-cve-announce/2024091330-CVE-2024-46705-b9c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46705', 'https://www.cve.org/CVERecord?id=CVE-2024-46705'], 'PublishedDate': '2024-09-13T07:15:05.477Z', 'LastModifiedDate': '2024-09-19T13:30:44.133Z'}, {'VulnerabilityID': 'CVE-2024-46706', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46706', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tty: serial: fsl_lpuart: mark last busy before uart_add_one_port', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: fsl_lpuart: mark last busy before uart_add_one_port\n\nWith "earlycon initcall_debug=1 loglevel=8" in bootargs, kernel\nsometimes boot hang. It is because normal console still is not ready,\nbut runtime suspend is called, so early console putchar will hang\nin waiting TRDE set in UARTSTAT.\n\nThe lpuart driver has auto suspend delay set to 3000ms, but during\nuart_add_one_port, a child device serial ctrl will added and probed with\nits pm runtime enabled(see serial_ctrl.c).\nThe runtime suspend call path is:\ndevice_add\n |-> bus_probe_device\n |->device_initial_probe\n\t |->__device_attach\n |-> pm_runtime_get_sync(dev->parent);\n\t\t\t |-> pm_request_idle(dev);\n\t\t\t |-> pm_runtime_put(dev->parent);\n\nSo in the end, before normal console ready, the lpuart get runtime\nsuspended. And earlycon putchar will hang.\n\nTo address the issue, mark last busy just after pm_runtime_enable,\nthree seconds is long enough to switch from bootconsole to normal\nconsole.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46706', 'https://git.kernel.org/linus/dc98d76a15bc29a9a4e76f2f65f39f3e590fb15c (6.11-rc4)', 'https://git.kernel.org/stable/c/3ecf625d4acb71d726bc0b49403cf68388b3d58d', 'https://git.kernel.org/stable/c/8eb92cfca6c2c5a15ab1773f3d18ab8d8f7dbb68', 'https://git.kernel.org/stable/c/dc98d76a15bc29a9a4e76f2f65f39f3e590fb15c', 'https://lore.kernel.org/linux-cve-announce/2024091330-CVE-2024-46706-ea07@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46706', 'https://www.cve.org/CVERecord?id=CVE-2024-46706'], 'PublishedDate': '2024-09-13T07:15:05.56Z', 'LastModifiedDate': '2024-09-19T17:51:07.67Z'}, {'VulnerabilityID': 'CVE-2024-46707', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46707', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3\n\nOn a system with a GICv3, if a guest hasn't been configured with\nGICv3 and that the host is not capable of GICv2 emulation,\na write to any of the ICC_*SGI*_EL1 registers is trapped to EL2.\n\nWe therefore try to emulate the SGI access, only to hit a NULL\npointer as no private interrupt is allocated (no GIC, remember?).\n\nThe obvious fix is to give the guest what it deserves, in the\nshape of a UNDEF exception.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46707', 'https://git.kernel.org/linus/3e6245ebe7ef341639e9a7e402b3ade8ad45a19f (6.11-rc5)', 'https://git.kernel.org/stable/c/15818af2f7aa55eff375333cb7689df15d3f24ef', 'https://git.kernel.org/stable/c/2073132f6ed3079369e857a8deb33d11bdd983bc', 'https://git.kernel.org/stable/c/3e6245ebe7ef341639e9a7e402b3ade8ad45a19f', 'https://git.kernel.org/stable/c/94d4fbad01b19ec5eab3d6b50aaec4f9db8b2d8d', 'https://git.kernel.org/stable/c/96b076e8ee5bc3a1126848c8add0f74bd30dc9d1', 'https://git.kernel.org/stable/c/9d7629bec5c3f80bd0e3bf8103c06a2f7046bd92', 'https://lore.kernel.org/linux-cve-announce/2024091330-CVE-2024-46707-9e4f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46707', 'https://www.cve.org/CVERecord?id=CVE-2024-46707'], 'PublishedDate': '2024-09-13T07:15:05.643Z', 'LastModifiedDate': '2024-09-19T13:29:46.757Z'}, {'VulnerabilityID': 'CVE-2024-46708', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46708', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pinctrl: qcom: x1e80100: Fix special pin offsets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: qcom: x1e80100: Fix special pin offsets\n\nRemove the erroneus 0x100000 offset to prevent the boards from crashing\non pin state setting, as well as for the intended state changes to take\neffect.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46708', 'https://git.kernel.org/linus/d3692d95cc4d88114b070ee63cffc976f00f207f (6.11-rc6)', 'https://git.kernel.org/stable/c/0197bf772f657fbdea5e9bdec5eea6e67d82cbde', 'https://git.kernel.org/stable/c/d3692d95cc4d88114b070ee63cffc976f00f207f', 'https://lore.kernel.org/linux-cve-announce/2024091347-CVE-2024-46708-95c1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46708', 'https://www.cve.org/CVERecord?id=CVE-2024-46708'], 'PublishedDate': '2024-09-13T07:15:05.717Z', 'LastModifiedDate': '2024-09-19T13:28:49.483Z'}, {'VulnerabilityID': 'CVE-2024-46709', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46709', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Fix prime with external buffers', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix prime with external buffers\n\nMake sure that for external buffers mapping goes through the dma_buf\ninterface instead of trying to access pages directly.\n\nExternal buffers might not provide direct access to readable/writable\npages so to make sure the bo's created from external dma_bufs can be\nread dma_buf interface has to be used.\n\nFixes crashes in IGT's kms_prime with vgem. Regular desktop usage won't\ntrigger this due to the fact that virtual machines will not have\nmultiple GPUs but it enables better test coverage in IGT.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46709', 'https://git.kernel.org/linus/50f1199250912568606b3778dc56646c10cb7b04 (6.11-rc6)', 'https://git.kernel.org/stable/c/50f1199250912568606b3778dc56646c10cb7b04', 'https://git.kernel.org/stable/c/5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854', 'https://git.kernel.org/stable/c/9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4', 'https://lore.kernel.org/linux-cve-announce/2024091347-CVE-2024-46709-2465@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46709', 'https://www.cve.org/CVERecord?id=CVE-2024-46709'], 'PublishedDate': '2024-09-13T07:15:05.793Z', 'LastModifiedDate': '2024-09-19T13:26:24.14Z'}, {'VulnerabilityID': 'CVE-2024-46710', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46710', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Prevent unmapping active read buffers', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Prevent unmapping active read buffers\n\nThe kms paths keep a persistent map active to read and compare the cursor\nbuffer. These maps can race with each other in simple scenario where:\na) buffer "a" mapped for update\nb) buffer "a" mapped for compare\nc) do the compare\nd) unmap "a" for compare\ne) update the cursor\nf) unmap "a" for update\nAt step "e" the buffer has been unmapped and the read contents is bogus.\n\nPrevent unmapping of active read buffers by simply keeping a count of\nhow many paths have currently active maps and unmap only when the count\nreaches 0.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46710', 'https://git.kernel.org/linus/aba07b9a0587f50e5d3346eaa19019cf3f86c0ea (6.11-rc6)', 'https://git.kernel.org/stable/c/0851b1ec650adadcaa23ec96daad95a55bf966f0', 'https://git.kernel.org/stable/c/58a3714db4d9dcaeb9fc4905141e17b9f536c0a5', 'https://git.kernel.org/stable/c/aba07b9a0587f50e5d3346eaa19019cf3f86c0ea', 'https://git.kernel.org/stable/c/d5228d158e4c0b1663b3983044913c15c3d0135e', 'https://lore.kernel.org/linux-cve-announce/2024091347-CVE-2024-46710-cd88@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46710', 'https://www.cve.org/CVERecord?id=CVE-2024-46710'], 'PublishedDate': '2024-09-13T07:15:05.88Z', 'LastModifiedDate': '2024-10-17T14:15:07.63Z'}, {'VulnerabilityID': 'CVE-2024-46711', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46711', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: fix ID 0 endp usage after multiple re-creations', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix ID 0 endp usage after multiple re-creations\n\n\'local_addr_used\' and \'add_addr_accepted\' are decremented for addresses\nnot related to the initial subflow (ID0), because the source and\ndestination addresses of the initial subflows are known from the\nbeginning: they don\'t count as "additional local address being used" or\n"ADD_ADDR being accepted".\n\nIt is then required not to increment them when the entrypoint used by\nthe initial subflow is removed and re-added during a connection. Without\nthis modification, this entrypoint cannot be removed and re-added more\nthan once.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46711', 'https://git.kernel.org/linus/9366922adc6a71378ca01f898c41be295309f044 (6.11-rc6)', 'https://git.kernel.org/stable/c/119806ae4e46cf239db8e6ad92bc2fd3daae86dc', 'https://git.kernel.org/stable/c/53e2173172d26c0617b29dd83618b71664bed1fb', 'https://git.kernel.org/stable/c/9366922adc6a71378ca01f898c41be295309f044', 'https://git.kernel.org/stable/c/c9c744666f7308a4daba520191e29d395260bcfe', 'https://lore.kernel.org/linux-cve-announce/2024091348-CVE-2024-46711-ab95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46711', 'https://www.cve.org/CVERecord?id=CVE-2024-46711'], 'PublishedDate': '2024-09-13T07:15:05.953Z', 'LastModifiedDate': '2024-09-19T13:12:30.39Z'}, {'VulnerabilityID': 'CVE-2024-46713', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46713', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf/aux: Fix AUX buffer serialization', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf/aux: Fix AUX buffer serialization\n\nOle reported that event->mmap_mutex is strictly insufficient to\nserialize the AUX buffer, add a per RB mutex to fully serialize it.\n\nNote that in the lock order comment the perf_event::mmap_mutex order\nwas already wrong, that is, it nesting under mmap_lock is not new with\nthis patch.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46713', 'https://git.kernel.org/linus/2ab9d830262c132ab5db2f571003d80850d56b2a (6.11-rc7)', 'https://git.kernel.org/stable/c/2ab9d830262c132ab5db2f571003d80850d56b2a', 'https://git.kernel.org/stable/c/52d13d224fdf1299c8b642807fa1ea14d693f5ff', 'https://git.kernel.org/stable/c/7882923f1cb88dc1a17f2bf0c81b1fc80d44db82', 'https://git.kernel.org/stable/c/9dc7ad2b67772cfb94ceb3b0c9c4023c2463215d', 'https://git.kernel.org/stable/c/b9b6882e243b653d379abbeaa64a500182aba370', 'https://git.kernel.org/stable/c/c4b69bee3f4ef76809288fe6827bc14d4ae788ef', 'https://lore.kernel.org/linux-cve-announce/2024091316-CVE-2024-46713-5e49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46713', 'https://www.cve.org/CVERecord?id=CVE-2024-46713'], 'PublishedDate': '2024-09-13T15:15:15.01Z', 'LastModifiedDate': '2024-09-13T16:37:22.997Z'}, {'VulnerabilityID': 'CVE-2024-46714', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46714', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip wbscl_set_scaler_filter if filter is null', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip wbscl_set_scaler_filter if filter is null\n\nCallers can pass null in filter (i.e. from returned from the function\nwbscl_get_filter_coeffs_16p) and a null check is added to ensure that is\nnot the case.\n\nThis fixes 4 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46714', 'https://git.kernel.org/linus/c4d31653c03b90e51515b1380115d1aedad925dd (6.11-rc1)', 'https://git.kernel.org/stable/c/0364f1f17a86d89dc39040beea4f099e60189f1b', 'https://git.kernel.org/stable/c/1726914cb17cedab233820d26b86764dc08857b4', 'https://git.kernel.org/stable/c/54834585e91cab13e9f82d3a811deb212a4df786', 'https://git.kernel.org/stable/c/6d94c05a13fadd80c3e732f14c83b2632ebfaa50', 'https://git.kernel.org/stable/c/c083c8be6bdd046049884bec076660d4ec9a19ca', 'https://git.kernel.org/stable/c/c4d31653c03b90e51515b1380115d1aedad925dd', 'https://git.kernel.org/stable/c/e3a95f29647ae45d1ec9541cd7df64f40bf2120a', 'https://lore.kernel.org/linux-cve-announce/2024091831-CVE-2024-46714-73de@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46714', 'https://www.cve.org/CVERecord?id=CVE-2024-46714'], 'PublishedDate': '2024-09-18T07:15:03.06Z', 'LastModifiedDate': '2024-09-30T12:50:27.723Z'}, {'VulnerabilityID': 'CVE-2024-46715', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46715', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: driver: iio: add missing checks on iio_info's callback access', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver: iio: add missing checks on iio_info's callback access\n\nSome callbacks from iio_info structure are accessed without any check, so\nif a driver doesn't implement them trying to access the corresponding\nsysfs entries produce a kernel oops such as:\n\n[ 2203.527791] Unable to handle kernel NULL pointer dereference at virtual address 00000000 when execute\n[...]\n[ 2203.783416] Call trace:\n[ 2203.783429] iio_read_channel_info_avail from dev_attr_show+0x18/0x48\n[ 2203.789807] dev_attr_show from sysfs_kf_seq_show+0x90/0x120\n[ 2203.794181] sysfs_kf_seq_show from seq_read_iter+0xd0/0x4e4\n[ 2203.798555] seq_read_iter from vfs_read+0x238/0x2a0\n[ 2203.802236] vfs_read from ksys_read+0xa4/0xd4\n[ 2203.805385] ksys_read from ret_fast_syscall+0x0/0x54\n[ 2203.809135] Exception stack(0xe0badfa8 to 0xe0badff0)\n[ 2203.812880] dfa0: 00000003 b6f10f80 00000003 b6eab000 00020000 00000000\n[ 2203.819746] dfc0: 00000003 b6f10f80 7ff00000 00000003 00000003 00000000 00020000 00000000\n[ 2203.826619] dfe0: b6e1bc88 bed80958 b6e1bc94 b6e1bcb0\n[ 2203.830363] Code: bad PC value\n[ 2203.832695] ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46715', 'https://git.kernel.org/linus/c4ec8dedca961db056ec85cb7ca8c9f7e2e92252 (6.11-rc1)', 'https://git.kernel.org/stable/c/0cc7e0ee31e5c44904e98e2229d591e093282a70', 'https://git.kernel.org/stable/c/72f022ebb9deac28663fa4c04ba315ed5d6654d1', 'https://git.kernel.org/stable/c/c4ec8dedca961db056ec85cb7ca8c9f7e2e92252', 'https://git.kernel.org/stable/c/dc537a72f64890d883d24ae4ac58733fc5bc523d', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46715-7e7b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46715', 'https://www.cve.org/CVERecord?id=CVE-2024-46715'], 'PublishedDate': '2024-09-18T07:15:03.13Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46716', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46716', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor\n\nRemove list_del call in msgdma_chan_desc_cleanup, this should be the role\nof msgdma_free_descriptor. In consequence replace list_add_tail with\nlist_move_tail in msgdma_free_descriptor.\n\nThis fixes the path:\n msgdma_free_chan_resources -> msgdma_free_descriptors ->\n msgdma_free_desc_list -> msgdma_free_descriptor\n\nwhich does not correctly free the descriptors as first nodes were not\nremoved from the list.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46716', 'https://git.kernel.org/linus/54e4ada1a4206f878e345ae01cf37347d803d1b1 (6.11-rc1)', 'https://git.kernel.org/stable/c/20bf2920a869f9dbda0ef8c94c87d1901a64a716', 'https://git.kernel.org/stable/c/54e4ada1a4206f878e345ae01cf37347d803d1b1', 'https://git.kernel.org/stable/c/a3480e59fdbe5585d2d1eff0bed7671583acf725', 'https://git.kernel.org/stable/c/db67686676c7becc1910bf1d6d51505876821863', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46716-f63f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46716', 'https://www.cve.org/CVERecord?id=CVE-2024-46716'], 'PublishedDate': '2024-09-18T07:15:03.183Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46717', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46717', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: SHAMPO, Fix incorrect page release', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix incorrect page release\n\nUnder the following conditions:\n1) No skb created yet\n2) header_size == 0 (no SHAMPO header)\n3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PAGE == 0 (this is the\n last page fragment of a SHAMPO header page)\n\na new skb is formed with a page that is NOT a SHAMPO header page (it\nis a regular data page). Further down in the same function\n(mlx5e_handle_rx_cqe_mpwrq_shampo()), a SHAMPO header page from\nheader_index is released. This is wrong and it leads to SHAMPO header\npages being released more than once.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46717', 'https://git.kernel.org/linus/70bd03b89f20b9bbe51a7f73c4950565a17a45f7 (6.11-rc1)', 'https://git.kernel.org/stable/c/03924d117625ecb10ee3c9b65930bcb2c37ae629', 'https://git.kernel.org/stable/c/70bd03b89f20b9bbe51a7f73c4950565a17a45f7', 'https://git.kernel.org/stable/c/ae9018e3f61ba5cc1f08a6e51d3c0bef0a79f3ab', 'https://git.kernel.org/stable/c/c909ab41df2b09cde919801c7a7b6bb2cc37ea22', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46717-2f30@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46717', 'https://www.cve.org/CVERecord?id=CVE-2024-46717'], 'PublishedDate': '2024-09-18T07:15:03.237Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46718', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46718', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe: Don't overmap identity VRAM mapping', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Don't overmap identity VRAM mapping\n\nOvermapping the identity VRAM mapping is triggering hardware bugs on\ncertain platforms. Use 2M pages for the last unaligned (to 1G) VRAM\nchunk.\n\nv2:\n - Always use 2M pages for last chunk (Fei Yang)\n - break loop when 2M pages are used\n - Add assert for usable_size being 2M aligned\nv3:\n - Fix checkpatch", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46718', 'https://git.kernel.org/linus/6d3581edffea0b3a64b0d3094d3f09222e0024f7 (6.11-rc1)', 'https://git.kernel.org/stable/c/6d3581edffea0b3a64b0d3094d3f09222e0024f7', 'https://git.kernel.org/stable/c/bb706e92c87beb9f2543faa1705ccc330b9e7c65', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46718-c5c7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46718', 'https://www.cve.org/CVERecord?id=CVE-2024-46718'], 'PublishedDate': '2024-09-18T07:15:03.303Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46719', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46719', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: typec: ucsi: Fix null pointer dereference in trace', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix null pointer dereference in trace\n\nucsi_register_altmode checks IS_ERR for the alt pointer and treats\nNULL as valid. When CONFIG_TYPEC_DP_ALTMODE is not enabled,\nucsi_register_displayport returns NULL which causes a NULL pointer\ndereference in trace. Rather than return NULL, call\ntypec_port_register_altmode to register DisplayPort alternate mode\nas a non-controllable mode when CONFIG_TYPEC_DP_ALTMODE is not enabled.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46719', 'https://git.kernel.org/linus/99516f76db48e1a9d54cdfed63c1babcee4e71a5 (6.11-rc1)', 'https://git.kernel.org/stable/c/3aa56313b0de06ce1911950b2cc0c269614a87a9', 'https://git.kernel.org/stable/c/3b9f2d9301ae67070fe77a0c06758722fd7172b7', 'https://git.kernel.org/stable/c/7e64cabe81c303bdf6fd26b6a09a3289b33bc870', 'https://git.kernel.org/stable/c/8095bf0579ed4906a33f7bec675bfb29b6b16a3b', 'https://git.kernel.org/stable/c/99331fe68a8eaa4097143a33fb0c12d5e5e8e830', 'https://git.kernel.org/stable/c/99516f76db48e1a9d54cdfed63c1babcee4e71a5', 'https://git.kernel.org/stable/c/b4243c05d7e3db0bdbf9124e6fa59b4ca7c807ae', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46719-4a53@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46719', 'https://www.cve.org/CVERecord?id=CVE-2024-46719'], 'PublishedDate': '2024-09-18T07:15:03.357Z', 'LastModifiedDate': '2024-09-20T18:21:49.963Z'}, {'VulnerabilityID': 'CVE-2024-46720', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46720', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix dereference after null check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix dereference after null check\n\ncheck the pointer hive before use.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46720', 'https://git.kernel.org/linus/b1f7810b05d1950350ac2e06992982974343e441 (6.11-rc1)', 'https://git.kernel.org/stable/c/00b9594d6310eb33e14d3f07b54866499efe0d50', 'https://git.kernel.org/stable/c/0aad97bf6d0bc7a34a19f266b0b9fb2861efe64c', 'https://git.kernel.org/stable/c/1b73ea3d97cc23f9b16d10021782b48397d2b517', 'https://git.kernel.org/stable/c/b1f7810b05d1950350ac2e06992982974343e441', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46720-a598@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46720', 'https://www.cve.org/CVERecord?id=CVE-2024-46720'], 'PublishedDate': '2024-09-18T07:15:03.42Z', 'LastModifiedDate': '2024-09-20T18:22:04.693Z'}, {'VulnerabilityID': 'CVE-2024-46721', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46721', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: apparmor: fix possible NULL pointer dereference', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix possible NULL pointer dereference\n\nprofile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made\nfrom __create_missing_ancestors(..) and 'ent->old' is NULL in\naa_replace_profiles(..).\nIn that case, it must return an error code and the code, -ENOENT represents\nits state that the path of its parent is not existed yet.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000030\nPGD 0 P4D 0\nPREEMPT SMP PTI\nCPU: 4 PID: 3362 Comm: apparmor_parser Not tainted 6.8.0-24-generic #24\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\nRIP: 0010:aafs_create.constprop.0+0x7f/0x130\nCode: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae\nRSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 00000000000041ed RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc9000b2c7cd8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffffff82baac10\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007be9f22cf740(0000) GS:ffff88817bc00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000030 CR3: 0000000134b08000 CR4: 00000000000006f0\nCall Trace:\n \n ? show_regs+0x6d/0x80\n ? __die+0x24/0x80\n ? page_fault_oops+0x99/0x1b0\n ? kernelmode_fixup_or_oops+0xb2/0x140\n ? __bad_area_nosemaphore+0x1a5/0x2c0\n ? find_vma+0x34/0x60\n ? bad_area_nosemaphore+0x16/0x30\n ? do_user_addr_fault+0x2a2/0x6b0\n ? exc_page_fault+0x83/0x1b0\n ? asm_exc_page_fault+0x27/0x30\n ? aafs_create.constprop.0+0x7f/0x130\n ? aafs_create.constprop.0+0x51/0x130\n __aafs_profile_mkdir+0x3d6/0x480\n aa_replace_profiles+0x83f/0x1270\n policy_update+0xe3/0x180\n profile_load+0xbc/0x150\n ? rw_verify_area+0x47/0x140\n vfs_write+0x100/0x480\n ? __x64_sys_openat+0x55/0xa0\n ? syscall_exit_to_user_mode+0x86/0x260\n ksys_write+0x73/0x100\n __x64_sys_write+0x19/0x30\n x64_sys_call+0x7e/0x25c0\n do_syscall_64+0x7f/0x180\n entry_SYSCALL_64_after_hwframe+0x78/0x80\nRIP: 0033:0x7be9f211c574\nCode: c7 00 16 00 00 00 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 80 3d d5 ea 0e 00 00 74 13 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 54 c3 0f 1f 00 55 48 89 e5 48 83 ec 20 48 89\nRSP: 002b:00007ffd26f2b8c8 EFLAGS: 00000202 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00005d504415e200 RCX: 00007be9f211c574\nRDX: 0000000000001fc1 RSI: 00005d504418bc80 RDI: 0000000000000004\nRBP: 0000000000001fc1 R08: 0000000000001fc1 R09: 0000000080000000\nR10: 0000000000000000 R11: 0000000000000202 R12: 00005d504418bc80\nR13: 0000000000000004 R14: 00007ffd26f2b9b0 R15: 00007ffd26f2ba30\n \nModules linked in: snd_seq_dummy snd_hrtimer qrtr snd_hda_codec_generic snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_seq_midi snd_seq_midi_event snd_rawmidi snd_seq snd_seq_device i2c_i801 snd_timer i2c_smbus qxl snd soundcore drm_ttm_helper lpc_ich ttm joydev input_leds serio_raw mac_hid binfmt_misc msr parport_pc ppdev lp parport efi_pstore nfnetlink dmi_sysfs qemu_fw_cfg ip_tables x_tables autofs4 hid_generic usbhid hid ahci libahci psmouse virtio_rng xhci_pci xhci_pci_renesas\nCR2: 0000000000000030\n---[ end trace 0000000000000000 ]---\nRIP: 0010:aafs_create.constprop.0+0x7f/0x130\nCode: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae\nRSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 00000000000041ed RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc9000b2c7cd8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46721', 'https://git.kernel.org/linus/3dd384108d53834002be5630132ad5c3f32166ad (6.11-rc1)', 'https://git.kernel.org/stable/c/09b2d107fe63e55b6ae643f9f26bf8eb14a261d9', 'https://git.kernel.org/stable/c/3dd384108d53834002be5630132ad5c3f32166ad', 'https://git.kernel.org/stable/c/52338a3aa772762b8392ce7cac106c1099aeab85', 'https://git.kernel.org/stable/c/59f742e55a469ef36c5c1533b6095a103b61eda8', 'https://git.kernel.org/stable/c/730ee2686af0d55372e97a2695005ff142702363', 'https://git.kernel.org/stable/c/8d9da10a392a32368392f7a16775e1f36e2a5346', 'https://git.kernel.org/stable/c/c49bbe69ee152bd9c1c1f314c0f582e76c578f64', 'https://git.kernel.org/stable/c/e3c7d23f7a5c0b11ba0093cea32261ab8098b94e', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46721-9aa7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46721', 'https://www.cve.org/CVERecord?id=CVE-2024-46721'], 'PublishedDate': '2024-09-18T07:15:03.48Z', 'LastModifiedDate': '2024-09-20T18:22:46.637Z'}, {'VulnerabilityID': 'CVE-2024-46722', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46722', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix mc_data out-of-bounds read warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix mc_data out-of-bounds read warning\n\nClear warning that read mc_data[i-1] may out-of-bounds.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46722', 'https://git.kernel.org/linus/51dfc0a4d609fe700750a62f41447f01b8c9ea50 (6.11-rc1)', 'https://git.kernel.org/stable/c/2097edede72ec5bb3869cf0205337d392fb2a553', 'https://git.kernel.org/stable/c/310b9d8363b88e818afec97ca7652bd7fe3d0650', 'https://git.kernel.org/stable/c/345bd3ad387f9e121aaad9c95957b80895e2f2ec', 'https://git.kernel.org/stable/c/51dfc0a4d609fe700750a62f41447f01b8c9ea50', 'https://git.kernel.org/stable/c/578ae965e8b90cd09edeb0252b50fa0503ea35c5', 'https://git.kernel.org/stable/c/5fa4df25ecfc7b6c9006f5b871c46cfe25ea8826', 'https://git.kernel.org/stable/c/b862a0bc5356197ed159fed7b1c647e77bc9f653', 'https://git.kernel.org/stable/c/d0a43bf367ed640e527e8ef3d53aac1e71f80114', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46722-34b3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46722', 'https://www.cve.org/CVERecord?id=CVE-2024-46722'], 'PublishedDate': '2024-09-18T07:15:03.547Z', 'LastModifiedDate': '2024-09-20T18:23:11.93Z'}, {'VulnerabilityID': 'CVE-2024-46723', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46723', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix ucode out-of-bounds read warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix ucode out-of-bounds read warning\n\nClear warning that read ucode[] may out-of-bounds.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46723', 'https://git.kernel.org/linus/8944acd0f9db33e17f387fdc75d33bb473d7936f (6.11-rc1)', 'https://git.kernel.org/stable/c/0bef65e069d84d1cd77ce757aea0e437b8e2bd33', 'https://git.kernel.org/stable/c/23fefef859c6057e6770584242bdd938254f8ddd', 'https://git.kernel.org/stable/c/5f09fa5e0ad45fbca71933a0e024ca52da47d59b', 'https://git.kernel.org/stable/c/82ac8f1d02886b5d8aeb9e058989d3bd6fc581e2', 'https://git.kernel.org/stable/c/8944acd0f9db33e17f387fdc75d33bb473d7936f', 'https://git.kernel.org/stable/c/8981927ebc6c12fa76b30c4178acb462bab15f54', 'https://git.kernel.org/stable/c/e789e05388854a5436b2b5d8695fdb864c9bcc27', 'https://git.kernel.org/stable/c/f2b7a9f3839e92f43559b2795b34640ca8cf839f', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46723-6726@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46723', 'https://www.cve.org/CVERecord?id=CVE-2024-46723'], 'PublishedDate': '2024-09-18T07:15:03.61Z', 'LastModifiedDate': '2024-09-20T18:30:30.117Z'}, {'VulnerabilityID': 'CVE-2024-46724', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46724', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number\n\nCheck the fb_channel_number range to avoid the array out-of-bounds\nread error', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46724', 'https://git.kernel.org/linus/d768394fa99467bcf2703bde74ddc96eeb0b71fa (6.11-rc1)', 'https://git.kernel.org/stable/c/32915dc909ff502823babfe07d5416c5b6e8a8b1', 'https://git.kernel.org/stable/c/45f7b02afc464c208e8f56bcbc672ef5c364c815', 'https://git.kernel.org/stable/c/725b728cc0c8c5fafdfb51cb0937870d33a40fa4', 'https://git.kernel.org/stable/c/d768394fa99467bcf2703bde74ddc96eeb0b71fa', 'https://git.kernel.org/stable/c/db7a86676fd624768a5d907faf34ad7bb4ff25f4', 'https://git.kernel.org/stable/c/f9267972490f9fcffe146e79828e97acc0da588c', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46724-02f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46724', 'https://www.cve.org/CVERecord?id=CVE-2024-46724'], 'PublishedDate': '2024-09-18T07:15:03.673Z', 'LastModifiedDate': '2024-09-20T18:30:58.98Z'}, {'VulnerabilityID': 'CVE-2024-46725', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46725', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix out-of-bounds write warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix out-of-bounds write warning\n\nCheck the ring type value to fix the out-of-bounds\nwrite warning', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46725', 'https://git.kernel.org/linus/be1684930f5262a622d40ce7a6f1423530d87f89 (6.11-rc1)', 'https://git.kernel.org/stable/c/130bee397b9cd52006145c87a456fd8719390cb5', 'https://git.kernel.org/stable/c/919f9bf9997b8dcdc132485ea96121e7d15555f9', 'https://git.kernel.org/stable/c/a60d1f7ff62e453dde2d3b4907e178954d199844', 'https://git.kernel.org/stable/c/be1684930f5262a622d40ce7a6f1423530d87f89', 'https://git.kernel.org/stable/c/c253b87c7c37ec40a2e0c84e4a6b636ba5cd66b2', 'https://git.kernel.org/stable/c/cf2db220b38301b6486a0f11da24a0f317de558c', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46725-af49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46725', 'https://www.cve.org/CVERecord?id=CVE-2024-46725'], 'PublishedDate': '2024-09-18T07:15:03.733Z', 'LastModifiedDate': '2024-09-20T18:40:42.753Z'}, {'VulnerabilityID': 'CVE-2024-46726', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46726', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Ensure index calculation will not overflow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Ensure index calculation will not overflow\n\n[WHY & HOW]\nMake sure vmid0p72_idx, vnom0p8_idx and vmax0p9_idx calculation will\nnever overflow and exceess array size.\n\nThis fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46726', 'https://git.kernel.org/linus/8e2734bf444767fed787305ccdcb36a2be5301a2 (6.11-rc1)', 'https://git.kernel.org/stable/c/3dc6bb57dab36b38b7374af0ac916174c146b6ed', 'https://git.kernel.org/stable/c/733ae185502d30bbe79575167b6178cfb6c5d6bd', 'https://git.kernel.org/stable/c/8e2734bf444767fed787305ccdcb36a2be5301a2', 'https://git.kernel.org/stable/c/d705b5869f6b1b46ad5ceb1bd2a08c04f7e5003b', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46726-587e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46726', 'https://www.cve.org/CVERecord?id=CVE-2024-46726'], 'PublishedDate': '2024-09-18T07:15:03.787Z', 'LastModifiedDate': '2024-09-20T18:36:27.07Z'}, {'VulnerabilityID': 'CVE-2024-46727', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46727', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update\n\n[Why]\nCoverity reports NULL_RETURN warning.\n\n[How]\nAdd otg_master NULL check.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46727', 'https://git.kernel.org/linus/871cd9d881fa791d3f82885000713de07041c0ae (6.11-rc1)', 'https://git.kernel.org/stable/c/871cd9d881fa791d3f82885000713de07041c0ae', 'https://git.kernel.org/stable/c/aad4d3d3d3b6a362bf5db11e1f28c4a60620900d', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46727-2565@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46727', 'https://www.cve.org/CVERecord?id=CVE-2024-46727'], 'PublishedDate': '2024-09-18T07:15:03.84Z', 'LastModifiedDate': '2024-09-30T12:49:43.097Z'}, {'VulnerabilityID': 'CVE-2024-46728', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46728', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check index for aux_rd_interval before using', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check index for aux_rd_interval before using\n\naux_rd_interval has size of 7 and should be checked.\n\nThis fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46728', 'https://git.kernel.org/linus/9ba2ea6337b4f159aecb177555a6a81da92d302e (6.11-rc1)', 'https://git.kernel.org/stable/c/48e0b68e2360b16edf2a0bae05c0051c00fbb48a', 'https://git.kernel.org/stable/c/6c588e9350dd7a9fb97a56fe74852c9ecc44450c', 'https://git.kernel.org/stable/c/9ba2ea6337b4f159aecb177555a6a81da92d302e', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46728-edfe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46728', 'https://www.cve.org/CVERecord?id=CVE-2024-46728'], 'PublishedDate': '2024-09-18T07:15:03.893Z', 'LastModifiedDate': '2024-09-26T13:31:34.347Z'}, {'VulnerabilityID': 'CVE-2024-46729', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46729', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix incorrect size calculation for loop', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix incorrect size calculation for loop\n\n[WHY]\nfe_clk_en has size of 5 but sizeof(fe_clk_en) has byte size 20 which is\nlager than the array size.\n\n[HOW]\nDivide byte size 20 by its element size.\n\nThis fixes 2 OVERRUN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46729', 'https://git.kernel.org/linus/3941a3aa4b653b69876d894d08f3fff1cc965267 (6.11-rc1)', 'https://git.kernel.org/stable/c/3941a3aa4b653b69876d894d08f3fff1cc965267', 'https://git.kernel.org/stable/c/712be65b3b372a82bff0865b9c090147764bf1c4', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46729-158c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46729', 'https://www.cve.org/CVERecord?id=CVE-2024-46729'], 'PublishedDate': '2024-09-18T07:15:03.95Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46730', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46730', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Ensure array index tg_inst won't be -1', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Ensure array index tg_inst won't be -1\n\n[WHY & HOW]\ntg_inst will be a negative if timing_generator_count equals 0, which\nshould be checked before used.\n\nThis fixes 2 OVERRUN issues reported by Coverity.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46730', 'https://git.kernel.org/linus/687fe329f18ab0ab0496b20ed2cb003d4879d931 (6.11-rc1)', 'https://git.kernel.org/stable/c/687fe329f18ab0ab0496b20ed2cb003d4879d931', 'https://git.kernel.org/stable/c/a64284b9e1999ad5580debced4bc6d6adb28aad4', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46730-b69e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46730', 'https://www.cve.org/CVERecord?id=CVE-2024-46730'], 'PublishedDate': '2024-09-18T07:15:04.003Z', 'LastModifiedDate': '2024-09-30T12:49:00.333Z'}, {'VulnerabilityID': 'CVE-2024-46731', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46731', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: fix the Out-of-bounds read warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: fix the Out-of-bounds read warning\n\nusing index i - 1U may beyond element index\nfor mc_data[] when i = 0.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46731', 'https://git.kernel.org/linus/12c6967428a099bbba9dfd247bb4322a984fcc0b (6.11-rc1)', 'https://git.kernel.org/stable/c/12c6967428a099bbba9dfd247bb4322a984fcc0b', 'https://git.kernel.org/stable/c/20c6373a6be93039f9d66029bb1e21038a060be1', 'https://git.kernel.org/stable/c/3317966efcdc5101e93db21514b68917e7eb34ea', 'https://git.kernel.org/stable/c/38e32a0d837443c91c4b615a067b976cfb925376', 'https://git.kernel.org/stable/c/d83fb9f9f63e9a120bf405b078f829f0b2e58934', 'https://git.kernel.org/stable/c/f1e261ced9bcad772a45a2fcdf413c3490e87299', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46731-0e54@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46731', 'https://www.cve.org/CVERecord?id=CVE-2024-46731'], 'PublishedDate': '2024-09-18T07:15:04.057Z', 'LastModifiedDate': '2024-09-26T13:29:19.877Z'}, {'VulnerabilityID': 'CVE-2024-46732', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46732', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Assign linear_pitch_alignment even for VM', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Assign linear_pitch_alignment even for VM\n\n[Description]\nAssign linear_pitch_alignment so we don't cause a divide by 0\nerror in VM environments", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46732', 'https://git.kernel.org/linus/984debc133efa05e62f5aa1a7a1dd8ca0ef041f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/4bd7710f2fecfc5fb2dda1ca2adc69db8a66b8b6', 'https://git.kernel.org/stable/c/984debc133efa05e62f5aa1a7a1dd8ca0ef041f4', 'https://git.kernel.org/stable/c/c44b568931d23aed9d37ecbb31fb5fbdd198bf7b', 'https://git.kernel.org/stable/c/d219f902b16d42f0cb8c499ea8f31cf3c0f36349', 'https://git.kernel.org/stable/c/d2fe7ac613a1ea8c346c9f5c89dc6ecc27232997', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46732-49a9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46732', 'https://www.cve.org/CVERecord?id=CVE-2024-46732'], 'PublishedDate': '2024-09-18T07:15:04.117Z', 'LastModifiedDate': '2024-09-26T13:28:07.157Z'}, {'VulnerabilityID': 'CVE-2024-46733', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46733', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix qgroup reserve leaks in cow_file_range', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix qgroup reserve leaks in cow_file_range\n\nIn the buffered write path, the dirty page owns the qgroup reserve until\nit creates an ordered_extent.\n\nTherefore, any errors that occur before the ordered_extent is created\nmust free that reservation, or else the space is leaked. The fstest\ngeneric/475 exercises various IO error paths, and is able to trigger\nerrors in cow_file_range where we fail to get to allocating the ordered\nextent. Note that because we *do* clear delalloc, we are likely to\nremove the inode from the delalloc list, so the inodes/pages to not have\ninvalidate/launder called on them in the commit abort path.\n\nThis results in failures at the unmount stage of the test that look like:\n\n BTRFS: error (device dm-8 state EA) in cleanup_transaction:2018: errno=-5 IO failure\n BTRFS: error (device dm-8 state EA) in btrfs_replace_file_extents:2416: errno=-5 IO failure\n BTRFS warning (device dm-8 state EA): qgroup 0/5 has unreleased space, type 0 rsv 28672\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 22588 at fs/btrfs/disk-io.c:4333 close_ctree+0x222/0x4d0 [btrfs]\n Modules linked in: btrfs blake2b_generic libcrc32c xor zstd_compress raid6_pq\n CPU: 3 PID: 22588 Comm: umount Kdump: loaded Tainted: G W 6.10.0-rc7-gab56fde445b8 #21\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n RIP: 0010:close_ctree+0x222/0x4d0 [btrfs]\n RSP: 0018:ffffb4465283be00 EFLAGS: 00010202\n RAX: 0000000000000001 RBX: ffffa1a1818e1000 RCX: 0000000000000001\n RDX: 0000000000000000 RSI: ffffb4465283bbe0 RDI: ffffa1a19374fcb8\n RBP: ffffa1a1818e13c0 R08: 0000000100028b16 R09: 0000000000000000\n R10: 0000000000000003 R11: 0000000000000003 R12: ffffa1a18ad7972c\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n FS: 00007f9168312b80(0000) GS:ffffa1a4afcc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f91683c9140 CR3: 000000010acaa000 CR4: 00000000000006f0\n Call Trace:\n \n ? close_ctree+0x222/0x4d0 [btrfs]\n ? __warn.cold+0x8e/0xea\n ? close_ctree+0x222/0x4d0 [btrfs]\n ? report_bug+0xff/0x140\n ? handle_bug+0x3b/0x70\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? close_ctree+0x222/0x4d0 [btrfs]\n generic_shutdown_super+0x70/0x160\n kill_anon_super+0x11/0x40\n btrfs_kill_super+0x11/0x20 [btrfs]\n deactivate_locked_super+0x2e/0xa0\n cleanup_mnt+0xb5/0x150\n task_work_run+0x57/0x80\n syscall_exit_to_user_mode+0x121/0x130\n do_syscall_64+0xab/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n RIP: 0033:0x7f916847a887\n ---[ end trace 0000000000000000 ]---\n BTRFS error (device dm-8 state EA): qgroup reserved space leaked\n\nCases 2 and 3 in the out_reserve path both pertain to this type of leak\nand must free the reserved qgroup data. Because it is already an error\npath, I opted not to handle the possible errors in\nbtrfs_free_qgroup_data.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46733', 'https://git.kernel.org/linus/30479f31d44d47ed00ae0c7453d9b253537005b2 (6.11-rc3)', 'https://git.kernel.org/stable/c/30479f31d44d47ed00ae0c7453d9b253537005b2', 'https://git.kernel.org/stable/c/e42ef22bc10f0309c0c65d8d6ca8b4127a674b7f', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46733-77eb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46733', 'https://www.cve.org/CVERecord?id=CVE-2024-46733'], 'PublishedDate': '2024-09-18T07:15:04.17Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46735', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46735', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery()\n\nWhen two UBLK_CMD_START_USER_RECOVERY commands are submitted, the\nfirst one sets 'ubq->ubq_daemon' to NULL, and the second one triggers\nWARN in ublk_queue_reinit() and subsequently a NULL pointer dereference\nissue.\n\nFix it by adding the check in ublk_ctrl_start_recovery() and return\nimmediately in case of zero 'ub->nr_queues_ready'.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n RIP: 0010:ublk_ctrl_start_recovery.constprop.0+0x82/0x180\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x75/0x170\n ? exc_page_fault+0x64/0x140\n ? asm_exc_page_fault+0x22/0x30\n ? ublk_ctrl_start_recovery.constprop.0+0x82/0x180\n ublk_ctrl_uring_cmd+0x4f7/0x6c0\n ? pick_next_task_idle+0x26/0x40\n io_uring_cmd+0x9a/0x1b0\n io_issue_sqe+0x193/0x3f0\n io_wq_submit_work+0x9b/0x390\n io_worker_handle_work+0x165/0x360\n io_wq_worker+0xcb/0x2f0\n ? finish_task_switch.isra.0+0x203/0x290\n ? finish_task_switch.isra.0+0x203/0x290\n ? __pfx_io_wq_worker+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_io_wq_worker+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46735', 'https://git.kernel.org/linus/e58f5142f88320a5b1449f96a146f2f24615c5c7 (6.11-rc7)', 'https://git.kernel.org/stable/c/136a29d8112df4ea0a57f9602ddf3579e04089dc', 'https://git.kernel.org/stable/c/7c890ef60bf417d3fe5c6f7a9f6cef0e1d77f74f', 'https://git.kernel.org/stable/c/ca249435893dda766f3845c15ca77ca5672022d8', 'https://git.kernel.org/stable/c/e58f5142f88320a5b1449f96a146f2f24615c5c7', 'https://lore.kernel.org/linux-cve-announce/2024091832-CVE-2024-46735-fbce@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46735', 'https://www.cve.org/CVERecord?id=CVE-2024-46735'], 'PublishedDate': '2024-09-18T08:15:03.057Z', 'LastModifiedDate': '2024-09-20T18:35:53.967Z'}, {'VulnerabilityID': 'CVE-2024-46737', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46737', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvmet-tcp: fix kernel crash if commands allocation fails', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: fix kernel crash if commands allocation fails\n\nIf the commands allocation fails in nvmet_tcp_alloc_cmds()\nthe kernel crashes in nvmet_tcp_release_queue_work() because of\na NULL pointer dereference.\n\n nvmet: failed to install queue 0 cntlid 1 ret 6\n Unable to handle kernel NULL pointer dereference at\n virtual address 0000000000000008\n\nFix the bug by setting queue->nr_cmds to zero in case\nnvmet_tcp_alloc_cmd() fails.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46737', 'https://git.kernel.org/linus/5572a55a6f830ee3f3a994b6b962a5c327d28cb3 (6.11-rc7)', 'https://git.kernel.org/stable/c/03e1fd0327fa5e2174567f5fe9290fe21d21b8f4', 'https://git.kernel.org/stable/c/489f2913a63f528cfe3f21722583fb981967ecda', 'https://git.kernel.org/stable/c/50632b877ce55356f5d276b9add289b1e7ddc683', 'https://git.kernel.org/stable/c/5572a55a6f830ee3f3a994b6b962a5c327d28cb3', 'https://git.kernel.org/stable/c/6c04d1e3ab22cc5394ef656429638a5947f87244', 'https://git.kernel.org/stable/c/7957c731fc2b23312f8935812dee5a0b14b04e2d', 'https://git.kernel.org/stable/c/91dad30c5607e62864f888e735d0965567827bdf', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46737-d36f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46737', 'https://www.cve.org/CVERecord?id=CVE-2024-46737'], 'PublishedDate': '2024-09-18T08:15:03.167Z', 'LastModifiedDate': '2024-09-20T18:35:34.7Z'}, {'VulnerabilityID': 'CVE-2024-46738', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46738', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: VMCI: Fix use-after-free when removing resource in vmci_resource_remove()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: Fix use-after-free when removing resource in vmci_resource_remove()\n\nWhen removing a resource from vmci_resource_table in\nvmci_resource_remove(), the search is performed using the resource\nhandle by comparing context and resource fields.\n\nIt is possible though to create two resources with different types\nbut same handle (same context and resource fields).\n\nWhen trying to remove one of the resources, vmci_resource_remove()\nmay not remove the intended one, but the object will still be freed\nas in the case of the datagram type in vmci_datagram_destroy_handle().\nvmci_resource_table will still hold a pointer to this freed resource\nleading to a use-after-free vulnerability.\n\nBUG: KASAN: use-after-free in vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]\nBUG: KASAN: use-after-free in vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147\nRead of size 4 at addr ffff88801c16d800 by task syz-executor197/1592\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x82/0xa9 lib/dump_stack.c:106\n print_address_description.constprop.0+0x21/0x366 mm/kasan/report.c:239\n __kasan_report.cold+0x7f/0x132 mm/kasan/report.c:425\n kasan_report+0x38/0x51 mm/kasan/report.c:442\n vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]\n vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147\n vmci_qp_broker_detach+0x89a/0x11b9 drivers/misc/vmw_vmci/vmci_queue_pair.c:2182\n ctx_free_ctx+0x473/0xbe1 drivers/misc/vmw_vmci/vmci_context.c:444\n kref_put include/linux/kref.h:65 [inline]\n vmci_ctx_put drivers/misc/vmw_vmci/vmci_context.c:497 [inline]\n vmci_ctx_destroy+0x170/0x1d6 drivers/misc/vmw_vmci/vmci_context.c:195\n vmci_host_close+0x125/0x1ac drivers/misc/vmw_vmci/vmci_host.c:143\n __fput+0x261/0xa34 fs/file_table.c:282\n task_work_run+0xf0/0x194 kernel/task_work.c:164\n tracehook_notify_resume include/linux/tracehook.h:189 [inline]\n exit_to_user_mode_loop+0x184/0x189 kernel/entry/common.c:187\n exit_to_user_mode_prepare+0x11b/0x123 kernel/entry/common.c:220\n __syscall_exit_to_user_mode_work kernel/entry/common.c:302 [inline]\n syscall_exit_to_user_mode+0x18/0x42 kernel/entry/common.c:313\n do_syscall_64+0x41/0x85 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x6e/0x0\n\nThis change ensures the type is also checked when removing\nthe resource from vmci_resource_table in vmci_resource_remove().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46738', 'https://git.kernel.org/linus/48b9a8dabcc3cf5f961b2ebcd8933bf9204babb7 (6.11-rc7)', 'https://git.kernel.org/stable/c/00fe5292f081f8d773e572df8e03bf6e1855fe49', 'https://git.kernel.org/stable/c/39e7e593418ccdbd151f2925fa6be1a616d16c96', 'https://git.kernel.org/stable/c/48b9a8dabcc3cf5f961b2ebcd8933bf9204babb7', 'https://git.kernel.org/stable/c/6c563a29857aa8053b67ee141191f69757f27f6e', 'https://git.kernel.org/stable/c/b243d52b5f6f59f9d39e69b191fb3d58b94a43b1', 'https://git.kernel.org/stable/c/b9efdf333174468651be40390cbc79c9f55d9cce', 'https://git.kernel.org/stable/c/ef5f4d0c5ee22d4f873116fec844ff6edaf3fa7d', 'https://git.kernel.org/stable/c/f6365931bf7c07b2b397dbb06a4f6573cc9fae73', 'https://linux.oracle.com/cve/CVE-2024-46738.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024091833-CVE-2024-46738-d871@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46738', 'https://www.cve.org/CVERecord?id=CVE-2024-46738'], 'PublishedDate': '2024-09-18T08:15:03.233Z', 'LastModifiedDate': '2024-09-20T18:35:04.373Z'}, {'VulnerabilityID': 'CVE-2024-46739', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46739', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind\n\nFor primary VM Bus channels, primary_channel pointer is always NULL. This\npointer is valid only for the secondary channels. Also, rescind callback\nis meant for primary channels only.\n\nFix NULL pointer dereference by retrieving the device_obj from the parent\nfor the primary channel.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46739', 'https://git.kernel.org/linus/fb1adbd7e50f3d2de56d0a2bb0700e2e819a329e (6.11-rc7)', 'https://git.kernel.org/stable/c/1d8e020e51ab07e40f9dd00b52f1da7d96fec04c', 'https://git.kernel.org/stable/c/2be373469be1774bbe03b0fa7e2854e65005b1cc', 'https://git.kernel.org/stable/c/3005091cd537ef8cdb7530dcb2ecfba8d2ef475c', 'https://git.kernel.org/stable/c/3d414b64ecf6fd717d7510ffb893c6f23acbf50e', 'https://git.kernel.org/stable/c/928e399e84f4e80307dce44e89415115c473275b', 'https://git.kernel.org/stable/c/de6946be9c8bc7d2279123433495af7c21011b99', 'https://git.kernel.org/stable/c/f38f46da80a2ab7d1b2f8fcb444c916034a2dac4', 'https://git.kernel.org/stable/c/fb1adbd7e50f3d2de56d0a2bb0700e2e819a329e', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46739-0aa7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46739', 'https://www.cve.org/CVERecord?id=CVE-2024-46739'], 'PublishedDate': '2024-09-18T08:15:03.293Z', 'LastModifiedDate': '2024-09-20T18:34:29.957Z'}, {'VulnerabilityID': 'CVE-2024-46740', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46740', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: binder: fix UAF caused by offsets overwrite', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF caused by offsets overwrite\n\nBinder objects are processed and copied individually into the target\nbuffer during transactions. Any raw data in-between these objects is\ncopied as well. However, this raw data copy lacks an out-of-bounds\ncheck. If the raw data exceeds the data section size then the copy\noverwrites the offsets section. This eventually triggers an error that\nattempts to unwind the processed objects. However, at this point the\noffsets used to index these objects are now corrupted.\n\nUnwinding with corrupted offsets can result in decrements of arbitrary\nnodes and lead to their premature release. Other users of such nodes are\nleft with a dangling pointer triggering a use-after-free. This issue is\nmade evident by the following KASAN report (trimmed):\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c\n Write of size 4 at addr ffff47fc91598f04 by task binder-util/743\n\n CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n _raw_spin_lock+0xe4/0x19c\n binder_free_buf+0x128/0x434\n binder_thread_write+0x8a4/0x3260\n binder_ioctl+0x18f0/0x258c\n [...]\n\n Allocated by task 743:\n __kmalloc_cache_noprof+0x110/0x270\n binder_new_node+0x50/0x700\n binder_transaction+0x413c/0x6da8\n binder_thread_write+0x978/0x3260\n binder_ioctl+0x18f0/0x258c\n [...]\n\n Freed by task 745:\n kfree+0xbc/0x208\n binder_thread_read+0x1c5c/0x37d4\n binder_ioctl+0x16d8/0x258c\n [...]\n ==================================================================\n\nTo avoid this issue, let's check that the raw data copy is within the\nboundaries of the data section.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46740', 'https://git.kernel.org/linus/4df153652cc46545722879415937582028c18af5 (6.11-rc7)', 'https://git.kernel.org/stable/c/109e845c1184c9f786d41516348ba3efd9112792', 'https://git.kernel.org/stable/c/1f33d9f1d9ac3f0129f8508925000900c2fe5bb0', 'https://git.kernel.org/stable/c/3a8154bb4ab4a01390a3abf1e6afac296e037da4', 'https://git.kernel.org/stable/c/4df153652cc46545722879415937582028c18af5', 'https://git.kernel.org/stable/c/4f79e0b80dc69bd5eaaed70f0df1b558728b4e59', 'https://git.kernel.org/stable/c/5a32bfd23022ffa7e152f273fa3fa29befb7d929', 'https://git.kernel.org/stable/c/eef79854a04feac5b861f94d7b19cbbe79874117', 'https://lore.kernel.org/linux-cve-announce/2024091834-CVE-2024-46740-e05a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46740', 'https://www.cve.org/CVERecord?id=CVE-2024-46740'], 'PublishedDate': '2024-09-18T08:15:03.377Z', 'LastModifiedDate': '2024-09-20T18:34:08.163Z'}, {'VulnerabilityID': 'CVE-2024-46741', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46741', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: misc: fastrpc: Fix double free of 'buf' in error path', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Fix double free of 'buf' in error path\n\nsmatch warning:\ndrivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf'\n\nIn fastrpc_req_mmap() error path, the fastrpc buffer is freed in\nfastrpc_req_munmap_impl() if unmap is successful.\n\nBut in the end, there is an unconditional call to fastrpc_buf_free().\nSo the above case triggers the double free of fastrpc buf.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46741', 'https://git.kernel.org/linus/e8c276d4dc0e19ee48385f74426aebc855b49aaf (6.11-rc7)', 'https://git.kernel.org/stable/c/bfc1704d909dc9911a558b1a5833d3d61a43a1f2', 'https://git.kernel.org/stable/c/e8c276d4dc0e19ee48385f74426aebc855b49aaf', 'https://git.kernel.org/stable/c/f77dc8a75859e559f3238a6d906206259227985e', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46741-4ce7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46741', 'https://www.cve.org/CVERecord?id=CVE-2024-46741'], 'PublishedDate': '2024-09-18T08:15:03.43Z', 'LastModifiedDate': '2024-09-20T18:33:27.96Z'}, {'VulnerabilityID': 'CVE-2024-46742', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46742', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: smb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open()\n\nnull-ptr-deref will occur when (req_op_level == SMB2_OPLOCK_LEVEL_LEASE)\nand parse_lease_state() return NULL.\n\nFix this by check if 'lease_ctx_info' is NULL.\n\nAdditionally, remove the redundant parentheses in\nparse_durable_handle_context().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46742', 'https://git.kernel.org/linus/4e8771a3666c8f216eefd6bd2fd50121c6c437db (6.11-rc5)', 'https://git.kernel.org/stable/c/07f384c5be1f8633b13f0a22616e227570450bc6', 'https://git.kernel.org/stable/c/3b692794b81f2ecad69a4adbba687f3836824ada', 'https://git.kernel.org/stable/c/4e8771a3666c8f216eefd6bd2fd50121c6c437db', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46742-223b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46742', 'https://www.cve.org/CVERecord?id=CVE-2024-46742'], 'PublishedDate': '2024-09-18T08:15:03.48Z', 'LastModifiedDate': '2024-09-20T18:32:34.303Z'}, {'VulnerabilityID': 'CVE-2024-46743', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46743', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: of/irq: Prevent device address out-of-bounds read in interrupt map walk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nof/irq: Prevent device address out-of-bounds read in interrupt map walk\n\nWhen of_irq_parse_raw() is invoked with a device address smaller than\nthe interrupt parent node (from #address-cells property), KASAN detects\nthe following out-of-bounds read when populating the initial match table\n(dyndbg="func of_irq_parse_* +p"):\n\n OF: of_irq_parse_one: dev=/soc@0/picasso/watchdog, index=0\n OF: parent=/soc@0/pci@878000000000/gpio0@17,0, intsize=2\n OF: intspec=4\n OF: of_irq_parse_raw: ipar=/soc@0/pci@878000000000/gpio0@17,0, size=2\n OF: -> addrsize=3\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in of_irq_parse_raw+0x2b8/0x8d0\n Read of size 4 at addr ffffff81beca5608 by task bash/764\n\n CPU: 1 PID: 764 Comm: bash Tainted: G O 6.1.67-484c613561-nokia_sm_arm64 #1\n Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2023.01-12.24.03-dirty 01/01/2023\n Call trace:\n dump_backtrace+0xdc/0x130\n show_stack+0x1c/0x30\n dump_stack_lvl+0x6c/0x84\n print_report+0x150/0x448\n kasan_report+0x98/0x140\n __asan_load4+0x78/0xa0\n of_irq_parse_raw+0x2b8/0x8d0\n of_irq_parse_one+0x24c/0x270\n parse_interrupts+0xc0/0x120\n of_fwnode_add_links+0x100/0x2d0\n fw_devlink_parse_fwtree+0x64/0xc0\n device_add+0xb38/0xc30\n of_device_add+0x64/0x90\n of_platform_device_create_pdata+0xd0/0x170\n of_platform_bus_create+0x244/0x600\n of_platform_notify+0x1b0/0x254\n blocking_notifier_call_chain+0x9c/0xd0\n __of_changeset_entry_notify+0x1b8/0x230\n __of_changeset_apply_notify+0x54/0xe4\n of_overlay_fdt_apply+0xc04/0xd94\n ...\n\n The buggy address belongs to the object at ffffff81beca5600\n which belongs to the cache kmalloc-128 of size 128\n The buggy address is located 8 bytes inside of\n 128-byte region [ffffff81beca5600, ffffff81beca5680)\n\n The buggy address belongs to the physical page:\n page:00000000230d3d03 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1beca4\n head:00000000230d3d03 order:1 compound_mapcount:0 compound_pincount:0\n flags: 0x8000000000010200(slab|head|zone=2)\n raw: 8000000000010200 0000000000000000 dead000000000122 ffffff810000c300\n raw: 0000000000000000 0000000000200020 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffffff81beca5500: 04 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffffff81beca5580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n >ffffff81beca5600: 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffffff81beca5680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffffff81beca5700: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc\n ==================================================================\n OF: -> got it !\n\nPrevent the out-of-bounds read by copying the device address into a\nbuffer of sufficient size.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46743', 'https://git.kernel.org/linus/b739dffa5d570b411d4bdf4bb9b8dfd6b7d72305 (6.11-rc4)', 'https://git.kernel.org/stable/c/7ead730af11ee7da107f16fc77995613c58d292d', 'https://git.kernel.org/stable/c/8ff351ea12e918db1373b915c4c268815929cbe5', 'https://git.kernel.org/stable/c/9d1e9f0876b03d74d44513a0ed3ed15ef8f2fed5', 'https://git.kernel.org/stable/c/b739dffa5d570b411d4bdf4bb9b8dfd6b7d72305', 'https://git.kernel.org/stable/c/baaf26723beab3a04da578d3008be3544f83758f', 'https://git.kernel.org/stable/c/bf68acd840b6a5bfd3777e0d5aaa204db6b461a9', 'https://git.kernel.org/stable/c/d2a79494d8a5262949736fb2c3ac44d20a51b0d8', 'https://git.kernel.org/stable/c/defcaa426ba0bc89ffdafb799d2e50b52f74ffc4', 'https://lore.kernel.org/linux-cve-announce/2024091835-CVE-2024-46743-f386@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46743', 'https://www.cve.org/CVERecord?id=CVE-2024-46743'], 'PublishedDate': '2024-09-18T08:15:03.54Z', 'LastModifiedDate': '2024-09-20T18:32:11.827Z'}, {'VulnerabilityID': 'CVE-2024-46744', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46744', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Squashfs: sanity check symbolic link size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: sanity check symbolic link size\n\nSyzkiller reports a "KMSAN: uninit-value in pick_link" bug.\n\nThis is caused by an uninitialised page, which is ultimately caused\nby a corrupted symbolic link size read from disk.\n\nThe reason why the corrupted symlink size causes an uninitialised\npage is due to the following sequence of events:\n\n1. squashfs_read_inode() is called to read the symbolic\n link from disk. This assigns the corrupted value\n 3875536935 to inode->i_size.\n\n2. Later squashfs_symlink_read_folio() is called, which assigns\n this corrupted value to the length variable, which being a\n signed int, overflows producing a negative number.\n\n3. The following loop that fills in the page contents checks that\n the copied bytes is less than length, which being negative means\n the loop is skipped, producing an uninitialised page.\n\nThis patch adds a sanity check which checks that the symbolic\nlink size is not larger than expected.\n\n--\n\nV2: fix spelling mistake.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-59'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46744', 'https://git.kernel.org/linus/810ee43d9cd245d138a2733d87a24858a23f577d (6.11-rc4)', 'https://git.kernel.org/stable/c/087f25b2d36adae19951114ffcbb7106ed405ebb', 'https://git.kernel.org/stable/c/1b9451ba6f21478a75288ea3e3fca4be35e2a438', 'https://git.kernel.org/stable/c/5c8906de98d0d7ad42ff3edf2cb6cd7e0ea658c4', 'https://git.kernel.org/stable/c/810ee43d9cd245d138a2733d87a24858a23f577d', 'https://git.kernel.org/stable/c/c3af7e460a526007e4bed1ce3623274a1a6afe5e', 'https://git.kernel.org/stable/c/ef4e249971eb77ec33d74c5c3de1e2576faf6c90', 'https://git.kernel.org/stable/c/f82cb7f24032ed023fc67d26ea9bf322d8431a90', 'https://git.kernel.org/stable/c/fac5e82ab1334fc8ed6ff7183702df634bd1d93d', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46744-451f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46744', 'https://www.cve.org/CVERecord?id=CVE-2024-46744'], 'PublishedDate': '2024-09-18T08:15:03.603Z', 'LastModifiedDate': '2024-09-30T13:36:19.557Z'}, {'VulnerabilityID': 'CVE-2024-46745', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46745', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Input: uinput - reject requests with unreasonable number of slots', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: uinput - reject requests with unreasonable number of slots\n\n\nWhen exercising uinput interface syzkaller may try setting up device\nwith a really large number of slots, which causes memory allocation\nfailure in input_mt_init_slots(). While this allocation failure is\nhandled properly and request is rejected, it results in syzkaller\nreports. Additionally, such request may put undue burden on the\nsystem which will try to free a lot of memory for a bogus request.\n\nFix it by limiting allowed number of slots to 100. This can easily\nbe extended if we see devices that can track more than 100 contacts.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46745', 'https://git.kernel.org/linus/206f533a0a7c683982af473079c4111f4a0f9f5e (6.11-rc5)', 'https://git.kernel.org/stable/c/206f533a0a7c683982af473079c4111f4a0f9f5e', 'https://git.kernel.org/stable/c/51fa08edd80003db700bdaa099385c5900d27f4b', 'https://git.kernel.org/stable/c/597ff930296c4c8fc6b6a536884d4f1a7187ec70', 'https://git.kernel.org/stable/c/61df76619e270a46fd427fbdeb670ad491c42de2', 'https://git.kernel.org/stable/c/9719687398dea8a6a12a10321a54dd75eec7ab2d', 'https://git.kernel.org/stable/c/9c6d189f0c1c59ba9a32326ec82a0b367a3cd47b', 'https://git.kernel.org/stable/c/a4858b00a1ec57043697fb935565fe267f161833', 'https://git.kernel.org/stable/c/d76fc0f0b18d49b7e721c9e4975ef4bffde2f3e7', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46745-7b05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46745', 'https://www.cve.org/CVERecord?id=CVE-2024-46745'], 'PublishedDate': '2024-09-18T08:15:03.667Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46746', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46746', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: HID: amd_sfh: free driver_data after destroying hid device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: amd_sfh: free driver_data after destroying hid device\n\nHID driver callbacks aren't called anymore once hid_destroy_device() has\nbeen called. Hence, hid driver_data should be freed only after the\nhid_destroy_device() function returned as driver_data is used in several\ncallbacks.\n\nI observed a crash with kernel 6.10.0 on my T14s Gen 3, after enabling\nKASAN to debug memory allocation, I got this output:\n\n [ 13.050438] ==================================================================\n [ 13.054060] BUG: KASAN: slab-use-after-free in amd_sfh_get_report+0x3ec/0x530 [amd_sfh]\n [ 13.054809] psmouse serio1: trackpoint: Synaptics TrackPoint firmware: 0x02, buttons: 3/3\n [ 13.056432] Read of size 8 at addr ffff88813152f408 by task (udev-worker)/479\n\n [ 13.060970] CPU: 5 PID: 479 Comm: (udev-worker) Not tainted 6.10.0-arch1-2 #1 893bb55d7f0073f25c46adbb49eb3785fefd74b0\n [ 13.063978] Hardware name: LENOVO 21CQCTO1WW/21CQCTO1WW, BIOS R22ET70W (1.40 ) 03/21/2024\n [ 13.067860] Call Trace:\n [ 13.069383] input: TPPS/2 Synaptics TrackPoint as /devices/platform/i8042/serio1/input/input8\n [ 13.071486] \n [ 13.071492] dump_stack_lvl+0x5d/0x80\n [ 13.074870] snd_hda_intel 0000:33:00.6: enabling device (0000 -> 0002)\n [ 13.078296] ? amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.082199] print_report+0x174/0x505\n [ 13.085776] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n [ 13.089367] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.093255] ? amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.097464] kasan_report+0xc8/0x150\n [ 13.101461] ? amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.105802] amd_sfh_get_report+0x3ec/0x530 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.110303] amdtp_hid_request+0xb8/0x110 [amd_sfh 05f43221435b5205f734cd9da29399130f398a38]\n [ 13.114879] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.119450] sensor_hub_get_feature+0x1d3/0x540 [hid_sensor_hub 3f13be3016ff415bea03008d45d99da837ee3082]\n [ 13.124097] hid_sensor_parse_common_attributes+0x4d0/0xad0 [hid_sensor_iio_common c3a5cbe93969c28b122609768bbe23efe52eb8f5]\n [ 13.127404] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.131925] ? __pfx_hid_sensor_parse_common_attributes+0x10/0x10 [hid_sensor_iio_common c3a5cbe93969c28b122609768bbe23efe52eb8f5]\n [ 13.136455] ? _raw_spin_lock_irqsave+0x96/0xf0\n [ 13.140197] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n [ 13.143602] ? devm_iio_device_alloc+0x34/0x50 [industrialio 3d261d5e5765625d2b052be40e526d62b1d2123b]\n [ 13.147234] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.150446] ? __devm_add_action+0x167/0x1d0\n [ 13.155061] hid_gyro_3d_probe+0x120/0x7f0 [hid_sensor_gyro_3d 63da36a143b775846ab2dbb86c343b401b5e3172]\n [ 13.158581] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.161814] platform_probe+0xa2/0x150\n [ 13.165029] really_probe+0x1e3/0x8a0\n [ 13.168243] __driver_probe_device+0x18c/0x370\n [ 13.171500] driver_probe_device+0x4a/0x120\n [ 13.175000] __driver_attach+0x190/0x4a0\n [ 13.178521] ? __pfx___driver_attach+0x10/0x10\n [ 13.181771] bus_for_each_dev+0x106/0x180\n [ 13.185033] ? __pfx__raw_spin_lock+0x10/0x10\n [ 13.188229] ? __pfx_bus_for_each_dev+0x10/0x10\n [ 13.191446] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.194382] bus_add_driver+0x29e/0x4d0\n [ 13.197328] driver_register+0x1a5/0x360\n [ 13.200283] ? __pfx_hid_gyro_3d_platform_driver_init+0x10/0x10 [hid_sensor_gyro_3d 63da36a143b775846ab2dbb86c343b401b5e3172]\n [ 13.203362] do_one_initcall+0xa7/0x380\n [ 13.206432] ? __pfx_do_one_initcall+0x10/0x10\n [ 13.210175] ? srso_alias_return_thunk+0x5/0xfbef5\n [ 13.213211] ? kasan_unpoison+0x44/0x70\n [ 13.216688] do_init_module+0x238/0x750\n [ 13.2196\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46746', 'https://git.kernel.org/linus/97155021ae17b86985121b33cf8098bcde00d497 (6.11-rc5)', 'https://git.kernel.org/stable/c/60dc4ee0428d70bcbb41436b6729d29f1cbdfb89', 'https://git.kernel.org/stable/c/775125c7fe38533aaa4b20769f5b5e62cc1170a0', 'https://git.kernel.org/stable/c/86b4f5cf91ca03c08e3822ac89476a677a780bcc', 'https://git.kernel.org/stable/c/97155021ae17b86985121b33cf8098bcde00d497', 'https://git.kernel.org/stable/c/adb3e3c1ddb5a23b8b7122ef1913f528d728937c', 'https://lore.kernel.org/linux-cve-announce/2024091836-CVE-2024-46746-eb7f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46746', 'https://www.cve.org/CVERecord?id=CVE-2024-46746'], 'PublishedDate': '2024-09-18T08:15:03.73Z', 'LastModifiedDate': '2024-09-26T12:47:53.267Z'}, {'VulnerabilityID': 'CVE-2024-46747', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46747', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup\n\nreport_fixup for the Cougar 500k Gaming Keyboard was not verifying\nthat the report descriptor size was correct before accessing it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46747', 'https://git.kernel.org/linus/a6e9c391d45b5865b61e569146304cff72821a5d (6.11-rc5)', 'https://git.kernel.org/stable/c/30e9ce7cd5591be639b53595c95812f1a2afdfdc', 'https://git.kernel.org/stable/c/34185de73d74fdc90e8651cfc472bfea6073a13f', 'https://git.kernel.org/stable/c/48b2108efa205f4579052c27fba2b22cc6ad8aa0', 'https://git.kernel.org/stable/c/890dde6001b651be79819ef7a3f8c71fc8f9cabf', 'https://git.kernel.org/stable/c/a6e9c391d45b5865b61e569146304cff72821a5d', 'https://git.kernel.org/stable/c/e239e44dcd419b13cf840e2a3a833204e4329714', 'https://git.kernel.org/stable/c/e4a602a45aecd6a98b4b37482f5c9f8f67a32ddd', 'https://git.kernel.org/stable/c/fac3cb3c6428afe2207593a183b5bc4742529dfd', 'https://lore.kernel.org/linux-cve-announce/2024091837-CVE-2024-46747-f489@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46747', 'https://www.cve.org/CVERecord?id=CVE-2024-46747'], 'PublishedDate': '2024-09-18T08:15:03.79Z', 'LastModifiedDate': '2024-09-20T18:31:19.19Z'}, {'VulnerabilityID': 'CVE-2024-46748', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46748', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cachefiles: Set the max subreq size for cache writes to MAX_RW_COUNT', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Set the max subreq size for cache writes to MAX_RW_COUNT\n\nSet the maximum size of a subrequest that writes to cachefiles to be\nMAX_RW_COUNT so that we don't overrun the maximum write we can make to the\nbacking filesystem.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46748', 'https://git.kernel.org/linus/51d37982bbac3ea0ca21b2797a9cb0044272b3aa (6.11-rc1)', 'https://git.kernel.org/stable/c/51d37982bbac3ea0ca21b2797a9cb0044272b3aa', 'https://git.kernel.org/stable/c/cec226f9b1fd6cf55bc157873aec61b523083e96', 'https://lore.kernel.org/linux-cve-announce/2024091837-CVE-2024-46748-03e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46748', 'https://www.cve.org/CVERecord?id=CVE-2024-46748'], 'PublishedDate': '2024-09-18T08:15:03.847Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46749', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46749', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: btnxpuart: Fix Null pointer dereference in btnxpuart_flush()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix Null pointer dereference in btnxpuart_flush()\n\nThis adds a check before freeing the rx->skb in flush and close\nfunctions to handle the kernel crash seen while removing driver after FW\ndownload fails or before FW download completes.\n\ndmesg log:\n[ 54.634586] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000080\n[ 54.643398] Mem abort info:\n[ 54.646204] ESR = 0x0000000096000004\n[ 54.649964] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 54.655286] SET = 0, FnV = 0\n[ 54.658348] EA = 0, S1PTW = 0\n[ 54.661498] FSC = 0x04: level 0 translation fault\n[ 54.666391] Data abort info:\n[ 54.669273] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 54.674768] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 54.674771] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 54.674775] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000048860000\n[ 54.674780] [0000000000000080] pgd=0000000000000000, p4d=0000000000000000\n[ 54.703880] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 54.710152] Modules linked in: btnxpuart(-) overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_micfil snd_soc_fsl_spdif snd_soc_fsl_sai snd_soc_fsl_utils imx_pcm_dma gpio_ir_recv rc_core sch_fq_codel fuse\n[ 54.744357] CPU: 3 PID: 72 Comm: kworker/u9:0 Not tainted 6.6.3-otbr-g128004619037 #2\n[ 54.744364] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 54.744368] Workqueue: hci0 hci_power_on\n[ 54.757244] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 54.757249] pc : kfree_skb_reason+0x18/0xb0\n[ 54.772299] lr : btnxpuart_flush+0x40/0x58 [btnxpuart]\n[ 54.782921] sp : ffff8000805ebca0\n[ 54.782923] x29: ffff8000805ebca0 x28: ffffa5c6cf1869c0 x27: ffffa5c6cf186000\n[ 54.782931] x26: ffff377b84852400 x25: ffff377b848523c0 x24: ffff377b845e7230\n[ 54.782938] x23: ffffa5c6ce8dbe08 x22: ffffa5c6ceb65410 x21: 00000000ffffff92\n[ 54.782945] x20: ffffa5c6ce8dbe98 x19: ffffffffffffffac x18: ffffffffffffffff\n[ 54.807651] x17: 0000000000000000 x16: ffffa5c6ce2824ec x15: ffff8001005eb857\n[ 54.821917] x14: 0000000000000000 x13: ffffa5c6cf1a02e0 x12: 0000000000000642\n[ 54.821924] x11: 0000000000000040 x10: ffffa5c6cf19d690 x9 : ffffa5c6cf19d688\n[ 54.821931] x8 : ffff377b86000028 x7 : 0000000000000000 x6 : 0000000000000000\n[ 54.821938] x5 : ffff377b86000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 54.843331] x2 : 0000000000000000 x1 : 0000000000000002 x0 : ffffffffffffffac\n[ 54.857599] Call trace:\n[ 54.857601] kfree_skb_reason+0x18/0xb0\n[ 54.863878] btnxpuart_flush+0x40/0x58 [btnxpuart]\n[ 54.863888] hci_dev_open_sync+0x3a8/0xa04\n[ 54.872773] hci_power_on+0x54/0x2e4\n[ 54.881832] process_one_work+0x138/0x260\n[ 54.881842] worker_thread+0x32c/0x438\n[ 54.881847] kthread+0x118/0x11c\n[ 54.881853] ret_from_fork+0x10/0x20\n[ 54.896406] Code: a9be7bfd 910003fd f9000bf3 aa0003f3 (b940d400)\n[ 54.896410] ---[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46749', 'https://git.kernel.org/linus/c68bbf5e334b35b36ac5b9f0419f1f93f796bad1 (6.11-rc1)', 'https://git.kernel.org/stable/c/013dae4735d2010544d1f2121bdeb8e6c9ea171e', 'https://git.kernel.org/stable/c/056e0cd381d59a9124b7c43dd715e15f56a11635', 'https://git.kernel.org/stable/c/c68bbf5e334b35b36ac5b9f0419f1f93f796bad1', 'https://lore.kernel.org/linux-cve-announce/2024091838-CVE-2024-46749-fc9c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46749', 'https://www.cve.org/CVERecord?id=CVE-2024-46749'], 'PublishedDate': '2024-09-18T08:15:03.893Z', 'LastModifiedDate': '2024-09-20T18:45:43.483Z'}, {'VulnerabilityID': 'CVE-2024-46750', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46750', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: Add missing bridge lock to pci_bus_lock()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Add missing bridge lock to pci_bus_lock()\n\nOne of the true positives that the cfg_access_lock lockdep effort\nidentified is this sequence:\n\n WARNING: CPU: 14 PID: 1 at drivers/pci/pci.c:4886 pci_bridge_secondary_bus_reset+0x5d/0x70\n RIP: 0010:pci_bridge_secondary_bus_reset+0x5d/0x70\n Call Trace:\n \n ? __warn+0x8c/0x190\n ? pci_bridge_secondary_bus_reset+0x5d/0x70\n ? report_bug+0x1f8/0x200\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? pci_bridge_secondary_bus_reset+0x5d/0x70\n pci_reset_bus+0x1d8/0x270\n vmd_probe+0x778/0xa10\n pci_device_probe+0x95/0x120\n\nWhere pci_reset_bus() users are triggering unlocked secondary bus resets.\nIronically pci_bus_reset(), several calls down from pci_reset_bus(), uses\npci_bus_lock() before issuing the reset which locks everything *but* the\nbridge itself.\n\nFor the same motivation as adding:\n\n bridge = pci_upstream_bridge(dev);\n if (bridge)\n pci_dev_lock(bridge);\n\nto pci_reset_function() for the "bus" and "cxl_bus" reset cases, add\npci_dev_lock() for @bus->self to pci_bus_lock().\n\n[bhelgaas: squash in recursive locking deadlock fix from Keith Busch:\nhttps://lore.kernel.org/r/20240711193650.701834-1-kbusch@meta.com]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46750', 'https://git.kernel.org/linus/a4e772898f8bf2e7e1cf661a12c60a5612c4afab (6.11-rc1)', 'https://git.kernel.org/stable/c/04e85a3285b0e5c5af6fd2c0fd6e95ffecc01945', 'https://git.kernel.org/stable/c/0790b89c7e911003b8c50ae50e3ac7645de1fae9', 'https://git.kernel.org/stable/c/7253b4fed46471cc247c6cacefac890a8472c083', 'https://git.kernel.org/stable/c/78c6e39fef5c428960aff742149bba302dd46f5a', 'https://git.kernel.org/stable/c/81c68e218ab883dfa368460a59b674084c0240da', 'https://git.kernel.org/stable/c/a4e772898f8bf2e7e1cf661a12c60a5612c4afab', 'https://git.kernel.org/stable/c/df77a678c33871a6e4ac5b54a71662f1d702335b', 'https://git.kernel.org/stable/c/e2355d513b89a2cb511b4ded0deb426cdb01acd0', 'https://lore.kernel.org/linux-cve-announce/2024091838-CVE-2024-46750-3be1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46750', 'https://www.cve.org/CVERecord?id=CVE-2024-46750'], 'PublishedDate': '2024-09-18T08:15:03.947Z', 'LastModifiedDate': '2024-09-30T13:27:45.787Z'}, {'VulnerabilityID': 'CVE-2024-46751', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46751', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()\n\nInstead of doing a BUG_ON() handle the error by returning -EUCLEAN,\naborting the transaction and logging an error message.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46751', 'https://git.kernel.org/linus/28cb13f29faf6290597b24b728dc3100c019356f (6.11-rc1)', 'https://git.kernel.org/stable/c/28cb13f29faf6290597b24b728dc3100c019356f', 'https://git.kernel.org/stable/c/ef9a8b73c8b60b27d9db4787e624a3438ffe8428', 'https://lore.kernel.org/linux-cve-announce/2024091838-CVE-2024-46751-17f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46751', 'https://www.cve.org/CVERecord?id=CVE-2024-46751'], 'PublishedDate': '2024-09-18T08:15:04.01Z', 'LastModifiedDate': '2024-09-30T12:45:56.957Z'}, {'VulnerabilityID': 'CVE-2024-46752', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46752', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: replace BUG_ON() with error handling at update_ref_for_cow()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: replace BUG_ON() with error handling at update_ref_for_cow()\n\nInstead of a BUG_ON() just return an error, log an error message and\nabort the transaction in case we find an extent buffer belonging to the\nrelocation tree that doesn't have the full backref flag set. This is\nunexpected and should never happen (save for bugs or a potential bad\nmemory).", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46752', 'https://git.kernel.org/linus/b56329a782314fde5b61058e2a25097af7ccb675 (6.11-rc1)', 'https://git.kernel.org/stable/c/0fbac73a97286a7ec72229cb9b42d760a2c717ac', 'https://git.kernel.org/stable/c/41a0f85e268d72fe04f731b8ceea4748c2d65491', 'https://git.kernel.org/stable/c/b50857b96429a09fd3beed9f7f21b7bb7c433688', 'https://git.kernel.org/stable/c/b56329a782314fde5b61058e2a25097af7ccb675', 'https://git.kernel.org/stable/c/f895db00c65e5d77c437cce946da9ec29dcdf563', 'https://lore.kernel.org/linux-cve-announce/2024091839-CVE-2024-46752-49e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46752', 'https://www.cve.org/CVERecord?id=CVE-2024-46752'], 'PublishedDate': '2024-09-18T08:15:04.057Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46753', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46753', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: handle errors from btrfs_dec_ref() properly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: handle errors from btrfs_dec_ref() properly\n\nIn walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is\nincorrect, we have proper error handling here, return the error.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46753', 'https://git.kernel.org/linus/5eb178f373b4f16f3b42d55ff88fc94dd95b93b1 (6.11-rc1)', 'https://git.kernel.org/stable/c/5eb178f373b4f16f3b42d55ff88fc94dd95b93b1', 'https://git.kernel.org/stable/c/a7f16a7a709845855cb5a0e080a52bda5873f9de', 'https://lore.kernel.org/linux-cve-announce/2024091839-CVE-2024-46753-5ec2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46753', 'https://www.cve.org/CVERecord?id=CVE-2024-46753'], 'PublishedDate': '2024-09-18T08:15:04.107Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46754', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46754', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Remove tst_run from lwt_seg6local_prog_ops.', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Remove tst_run from lwt_seg6local_prog_ops.\n\nThe syzbot reported that the lwt_seg6 related BPF ops can be invoked\nvia bpf_test_run() without without entering input_action_end_bpf()\nfirst.\n\nMartin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL\nprobably didn\'t work since it was introduced in commit 04d4b274e2a\n("ipv6: sr: Add seg6local action End.BPF"). The reason is that the\nper-CPU variable seg6_bpf_srh_states::srh is never assigned in the self\ntest case but each BPF function expects it.\n\nRemove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46754', 'https://git.kernel.org/linus/c13fda93aca118b8e5cd202e339046728ee7dddb (6.11-rc1)', 'https://git.kernel.org/stable/c/9cd15511de7c619bbd0f54bb3f28e6e720ded5d6', 'https://git.kernel.org/stable/c/c13fda93aca118b8e5cd202e339046728ee7dddb', 'https://lore.kernel.org/linux-cve-announce/2024091840-CVE-2024-46754-7f04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46754', 'https://www.cve.org/CVERecord?id=CVE-2024-46754'], 'PublishedDate': '2024-09-18T08:15:04.153Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46755', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46755', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()\n\nmwifiex_get_priv_by_id() returns the priv pointer corresponding to\nthe bss_num and bss_type, but without checking if the priv is actually\ncurrently in use.\nUnused priv pointers do not have a wiphy attached to them which can\nlead to NULL pointer dereferences further down the callstack. Fix\nthis by returning only used priv pointers which have priv->bss_mode\nset to something else than NL80211_IFTYPE_UNSPECIFIED.\n\nSaid NULL pointer dereference happened when an Accesspoint was started\nwith wpa_supplicant -i mlan0 with this config:\n\nnetwork={\n ssid="somessid"\n mode=2\n frequency=2412\n key_mgmt=WPA-PSK WPA-PSK-SHA256\n proto=RSN\n group=CCMP\n pairwise=CCMP\n psk="12345678"\n}\n\nWhen waiting for the AP to be established, interrupting wpa_supplicant\nwith and starting it again this happens:\n\n| Unable to handle kernel NULL pointer dereference at virtual address 0000000000000140\n| Mem abort info:\n| ESR = 0x0000000096000004\n| EC = 0x25: DABT (current EL), IL = 32 bits\n| SET = 0, FnV = 0\n| EA = 0, S1PTW = 0\n| FSC = 0x04: level 0 translation fault\n| Data abort info:\n| ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n| CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n| GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n| user pgtable: 4k pages, 48-bit VAs, pgdp=0000000046d96000\n| [0000000000000140] pgd=0000000000000000, p4d=0000000000000000\n| Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n| Modules linked in: caam_jr caamhash_desc spidev caamalg_desc crypto_engine authenc libdes mwifiex_sdio\n+mwifiex crct10dif_ce cdc_acm onboard_usb_hub fsl_imx8_ddr_perf imx8m_ddrc rtc_ds1307 lm75 rtc_snvs\n+imx_sdma caam imx8mm_thermal spi_imx error imx_cpufreq_dt fuse ip_tables x_tables ipv6\n| CPU: 0 PID: 8 Comm: kworker/0:1 Not tainted 6.9.0-00007-g937242013fce-dirty #18\n| Hardware name: somemachine (DT)\n| Workqueue: events sdio_irq_work\n| pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n| pc : mwifiex_get_cfp+0xd8/0x15c [mwifiex]\n| lr : mwifiex_get_cfp+0x34/0x15c [mwifiex]\n| sp : ffff8000818b3a70\n| x29: ffff8000818b3a70 x28: ffff000006bfd8a5 x27: 0000000000000004\n| x26: 000000000000002c x25: 0000000000001511 x24: 0000000002e86bc9\n| x23: ffff000006bfd996 x22: 0000000000000004 x21: ffff000007bec000\n| x20: 000000000000002c x19: 0000000000000000 x18: 0000000000000000\n| x17: 000000040044ffff x16: 00500072b5503510 x15: ccc283740681e517\n| x14: 0201000101006d15 x13: 0000000002e8ff43 x12: 002c01000000ffb1\n| x11: 0100000000000000 x10: 02e8ff43002c0100 x9 : 0000ffb100100157\n| x8 : ffff000003d20000 x7 : 00000000000002f1 x6 : 00000000ffffe124\n| x5 : 0000000000000001 x4 : 0000000000000003 x3 : 0000000000000000\n| x2 : 0000000000000000 x1 : 0001000000011001 x0 : 0000000000000000\n| Call trace:\n| mwifiex_get_cfp+0xd8/0x15c [mwifiex]\n| mwifiex_parse_single_response_buf+0x1d0/0x504 [mwifiex]\n| mwifiex_handle_event_ext_scan_report+0x19c/0x2f8 [mwifiex]\n| mwifiex_process_sta_event+0x298/0xf0c [mwifiex]\n| mwifiex_process_event+0x110/0x238 [mwifiex]\n| mwifiex_main_process+0x428/0xa44 [mwifiex]\n| mwifiex_sdio_interrupt+0x64/0x12c [mwifiex_sdio]\n| process_sdio_pending_irqs+0x64/0x1b8\n| sdio_irq_work+0x4c/0x7c\n| process_one_work+0x148/0x2a0\n| worker_thread+0x2fc/0x40c\n| kthread+0x110/0x114\n| ret_from_fork+0x10/0x20\n| Code: a94153f3 a8c37bfd d50323bf d65f03c0 (f940a000)\n| ---[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46755', 'https://git.kernel.org/linus/c145eea2f75ff7949392aebecf7ef0a81c1f6c14 (6.11-rc1)', 'https://git.kernel.org/stable/c/1a05d8d02cfa3540ea5dbd6b39446bd3f515521f', 'https://git.kernel.org/stable/c/9813770f25855b866b8ead8155b8806b2db70f6d', 'https://git.kernel.org/stable/c/a12cf97cbefa139ef8d95081f2ea047cbbd74b7a', 'https://git.kernel.org/stable/c/c145eea2f75ff7949392aebecf7ef0a81c1f6c14', 'https://git.kernel.org/stable/c/c16916dd6c16fa7e13ca3923eb6b9f50d848ad03', 'https://git.kernel.org/stable/c/c2618dcb26c7211342b54520b5b148c0d3471c8a', 'https://git.kernel.org/stable/c/cb67b2e51b75f1a17bee7599c8161b96e1808a70', 'https://git.kernel.org/stable/c/d834433ff313838a259bb6607055ece87b895b66', 'https://lore.kernel.org/linux-cve-announce/2024091840-CVE-2024-46755-1f46@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46755', 'https://www.cve.org/CVERecord?id=CVE-2024-46755'], 'PublishedDate': '2024-09-18T08:15:04.203Z', 'LastModifiedDate': '2024-09-26T13:25:54.593Z'}, {'VulnerabilityID': 'CVE-2024-46756', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46756', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (w83627ehf) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83627ehf) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46756', 'https://git.kernel.org/linus/5c1de37969b7bc0abcb20b86e91e70caebbd4f89 (6.11-rc1)', 'https://git.kernel.org/stable/c/26825b62bd1bd3e53b4f44e0745cb516d5186343', 'https://git.kernel.org/stable/c/56cfdeb2c77291f0b5e4592731adfb6ca8fc7c24', 'https://git.kernel.org/stable/c/5c1de37969b7bc0abcb20b86e91e70caebbd4f89', 'https://git.kernel.org/stable/c/77ab0fd231c4ca873ec6908e761970360acc6df2', 'https://git.kernel.org/stable/c/8fecb75bff1b7d87a071c32a37aa0700f2be379d', 'https://git.kernel.org/stable/c/93cf73a7bfdce683bde3a7bb65f270d3bd24497b', 'https://git.kernel.org/stable/c/cc4be794c8d8c253770103e097ab9dbdb5f99ae1', 'https://git.kernel.org/stable/c/d92f0baf99a7e327dcceab37cce57c38aab1f691', 'https://lore.kernel.org/linux-cve-announce/2024091840-CVE-2024-46756-2ca6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46756', 'https://www.cve.org/CVERecord?id=CVE-2024-46756'], 'PublishedDate': '2024-09-18T08:15:04.26Z', 'LastModifiedDate': '2024-09-23T16:29:45.077Z'}, {'VulnerabilityID': 'CVE-2024-46757', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46757', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (nct6775-core) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46757', 'https://git.kernel.org/linus/0403e10bf0824bf0ec2bb135d4cf1c0cc3bf4bf0 (6.11-rc1)', 'https://git.kernel.org/stable/c/02bb3b4c7d5695ff4be01e0f55676bba49df435e', 'https://git.kernel.org/stable/c/0403e10bf0824bf0ec2bb135d4cf1c0cc3bf4bf0', 'https://git.kernel.org/stable/c/0c23e18cef20b989a9fd7cb0a745e1259b969159', 'https://git.kernel.org/stable/c/298a55f11edd811f2189b74eb8f53dee34d4f14c', 'https://git.kernel.org/stable/c/2f695544084a559f181cafdfd3f864c5ff9dd1db', 'https://git.kernel.org/stable/c/8a1e958e26640ce015abdbb75c8896301b9bf398', 'https://git.kernel.org/stable/c/996221b030995cc5f5baa4a642201d64b62a17cd', 'https://git.kernel.org/stable/c/d6035c55fa9afefc23f85f57eff1d4a1d82c5b10', 'https://lore.kernel.org/linux-cve-announce/2024091841-CVE-2024-46757-4fbb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46757', 'https://www.cve.org/CVERecord?id=CVE-2024-46757'], 'PublishedDate': '2024-09-18T08:15:04.313Z', 'LastModifiedDate': '2024-09-23T16:29:51.65Z'}, {'VulnerabilityID': 'CVE-2024-46758', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46758', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (lm95234) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm95234) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46758', 'https://git.kernel.org/linus/af64e3e1537896337405f880c1e9ac1f8c0c6198 (6.11-rc1)', 'https://git.kernel.org/stable/c/0fc27747633aa419f9af40e7bdfa00d2ec94ea81', 'https://git.kernel.org/stable/c/16f42953231be1e7be77bc24005270d9e0d9d2ee', 'https://git.kernel.org/stable/c/438453dfbbdcf4be26891492644aa3ecbb42c336', 'https://git.kernel.org/stable/c/46e4fd338d5bdbaf60e41cda625b24949d2af201', 'https://git.kernel.org/stable/c/59c1fb9874a01c9abc49a0a32f192a7e7b4e2650', 'https://git.kernel.org/stable/c/93f0f5721d0cca45dac50af1ae6f9a9826c699fd', 'https://git.kernel.org/stable/c/af64e3e1537896337405f880c1e9ac1f8c0c6198', 'https://git.kernel.org/stable/c/da765bebd90e1b92bdbc3c6a27a3f3cc81529ab6', 'https://lore.kernel.org/linux-cve-announce/2024091841-CVE-2024-46758-6154@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46758', 'https://www.cve.org/CVERecord?id=CVE-2024-46758'], 'PublishedDate': '2024-09-18T08:15:04.367Z', 'LastModifiedDate': '2024-09-23T16:29:24.767Z'}, {'VulnerabilityID': 'CVE-2024-46759', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46759', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (adc128d818) Fix underflows seen when writing limit attributes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adc128d818) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-191'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46759', 'https://git.kernel.org/linus/8cad724c8537fe3e0da8004646abc00290adae40 (6.11-rc1)', 'https://git.kernel.org/stable/c/019ef2d396363ecddc46e826153a842f8603799b', 'https://git.kernel.org/stable/c/05419d0056dcf7088687e561bb583cc06deba777', 'https://git.kernel.org/stable/c/2a3add62f183459a057336381ef3a896da01ce38', 'https://git.kernel.org/stable/c/6891b11a0c6227ca7ed15786928a07b1c0e4d4af', 'https://git.kernel.org/stable/c/7645d783df23878342d5d8d22030c3861d2d5426', 'https://git.kernel.org/stable/c/8cad724c8537fe3e0da8004646abc00290adae40', 'https://git.kernel.org/stable/c/b0bdb43852bf7f55ba02f0cbf00b4ea7ca897bff', 'https://git.kernel.org/stable/c/f7f5101af5b47a331cdbfa42ba64c507b47dd1fe', 'https://lore.kernel.org/linux-cve-announce/2024091841-CVE-2024-46759-9b86@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46759', 'https://www.cve.org/CVERecord?id=CVE-2024-46759'], 'PublishedDate': '2024-09-18T08:15:04.413Z', 'LastModifiedDate': '2024-09-23T16:28:53.257Z'}, {'VulnerabilityID': 'CVE-2024-46760', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46760', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw88: usb: schedule rx work after everything is set up', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: usb: schedule rx work after everything is set up\n\nRight now it's possible to hit NULL pointer dereference in\nrtw_rx_fill_rx_status on hw object and/or its fields because\ninitialization routine can start getting USB replies before\nrtw_dev is fully setup.\n\nThe stack trace looks like this:\n\nrtw_rx_fill_rx_status\nrtw8821c_query_rx_desc\nrtw_usb_rx_handler\n...\nqueue_work\nrtw_usb_read_port_complete\n...\nusb_submit_urb\nrtw_usb_rx_resubmit\nrtw_usb_init_rx\nrtw_usb_probe\n\nSo while we do the async stuff rtw_usb_probe continues and calls\nrtw_register_hw, which does all kinds of initialization (e.g.\nvia ieee80211_register_hw) that rtw_rx_fill_rx_status relies on.\n\nFix this by moving the first usb_submit_urb after everything\nis set up.\n\nFor me, this bug manifested as:\n[ 8.893177] rtw_8821cu 1-1:1.2: band wrong, packet dropped\n[ 8.910904] rtw_8821cu 1-1:1.2: hw->conf.chandef.chan NULL in rtw_rx_fill_rx_status\nbecause I'm using Larry's backport of rtw88 driver with the NULL\nchecks in rtw_rx_fill_rx_status.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46760', 'https://git.kernel.org/linus/adc539784c98a7cc602cbf557debfc2e7b9be8b3 (6.11-rc1)', 'https://git.kernel.org/stable/c/25eaef533bf3ccc6fee5067aac16f41f280e343e', 'https://git.kernel.org/stable/c/adc539784c98a7cc602cbf557debfc2e7b9be8b3', 'https://git.kernel.org/stable/c/c83d464b82a8ad62ec9077637f75d73fe955635a', 'https://lore.kernel.org/linux-cve-announce/2024091842-CVE-2024-46760-1eb3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46760', 'https://www.cve.org/CVERecord?id=CVE-2024-46760'], 'PublishedDate': '2024-09-18T08:15:04.47Z', 'LastModifiedDate': '2024-09-23T16:18:28.87Z'}, {'VulnerabilityID': 'CVE-2024-46761', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46761', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npci/hotplug/pnv_php: Fix hotplug driver crash on Powernv\n\nThe hotplug driver for powerpc (pci/hotplug/pnv_php.c) causes a kernel\ncrash when we try to hot-unplug/disable the PCIe switch/bridge from\nthe PHB.\n\nThe crash occurs because although the MSI data structure has been\nreleased during disable/hot-unplug path and it has been assigned\nwith NULL, still during unregistration the code was again trying to\nexplicitly disable the MSI which causes the NULL pointer dereference and\nkernel crash.\n\nThe patch fixes the check during unregistration path to prevent invoking\npci_disable_msi/msix() since its data structure is already freed.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46761', 'https://git.kernel.org/linus/335e35b748527f0c06ded9eebb65387f60647fda (6.11-rc1)', 'https://git.kernel.org/stable/c/335e35b748527f0c06ded9eebb65387f60647fda', 'https://git.kernel.org/stable/c/438d522227374042b5c8798f8ce83bbe479dca4d', 'https://git.kernel.org/stable/c/4eb4085c1346d19d4a05c55246eb93e74e671048', 'https://git.kernel.org/stable/c/b82d4d5c736f4fd2ed224c35f554f50d1953d21e', 'https://git.kernel.org/stable/c/bc1faed19db95abf0933b104910a3fb01b138f59', 'https://git.kernel.org/stable/c/bfc44075b19740d372f989f21dd03168bfda0689', 'https://git.kernel.org/stable/c/c0d8094dc740cfacf3775bbc6a1c4720459e8de4', 'https://git.kernel.org/stable/c/c4c681999d385e28f84808bbf3a85ea8e982da55', 'https://lore.kernel.org/linux-cve-announce/2024091842-CVE-2024-46761-289f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46761', 'https://www.cve.org/CVERecord?id=CVE-2024-46761'], 'PublishedDate': '2024-09-18T08:15:04.517Z', 'LastModifiedDate': '2024-09-23T16:06:58.397Z'}, {'VulnerabilityID': 'CVE-2024-46762', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46762', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xen: privcmd: Fix possible access to a freed kirqfd instance', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Fix possible access to a freed kirqfd instance\n\nNothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and\nprivcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd\ncreated and added to the irqfds_list by privcmd_irqfd_assign() may get\nremoved by another thread executing privcmd_irqfd_deassign(), while the\nformer is still using it after dropping the locks.\n\nThis can lead to a situation where an already freed kirqfd instance may\nbe accessed and cause kernel oops.\n\nUse SRCU locking to prevent the same, as is done for the KVM\nimplementation for irqfds.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46762', 'https://git.kernel.org/linus/611ff1b1ae989a7bcce3e2a8e132ee30e968c557 (6.11-rc1)', 'https://git.kernel.org/stable/c/112fd2f02b308564724b8e81006c254d20945c4b', 'https://git.kernel.org/stable/c/611ff1b1ae989a7bcce3e2a8e132ee30e968c557', 'https://git.kernel.org/stable/c/e997b357b13a7d95de31681fc54fcc34235fa527', 'https://lore.kernel.org/linux-cve-announce/2024091843-CVE-2024-46762-6512@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46762', 'https://www.cve.org/CVERecord?id=CVE-2024-46762'], 'PublishedDate': '2024-09-18T08:15:04.57Z', 'LastModifiedDate': '2024-09-23T16:12:34.42Z'}, {'VulnerabilityID': 'CVE-2024-46763', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46763', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fou: Fix null-ptr-deref in GRO.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix null-ptr-deref in GRO.\n\nWe observed a null-ptr-deref in fou_gro_receive() while shutting down\na host. [0]\n\nThe NULL pointer is sk->sk_user_data, and the offset 8 is of protocol\nin struct fou.\n\nWhen fou_release() is called due to netns dismantle or explicit tunnel\nteardown, udp_tunnel_sock_release() sets NULL to sk->sk_user_data.\nThen, the tunnel socket is destroyed after a single RCU grace period.\n\nSo, in-flight udp4_gro_receive() could find the socket and execute the\nFOU GRO handler, where sk->sk_user_data could be NULL.\n\nLet's use rcu_dereference_sk_user_data() in fou_from_sock() and add NULL\nchecks in FOU GRO handlers.\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 80000001032f4067 P4D 80000001032f4067 PUD 103240067 PMD 0\nSMP PTI\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.216-204.855.amzn2.x86_64 #1\nHardware name: Amazon EC2 c5.large/, BIOS 1.0 10/16/2017\nRIP: 0010:fou_gro_receive (net/ipv4/fou.c:233) [fou]\nCode: 41 5f c3 cc cc cc cc e8 e7 2e 69 f4 0f 1f 80 00 00 00 00 0f 1f 44 00 00 49 89 f8 41 54 48 89 f7 48 89 d6 49 8b 80 88 02 00 00 <0f> b6 48 08 0f b7 42 4a 66 25 fd fd 80 cc 02 66 89 42 4a 0f b6 42\nRSP: 0018:ffffa330c0003d08 EFLAGS: 00010297\nRAX: 0000000000000000 RBX: ffff93d9e3a6b900 RCX: 0000000000000010\nRDX: ffff93d9e3a6b900 RSI: ffff93d9e3a6b900 RDI: ffff93dac2e24d08\nRBP: ffff93d9e3a6b900 R08: ffff93dacbce6400 R09: 0000000000000002\nR10: 0000000000000000 R11: ffffffffb5f369b0 R12: ffff93dacbce6400\nR13: ffff93dac2e24d08 R14: 0000000000000000 R15: ffffffffb4edd1c0\nFS: 0000000000000000(0000) GS:ffff93daee800000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000102140001 CR4: 00000000007706f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? no_context (arch/x86/mm/fault.c:752)\n ? exc_page_fault (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 arch/x86/mm/fault.c:1435 arch/x86/mm/fault.c:1483)\n ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:571)\n ? fou_gro_receive (net/ipv4/fou.c:233) [fou]\n udp_gro_receive (include/linux/netdevice.h:2552 net/ipv4/udp_offload.c:559)\n udp4_gro_receive (net/ipv4/udp_offload.c:604)\n inet_gro_receive (net/ipv4/af_inet.c:1549 (discriminator 7))\n dev_gro_receive (net/core/dev.c:6035 (discriminator 4))\n napi_gro_receive (net/core/dev.c:6170)\n ena_clean_rx_irq (drivers/amazon/net/ena/ena_netdev.c:1558) [ena]\n ena_io_poll (drivers/amazon/net/ena/ena_netdev.c:1742) [ena]\n napi_poll (net/core/dev.c:6847)\n net_rx_action (net/core/dev.c:6917)\n __do_softirq (arch/x86/include/asm/jump_label.h:25 include/linux/jump_label.h:200 include/trace/events/irq.h:142 kernel/softirq.c:299)\n asm_call_irq_on_stack (arch/x86/entry/entry_64.S:809)\n\n do_softirq_own_stack (arch/x86/include/asm/irq_stack.h:27 arch/x86/include/asm/irq_stack.h:77 arch/x86/kernel/irq_64.c:77)\n irq_exit_rcu (kernel/softirq.c:393 kernel/softirq.c:423 kernel/softirq.c:435)\n common_interrupt (arch/x86/kernel/irq.c:239)\n asm_common_interrupt (arch/x86/include/asm/idtentry.h:626)\nRIP: 0010:acpi_idle_do_entry (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 drivers/acpi/processor_idle.c:114 drivers/acpi/processor_idle.c:575)\nCode: 8b 15 d1 3c c4 02 ed c3 cc cc cc cc 65 48 8b 04 25 40 ef 01 00 48 8b 00 a8 08 75 eb 0f 1f 44 00 00 0f 00 2d d5 09 55 00 fb f4 c3 cc cc cc cc e9 be fc ff ff 66 66 2e 0f 1f 84 00 00 00 00 00\nRSP: 0018:ffffffffb5603e58 EFLAGS: 00000246\nRAX: 0000000000004000 RBX: ffff93dac0929c00 RCX: ffff93daee833900\nRDX: ffff93daee800000 RSI: ffff93d\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46763', 'https://git.kernel.org/linus/7e4196935069947d8b70b09c1660b67b067e75cb (6.11-rc7)', 'https://git.kernel.org/stable/c/1df42be305fe478ded1ee0c1d775f4ece713483b', 'https://git.kernel.org/stable/c/231c235d2f7a66f018f172e26ffd47c363f244ef', 'https://git.kernel.org/stable/c/4494bccb52ffda22ce5a1163a776d970e6229e08', 'https://git.kernel.org/stable/c/7e4196935069947d8b70b09c1660b67b067e75cb', 'https://git.kernel.org/stable/c/c46cd6aaca81040deaea3500ba75126963294bd9', 'https://git.kernel.org/stable/c/d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3', 'https://lore.kernel.org/linux-cve-announce/2024091843-CVE-2024-46763-a580@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46763', 'https://www.cve.org/CVERecord?id=CVE-2024-46763'], 'PublishedDate': '2024-09-18T08:15:04.613Z', 'LastModifiedDate': '2024-09-23T16:14:18.297Z'}, {'VulnerabilityID': 'CVE-2024-46765', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46765', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: protect XDP configuration with a mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: protect XDP configuration with a mutex\n\nThe main threat to data consistency in ice_xdp() is a possible asynchronous\nPF reset. It can be triggered by a user or by TX timeout handler.\n\nXDP setup and PF reset code access the same resources in the following\nsections:\n* ice_vsi_close() in ice_prepare_for_reset() - already rtnl-locked\n* ice_vsi_rebuild() for the PF VSI - not protected\n* ice_vsi_open() - already rtnl-locked\n\nWith an unfortunate timing, such accesses can result in a crash such as the\none below:\n\n[ +1.999878] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 14\n[ +2.002992] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 18\n[Mar15 18:17] ice 0000:b1:00.0 ens801f0np0: NETDEV WATCHDOG: CPU: 38: transmit queue 14 timed out 80692736 ms\n[ +0.000093] ice 0000:b1:00.0 ens801f0np0: tx_timeout: VSI_num: 6, Q 14, NTC: 0x0, HW_HEAD: 0x0, NTU: 0x0, INT: 0x4000001\n[ +0.000012] ice 0000:b1:00.0 ens801f0np0: tx_timeout recovery level 1, txqueue 14\n[ +0.394718] ice 0000:b1:00.0: PTP reset successful\n[ +0.006184] BUG: kernel NULL pointer dereference, address: 0000000000000098\n[ +0.000045] #PF: supervisor read access in kernel mode\n[ +0.000023] #PF: error_code(0x0000) - not-present page\n[ +0.000023] PGD 0 P4D 0\n[ +0.000018] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ +0.000023] CPU: 38 PID: 7540 Comm: kworker/38:1 Not tainted 6.8.0-rc7 #1\n[ +0.000031] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000036] Workqueue: ice ice_service_task [ice]\n[ +0.000183] RIP: 0010:ice_clean_tx_ring+0xa/0xd0 [ice]\n[...]\n[ +0.000013] Call Trace:\n[ +0.000016] \n[ +0.000014] ? __die+0x1f/0x70\n[ +0.000029] ? page_fault_oops+0x171/0x4f0\n[ +0.000029] ? schedule+0x3b/0xd0\n[ +0.000027] ? exc_page_fault+0x7b/0x180\n[ +0.000022] ? asm_exc_page_fault+0x22/0x30\n[ +0.000031] ? ice_clean_tx_ring+0xa/0xd0 [ice]\n[ +0.000194] ice_free_tx_ring+0xe/0x60 [ice]\n[ +0.000186] ice_destroy_xdp_rings+0x157/0x310 [ice]\n[ +0.000151] ice_vsi_decfg+0x53/0xe0 [ice]\n[ +0.000180] ice_vsi_rebuild+0x239/0x540 [ice]\n[ +0.000186] ice_vsi_rebuild_by_type+0x76/0x180 [ice]\n[ +0.000145] ice_rebuild+0x18c/0x840 [ice]\n[ +0.000145] ? delay_tsc+0x4a/0xc0\n[ +0.000022] ? delay_tsc+0x92/0xc0\n[ +0.000020] ice_do_reset+0x140/0x180 [ice]\n[ +0.000886] ice_service_task+0x404/0x1030 [ice]\n[ +0.000824] process_one_work+0x171/0x340\n[ +0.000685] worker_thread+0x277/0x3a0\n[ +0.000675] ? preempt_count_add+0x6a/0xa0\n[ +0.000677] ? _raw_spin_lock_irqsave+0x23/0x50\n[ +0.000679] ? __pfx_worker_thread+0x10/0x10\n[ +0.000653] kthread+0xf0/0x120\n[ +0.000635] ? __pfx_kthread+0x10/0x10\n[ +0.000616] ret_from_fork+0x2d/0x50\n[ +0.000612] ? __pfx_kthread+0x10/0x10\n[ +0.000604] ret_from_fork_asm+0x1b/0x30\n[ +0.000604] \n\nThe previous way of handling this through returning -EBUSY is not viable,\nparticularly when destroying AF_XDP socket, because the kernel proceeds\nwith removal anyway.\n\nThere is plenty of code between those calls and there is no need to create\na large critical section that covers all of them, same as there is no need\nto protect ice_vsi_rebuild() with rtnl_lock().\n\nAdd xdp_state_lock mutex to protect ice_vsi_rebuild() and ice_xdp().\n\nLeaving unprotected sections in between would result in two states that\nhave to be considered:\n1. when the VSI is closed, but not yet rebuild\n2. when VSI is already rebuild, but not yet open\n\nThe latter case is actually already handled through !netif_running() case,\nwe just need to adjust flag checking a little. The former one is not as\ntrivial, because between ice_vsi_close() and ice_vsi_rebuild(), a lot of\nhardware interaction happens, this can make adding/deleting rings exit\nwith an error. Luckily, VSI rebuild is pending and can apply new\nconfiguration for us in a managed fashion.\n\nTherefore, add an additional VSI state flag ICE_VSI_REBUILD_PENDING to\nindicate that ice_x\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46765', 'https://git.kernel.org/linus/2504b8405768a57a71e660dbfd5abd59f679a03f (6.11-rc7)', 'https://git.kernel.org/stable/c/2504b8405768a57a71e660dbfd5abd59f679a03f', 'https://git.kernel.org/stable/c/2f057db2fb29bc209c103050647562e60554d3d3', 'https://git.kernel.org/stable/c/391f7dae3d836891fc6cfbde38add2d0e10c6b7f', 'https://lore.kernel.org/linux-cve-announce/2024091844-CVE-2024-46765-1b8f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46765', 'https://www.cve.org/CVERecord?id=CVE-2024-46765'], 'PublishedDate': '2024-09-18T08:15:04.71Z', 'LastModifiedDate': '2024-09-26T13:24:29.697Z'}, {'VulnerabilityID': 'CVE-2024-46766', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46766', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: move netif_queue_set_napi to rtnl-protected sections', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: move netif_queue_set_napi to rtnl-protected sections\n\nCurrently, netif_queue_set_napi() is called from ice_vsi_rebuild() that is\nnot rtnl-locked when called from the reset. This creates the need to take\nthe rtnl_lock just for a single function and complicates the\nsynchronization with .ndo_bpf. At the same time, there no actual need to\nfill napi-to-queue information at this exact point.\n\nFill napi-to-queue information when opening the VSI and clear it when the\nVSI is being closed. Those routines are already rtnl-locked.\n\nAlso, rewrite napi-to-queue assignment in a way that prevents inclusion of\nXDP queues, as this leads to out-of-bounds writes, such as one below.\n\n[ +0.000004] BUG: KASAN: slab-out-of-bounds in netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000012] Write of size 8 at addr ffff889881727c80 by task bash/7047\n[ +0.000006] CPU: 24 PID: 7047 Comm: bash Not tainted 6.10.0-rc2+ #2\n[ +0.000004] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000003] Call Trace:\n[ +0.000003] \n[ +0.000002] dump_stack_lvl+0x60/0x80\n[ +0.000007] print_report+0xce/0x630\n[ +0.000007] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n[ +0.000007] ? __virt_addr_valid+0x1c9/0x2c0\n[ +0.000005] ? netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000003] kasan_report+0xe9/0x120\n[ +0.000004] ? netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000004] netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000005] ice_vsi_close+0x161/0x670 [ice]\n[ +0.000114] ice_dis_vsi+0x22f/0x270 [ice]\n[ +0.000095] ice_pf_dis_all_vsi.constprop.0+0xae/0x1c0 [ice]\n[ +0.000086] ice_prepare_for_reset+0x299/0x750 [ice]\n[ +0.000087] pci_dev_save_and_disable+0x82/0xd0\n[ +0.000006] pci_reset_function+0x12d/0x230\n[ +0.000004] reset_store+0xa0/0x100\n[ +0.000006] ? __pfx_reset_store+0x10/0x10\n[ +0.000002] ? __pfx_mutex_lock+0x10/0x10\n[ +0.000004] ? __check_object_size+0x4c1/0x640\n[ +0.000007] kernfs_fop_write_iter+0x30b/0x4a0\n[ +0.000006] vfs_write+0x5d6/0xdf0\n[ +0.000005] ? fd_install+0x180/0x350\n[ +0.000005] ? __pfx_vfs_write+0x10/0xA10\n[ +0.000004] ? do_fcntl+0x52c/0xcd0\n[ +0.000004] ? kasan_save_track+0x13/0x60\n[ +0.000003] ? kasan_save_free_info+0x37/0x60\n[ +0.000006] ksys_write+0xfa/0x1d0\n[ +0.000003] ? __pfx_ksys_write+0x10/0x10\n[ +0.000002] ? __x64_sys_fcntl+0x121/0x180\n[ +0.000004] ? _raw_spin_lock+0x87/0xe0\n[ +0.000005] do_syscall_64+0x80/0x170\n[ +0.000007] ? _raw_spin_lock+0x87/0xe0\n[ +0.000004] ? __pfx__raw_spin_lock+0x10/0x10\n[ +0.000003] ? file_close_fd_locked+0x167/0x230\n[ +0.000005] ? syscall_exit_to_user_mode+0x7d/0x220\n[ +0.000005] ? do_syscall_64+0x8c/0x170\n[ +0.000004] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? fput+0x1a/0x2c0\n[ +0.000004] ? filp_close+0x19/0x30\n[ +0.000004] ? do_dup2+0x25a/0x4c0\n[ +0.000004] ? __x64_sys_dup2+0x6e/0x2e0\n[ +0.000002] ? syscall_exit_to_user_mode+0x7d/0x220\n[ +0.000004] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? __count_memcg_events+0x113/0x380\n[ +0.000005] ? handle_mm_fault+0x136/0x820\n[ +0.000005] ? do_user_addr_fault+0x444/0xa80\n[ +0.000004] ? clear_bhb_loop+0x25/0x80\n[ +0.000004] ? clear_bhb_loop+0x25/0x80\n[ +0.000002] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ +0.000005] RIP: 0033:0x7f2033593154', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46766', 'https://git.kernel.org/linus/2a5dc090b92cfa5270e20056074241c6db5c9cdd (6.11-rc7)', 'https://git.kernel.org/stable/c/2285c2faef19ee08a6bd6754f4c3ec07dceb2889', 'https://git.kernel.org/stable/c/2a5dc090b92cfa5270e20056074241c6db5c9cdd', 'https://lore.kernel.org/linux-cve-announce/2024091844-CVE-2024-46766-417c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46766', 'https://www.cve.org/CVERecord?id=CVE-2024-46766'], 'PublishedDate': '2024-09-18T08:15:04.76Z', 'LastModifiedDate': '2024-09-23T16:15:23.823Z'}, {'VulnerabilityID': 'CVE-2024-46767', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46767', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: phy: Fix missing of_node_put() for leds', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: Fix missing of_node_put() for leds\n\nThe call of of_get_child_by_name() will cause refcount incremented\nfor leds, if it succeeds, it should call of_node_put() to decrease\nit, fix it.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46767', 'https://git.kernel.org/linus/2560db6ede1aaf162a73b2df43e0b6c5ed8819f7 (6.11-rc7)', 'https://git.kernel.org/stable/c/2560db6ede1aaf162a73b2df43e0b6c5ed8819f7', 'https://git.kernel.org/stable/c/26928c8f00f6bb0e194f3957fe51c69d36838eb2', 'https://git.kernel.org/stable/c/d9c8dbbc236cdc6231ee91cdede2fc97b430cfff', 'https://lore.kernel.org/linux-cve-announce/2024091844-CVE-2024-46767-31a2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46767', 'https://www.cve.org/CVERecord?id=CVE-2024-46767'], 'PublishedDate': '2024-09-18T08:15:04.81Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46768', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46768', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (hp-wmi-sensors) Check if WMI event data exists', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Check if WMI event data exists\n\nThe BIOS can choose to return no event data in response to a\nWMI event, so the ACPI object passed to the WMI notify handler\ncan be NULL.\n\nCheck for such a situation and ignore the event in such a case.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46768', 'https://git.kernel.org/linus/a54da9df75cd1b4b5028f6c60f9a211532680585 (6.11-rc7)', 'https://git.kernel.org/stable/c/217539e994e53206bbf3fb330261cc78c480d311', 'https://git.kernel.org/stable/c/4b19c83ba108aa66226da5b79810e4d19e005f12', 'https://git.kernel.org/stable/c/a54da9df75cd1b4b5028f6c60f9a211532680585', 'https://lore.kernel.org/linux-cve-announce/2024091845-CVE-2024-46768-b0bb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46768', 'https://www.cve.org/CVERecord?id=CVE-2024-46768'], 'PublishedDate': '2024-09-18T08:15:04.853Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46770', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46770', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Add netif_device_attach/detach into PF reset flow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add netif_device_attach/detach into PF reset flow\n\nEthtool callbacks can be executed while reset is in progress and try to\naccess deleted resources, e.g. getting coalesce settings can result in a\nNULL pointer dereference seen below.\n\nReproduction steps:\nOnce the driver is fully initialized, trigger reset:\n\t# echo 1 > /sys/class/net//device/reset\nwhen reset is in progress try to get coalesce settings using ethtool:\n\t# ethtool -c \n\nBUG: kernel NULL pointer dereference, address: 0000000000000020\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] PREEMPT SMP PTI\nCPU: 11 PID: 19713 Comm: ethtool Tainted: G S 6.10.0-rc7+ #7\nRIP: 0010:ice_get_q_coalesce+0x2e/0xa0 [ice]\nRSP: 0018:ffffbab1e9bcf6a8 EFLAGS: 00010206\nRAX: 000000000000000c RBX: ffff94512305b028 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffff9451c3f2e588 RDI: ffff9451c3f2e588\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffff9451c3f2e580 R11: 000000000000001f R12: ffff945121fa9000\nR13: ffffbab1e9bcf760 R14: 0000000000000013 R15: ffffffff9e65dd40\nFS: 00007faee5fbe740(0000) GS:ffff94546fd80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000020 CR3: 0000000106c2e005 CR4: 00000000001706f0\nCall Trace:\n\nice_get_coalesce+0x17/0x30 [ice]\ncoalesce_prepare_data+0x61/0x80\nethnl_default_doit+0xde/0x340\ngenl_family_rcv_msg_doit+0xf2/0x150\ngenl_rcv_msg+0x1b3/0x2c0\nnetlink_rcv_skb+0x5b/0x110\ngenl_rcv+0x28/0x40\nnetlink_unicast+0x19c/0x290\nnetlink_sendmsg+0x222/0x490\n__sys_sendto+0x1df/0x1f0\n__x64_sys_sendto+0x24/0x30\ndo_syscall_64+0x82/0x160\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7faee60d8e27\n\nCalling netif_device_detach() before reset makes the net core not call\nthe driver when ethtool command is issued, the attempt to execute an\nethtool command during reset will result in the following message:\n\n netlink error: No such device\n\ninstead of NULL pointer dereference. Once reset is done and\nice_rebuild() is executing, the netif_device_attach() is called to allow\nfor ethtool operations to occur again in a safe manner.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46770', 'https://git.kernel.org/linus/d11a67634227f9f9da51938af085fb41a733848f (6.11-rc7)', 'https://git.kernel.org/stable/c/36486c9e8e01b84faaee47203eac0b7e9cc7fa4a', 'https://git.kernel.org/stable/c/9e3ffb839249eca113062587659224f856fe14e5', 'https://git.kernel.org/stable/c/d11a67634227f9f9da51938af085fb41a733848f', 'https://git.kernel.org/stable/c/efe8effe138044a4747d1112ebb8c454d1663723', 'https://lore.kernel.org/linux-cve-announce/2024091845-CVE-2024-46770-3a5d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46770', 'https://www.cve.org/CVERecord?id=CVE-2024-46770'], 'PublishedDate': '2024-09-18T08:15:04.957Z', 'LastModifiedDate': '2024-09-23T16:13:25.563Z'}, {'VulnerabilityID': 'CVE-2024-46771', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46771', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: can: bcm: Remove proc entry when dev is unregistered.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: Remove proc entry when dev is unregistered.\n\nsyzkaller reported a warning in bcm_connect() below. [0]\n\nThe repro calls connect() to vxcan1, removes vxcan1, and calls\nconnect() with ifindex == 0.\n\nCalling connect() for a BCM socket allocates a proc entry.\nThen, bcm_sk(sk)->bound is set to 1 to prevent further connect().\n\nHowever, removing the bound device resets bcm_sk(sk)->bound to 0\nin bcm_notify().\n\nThe 2nd connect() tries to allocate a proc entry with the same\nname and sets NULL to bcm_sk(sk)->bcm_proc_read, leaking the\noriginal proc entry.\n\nSince the proc entry is available only for connect()ed sockets,\nlet's clean up the entry when the bound netdev is unregistered.\n\n[0]:\nproc_dir_entry 'can-bcm/2456' already registered\nWARNING: CPU: 1 PID: 394 at fs/proc/generic.c:376 proc_register+0x645/0x8f0 fs/proc/generic.c:375\nModules linked in:\nCPU: 1 PID: 394 Comm: syz-executor403 Not tainted 6.10.0-rc7-g852e42cc2dd4\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nRIP: 0010:proc_register+0x645/0x8f0 fs/proc/generic.c:375\nCode: 00 00 00 00 00 48 85 ed 0f 85 97 02 00 00 4d 85 f6 0f 85 9f 02 00 00 48 c7 c7 9b cb cf 87 48 89 de 4c 89 fa e8 1c 6f eb fe 90 <0f> 0b 90 90 48 c7 c7 98 37 99 89 e8 cb 7e 22 05 bb 00 00 00 10 48\nRSP: 0018:ffa0000000cd7c30 EFLAGS: 00010246\nRAX: 9e129be1950f0200 RBX: ff1100011b51582c RCX: ff1100011857cd80\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000002\nRBP: 0000000000000000 R08: ffd400000000000f R09: ff1100013e78cac0\nR10: ffac800000cd7980 R11: ff1100013e12b1f0 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000000 R15: ff1100011a99a2ec\nFS: 00007fbd7086f740(0000) GS:ff1100013fd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000200071c0 CR3: 0000000118556004 CR4: 0000000000771ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n proc_create_net_single+0x144/0x210 fs/proc/proc_net.c:220\n bcm_connect+0x472/0x840 net/can/bcm.c:1673\n __sys_connect_file net/socket.c:2049 [inline]\n __sys_connect+0x5d2/0x690 net/socket.c:2066\n __do_sys_connect net/socket.c:2076 [inline]\n __se_sys_connect net/socket.c:2073 [inline]\n __x64_sys_connect+0x8f/0x100 net/socket.c:2073\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd9/0x1c0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7fbd708b0e5d\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 9f 1b 00 f7 d8 64 89 01 48\nRSP: 002b:00007fff8cd33f08 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fbd708b0e5d\nRDX: 0000000000000010 RSI: 0000000020000040 RDI: 0000000000000003\nRBP: 0000000000000000 R08: 0000000000000040 R09: 0000000000000040\nR10: 0000000000000040 R11: 0000000000000246 R12: 00007fff8cd34098\nR13: 0000000000401280 R14: 0000000000406de8 R15: 00007fbd70ab9000\n \nremove_proc_entry: removing non-empty directory 'net/can-bcm', leaking at least '2456'", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46771', 'https://git.kernel.org/linus/76fe372ccb81b0c89b6cd2fec26e2f38c958be85 (6.11-rc7)', 'https://git.kernel.org/stable/c/10bfacbd5e8d821011d857bee73310457c9c989a', 'https://git.kernel.org/stable/c/33ed4ba73caae39f34ab874ba79138badc2c65dd', 'https://git.kernel.org/stable/c/3b39dc2901aa7a679a5ca981a3de9f8d5658afe8', 'https://git.kernel.org/stable/c/4377b79323df62eb5d310354f19b4d130ff58d50', 'https://git.kernel.org/stable/c/5c680022c4e28ba18ea500f3e29f0428271afa92', 'https://git.kernel.org/stable/c/76fe372ccb81b0c89b6cd2fec26e2f38c958be85', 'https://git.kernel.org/stable/c/abb0a615569ec008e8a93d9f3ab2d5b418ea94d4', 'https://git.kernel.org/stable/c/aec92dbebdbec7567d9f56d7c9296a572b8fd849', 'https://lore.kernel.org/linux-cve-announce/2024091846-CVE-2024-46771-913d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46771', 'https://www.cve.org/CVERecord?id=CVE-2024-46771'], 'PublishedDate': '2024-09-18T08:15:05.01Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46772', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46772', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check denominator crb_pipes before used', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check denominator crb_pipes before used\n\n[WHAT & HOW]\nA denominator cannot be 0, and is checked before used.\n\nThis fixes 2 DIVIDE_BY_ZERO issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46772', 'https://git.kernel.org/linus/ea79068d4073bf303f8203f2625af7d9185a1bc6 (6.11-rc1)', 'https://git.kernel.org/stable/c/ea79068d4073bf303f8203f2625af7d9185a1bc6', 'https://git.kernel.org/stable/c/ede06d23392529b039cf7ac11b5875b047900f1c', 'https://lore.kernel.org/linux-cve-announce/2024091846-CVE-2024-46772-4ad6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46772', 'https://www.cve.org/CVERecord?id=CVE-2024-46772'], 'PublishedDate': '2024-09-18T08:15:05.073Z', 'LastModifiedDate': '2024-09-23T16:52:17.577Z'}, {'VulnerabilityID': 'CVE-2024-46773', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46773', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check denominator pbn_div before used', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check denominator pbn_div before used\n\n[WHAT & HOW]\nA denominator cannot be 0, and is checked before used.\n\nThis fixes 1 DIVIDE_BY_ZERO issue reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46773', 'https://git.kernel.org/linus/116a678f3a9abc24f5c9d2525b7393d18d9eb58e (6.11-rc1)', 'https://git.kernel.org/stable/c/116a678f3a9abc24f5c9d2525b7393d18d9eb58e', 'https://git.kernel.org/stable/c/11f997143c67680d6e40a13363618380cd57a414', 'https://git.kernel.org/stable/c/20e7164c52d9bfbb9d9862b833fa989624a61345', 'https://git.kernel.org/stable/c/dfafee0a7b51c7c9612edd2d991401294964d02f', 'https://lore.kernel.org/linux-cve-announce/2024091847-CVE-2024-46773-5781@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46773', 'https://www.cve.org/CVERecord?id=CVE-2024-46773'], 'PublishedDate': '2024-09-18T08:15:05.123Z', 'LastModifiedDate': '2024-09-23T16:51:59.983Z'}, {'VulnerabilityID': 'CVE-2024-46774', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46774', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()\n\nSmatch warns:\n\n arch/powerpc/kernel/rtas.c:1932 __do_sys_rtas() warn: potential\n spectre issue 'args.args' [r] (local cap)\n\nThe 'nargs' and 'nret' locals come directly from a user-supplied\nbuffer and are used as indexes into a small stack-based array and as\ninputs to copy_to_user() after they are subject to bounds checks.\n\nUse array_index_nospec() after the bounds checks to clamp these values\nfor speculative execution.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46774', 'https://git.kernel.org/linus/0974d03eb479384466d828d65637814bee6b26d7 (6.11-rc1)', 'https://git.kernel.org/stable/c/0974d03eb479384466d828d65637814bee6b26d7', 'https://git.kernel.org/stable/c/68d8156480940b79227d58865ec5d2947b9384a8', 'https://lore.kernel.org/linux-cve-announce/2024091847-CVE-2024-46774-48d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46774', 'https://www.cve.org/CVERecord?id=CVE-2024-46774'], 'PublishedDate': '2024-09-18T08:15:05.18Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46775', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46775', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Validate function returns', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate function returns\n\n[WHAT & HOW]\nFunction return values must be checked before data can be used\nin subsequent functions.\n\nThis fixes 4 CHECKED_RETURN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46775', 'https://git.kernel.org/linus/673f816b9e1e92d1f70e1bf5f21b531e0ff9ad6c (6.11-rc1)', 'https://git.kernel.org/stable/c/5639a3048c7079803256374204ad55ec52cd0b49', 'https://git.kernel.org/stable/c/673f816b9e1e92d1f70e1bf5f21b531e0ff9ad6c', 'https://lore.kernel.org/linux-cve-announce/2024091847-CVE-2024-46775-aecc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46775', 'https://www.cve.org/CVERecord?id=CVE-2024-46775'], 'PublishedDate': '2024-09-18T08:15:05.24Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46776', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46776', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Run DC_LOG_DC after checking link->link_enc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Run DC_LOG_DC after checking link->link_enc\n\n[WHAT]\nThe DC_LOG_DC should be run after link->link_enc is checked, not before.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46776', 'https://git.kernel.org/linus/3a82f62b0d9d7687eac47603bb6cd14a50fa718b (6.11-rc1)', 'https://git.kernel.org/stable/c/3a82f62b0d9d7687eac47603bb6cd14a50fa718b', 'https://git.kernel.org/stable/c/874e3bb302f97b94ac548959ec4f925b8e7b45e2', 'https://git.kernel.org/stable/c/adc74d25cdbba978afbb57caec23bbcd0329f7b8', 'https://lore.kernel.org/linux-cve-announce/2024091848-CVE-2024-46776-7a95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46776', 'https://www.cve.org/CVERecord?id=CVE-2024-46776'], 'PublishedDate': '2024-09-18T08:15:05.287Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46777', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46777', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Avoid excessive partition lengths', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid excessive partition lengths\n\nAvoid mounting filesystems where the partition would overflow the\n32-bits used for block number. Also refuse to mount filesystems where\nthe partition length is so large we cannot safely index bits in a\nblock bitmap.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46777', 'https://git.kernel.org/linus/ebbe26fd54a9621994bc16b14f2ba8f84c089693 (6.11-rc1)', 'https://git.kernel.org/stable/c/0173999123082280cf904bd640015951f194a294', 'https://git.kernel.org/stable/c/1497a4484cdb2cf6c37960d788fb6ba67567bdb7', 'https://git.kernel.org/stable/c/2ddf831451357c6da4b64645eb797c93c1c054d1', 'https://git.kernel.org/stable/c/551966371e17912564bc387fbeb2ac13077c3db1', 'https://git.kernel.org/stable/c/925fd8ee80d5348a5e965548e5484d164d19221d', 'https://git.kernel.org/stable/c/a56330761950cb83de1dfb348479f20c56c95f90', 'https://git.kernel.org/stable/c/c0c23130d38e8bc28e9ef581443de9b1fc749966', 'https://git.kernel.org/stable/c/ebbe26fd54a9621994bc16b14f2ba8f84c089693', 'https://lore.kernel.org/linux-cve-announce/2024091848-CVE-2024-46777-6114@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46777', 'https://www.cve.org/CVERecord?id=CVE-2024-46777'], 'PublishedDate': '2024-09-18T08:15:05.33Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46778', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46778', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check UnboundedRequestEnabled's value', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check UnboundedRequestEnabled's value\n\nCalculateSwathAndDETConfiguration_params_st's UnboundedRequestEnabled\nis a pointer (i.e. dml_bool_t *UnboundedRequestEnabled), and thus\nif (p->UnboundedRequestEnabled) checks its address, not bool value.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46778', 'https://git.kernel.org/linus/a7b38c7852093385d0605aa3c8a2efd6edd1edfd (6.11-rc1)', 'https://git.kernel.org/stable/c/4e2b49a85e7974d21364798c5d4aa8070aa864d9', 'https://git.kernel.org/stable/c/a7b38c7852093385d0605aa3c8a2efd6edd1edfd', 'https://lore.kernel.org/linux-cve-announce/2024091848-CVE-2024-46778-ded6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46778', 'https://www.cve.org/CVERecord?id=CVE-2024-46778'], 'PublishedDate': '2024-09-18T08:15:05.38Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46779', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46779', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/imagination: Free pvr_vm_gpuva after unlink', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Free pvr_vm_gpuva after unlink\n\nThis caused a measurable memory leak. Although the individual\nallocations are small, the leaks occurs in a high-usage codepath\n(remapping or unmapping device memory) so they add up quickly.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46779', 'https://git.kernel.org/linus/3f6b2f60b4631cd0c368da6a1587ab55a696164d (6.11-rc7)', 'https://git.kernel.org/stable/c/1cc695be8920df234f83270d789078cb2d3bc564', 'https://git.kernel.org/stable/c/3f6b2f60b4631cd0c368da6a1587ab55a696164d', 'https://lore.kernel.org/linux-cve-announce/2024091849-CVE-2024-46779-3186@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46779', 'https://www.cve.org/CVERecord?id=CVE-2024-46779'], 'PublishedDate': '2024-09-18T08:15:05.43Z', 'LastModifiedDate': '2024-09-23T16:37:51.473Z'}, {'VulnerabilityID': 'CVE-2024-46780', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46780', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: protect references to superblock parameters exposed in sysfs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect references to superblock parameters exposed in sysfs\n\nThe superblock buffers of nilfs2 can not only be overwritten at runtime\nfor modifications/repairs, but they are also regularly swapped, replaced\nduring resizing, and even abandoned when degrading to one side due to\nbacking device issues. So, accessing them requires mutual exclusion using\nthe reader/writer semaphore "nilfs->ns_sem".\n\nSome sysfs attribute show methods read this superblock buffer without the\nnecessary mutual exclusion, which can cause problems with pointer\ndereferencing and memory access, so fix it.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46780', 'https://git.kernel.org/linus/683408258917541bdb294cd717c210a04381931e (6.11-rc7)', 'https://git.kernel.org/stable/c/157c0d94b4c40887329418c70ef4edd1a8d6b4ed', 'https://git.kernel.org/stable/c/19cfeba0e4b8eda51484fcf8cf7d150418e1d880', 'https://git.kernel.org/stable/c/683408258917541bdb294cd717c210a04381931e', 'https://git.kernel.org/stable/c/8c6e43b3d5f109cf9c61bc188fcc8175404e924f', 'https://git.kernel.org/stable/c/962562d4c70c5cdeb4e955d63ff2017c4eca1aad', 'https://git.kernel.org/stable/c/b14e7260bb691d7f563f61da07d61e3c8b59a614', 'https://git.kernel.org/stable/c/b90beafac05931cbfcb6b1bd4f67c1923f47040e', 'https://git.kernel.org/stable/c/ba97ba173f9625d5f34a986088979eae8b80d38e', 'https://lore.kernel.org/linux-cve-announce/2024091849-CVE-2024-46780-9155@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46780', 'https://www.cve.org/CVERecord?id=CVE-2024-46780'], 'PublishedDate': '2024-09-18T08:15:05.473Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46781', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46781', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: fix missing cleanup on rollforward recovery error', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix missing cleanup on rollforward recovery error\n\nIn an error injection test of a routine for mount-time recovery, KASAN\nfound a use-after-free bug.\n\nIt turned out that if data recovery was performed using partial logs\ncreated by dsync writes, but an error occurred before starting the log\nwriter to create a recovered checkpoint, the inodes whose data had been\nrecovered were left in the ns_dirty_files list of the nilfs object and\nwere not freed.\n\nFix this issue by cleaning up inodes that have read the recovery data if\nthe recovery routine fails midway before the log writer starts.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46781', 'https://git.kernel.org/linus/5787fcaab9eb5930f5378d6a1dd03d916d146622 (6.11-rc7)', 'https://git.kernel.org/stable/c/07e4dc2fe000ab008bcfe90be4324ef56b5b4355', 'https://git.kernel.org/stable/c/1cf1f7e8cd47244fa947d357ef1f642d91e219a3', 'https://git.kernel.org/stable/c/35a9a7a7d94662146396199b0cfd95f9517cdd14', 'https://git.kernel.org/stable/c/5787fcaab9eb5930f5378d6a1dd03d916d146622', 'https://git.kernel.org/stable/c/8e2d1e9d93c4ec51354229361ac3373058529ec4', 'https://git.kernel.org/stable/c/9d8c3a585d564d776ee60d4aabec59b404be7403', 'https://git.kernel.org/stable/c/ca92c4bff2833cb30d493b935168d6cccd5c805d', 'https://git.kernel.org/stable/c/da02f9eb333333b2e4f25d2a14967cff785ac82e', 'https://lore.kernel.org/linux-cve-announce/2024091850-CVE-2024-46781-377e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46781', 'https://www.cve.org/CVERecord?id=CVE-2024-46781'], 'PublishedDate': '2024-09-18T08:15:05.527Z', 'LastModifiedDate': '2024-09-23T16:37:07.117Z'}, {'VulnerabilityID': 'CVE-2024-46782', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46782', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ila: call nf_unregister_net_hooks() sooner', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nila: call nf_unregister_net_hooks() sooner\n\nsyzbot found an use-after-free Read in ila_nf_input [1]\n\nIssue here is that ila_xlat_exit_net() frees the rhashtable,\nthen call nf_unregister_net_hooks().\n\nIt should be done in the reverse way, with a synchronize_rcu().\n\nThis is a good match for a pre_exit() method.\n\n[1]\n BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline]\n BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672\nRead of size 4 at addr ffff888064620008 by task ksoftirqd/0/16\n\nCPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n __rhashtable_lookup include/linux/rhashtable.h:604 [inline]\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672\n ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:132 [inline]\n ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]\n ila_nf_input+0x1fe/0x3c0 net/ipv6/ila/ila_xlat.c:190\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626\n nf_hook include/linux/netfilter.h:269 [inline]\n NF_HOOK+0x29e/0x450 include/linux/netfilter.h:312\n __netif_receive_skb_one_core net/core/dev.c:5661 [inline]\n __netif_receive_skb+0x1ea/0x650 net/core/dev.c:5775\n process_backlog+0x662/0x15b0 net/core/dev.c:6108\n __napi_poll+0xcb/0x490 net/core/dev.c:6772\n napi_poll net/core/dev.c:6841 [inline]\n net_rx_action+0x89b/0x1240 net/core/dev.c:6963\n handle_softirqs+0x2c4/0x970 kernel/softirq.c:554\n run_ksoftirqd+0xca/0x130 kernel/softirq.c:928\n smpboot_thread_fn+0x544/0xa30 kernel/smpboot.c:164\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x64620\nflags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)\npage_type: 0xbfffffff(buddy)\nraw: 00fff00000000000 ffffea0000959608 ffffea00019d9408 0000000000000000\nraw: 0000000000000000 0000000000000003 00000000bfffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as freed\npage last allocated via order 3, migratetype Unmovable, gfp_mask 0x52dc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_ZERO), pid 5242, tgid 5242 (syz-executor), ts 73611328570, free_ts 618981657187\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x1f3/0x230 mm/page_alloc.c:1493\n prep_new_page mm/page_alloc.c:1501 [inline]\n get_page_from_freelist+0x2e4c/0x2f10 mm/page_alloc.c:3439\n __alloc_pages_noprof+0x256/0x6c0 mm/page_alloc.c:4695\n __alloc_pages_node_noprof include/linux/gfp.h:269 [inline]\n alloc_pages_node_noprof include/linux/gfp.h:296 [inline]\n ___kmalloc_large_node+0x8b/0x1d0 mm/slub.c:4103\n __kmalloc_large_node_noprof+0x1a/0x80 mm/slub.c:4130\n __do_kmalloc_node mm/slub.c:4146 [inline]\n __kmalloc_node_noprof+0x2d2/0x440 mm/slub.c:4164\n __kvmalloc_node_noprof+0x72/0x190 mm/util.c:650\n bucket_table_alloc lib/rhashtable.c:186 [inline]\n rhashtable_init_noprof+0x534/0xa60 lib/rhashtable.c:1071\n ila_xlat_init_net+0xa0/0x110 net/ipv6/ila/ila_xlat.c:613\n ops_ini\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46782', 'https://git.kernel.org/linus/031ae72825cef43e4650140b800ad58bf7a6a466 (6.11-rc7)', 'https://git.kernel.org/stable/c/031ae72825cef43e4650140b800ad58bf7a6a466', 'https://git.kernel.org/stable/c/18a5a16940464b301ea91bf5da3a324aedb347b2', 'https://git.kernel.org/stable/c/43d34110882b97ba1ec66cc8234b18983efb9abf', 'https://git.kernel.org/stable/c/47abd8adddbc0aecb8f231269ef659148d5dabe4', 'https://git.kernel.org/stable/c/925c18a7cff93d8a4320d652351294ff7d0ac93c', 'https://git.kernel.org/stable/c/93ee345ba349922834e6a9d1dadabaedcc12dce6', 'https://git.kernel.org/stable/c/bda4d84ac0d5421b346faee720011f58bdb99673', 'https://git.kernel.org/stable/c/dcaf4e2216824839d26727a15b638c6a677bd9fc', 'https://lore.kernel.org/linux-cve-announce/2024091850-CVE-2024-46782-00ff@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46782', 'https://www.cve.org/CVERecord?id=CVE-2024-46782'], 'PublishedDate': '2024-09-18T08:15:05.577Z', 'LastModifiedDate': '2024-09-23T16:32:04.373Z'}, {'VulnerabilityID': 'CVE-2024-46783', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46783', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp_bpf: fix return value of tcp_bpf_sendmsg()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_bpf: fix return value of tcp_bpf_sendmsg()\n\nWhen we cork messages in psock->cork, the last message triggers the\nflushing will result in sending a sk_msg larger than the current\nmessage size. In this case, in tcp_bpf_send_verdict(), 'copied' becomes\nnegative at least in the following case:\n\n468 case __SK_DROP:\n469 default:\n470 sk_msg_free_partial(sk, msg, tosend);\n471 sk_msg_apply_bytes(psock, tosend);\n472 *copied -= (tosend + delta); // <==== HERE\n473 return -EACCES;\n\nTherefore, it could lead to the following BUG with a proper value of\n'copied' (thanks to syzbot). We should not use negative 'copied' as a\nreturn value here.\n\n ------------[ cut here ]------------\n kernel BUG at net/socket.c:733!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 0 UID: 0 PID: 3265 Comm: syz-executor510 Not tainted 6.11.0-rc3-syzkaller-00060-gd07b43284ab3 #0\n Hardware name: linux,dummy-virt (DT)\n pstate: 61400009 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n pc : sock_sendmsg_nosec net/socket.c:733 [inline]\n pc : sock_sendmsg_nosec net/socket.c:728 [inline]\n pc : __sock_sendmsg+0x5c/0x60 net/socket.c:745\n lr : sock_sendmsg_nosec net/socket.c:730 [inline]\n lr : __sock_sendmsg+0x54/0x60 net/socket.c:745\n sp : ffff800088ea3b30\n x29: ffff800088ea3b30 x28: fbf00000062bc900 x27: 0000000000000000\n x26: ffff800088ea3bc0 x25: ffff800088ea3bc0 x24: 0000000000000000\n x23: f9f00000048dc000 x22: 0000000000000000 x21: ffff800088ea3d90\n x20: f9f00000048dc000 x19: ffff800088ea3d90 x18: 0000000000000001\n x17: 0000000000000000 x16: 0000000000000000 x15: 000000002002ffaf\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: ffff8000815849c0 x9 : ffff8000815b49c0\n x8 : 0000000000000000 x7 : 000000000000003f x6 : 0000000000000000\n x5 : 00000000000007e0 x4 : fff07ffffd239000 x3 : fbf00000062bc900\n x2 : 0000000000000000 x1 : 0000000000000000 x0 : 00000000fffffdef\n Call trace:\n sock_sendmsg_nosec net/socket.c:733 [inline]\n __sock_sendmsg+0x5c/0x60 net/socket.c:745\n ____sys_sendmsg+0x274/0x2ac net/socket.c:2597\n ___sys_sendmsg+0xac/0x100 net/socket.c:2651\n __sys_sendmsg+0x84/0xe0 net/socket.c:2680\n __do_sys_sendmsg net/socket.c:2689 [inline]\n __se_sys_sendmsg net/socket.c:2687 [inline]\n __arm64_sys_sendmsg+0x24/0x30 net/socket.c:2687\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x48/0x110 arch/arm64/kernel/syscall.c:49\n el0_svc_common.constprop.0+0x40/0xe0 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x1c/0x28 arch/arm64/kernel/syscall.c:151\n el0_svc+0x34/0xec arch/arm64/kernel/entry-common.c:712\n el0t_64_sync_handler+0x100/0x12c arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x19c/0x1a0 arch/arm64/kernel/entry.S:598\n Code: f9404463 d63f0060 3108441f 54fffe81 (d4210000)\n ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46783', 'https://git.kernel.org/linus/fe1910f9337bd46a9343967b547ccab26b4b2c6e (6.11-rc7)', 'https://git.kernel.org/stable/c/126d72b726c4cf1119f3a7fe413a78d341c3fea9', 'https://git.kernel.org/stable/c/3efe53eb221a38e207c1e3f81c51e4ca057d50c2', 'https://git.kernel.org/stable/c/6f9fdf5806cced888c43512bccbdf7fefd50f510', 'https://git.kernel.org/stable/c/78bb38d9c5a311c5f8bdef7c9557d7d81ca30e4a', 'https://git.kernel.org/stable/c/810a4e7d92dea4074cb04c25758320909d752193', 'https://git.kernel.org/stable/c/c8219a27fa43a2cbf99f5176f6dddfe73e7a24ae', 'https://git.kernel.org/stable/c/fe1910f9337bd46a9343967b547ccab26b4b2c6e', 'https://lore.kernel.org/linux-cve-announce/2024091850-CVE-2024-46783-edcb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46783', 'https://www.cve.org/CVERecord?id=CVE-2024-46783'], 'PublishedDate': '2024-09-18T08:15:05.63Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46784', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46784', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup\n\nCurrently napi_disable() gets called during rxq and txq cleanup,\neven before napi is enabled and hrtimer is initialized. It causes\nkernel panic.\n\n? page_fault_oops+0x136/0x2b0\n ? page_counter_cancel+0x2e/0x80\n ? do_user_addr_fault+0x2f2/0x640\n ? refill_obj_stock+0xc4/0x110\n ? exc_page_fault+0x71/0x160\n ? asm_exc_page_fault+0x27/0x30\n ? __mmdrop+0x10/0x180\n ? __mmdrop+0xec/0x180\n ? hrtimer_active+0xd/0x50\n hrtimer_try_to_cancel+0x2c/0xf0\n hrtimer_cancel+0x15/0x30\n napi_disable+0x65/0x90\n mana_destroy_rxq+0x4c/0x2f0\n mana_create_rxq.isra.0+0x56c/0x6d0\n ? mana_uncfg_vport+0x50/0x50\n mana_alloc_queues+0x21b/0x320\n ? skb_dequeue+0x5f/0x80", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46784', 'https://git.kernel.org/linus/b6ecc662037694488bfff7c9fd21c405df8411f2 (6.11-rc7)', 'https://git.kernel.org/stable/c/4982a47154f0b50de81ee0a0b169a3fc74120a65', 'https://git.kernel.org/stable/c/9178eb8ebcd887ab75e54ac40d538e54bb9c7788', 'https://git.kernel.org/stable/c/9e0bff4900b5d412a9bafe4baeaa6facd34f671c', 'https://git.kernel.org/stable/c/b6ecc662037694488bfff7c9fd21c405df8411f2', 'https://lore.kernel.org/linux-cve-announce/2024091851-CVE-2024-46784-4773@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46784', 'https://www.cve.org/CVERecord?id=CVE-2024-46784'], 'PublishedDate': '2024-09-18T08:15:05.683Z', 'LastModifiedDate': '2024-09-26T13:21:30.657Z'}, {'VulnerabilityID': 'CVE-2024-46785', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46785', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: eventfs: Use list_del_rcu() for SRCU protected list variable', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Use list_del_rcu() for SRCU protected list variable\n\nChi Zhiling reported:\n\n We found a null pointer accessing in tracefs[1], the reason is that the\n variable \'ei_child\' is set to LIST_POISON1, that means the list was\n removed in eventfs_remove_rec. so when access the ei_child->is_freed, the\n panic triggered.\n\n by the way, the following script can reproduce this panic\n\n loop1 (){\n while true\n do\n echo "p:kp submit_bio" > /sys/kernel/debug/tracing/kprobe_events\n echo "" > /sys/kernel/debug/tracing/kprobe_events\n done\n }\n loop2 (){\n while true\n do\n tree /sys/kernel/debug/tracing/events/kprobes/\n done\n }\n loop1 &\n loop2\n\n [1]:\n [ 1147.959632][T17331] Unable to handle kernel paging request at virtual address dead000000000150\n [ 1147.968239][T17331] Mem abort info:\n [ 1147.971739][T17331] ESR = 0x0000000096000004\n [ 1147.976172][T17331] EC = 0x25: DABT (current EL), IL = 32 bits\n [ 1147.982171][T17331] SET = 0, FnV = 0\n [ 1147.985906][T17331] EA = 0, S1PTW = 0\n [ 1147.989734][T17331] FSC = 0x04: level 0 translation fault\n [ 1147.995292][T17331] Data abort info:\n [ 1147.998858][T17331] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n [ 1148.005023][T17331] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n [ 1148.010759][T17331] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n [ 1148.016752][T17331] [dead000000000150] address between user and kernel address ranges\n [ 1148.024571][T17331] Internal error: Oops: 0000000096000004 [#1] SMP\n [ 1148.030825][T17331] Modules linked in: team_mode_loadbalance team nlmon act_gact cls_flower sch_ingress bonding tls macvlan dummy ib_core bridge stp llc veth amdgpu amdxcp mfd_core gpu_sched drm_exec drm_buddy radeon crct10dif_ce video drm_suballoc_helper ghash_ce drm_ttm_helper sha2_ce ttm sha256_arm64 i2c_algo_bit sha1_ce sbsa_gwdt cp210x drm_display_helper cec sr_mod cdrom drm_kms_helper binfmt_misc sg loop fuse drm dm_mod nfnetlink ip_tables autofs4 [last unloaded: tls]\n [ 1148.072808][T17331] CPU: 3 PID: 17331 Comm: ls Tainted: G W ------- ---- 6.6.43 #2\n [ 1148.081751][T17331] Source Version: 21b3b386e948bedd29369af66f3e98ab01b1c650\n [ 1148.088783][T17331] Hardware name: Greatwall GW-001M1A-FTF/GW-001M1A-FTF, BIOS KunLun BIOS V4.0 07/16/2020\n [ 1148.098419][T17331] pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 1148.106060][T17331] pc : eventfs_iterate+0x2c0/0x398\n [ 1148.111017][T17331] lr : eventfs_iterate+0x2fc/0x398\n [ 1148.115969][T17331] sp : ffff80008d56bbd0\n [ 1148.119964][T17331] x29: ffff80008d56bbf0 x28: ffff001ff5be2600 x27: 0000000000000000\n [ 1148.127781][T17331] x26: ffff001ff52ca4e0 x25: 0000000000009977 x24: dead000000000100\n [ 1148.135598][T17331] x23: 0000000000000000 x22: 000000000000000b x21: ffff800082645f10\n [ 1148.143415][T17331] x20: ffff001fddf87c70 x19: ffff80008d56bc90 x18: 0000000000000000\n [ 1148.151231][T17331] x17: 0000000000000000 x16: 0000000000000000 x15: ffff001ff52ca4e0\n [ 1148.159048][T17331] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 1148.166864][T17331] x11: 0000000000000000 x10: 0000000000000000 x9 : ffff8000804391d0\n [ 1148.174680][T17331] x8 : 0000000180000000 x7 : 0000000000000018 x6 : 0000aaab04b92862\n [ 1148.182498][T17331] x5 : 0000aaab04b92862 x4 : 0000000080000000 x3 : 0000000000000068\n [ 1148.190314][T17331] x2 : 000000000000000f x1 : 0000000000007ea8 x0 : 0000000000000001\n [ 1148.198131][T17331] Call trace:\n [ 1148.201259][T17331] eventfs_iterate+0x2c0/0x398\n [ 1148.205864][T17331] iterate_dir+0x98/0x188\n [ 1148.210036][T17331] __arm64_sys_getdents64+0x78/0x160\n [ 1148.215161][T17331] invoke_syscall+0x78/0x108\n [ 1148.219593][T17331] el0_svc_common.constprop.0+0x48/0xf0\n [ 1148.224977][T17331] do_el0_svc+0x24/0x38\n [ 1148.228974][T17331] el0_svc+0x40/0x168\n [ 1148.232798][T17\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46785', 'https://git.kernel.org/linus/d2603279c7d645bf0d11fa253b23f1ab48fc8d3c (6.11-rc7)', 'https://git.kernel.org/stable/c/05e08297c3c298d8ec28e5a5adb55840312dd87e', 'https://git.kernel.org/stable/c/d2603279c7d645bf0d11fa253b23f1ab48fc8d3c', 'https://git.kernel.org/stable/c/f579d17a86448779f9642ad8baca6e3036a8e2d6', 'https://lore.kernel.org/linux-cve-announce/2024091851-CVE-2024-46785-5351@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46785', 'https://www.cve.org/CVERecord?id=CVE-2024-46785'], 'PublishedDate': '2024-09-18T08:15:05.73Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46786', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46786', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF\n\nThe fscache_cookie_lru_timer is initialized when the fscache module\nis inserted, but is not deleted when the fscache module is removed.\nIf timer_reduce() is called before removing the fscache module,\nthe fscache_cookie_lru_timer will be added to the timer list of\nthe current cpu. Afterwards, a use-after-free will be triggered\nin the softIRQ after removing the fscache module, as follows:\n\n==================================================================\nBUG: unable to handle page fault for address: fffffbfff803c9e9\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 21ffea067 P4D 21ffea067 PUD 21ffe6067 PMD 110a7c067 PTE 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 1 UID: 0 PID: 0 Comm: swapper/1 Tainted: G W 6.11.0-rc3 #855\nTainted: [W]=WARN\nRIP: 0010:__run_timer_base.part.0+0x254/0x8a0\nCall Trace:\n \n tmigr_handle_remote_up+0x627/0x810\n __walk_groups.isra.0+0x47/0x140\n tmigr_handle_remote+0x1fa/0x2f0\n handle_softirqs+0x180/0x590\n irq_exit_rcu+0x84/0xb0\n sysvec_apic_timer_interrupt+0x6e/0x90\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20\nRIP: 0010:default_idle+0xf/0x20\n default_idle_call+0x38/0x60\n do_idle+0x2b5/0x300\n cpu_startup_entry+0x54/0x60\n start_secondary+0x20d/0x280\n common_startup_64+0x13e/0x148\n \nModules linked in: [last unloaded: netfs]\n==================================================================\n\nTherefore delete fscache_cookie_lru_timer when removing the fscahe module.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46786', 'https://git.kernel.org/linus/72a6e22c604c95ddb3b10b5d3bb85b6ff4dbc34f (6.11-rc7)', 'https://git.kernel.org/stable/c/0a11262549ac2ac6fb98c7cd40a67136817e5a52', 'https://git.kernel.org/stable/c/72a6e22c604c95ddb3b10b5d3bb85b6ff4dbc34f', 'https://git.kernel.org/stable/c/e0d724932ad12e3528f4ce97fc0f6078d0cce4bc', 'https://lore.kernel.org/linux-cve-announce/2024091851-CVE-2024-46786-a167@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46786', 'https://www.cve.org/CVERecord?id=CVE-2024-46786'], 'PublishedDate': '2024-09-18T08:15:05.783Z', 'LastModifiedDate': '2024-09-26T12:48:37.447Z'}, {'VulnerabilityID': 'CVE-2024-46787', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46787', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: userfaultfd: fix checks for huge PMDs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: fix checks for huge PMDs\n\nPatch series "userfaultfd: fix races around pmd_trans_huge() check", v2.\n\nThe pmd_trans_huge() code in mfill_atomic() is wrong in three different\nways depending on kernel version:\n\n1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit\n the right two race windows) - I\'ve tested this in a kernel build with\n some extra mdelay() calls. See the commit message for a description\n of the race scenario.\n On older kernels (before 6.5), I think the same bug can even\n theoretically lead to accessing transhuge page contents as a page table\n if you hit the right 5 narrow race windows (I haven\'t tested this case).\n2. As pointed out by Qi Zheng, pmd_trans_huge() is not sufficient for\n detecting PMDs that don\'t point to page tables.\n On older kernels (before 6.5), you\'d just have to win a single fairly\n wide race to hit this.\n I\'ve tested this on 6.1 stable by racing migration (with a mdelay()\n patched into try_to_migrate()) against UFFDIO_ZEROPAGE - on my x86\n VM, that causes a kernel oops in ptlock_ptr().\n3. On newer kernels (>=6.5), for shmem mappings, khugepaged is allowed\n to yank page tables out from under us (though I haven\'t tested that),\n so I think the BUG_ON() checks in mfill_atomic() are just wrong.\n\nI decided to write two separate fixes for these (one fix for bugs 1+2, one\nfix for bug 3), so that the first fix can be backported to kernels\naffected by bugs 1+2.\n\n\nThis patch (of 2):\n\nThis fixes two issues.\n\nI discovered that the following race can occur:\n\n mfill_atomic other thread\n ============ ============\n \n pmdp_get_lockless() [reads none pmd]\n \n \n \n __pte_alloc [no-op]\n \n \n BUG_ON(pmd_none(*dst_pmd))\n\nI have experimentally verified this in a kernel with extra mdelay() calls;\nthe BUG_ON(pmd_none(*dst_pmd)) triggers.\n\nOn kernels newer than commit 0d940a9b270b ("mm/pgtable: allow\npte_offset_map[_lock]() to fail"), this can\'t lead to anything worse than\na BUG_ON(), since the page table access helpers are actually designed to\ndeal with page tables concurrently disappearing; but on older kernels\n(<=6.4), I think we could probably theoretically race past the two\nBUG_ON() checks and end up treating a hugepage as a page table.\n\nThe second issue is that, as Qi Zheng pointed out, there are other types\nof huge PMDs that pmd_trans_huge() can\'t catch: devmap PMDs and swap PMDs\n(in particular, migration PMDs).\n\nOn <=6.4, this is worse than the first issue: If mfill_atomic() runs on a\nPMD that contains a migration entry (which just requires winning a single,\nfairly wide race), it will pass the PMD to pte_offset_map_lock(), which\nassumes that the PMD points to a page table.\n\nBreakage follows: First, the kernel tries to take the PTE lock (which will\ncrash or maybe worse if there is no "struct page" for the address bits in\nthe migration entry PMD - I think at least on X86 there usually is no\ncorresponding "struct page" thanks to the PTE inversion mitigation, amd64\nlooks different).\n\nIf that didn\'t crash, the kernel would next try to write a PTE into what\nit wrongly thinks is a page table.\n\nAs part of fixing these issues, get rid of the check for pmd_trans_huge()\nbefore __pte_alloc() - that\'s redundant, we\'re going to have to check for\nthat after the __pte_alloc() anyway.\n\nBackport note: pmdp_get_lockless() is pmd_read_atomic() in older kernels.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46787', 'https://git.kernel.org/linus/71c186efc1b2cf1aeabfeff3b9bd5ac4c5ac14d8 (6.11-rc7)', 'https://git.kernel.org/stable/c/3c6b4bcf37845c9359aed926324bed66bdd2448d', 'https://git.kernel.org/stable/c/71c186efc1b2cf1aeabfeff3b9bd5ac4c5ac14d8', 'https://git.kernel.org/stable/c/98cc18b1b71e23fe81a5194ed432b20c2d81a01a', 'https://lore.kernel.org/linux-cve-announce/2024091852-CVE-2024-46787-8b6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46787', 'https://www.cve.org/CVERecord?id=CVE-2024-46787'], 'PublishedDate': '2024-09-18T08:15:05.833Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46788', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46788', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing/osnoise: Use a cpumask to know what threads are kthreads', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Use a cpumask to know what threads are kthreads\n\nThe start_kthread() and stop_thread() code was not always called with the\ninterface_lock held. This means that the kthread variable could be\nunexpectedly changed causing the kthread_stop() to be called on it when it\nshould not have been, leading to:\n\n while true; do\n rtla timerlat top -u -q & PID=$!;\n sleep 5;\n kill -INT $PID;\n sleep 0.001;\n kill -TERM $PID;\n wait $PID;\n done\n\nCausing the following OOPS:\n\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n CPU: 5 UID: 0 PID: 885 Comm: timerlatu/5 Not tainted 6.11.0-rc4-test-00002-gbc754cc76d1b-dirty #125 a533010b71dab205ad2f507188ce8c82203b0254\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n RIP: 0010:hrtimer_active+0x58/0x300\n Code: 48 c1 ee 03 41 54 48 01 d1 48 01 d6 55 53 48 83 ec 20 80 39 00 0f 85 30 02 00 00 49 8b 6f 30 4c 8d 75 10 4c 89 f0 48 c1 e8 03 <0f> b6 3c 10 4c 89 f0 83 e0 07 83 c0 03 40 38 f8 7c 09 40 84 ff 0f\n RSP: 0018:ffff88811d97f940 EFLAGS: 00010202\n RAX: 0000000000000002 RBX: ffff88823c6b5b28 RCX: ffffed10478d6b6b\n RDX: dffffc0000000000 RSI: ffffed10478d6b6c RDI: ffff88823c6b5b28\n RBP: 0000000000000000 R08: ffff88823c6b5b58 R09: ffff88823c6b5b60\n R10: ffff88811d97f957 R11: 0000000000000010 R12: 00000000000a801d\n R13: ffff88810d8b35d8 R14: 0000000000000010 R15: ffff88823c6b5b28\n FS: 0000000000000000(0000) GS:ffff88823c680000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000561858ad7258 CR3: 000000007729e001 CR4: 0000000000170ef0\n Call Trace:\n \n ? die_addr+0x40/0xa0\n ? exc_general_protection+0x154/0x230\n ? asm_exc_general_protection+0x26/0x30\n ? hrtimer_active+0x58/0x300\n ? __pfx_mutex_lock+0x10/0x10\n ? __pfx_locks_remove_file+0x10/0x10\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x8e/0x1f0\n ? security_file_release+0x43/0x80\n __fput+0x372/0xb10\n task_work_run+0x11e/0x1f0\n ? _raw_spin_lock+0x85/0xe0\n ? __pfx_task_work_run+0x10/0x10\n ? poison_slab_object+0x109/0x170\n ? do_exit+0x7a0/0x24b0\n do_exit+0x7bd/0x24b0\n ? __pfx_migrate_enable+0x10/0x10\n ? __pfx_do_exit+0x10/0x10\n ? __pfx_read_tsc+0x10/0x10\n ? ktime_get+0x64/0x140\n ? _raw_spin_lock_irq+0x86/0xe0\n do_group_exit+0xb0/0x220\n get_signal+0x17ba/0x1b50\n ? vfs_read+0x179/0xa40\n ? timerlat_fd_read+0x30b/0x9d0\n ? __pfx_get_signal+0x10/0x10\n ? __pfx_timerlat_fd_read+0x10/0x10\n arch_do_signal_or_restart+0x8c/0x570\n ? __pfx_arch_do_signal_or_restart+0x10/0x10\n ? vfs_read+0x179/0xa40\n ? ksys_read+0xfe/0x1d0\n ? __pfx_ksys_read+0x10/0x10\n syscall_exit_to_user_mode+0xbc/0x130\n do_syscall_64+0x74/0x110\n ? __pfx___rseq_handle_notify_resume+0x10/0x10\n ? __pfx_ksys_read+0x10/0x10\n ? fpregs_restore_userregs+0xdb/0x1e0\n ? fpregs_restore_userregs+0xdb/0x1e0\n ? syscall_exit_to_user_mode+0x116/0x130\n ? do_syscall_64+0x74/0x110\n ? do_syscall_64+0x74/0x110\n ? do_syscall_64+0x74/0x110\n entry_SYSCALL_64_after_hwframe+0x71/0x79\n RIP: 0033:0x7ff0070eca9c\n Code: Unable to access opcode bytes at 0x7ff0070eca72.\n RSP: 002b:00007ff006dff8c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n RAX: 0000000000000000 RBX: 0000000000000005 RCX: 00007ff0070eca9c\n RDX: 0000000000000400 RSI: 00007ff006dff9a0 RDI: 0000000000000003\n RBP: 00007ff006dffde0 R08: 0000000000000000 R09: 00007ff000000ba0\n R10: 00007ff007004b08 R11: 0000000000000246 R12: 0000000000000003\n R13: 00007ff006dff9a0 R14: 0000000000000007 R15: 0000000000000008\n \n Modules linked in: snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hwdep snd_hda_core\n ---[ end trace 0000000000000000 ]---\n\nThis is because it would mistakenly call kthread_stop() on a user space\nthread making it "exit" before it actually exits.\n\nSince kthread\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46788', 'https://git.kernel.org/linus/177e1cc2f41235c145041eed03ef5bab18f32328 (6.11-rc7)', 'https://git.kernel.org/stable/c/177e1cc2f41235c145041eed03ef5bab18f32328', 'https://git.kernel.org/stable/c/27282d2505b402f39371fd60d19d95c01a4b6776', 'https://git.kernel.org/stable/c/7a5f01828edf152c144d27cf63de446fdf2dc222', 'https://lore.kernel.org/linux-cve-announce/2024091852-CVE-2024-46788-1fbc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46788', 'https://www.cve.org/CVERecord?id=CVE-2024-46788'], 'PublishedDate': '2024-09-18T08:15:05.893Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46791', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46791', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: can: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open\n\nThe mcp251x_hw_wake() function is called with the mpc_lock mutex held and\ndisables the interrupt handler so that no interrupts can be processed while\nwaking the device. If an interrupt has already occurred then waiting for\nthe interrupt handler to complete will deadlock because it will be trying\nto acquire the same mutex.\n\nCPU0 CPU1\n---- ----\nmcp251x_open()\n mutex_lock(&priv->mcp_lock)\n request_threaded_irq()\n \n mcp251x_can_ist()\n mutex_lock(&priv->mcp_lock)\n mcp251x_hw_wake()\n disable_irq() <-- deadlock\n\nUse disable_irq_nosync() instead because the interrupt handler does\neverything while holding the mutex so it doesn't matter if it's still\nrunning.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46791', 'https://git.kernel.org/linus/7dd9c26bd6cf679bcfdef01a8659791aa6487a29 (6.11-rc7)', 'https://git.kernel.org/stable/c/3a49b6b1caf5cefc05264d29079d52c99cb188e0', 'https://git.kernel.org/stable/c/513c8fc189b52f7922e36bdca58997482b198f0e', 'https://git.kernel.org/stable/c/7dd9c26bd6cf679bcfdef01a8659791aa6487a29', 'https://git.kernel.org/stable/c/8fecde9c3f9a4b97b68bb97c9f47e5b662586ba7', 'https://git.kernel.org/stable/c/e554113a1cd2a9cfc6c7af7bdea2141c5757e188', 'https://git.kernel.org/stable/c/f7ab9e14b23a3eac6714bdc4dba244d8aa1ef646', 'https://lore.kernel.org/linux-cve-announce/2024091853-CVE-2024-46791-af66@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46791', 'https://www.cve.org/CVERecord?id=CVE-2024-46791'], 'PublishedDate': '2024-09-18T08:15:06.067Z', 'LastModifiedDate': '2024-09-20T18:21:19.457Z'}, {'VulnerabilityID': 'CVE-2024-46792', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46792', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv: misaligned: Restrict user access to kernel memory', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: misaligned: Restrict user access to kernel memory\n\nraw_copy_{to,from}_user() do not call access_ok(), so this code allowed\nuserspace to access any virtual memory address.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46792', 'https://git.kernel.org/linus/b686ecdeacf6658e1348c1a32a08e2e72f7c0f00 (6.11-rc7)', 'https://git.kernel.org/stable/c/a3b6ff6c896aee5ef9b581e40d0045ff04fcbc8c', 'https://git.kernel.org/stable/c/b686ecdeacf6658e1348c1a32a08e2e72f7c0f00', 'https://lore.kernel.org/linux-cve-announce/2024091854-CVE-2024-46792-7745@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46792', 'https://www.cve.org/CVERecord?id=CVE-2024-46792'], 'PublishedDate': '2024-09-18T08:15:06.123Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46793', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46793', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: Intel: Boards: Fix NULL pointer deref in BYT/CHT boards harder', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: Boards: Fix NULL pointer deref in BYT/CHT boards harder\n\nSince commit 13f58267cda3 ("ASoC: soc.h: don\'t create dummy Component\nvia COMP_DUMMY()") dummy codecs declared like this:\n\nSND_SOC_DAILINK_DEF(dummy,\n DAILINK_COMP_ARRAY(COMP_DUMMY()));\n\nexpand to:\n\nstatic struct snd_soc_dai_link_component dummy[] = {\n};\n\nWhich means that dummy is a zero sized array and thus dais[i].codecs should\nnot be dereferenced *at all* since it points to the address of the next\nvariable stored in the data section as the "dummy" variable has an address\nbut no size, so even dereferencing dais[0] is already an out of bounds\narray reference.\n\nWhich means that the if (dais[i].codecs->name) check added in\ncommit 7d99a70b6595 ("ASoC: Intel: Boards: Fix NULL pointer deref\nin BYT/CHT boards") relies on that the part of the next variable which\nthe name member maps to just happens to be NULL.\n\nWhich apparently so far it usually is, except when it isn\'t\nand then it results in crashes like this one:\n\n[ 28.795659] BUG: unable to handle page fault for address: 0000000000030011\n...\n[ 28.795780] Call Trace:\n[ 28.795787] \n...\n[ 28.795862] ? strcmp+0x18/0x40\n[ 28.795872] 0xffffffffc150c605\n[ 28.795887] platform_probe+0x40/0xa0\n...\n[ 28.795979] ? __pfx_init_module+0x10/0x10 [snd_soc_sst_bytcr_wm5102]\n\nReally fix things this time around by checking dais.num_codecs != 0.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46793', 'https://git.kernel.org/linus/0cc65482f5b03ac2b1c240bc34665e43ea2d71bb (6.11-rc7)', 'https://git.kernel.org/stable/c/0cc65482f5b03ac2b1c240bc34665e43ea2d71bb', 'https://git.kernel.org/stable/c/85cda5b040bda9c577b34eb72d5b2e5b7e31985c', 'https://lore.kernel.org/linux-cve-announce/2024091854-CVE-2024-46793-268d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46793', 'https://www.cve.org/CVERecord?id=CVE-2024-46793'], 'PublishedDate': '2024-09-18T08:15:06.177Z', 'LastModifiedDate': '2024-09-24T16:00:17.977Z'}, {'VulnerabilityID': 'CVE-2024-46794', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46794', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/tdx: Fix data leak in mmio_read()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Fix data leak in mmio_read()\n\nThe mmio_read() function makes a TDVMCALL to retrieve MMIO data for an\naddress from the VMM.\n\nSean noticed that mmio_read() unintentionally exposes the value of an\ninitialized variable (val) on the stack to the VMM.\n\nThis variable is only needed as an output value. It did not need to be\npassed to the VMM in the first place.\n\nDo not send the original value of *val to the VMM.\n\n[ dhansen: clarify what 'val' is used for. ]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46794', 'https://git.kernel.org/linus/b6fb565a2d15277896583d471b21bc14a0c99661 (6.11-rc7)', 'https://git.kernel.org/stable/c/26c6af49d26ffc377e392e30d4086db19eed0ef7', 'https://git.kernel.org/stable/c/b55ce742afcb8e8189d82f2f1e635ba1b5a461fa', 'https://git.kernel.org/stable/c/b6fb565a2d15277896583d471b21bc14a0c99661', 'https://git.kernel.org/stable/c/ef00818c50cf55a3a56bd9a9fae867c92dfb84e7', 'https://lore.kernel.org/linux-cve-announce/2024091854-CVE-2024-46794-9f64@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46794', 'https://www.cve.org/CVERecord?id=CVE-2024-46794'], 'PublishedDate': '2024-09-18T08:15:06.23Z', 'LastModifiedDate': '2024-09-20T12:30:51.22Z'}, {'VulnerabilityID': 'CVE-2024-46795', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46795', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ksmbd: unset the binding mark of a reused connection', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: unset the binding mark of a reused connection\n\nSteve French reported null pointer dereference error from sha256 lib.\ncifs.ko can send session setup requests on reused connection.\nIf reused connection is used for binding session, conn->binding can\nstill remain true and generate_preauth_hash() will not set\nsess->Preauth_HashValue and it will be NULL.\nIt is used as a material to create an encryption key in\nksmbd_gen_smb311_encryptionkey. ->Preauth_HashValue cause null pointer\ndereference error from crypto_shash_update().\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n#PF: supervisor read access in kernel mode\n#PF: error_code(0x0000) - not-present page\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 8 PID: 429254 Comm: kworker/8:39\nHardware name: LENOVO 20MAS08500/20MAS08500, BIOS N2CET69W (1.52 )\nWorkqueue: ksmbd-io handle_ksmbd_work [ksmbd]\nRIP: 0010:lib_sha256_base_do_update.isra.0+0x11e/0x1d0 [sha256_ssse3]\n\n? show_regs+0x6d/0x80\n? __die+0x24/0x80\n? page_fault_oops+0x99/0x1b0\n? do_user_addr_fault+0x2ee/0x6b0\n? exc_page_fault+0x83/0x1b0\n? asm_exc_page_fault+0x27/0x30\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n? lib_sha256_base_do_update.isra.0+0x11e/0x1d0 [sha256_ssse3]\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n_sha256_update+0x77/0xa0 [sha256_ssse3]\nsha256_avx2_update+0x15/0x30 [sha256_ssse3]\ncrypto_shash_update+0x1e/0x40\nhmac_update+0x12/0x20\ncrypto_shash_update+0x1e/0x40\ngenerate_key+0x234/0x380 [ksmbd]\ngenerate_smb3encryptionkey+0x40/0x1c0 [ksmbd]\nksmbd_gen_smb311_encryptionkey+0x72/0xa0 [ksmbd]\nntlm_authenticate.isra.0+0x423/0x5d0 [ksmbd]\nsmb2_sess_setup+0x952/0xaa0 [ksmbd]\n__process_request+0xa3/0x1d0 [ksmbd]\n__handle_ksmbd_work+0x1c4/0x2f0 [ksmbd]\nhandle_ksmbd_work+0x2d/0xa0 [ksmbd]\nprocess_one_work+0x16c/0x350\nworker_thread+0x306/0x440\n? __pfx_worker_thread+0x10/0x10\nkthread+0xef/0x120\n? __pfx_kthread+0x10/0x10\nret_from_fork+0x44/0x70\n? __pfx_kthread+0x10/0x10\nret_from_fork_asm+0x1b/0x30\n', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46795', 'https://git.kernel.org/linus/78c5a6f1f630172b19af4912e755e1da93ef0ab5 (6.11-rc7)', 'https://git.kernel.org/stable/c/41bc256da7e47b679df87c7fc7a5b393052b9cce', 'https://git.kernel.org/stable/c/4c8496f44f5bb5c06cdef5eb130ab259643392a1', 'https://git.kernel.org/stable/c/78c5a6f1f630172b19af4912e755e1da93ef0ab5', 'https://git.kernel.org/stable/c/93d54a4b59c4b3d803d20aa645ab5ca71f3b3b02', 'https://git.kernel.org/stable/c/9914f1bd61d5e838bb1ab15a71076d37a6db65d1', 'https://lore.kernel.org/linux-cve-announce/2024091855-CVE-2024-46795-9908@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46795', 'https://www.cve.org/CVERecord?id=CVE-2024-46795'], 'PublishedDate': '2024-09-18T08:15:06.28Z', 'LastModifiedDate': '2024-09-20T18:21:04.067Z'}, {'VulnerabilityID': 'CVE-2024-46797', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46797', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/qspinlock: Fix deadlock in MCS queue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/qspinlock: Fix deadlock in MCS queue\n\nIf an interrupt occurs in queued_spin_lock_slowpath() after we increment\nqnodesp->count and before node->lock is initialized, another CPU might\nsee stale lock values in get_tail_qnode(). If the stale lock value happens\nto match the lock on that CPU, then we write to the "next" pointer of\nthe wrong qnode. This causes a deadlock as the former CPU, once it becomes\nthe head of the MCS queue, will spin indefinitely until it\'s "next" pointer\nis set by its successor in the queue.\n\nRunning stress-ng on a 16 core (16EC/16VP) shared LPAR, results in\noccasional lockups similar to the following:\n\n $ stress-ng --all 128 --vm-bytes 80% --aggressive \\\n --maximize --oomable --verify --syslog \\\n --metrics --times --timeout 5m\n\n watchdog: CPU 15 Hard LOCKUP\n ......\n NIP [c0000000000b78f4] queued_spin_lock_slowpath+0x1184/0x1490\n LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90\n Call Trace:\n 0xc000002cfffa3bf0 (unreliable)\n _raw_spin_lock+0x6c/0x90\n raw_spin_rq_lock_nested.part.135+0x4c/0xd0\n sched_ttwu_pending+0x60/0x1f0\n __flush_smp_call_function_queue+0x1dc/0x670\n smp_ipi_demux_relaxed+0xa4/0x100\n xive_muxed_ipi_action+0x20/0x40\n __handle_irq_event_percpu+0x80/0x240\n handle_irq_event_percpu+0x2c/0x80\n handle_percpu_irq+0x84/0xd0\n generic_handle_irq+0x54/0x80\n __do_irq+0xac/0x210\n __do_IRQ+0x74/0xd0\n 0x0\n do_IRQ+0x8c/0x170\n hardware_interrupt_common_virt+0x29c/0x2a0\n --- interrupt: 500 at queued_spin_lock_slowpath+0x4b8/0x1490\n ......\n NIP [c0000000000b6c28] queued_spin_lock_slowpath+0x4b8/0x1490\n LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90\n --- interrupt: 500\n 0xc0000029c1a41d00 (unreliable)\n _raw_spin_lock+0x6c/0x90\n futex_wake+0x100/0x260\n do_futex+0x21c/0x2a0\n sys_futex+0x98/0x270\n system_call_exception+0x14c/0x2f0\n system_call_vectored_common+0x15c/0x2ec\n\nThe following code flow illustrates how the deadlock occurs.\nFor the sake of brevity, assume that both locks (A and B) are\ncontended and we call the queued_spin_lock_slowpath() function.\n\n CPU0 CPU1\n ---- ----\n spin_lock_irqsave(A) |\n spin_unlock_irqrestore(A) |\n spin_lock(B) |\n | |\n ▼ |\n id = qnodesp->count++; |\n (Note that nodes[0].lock == A) |\n | |\n ▼ |\n Interrupt |\n (happens before "nodes[0].lock = B") |\n | |\n ▼ |\n spin_lock_irqsave(A) |\n | |\n ▼ |\n id = qnodesp->count++ |\n nodes[1].lock = A |\n | |\n ▼ |\n Tail of MCS queue |\n | spin_lock_irqsave(A)\n ▼ |\n Head of MCS queue ▼\n | CPU0 is previous tail\n ▼ |\n Spin indefinitely ▼\n (until "nodes[1].next != NULL") prev = get_tail_qnode(A, CPU0)\n |\n ▼\n prev == &qnodes[CPU0].nodes[0]\n (as qnodes\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46797', 'https://git.kernel.org/linus/734ad0af3609464f8f93e00b6c0de1e112f44559 (6.11-rc7)', 'https://git.kernel.org/stable/c/734ad0af3609464f8f93e00b6c0de1e112f44559', 'https://git.kernel.org/stable/c/d84ab6661e8d09092de9b034b016515ef9b66085', 'https://git.kernel.org/stable/c/f06af737e4be28c0e926dc25d5f0a111da4e2987', 'https://lore.kernel.org/linux-cve-announce/2024091856-CVE-2024-46797-9174@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46797', 'https://www.cve.org/CVERecord?id=CVE-2024-46797'], 'PublishedDate': '2024-09-18T08:15:06.403Z', 'LastModifiedDate': '2024-09-29T15:15:15.837Z'}, {'VulnerabilityID': 'CVE-2024-46798', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46798', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: Fix UAF for snd_soc_pcm_runtime object\n\nWhen using kernel with the following extra config,\n\n - CONFIG_KASAN=y\n - CONFIG_KASAN_GENERIC=y\n - CONFIG_KASAN_INLINE=y\n - CONFIG_KASAN_VMALLOC=y\n - CONFIG_FRAME_WARN=4096\n\nkernel detects that snd_pcm_suspend_all() access a freed\n'snd_soc_pcm_runtime' object when the system is suspended, which\nleads to a use-after-free bug:\n\n[ 52.047746] BUG: KASAN: use-after-free in snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047765] Read of size 1 at addr ffff0000b9434d50 by task systemd-sleep/2330\n\n[ 52.047785] Call trace:\n[ 52.047787] dump_backtrace+0x0/0x3c0\n[ 52.047794] show_stack+0x34/0x50\n[ 52.047797] dump_stack_lvl+0x68/0x8c\n[ 52.047802] print_address_description.constprop.0+0x74/0x2c0\n[ 52.047809] kasan_report+0x210/0x230\n[ 52.047815] __asan_report_load1_noabort+0x3c/0x50\n[ 52.047820] snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047824] snd_soc_suspend+0x19c/0x4e0\n\nThe snd_pcm_sync_stop() has a NULL check on 'substream->runtime' before\nmaking any access. So we need to always set 'substream->runtime' to NULL\neverytime we kfree() it.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46798', 'https://git.kernel.org/linus/b4a90b543d9f62d3ac34ec1ab97fc5334b048565 (6.11-rc7)', 'https://git.kernel.org/stable/c/3033ed903b4f28b5e1ab66042084fbc2c48f8624', 'https://git.kernel.org/stable/c/5d13afd021eb43868fe03cef6da34ad08831ad6d', 'https://git.kernel.org/stable/c/6a14fad8be178df6c4589667efec1789a3307b4e', 'https://git.kernel.org/stable/c/8ca21e7a27c66b95a4b215edc8e45e5d66679f9f', 'https://git.kernel.org/stable/c/993b60c7f93fa1d8ff296b58f646a867e945ae89', 'https://git.kernel.org/stable/c/b4a90b543d9f62d3ac34ec1ab97fc5334b048565', 'https://git.kernel.org/stable/c/fe5046ca91d631ec432eee3bdb1f1c49b09c8b5e', 'https://lore.kernel.org/linux-cve-announce/2024091856-CVE-2024-46798-ce16@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46798', 'https://www.cve.org/CVERecord?id=CVE-2024-46798'], 'PublishedDate': '2024-09-18T08:15:06.463Z', 'LastModifiedDate': '2024-09-20T18:17:50.763Z'}, {'VulnerabilityID': 'CVE-2024-46800', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46800', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sch/netem: fix use after free in netem_dequeue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsch/netem: fix use after free in netem_dequeue\n\nIf netem_dequeue() enqueues packet to inner qdisc and that qdisc\nreturns __NET_XMIT_STOLEN. The packet is dropped but\nqdisc_tree_reduce_backlog() is not called to update the parent\'s\nq.qlen, leading to the similar use-after-free as Commit\ne04991a48dbaf382 ("netem: fix return value if duplicate enqueue\nfails")\n\nCommands to trigger KASAN UaF:\n\nip link add type dummy\nip link set lo up\nip link set dummy0 up\ntc qdisc add dev lo parent root handle 1: drr\ntc filter add dev lo parent 1: basic classid 1:1\ntc class add dev lo classid 1:1 drr\ntc qdisc add dev lo parent 1:1 handle 2: netem\ntc qdisc add dev lo parent 2: handle 3: drr\ntc filter add dev lo parent 3: basic classid 3:1 action mirred egress\nredirect dev dummy0\ntc class add dev lo classid 3:1 drr\nping -c1 -W0.01 localhost # Trigger bug\ntc class del dev lo classid 1:1\ntc class add dev lo classid 1:1 drr\nping -c1 -W0.01 localhost # UaF', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46800', 'https://git.kernel.org/linus/3b3a2a9c6349e25a025d2330f479bc33a6ccb54a (6.11-rc7)', 'https://git.kernel.org/stable/c/14f91ab8d391f249b845916820a56f42cf747241', 'https://git.kernel.org/stable/c/295ad5afd9efc5f67b86c64fce28fb94e26dc4c9', 'https://git.kernel.org/stable/c/32008ab989ddcff1a485fa2b4906234c25dc5cd6', 'https://git.kernel.org/stable/c/3b3a2a9c6349e25a025d2330f479bc33a6ccb54a', 'https://git.kernel.org/stable/c/98c75d76187944296068d685dfd8a1e9fd8c4fdc', 'https://git.kernel.org/stable/c/db2c235682913a63054e741fe4e19645fdf2d68e', 'https://git.kernel.org/stable/c/dde33a9d0b80aae0c69594d1f462515d7ff1cb3d', 'https://git.kernel.org/stable/c/f0bddb4de043399f16d1969dad5ee5b984a64e7b', 'https://lore.kernel.org/linux-cve-announce/2024091857-CVE-2024-46800-0f62@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46800', 'https://www.cve.org/CVERecord?id=CVE-2024-46800'], 'PublishedDate': '2024-09-18T08:15:06.573Z', 'LastModifiedDate': '2024-09-20T17:18:55.26Z'}, {'VulnerabilityID': 'CVE-2024-46802', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46802', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: added NULL check at start of dc_validate_stream', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: added NULL check at start of dc_validate_stream\n\n[Why]\nprevent invalid memory access\n\n[How]\ncheck if dc and stream are NULL', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46802', 'https://git.kernel.org/linus/26c56049cc4f1705b498df013949427692a4b0d5 (6.11-rc1)', 'https://git.kernel.org/stable/c/154a50bf4221a6a6ccf88d565b8184da7c40a2dd', 'https://git.kernel.org/stable/c/26c56049cc4f1705b498df013949427692a4b0d5', 'https://git.kernel.org/stable/c/356fcce9cdbfe338a275e9e1836adfdd7f5c52a9', 'https://git.kernel.org/stable/c/6bf920193ba1853bad780bba565a789246d9003c', 'https://lore.kernel.org/linux-cve-announce/2024092706-CVE-2024-46802-c5e1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46802', 'https://www.cve.org/CVERecord?id=CVE-2024-46802'], 'PublishedDate': '2024-09-27T13:15:13.483Z', 'LastModifiedDate': '2024-10-07T14:21:55.687Z'}, {'VulnerabilityID': 'CVE-2024-46803', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46803', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdkfd: Check debug trap enable before write dbg_ev_file', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check debug trap enable before write dbg_ev_file\n\nIn interrupt context, write dbg_ev_file will be run by work queue. It\nwill cause write dbg_ev_file execution after debug_trap_disable, which\nwill cause NULL pointer access.\nv2: cancel work "debug_event_workarea" before set dbg_ev_file as NULL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46803', 'https://git.kernel.org/linus/547033b593063eb85bfdf9b25a5f1b8fd1911be2 (6.11-rc1)', 'https://git.kernel.org/stable/c/547033b593063eb85bfdf9b25a5f1b8fd1911be2', 'https://git.kernel.org/stable/c/820dcbd38a77bd5fdc4236d521c1c122841227d0', 'https://git.kernel.org/stable/c/e6ea3b8fe398915338147fe54dd2db8155fdafd8', 'https://lore.kernel.org/linux-cve-announce/2024092708-CVE-2024-46803-689b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46803', 'https://www.cve.org/CVERecord?id=CVE-2024-46803'], 'PublishedDate': '2024-09-27T13:15:13.57Z', 'LastModifiedDate': '2024-10-04T17:45:16.867Z'}, {'VulnerabilityID': 'CVE-2024-46804', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46804', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add array index check for hdcp ddc access', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add array index check for hdcp ddc access\n\n[Why]\nCoverity reports OVERRUN warning. Do not check if array\nindex valid.\n\n[How]\nCheck msg_id valid and valid array index.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46804', 'https://git.kernel.org/linus/4e70c0f5251c25885c31ee84a31f99a01f7cf50e (6.11-rc1)', 'https://git.kernel.org/stable/c/0ee4387c5a4b57ec733c3fb4365188d5979cd9c7', 'https://git.kernel.org/stable/c/2a63c90c7a90ab2bd23deebc2814fc5b52abf6d2', 'https://git.kernel.org/stable/c/4e70c0f5251c25885c31ee84a31f99a01f7cf50e', 'https://git.kernel.org/stable/c/8b5ccf3d011969417be653b5a145c72dbd30472c', 'https://git.kernel.org/stable/c/a3b5ee22a9d3a30045191da5678ca8451ebaea30', 'https://git.kernel.org/stable/c/f338f99f6a04d03c802087d82a83561cbd5bdc99', 'https://lore.kernel.org/linux-cve-announce/2024092708-CVE-2024-46804-c90d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46804', 'https://www.cve.org/CVERecord?id=CVE-2024-46804'], 'PublishedDate': '2024-09-27T13:15:13.637Z', 'LastModifiedDate': '2024-10-04T17:51:43.73Z'}, {'VulnerabilityID': 'CVE-2024-46805', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46805', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: fix the waring dereferencing hive', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix the waring dereferencing hive\n\nCheck the amdgpu_hive_info *hive that maybe is NULL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46805', 'https://git.kernel.org/linus/1940708ccf5aff76de4e0b399f99267c93a89193 (6.11-rc1)', 'https://git.kernel.org/stable/c/01cd55b971131b07b7ff8d622fa93bb4f8be07df', 'https://git.kernel.org/stable/c/1940708ccf5aff76de4e0b399f99267c93a89193', 'https://git.kernel.org/stable/c/4ab720b6aa1ef5e71db1e534b5b45c80ac4ec58a', 'https://git.kernel.org/stable/c/d3f927ef0607b3c8c3f79ab6d9a4ebead3e35f4c', 'https://git.kernel.org/stable/c/f20d1d5cbb39802f68be24458861094f3e66f356', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46805-b06a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46805', 'https://www.cve.org/CVERecord?id=CVE-2024-46805'], 'PublishedDate': '2024-09-27T13:15:13.707Z', 'LastModifiedDate': '2024-10-02T12:58:59.767Z'}, {'VulnerabilityID': 'CVE-2024-46806', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46806', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix the warning division or modulo by zero', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the warning division or modulo by zero\n\nChecks the partition mode and returns an error for an invalid mode.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46806', 'https://git.kernel.org/linus/1a00f2ac82d6bc6689388c7edcd2a4bd82664f3c (6.11-rc1)', 'https://git.kernel.org/stable/c/1a00f2ac82d6bc6689388c7edcd2a4bd82664f3c', 'https://git.kernel.org/stable/c/a01618adcba78c6bd6c4557a4a5e32f58b658cd1', 'https://git.kernel.org/stable/c/d116bb921e8b104f45d1f30a473ea99ef4262b9a', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46806-2cc7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46806', 'https://www.cve.org/CVERecord?id=CVE-2024-46806'], 'PublishedDate': '2024-09-27T13:15:13.773Z', 'LastModifiedDate': '2024-10-02T13:17:04.64Z'}, {'VulnerabilityID': 'CVE-2024-46807', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46807', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/amdgpu: Check tbo resource pointer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/amdgpu: Check tbo resource pointer\n\nValidate tbo resource pointer, skip if NULL', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46807', 'https://git.kernel.org/linus/6cd2b872643bb29bba01a8ac739138db7bd79007 (6.11-rc1)', 'https://git.kernel.org/stable/c/2be1eb6304d9623ba21dd6f3e68ffb753a759635', 'https://git.kernel.org/stable/c/4dfec5f5501a27e0a0da00e136d65ef9011ded4c', 'https://git.kernel.org/stable/c/6cd2b872643bb29bba01a8ac739138db7bd79007', 'https://git.kernel.org/stable/c/e55e3904ffeaff81715256a711b1a61f4ad5258a', 'https://git.kernel.org/stable/c/e8765364d4f3aaf88c7abe0a4fc99089d059ab49', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46807-b78e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46807', 'https://www.cve.org/CVERecord?id=CVE-2024-46807'], 'PublishedDate': '2024-09-27T13:15:13.84Z', 'LastModifiedDate': '2024-10-04T17:40:08.083Z'}, {'VulnerabilityID': 'CVE-2024-46808', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46808', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range\n\n[Why & How]\nASSERT if return NULL from kcalloc.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46808', 'https://git.kernel.org/linus/5524fa301ba649f8cf00848f91468e0ba7e4f24c (6.11-rc1)', 'https://git.kernel.org/stable/c/5524fa301ba649f8cf00848f91468e0ba7e4f24c', 'https://git.kernel.org/stable/c/ca0b0b0a22306f2e51105ac48f4a09c2fbbb504e', 'https://lore.kernel.org/linux-cve-announce/2024092709-CVE-2024-46808-8886@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46808', 'https://www.cve.org/CVERecord?id=CVE-2024-46808'], 'PublishedDate': '2024-09-27T13:15:13.907Z', 'LastModifiedDate': '2024-10-02T14:23:39.863Z'}, {'VulnerabilityID': 'CVE-2024-46809', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46809', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check BIOS images before it is used', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check BIOS images before it is used\n\nBIOS images may fail to load and null checks are added before they are\nused.\n\nThis fixes 6 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46809', 'https://git.kernel.org/linus/8b0ddf19cca2a352b2a7e01d99d3ba949a99c84c (6.11-rc1)', 'https://git.kernel.org/stable/c/8b0ddf19cca2a352b2a7e01d99d3ba949a99c84c', 'https://git.kernel.org/stable/c/e46b70a7cfed71cb84e985c785c39c16df5c28cb', 'https://git.kernel.org/stable/c/e50bec62acaeec03afc6fa5dfb2426e52d049cf5', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46809-5b37@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46809', 'https://www.cve.org/CVERecord?id=CVE-2024-46809'], 'PublishedDate': '2024-09-27T13:15:13.973Z', 'LastModifiedDate': '2024-10-04T17:33:33.753Z'}, {'VulnerabilityID': 'CVE-2024-46810', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46810', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ\n\nMake sure the connector is fully initialized before signalling any\nHPD events via drm_kms_helper_hotplug_event(), otherwise this may\nlead to NULL pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46810', 'https://git.kernel.org/linus/162e48cb1d84c2c966b649b8ac5c9d4f75f6d44f (6.11-rc1)', 'https://git.kernel.org/stable/c/162e48cb1d84c2c966b649b8ac5c9d4f75f6d44f', 'https://git.kernel.org/stable/c/1fb13693953737783b424aa4712f0a27a9eaf5a8', 'https://git.kernel.org/stable/c/9d567126474e68f959b2c2543c375f3bb32e948a', 'https://git.kernel.org/stable/c/adc5674c23b8191e596ed0dbaa9600265ac896a8', 'https://git.kernel.org/stable/c/e1b121f21bbc56a6ae035aa5b77daac62bfb9be5', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46810-2eb3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46810', 'https://www.cve.org/CVERecord?id=CVE-2024-46810'], 'PublishedDate': '2024-09-27T13:15:14.037Z', 'LastModifiedDate': '2024-10-04T17:43:04.277Z'}, {'VulnerabilityID': 'CVE-2024-46811', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46811', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box\n\n[Why]\nCoverity reports OVERRUN warning. soc.num_states could\nbe 40. But array range of bw_params->clk_table.entries is 8.\n\n[How]\nAssert if soc.num_states greater than 8.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46811', 'https://git.kernel.org/linus/188fd1616ec43033cedbe343b6579e9921e2d898 (6.11-rc1)', 'https://git.kernel.org/stable/c/188fd1616ec43033cedbe343b6579e9921e2d898', 'https://git.kernel.org/stable/c/4003bac784380fed1f94f197350567eaa73a409d', 'https://git.kernel.org/stable/c/aba188d6f4ebaf52acf13f204db2bd2c22072504', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46811-f01c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46811', 'https://www.cve.org/CVERecord?id=CVE-2024-46811'], 'PublishedDate': '2024-09-27T13:15:14.107Z', 'LastModifiedDate': '2024-10-07T14:24:56.86Z'}, {'VulnerabilityID': 'CVE-2024-46812', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46812', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration\n\n[Why]\nCoverity reports Memory - illegal accesses.\n\n[How]\nSkip inactive planes.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46812', 'https://git.kernel.org/linus/a54f7e866cc73a4cb71b8b24bb568ba35c8969df (6.11-rc1)', 'https://git.kernel.org/stable/c/3300a039caf850376bc3416c808cd8879da412bb', 'https://git.kernel.org/stable/c/8406158a546441b73f0b216aedacbf9a1e5748fb', 'https://git.kernel.org/stable/c/a54f7e866cc73a4cb71b8b24bb568ba35c8969df', 'https://git.kernel.org/stable/c/ee9d6df6d9172917d9ddbd948bb882652d5ecd29', 'https://lore.kernel.org/linux-cve-announce/2024092710-CVE-2024-46812-5954@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46812', 'https://www.cve.org/CVERecord?id=CVE-2024-46812'], 'PublishedDate': '2024-09-27T13:15:14.163Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46813', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46813', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check link_index before accessing dc->links[]', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check link_index before accessing dc->links[]\n\n[WHY & HOW]\ndc->links[] has max size of MAX_LINKS and NULL is return when trying to\naccess with out-of-bound index.\n\nThis fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46813', 'https://git.kernel.org/linus/8aa2864044b9d13e95fe224f32e808afbf79ecdf (6.11-rc1)', 'https://git.kernel.org/stable/c/8aa2864044b9d13e95fe224f32e808afbf79ecdf', 'https://git.kernel.org/stable/c/ac04759b4a002969cf0f1384f1b8bb2001cfa782', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46813-5eb9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46813', 'https://www.cve.org/CVERecord?id=CVE-2024-46813'], 'PublishedDate': '2024-09-27T13:15:14.23Z', 'LastModifiedDate': '2024-10-04T17:38:17.74Z'}, {'VulnerabilityID': 'CVE-2024-46814', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46814', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check msg_id before processing transcation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check msg_id before processing transcation\n\n[WHY & HOW]\nHDCP_MESSAGE_ID_INVALID (-1) is not a valid msg_id nor is it a valid\narray index, and it needs checking before used.\n\nThis fixes 4 OVERRUN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46814', 'https://git.kernel.org/linus/fa71face755e27dc44bc296416ebdf2c67163316 (6.11-rc1)', 'https://git.kernel.org/stable/c/0147505f08220c89b3a9c90eb608191276e263a8', 'https://git.kernel.org/stable/c/6590643c5de74098d27933b7d224d5ac065d7755', 'https://git.kernel.org/stable/c/916083054670060023d3f8a8ace895d710e268f4', 'https://git.kernel.org/stable/c/cb63090a17d3abb87f132851fa3711281249b7d2', 'https://git.kernel.org/stable/c/fa71face755e27dc44bc296416ebdf2c67163316', 'https://git.kernel.org/stable/c/fe63daf7b10253b0faaa60c55d6153cd276927aa', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46814-5021@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46814', 'https://www.cve.org/CVERecord?id=CVE-2024-46814'], 'PublishedDate': '2024-09-27T13:15:14.297Z', 'LastModifiedDate': '2024-10-04T17:27:47.45Z'}, {'VulnerabilityID': 'CVE-2024-46815', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46815', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]\n\n[WHY & HOW]\nnum_valid_sets needs to be checked to avoid a negative index when\naccessing reader_wm_sets[num_valid_sets - 1].\n\nThis fixes an OVERRUN issue reported by Coverity.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46815', 'https://git.kernel.org/linus/b38a4815f79b87efb196cd5121579fc51e29a7fb (6.11-rc1)', 'https://git.kernel.org/stable/c/21f9cb44f8c60bf6c26487d428b1a09ad3e8aebf', 'https://git.kernel.org/stable/c/6a4a08e45e614cfa7a56498cdfaeb7fae2f07fa0', 'https://git.kernel.org/stable/c/7c47dd2e92341f2989ab73dbed07f8894593ad7b', 'https://git.kernel.org/stable/c/a72d4996409569027b4609414a14a87679b12267', 'https://git.kernel.org/stable/c/b36e9b3104c4ba0f2f5dd083dcf6159cb316c996', 'https://git.kernel.org/stable/c/b38a4815f79b87efb196cd5121579fc51e29a7fb', 'https://git.kernel.org/stable/c/c4a7f7c0062fe2c73f70bb7e335199e25bd71492', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46815-fce2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46815', 'https://www.cve.org/CVERecord?id=CVE-2024-46815'], 'PublishedDate': '2024-09-27T13:15:14.37Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46816', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46816', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links\n\n[Why]\nCoverity report OVERRUN warning. There are\nonly max_links elements within dc->links. link\ncount could up to AMDGPU_DM_MAX_DISPLAY_INDEX 31.\n\n[How]\nMake sure link count less than max_links.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46816', 'https://git.kernel.org/linus/cf8b16857db702ceb8d52f9219a4613363e2b1cf (6.11-rc1)', 'https://git.kernel.org/stable/c/36c39a8dcce210649f2f45f252abaa09fcc1ae87', 'https://git.kernel.org/stable/c/cf8b16857db702ceb8d52f9219a4613363e2b1cf', 'https://lore.kernel.org/linux-cve-announce/2024092711-CVE-2024-46816-0526@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46816', 'https://www.cve.org/CVERecord?id=CVE-2024-46816'], 'PublishedDate': '2024-09-27T13:15:14.433Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46817', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46817', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6\n\n[Why]\nCoverity reports OVERRUN warning. Should abort amdgpu_dm\ninitialize.\n\n[How]\nReturn failure to amdgpu_dm_init.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46817', 'https://git.kernel.org/linus/84723eb6068c50610c5c0893980d230d7afa2105 (6.11-rc1)', 'https://git.kernel.org/stable/c/21bbb39863f10f5fb4bf772d15b07d5d13590e9d', 'https://git.kernel.org/stable/c/28b515c458aa9c92bfcb99884c94713a5f471cea', 'https://git.kernel.org/stable/c/754321ed63f0a4a31252ca72e0bd89a9e1888018', 'https://git.kernel.org/stable/c/84723eb6068c50610c5c0893980d230d7afa2105', 'https://git.kernel.org/stable/c/94cb77700fa4ae6200486bfa0ba2ac547534afd2', 'https://git.kernel.org/stable/c/d398c74c881dee695f6eb6138c9891644e1c3d9d', 'https://git.kernel.org/stable/c/d619b91d3c4af60ac422f1763ce53d721fb91262', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46817-7a2c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46817', 'https://www.cve.org/CVERecord?id=CVE-2024-46817'], 'PublishedDate': '2024-09-27T13:15:14.493Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46818', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46818', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check gpio_id before used as array index', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check gpio_id before used as array index\n\n[WHY & HOW]\nGPIO_ID_UNKNOWN (-1) is not a valid value for array index and therefore\nshould be checked in advance.\n\nThis fixes 5 OVERRUN issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46818', 'https://git.kernel.org/linus/2a5626eeb3b5eec7a36886f9556113dd93ec8ed6 (6.11-rc1)', 'https://git.kernel.org/stable/c/0184cca30cad74d88f5c875d4e26999e26325700', 'https://git.kernel.org/stable/c/08e7755f754e3d2cef7d3a7da538d33526bd6f7c', 'https://git.kernel.org/stable/c/276e3fd93e3beb5894eb1cc8480f9f417d51524d', 'https://git.kernel.org/stable/c/2a5626eeb3b5eec7a36886f9556113dd93ec8ed6', 'https://git.kernel.org/stable/c/3d4198ab612ad48f73383ad3bb5663e6f0cdf406', 'https://git.kernel.org/stable/c/40c2e8bc117cab8bca8814735f28a8b121654a84', 'https://git.kernel.org/stable/c/8520fdc8ecc38f240a8e9e7af89cca6739c3e790', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46818-8d41@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46818', 'https://www.cve.org/CVERecord?id=CVE-2024-46818'], 'PublishedDate': '2024-09-27T13:15:14.563Z', 'LastModifiedDate': '2024-10-04T17:18:36.613Z'}, {'VulnerabilityID': 'CVE-2024-46819', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46819', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: the warning dereferencing obj for nbio_v7_4', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: the warning dereferencing obj for nbio_v7_4\n\nif ras_manager obj null, don't print NBIO err data", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46819', 'https://git.kernel.org/linus/d190b459b2a4304307c3468ed97477b808381011 (6.11-rc1)', 'https://git.kernel.org/stable/c/130c2dc75c8c40acc3c96ededea6af80e03c14b8', 'https://git.kernel.org/stable/c/614564a5b28983de53b23a358ebe6c483a2aa21e', 'https://git.kernel.org/stable/c/70e8ec21fcb8c51446899d3bfe416b31adfa3661', 'https://git.kernel.org/stable/c/7d265772e44d403071a2b573eac0db60250b1c21', 'https://git.kernel.org/stable/c/d04ded1e73f1dcf19a71ec8b9cda3faa7acd8828', 'https://git.kernel.org/stable/c/d190b459b2a4304307c3468ed97477b808381011', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46819-d958@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46819', 'https://www.cve.org/CVERecord?id=CVE-2024-46819'], 'PublishedDate': '2024-09-27T13:15:14.64Z', 'LastModifiedDate': '2024-10-04T17:11:00.57Z'}, {'VulnerabilityID': 'CVE-2024-46820', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46820', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/vcn: remove irq disabling in vcn 5 suspend', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: remove irq disabling in vcn 5 suspend\n\nWe do not directly enable/disable VCN IRQ in vcn 5.0.0.\nAnd we do not handle the IRQ state as well. So the calls to\ndisable IRQ and set state are removed. This effectively gets\nrid of the warining of\n "WARN_ON(!amdgpu_irq_enabled(adev, src, type))"\nin amdgpu_irq_put().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46820', 'https://git.kernel.org/linus/10fe1a79cd1bff3048e13120e93c02f8ecd05e9d (6.11-rc1)', 'https://git.kernel.org/stable/c/10fe1a79cd1bff3048e13120e93c02f8ecd05e9d', 'https://git.kernel.org/stable/c/aa92264ba6fd4fb570002f69762634221316e7ae', 'https://lore.kernel.org/linux-cve-announce/2024092712-CVE-2024-46820-6405@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46820', 'https://www.cve.org/CVERecord?id=CVE-2024-46820'], 'PublishedDate': '2024-09-27T13:15:14.707Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46821', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46821', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: Fix negative array index read', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Fix negative array index read\n\nAvoid using the negative values\nfor clk_idex as an index into an array pptable->DpmDescriptor.\n\nV2: fix clk_index return check (Tim Huang)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46821', 'https://git.kernel.org/linus/c8c19ebf7c0b202a6a2d37a52ca112432723db5f (6.11-rc1)', 'https://git.kernel.org/stable/c/06a3810010b525b9958424e344f0c25b09e128fa', 'https://git.kernel.org/stable/c/4711b1347cb9f0c3083da6d87c624d75f9bd1d50', 'https://git.kernel.org/stable/c/60f4a4bc3329e5cb8c4df0cc961f0d5ffd96e22d', 'https://git.kernel.org/stable/c/c8c19ebf7c0b202a6a2d37a52ca112432723db5f', 'https://lore.kernel.org/linux-cve-announce/2024092713-CVE-2024-46821-a13a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46821', 'https://www.cve.org/CVERecord?id=CVE-2024-46821'], 'PublishedDate': '2024-09-27T13:15:14.767Z', 'LastModifiedDate': '2024-10-04T17:06:43.573Z'}, {'VulnerabilityID': 'CVE-2024-46822', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46822', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry\n\nIn a review discussion of the changes to support vCPU hotplug where\na check was added on the GICC being enabled if was online, it was\nnoted that there is need to map back to the cpu and use that to index\ninto a cpumask. As such, a valid ID is needed.\n\nIf an MPIDR check fails in acpi_map_gic_cpu_interface() it is possible\nfor the entry in cpu_madt_gicc[cpu] == NULL. This function would\nthen cause a NULL pointer dereference. Whilst a path to trigger\nthis has not been established, harden this caller against the\npossibility.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46822', 'https://git.kernel.org/linus/2488444274c70038eb6b686cba5f1ce48ebb9cdd (6.11-rc1)', 'https://git.kernel.org/stable/c/2488444274c70038eb6b686cba5f1ce48ebb9cdd', 'https://git.kernel.org/stable/c/40cae0df42e5e7f7a1c0f32deed9c4027c1ba94e', 'https://git.kernel.org/stable/c/4c3b21204abb4fa3ab310fbbb5cf7f0e85f3a1bc', 'https://git.kernel.org/stable/c/62ca6d3a905b4c40cd942f3cc645a6718f8bc7e7', 'https://git.kernel.org/stable/c/945be49f4e832a9184c313fdf8917475438a795b', 'https://git.kernel.org/stable/c/bc7fbb37e3d2df59336eadbd6a56be632e3c7df7', 'https://git.kernel.org/stable/c/f57769ff6fa7f97f1296965f20e8a2bb3ee9fd0f', 'https://lore.kernel.org/linux-cve-announce/2024092749-CVE-2024-46822-b901@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46822', 'https://www.cve.org/CVERecord?id=CVE-2024-46822'], 'PublishedDate': '2024-09-27T13:15:14.83Z', 'LastModifiedDate': '2024-10-02T14:24:01.757Z'}, {'VulnerabilityID': 'CVE-2024-46823', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46823', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kunit/overflow: Fix UB in overflow_allocation_test', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit/overflow: Fix UB in overflow_allocation_test\n\nThe 'device_name' array doesn't exist out of the\n'overflow_allocation_test' function scope. However, it is being used as\na driver name when calling 'kunit_driver_create' from\n'kunit_device_register'. It produces the kernel panic with KASAN\nenabled.\n\nSince this variable is used in one place only, remove it and pass the\ndevice name into kunit_device_register directly as an ascii string.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46823', 'https://git.kernel.org/linus/92e9bac18124682c4b99ede9ee3bcdd68f121e92 (6.11-rc4)', 'https://git.kernel.org/stable/c/92e9bac18124682c4b99ede9ee3bcdd68f121e92', 'https://git.kernel.org/stable/c/d1207f07decc66546a7fa463d2f335a856c986ef', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46823-b19e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46823', 'https://www.cve.org/CVERecord?id=CVE-2024-46823'], 'PublishedDate': '2024-09-27T13:15:14.897Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46824', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46824', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iommufd: Require drivers to supply the cache_invalidate_user ops', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Require drivers to supply the cache_invalidate_user ops\n\nIf drivers don't do this then iommufd will oops invalidation ioctls with\nsomething like:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Mem abort info:\n ESR = 0x0000000086000004\n EC = 0x21: IABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\n user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101059000\n [0000000000000000] pgd=0000000000000000, p4d=0000000000000000\n Internal error: Oops: 0000000086000004 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 2 PID: 371 Comm: qemu-system-aar Not tainted 6.8.0-rc7-gde77230ac23a #9\n Hardware name: linux,dummy-virt (DT)\n pstate: 81400809 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=-c)\n pc : 0x0\n lr : iommufd_hwpt_invalidate+0xa4/0x204\n sp : ffff800080f3bcc0\n x29: ffff800080f3bcf0 x28: ffff0000c369b300 x27: 0000000000000000\n x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n x23: 0000000000000000 x22: 00000000c1e334a0 x21: ffff0000c1e334a0\n x20: ffff800080f3bd38 x19: ffff800080f3bd58 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 0000ffff8240d6d8\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n x8 : 0000001000000002 x7 : 0000fffeac1ec950 x6 : 0000000000000000\n x5 : ffff800080f3bd78 x4 : 0000000000000003 x3 : 0000000000000002\n x2 : 0000000000000000 x1 : ffff800080f3bcc8 x0 : ffff0000c6034d80\n Call trace:\n 0x0\n iommufd_fops_ioctl+0x154/0x274\n __arm64_sys_ioctl+0xac/0xf0\n invoke_syscall+0x48/0x110\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x34/0xb4\n el0t_64_sync_handler+0x120/0x12c\n el0t_64_sync+0x190/0x194\n\nAll existing drivers implement this op for nesting, this is mostly a\nbisection aid.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46824', 'https://git.kernel.org/linus/a11dda723c6493bb1853bbc61c093377f96e2d47 (6.11-rc1)', 'https://git.kernel.org/stable/c/89827a4de802765b1ebb401fc1e73a90108c7520', 'https://git.kernel.org/stable/c/a11dda723c6493bb1853bbc61c093377f96e2d47', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46824-03d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46824', 'https://www.cve.org/CVERecord?id=CVE-2024-46824'], 'PublishedDate': '2024-09-27T13:15:14.96Z', 'LastModifiedDate': '2024-10-02T14:29:08.417Z'}, {'VulnerabilityID': 'CVE-2024-46825', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46825', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check\n\nThe lookup function iwl_mvm_rcu_fw_link_id_to_link_conf() is\nnormally called with input from the firmware, so it should use\nIWL_FW_CHECK() instead of WARN_ON().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46825', 'https://git.kernel.org/linus/9215152677d4b321801a92b06f6d5248b2b4465f (6.11-rc1)', 'https://git.kernel.org/stable/c/3cca098c91391b3fa48142bfda57048b985c87f6', 'https://git.kernel.org/stable/c/415f3634d53c7fb4cf07d2f5a0be7f2e15e6da33', 'https://git.kernel.org/stable/c/9215152677d4b321801a92b06f6d5248b2b4465f', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46825-a5aa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46825', 'https://www.cve.org/CVERecord?id=CVE-2024-46825'], 'PublishedDate': '2024-09-27T13:15:15.027Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46826', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46826', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ELF: fix kernel.randomize_va_space double read', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nELF: fix kernel.randomize_va_space double read\n\nELF loader uses "randomize_va_space" twice. It is sysctl and can change\nat any moment, so 2 loads could see 2 different values in theory with\nunpredictable consequences.\n\nIssue exactly one load for consistent value across one exec.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46826', 'https://git.kernel.org/linus/2a97388a807b6ab5538aa8f8537b2463c6988bd2 (6.11-rc1)', 'https://git.kernel.org/stable/c/1cf8cd80903073440b6ea055811d04edd24fe4f7', 'https://git.kernel.org/stable/c/1f81d51141a234ad0a3874b4d185dc27a521cd27', 'https://git.kernel.org/stable/c/2a97388a807b6ab5538aa8f8537b2463c6988bd2', 'https://git.kernel.org/stable/c/53f17409abf61f66b6f05aff795e938e5ba811d1', 'https://lore.kernel.org/linux-cve-announce/2024092750-CVE-2024-46826-7b80@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46826', 'https://www.cve.org/CVERecord?id=CVE-2024-46826'], 'PublishedDate': '2024-09-27T13:15:15.087Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46827', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46827', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: fix firmware crash due to invalid peer nss', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix firmware crash due to invalid peer nss\n\nCurrently, if the access point receives an association\nrequest containing an Extended HE Capabilities Information\nElement with an invalid MCS-NSS, it triggers a firmware\ncrash.\n\nThis issue arises when EHT-PHY capabilities shows support\nfor a bandwidth and MCS-NSS set for that particular\nbandwidth is filled by zeros and due to this, driver obtains\npeer_nss as 0 and sending this value to firmware causes\ncrash.\n\nAddress this issue by implementing a validation step for\nthe peer_nss value before passing it to the firmware. If\nthe value is greater than zero, proceed with forwarding\nit to the firmware. However, if the value is invalid,\nreject the association request to prevent potential\nfirmware crashes.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46827', 'https://git.kernel.org/linus/db163a463bb93cd3e37e1e7b10b9726fb6f95857 (6.11-rc1)', 'https://git.kernel.org/stable/c/25a15f80253a7c8776e4e4880d797d20ec864154', 'https://git.kernel.org/stable/c/838c2cfdb6be7d7d8c06c711edf893eb34ca2e7c', 'https://git.kernel.org/stable/c/db163a463bb93cd3e37e1e7b10b9726fb6f95857', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46827-0300@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46827', 'https://www.cve.org/CVERecord?id=CVE-2024-46827'], 'PublishedDate': '2024-09-27T13:15:15.153Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46828', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46828', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched: sch_cake: fix bulk flow accounting logic for host fairness', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsched: sch_cake: fix bulk flow accounting logic for host fairness\n\nIn sch_cake, we keep track of the count of active bulk flows per host,\nwhen running in dst/src host fairness mode, which is used as the\nround-robin weight when iterating through flows. The count of active\nbulk flows is updated whenever a flow changes state.\n\nThis has a peculiar interaction with the hash collision handling: when a\nhash collision occurs (after the set-associative hashing), the state of\nthe hash bucket is simply updated to match the new packet that collided,\nand if host fairness is enabled, that also means assigning new per-host\nstate to the flow. For this reason, the bulk flow counters of the\nhost(s) assigned to the flow are decremented, before new state is\nassigned (and the counters, which may not belong to the same host\nanymore, are incremented again).\n\nBack when this code was introduced, the host fairness mode was always\nenabled, so the decrement was unconditional. When the configuration\nflags were introduced the *increment* was made conditional, but\nthe *decrement* was not. Which of course can lead to a spurious\ndecrement (and associated wrap-around to U16_MAX).\n\nAFAICT, when host fairness is disabled, the decrement and wrap-around\nhappens as soon as a hash collision occurs (which is not that common in\nitself, due to the set-associative hashing). However, in most cases this\nis harmless, as the value is only used when host fairness mode is\nenabled. So in order to trigger an array overflow, sch_cake has to first\nbe configured with host fairness disabled, and while running in this\nmode, a hash collision has to occur to cause the overflow. Then, the\nqdisc has to be reconfigured to enable host fairness, which leads to the\narray out-of-bounds because the wrapped-around value is retained and\nused as an array index. It seems that syzbot managed to trigger this,\nwhich is quite impressive in its own right.\n\nThis patch fixes the issue by introducing the same conditional check on\ndecrement as is used on increment.\n\nThe original bug predates the upstreaming of cake, but the commit listed\nin the Fixes tag touched that code, meaning that this patch won't apply\nbefore that.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46828', 'https://git.kernel.org/linus/546ea84d07e3e324644025e2aae2d12ea4c5896e (6.11-rc7)', 'https://git.kernel.org/stable/c/4a4eeefa514db570be025ab46d779af180e2c9bb', 'https://git.kernel.org/stable/c/546ea84d07e3e324644025e2aae2d12ea4c5896e', 'https://git.kernel.org/stable/c/549e407569e08459d16122341d332cb508024094', 'https://git.kernel.org/stable/c/7725152b54d295b7da5e34c2f419539b30d017bd', 'https://git.kernel.org/stable/c/cde71a5677971f4f1b69b25e854891dbe78066a4', 'https://git.kernel.org/stable/c/d4a9039a7b3d8005b90c7b1a55a306444f0e5447', 'https://git.kernel.org/stable/c/d7c01c0714c04431b5e18cf17a9ea68a553d1c3c', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46828-2184@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46828', 'https://www.cve.org/CVERecord?id=CVE-2024-46828'], 'PublishedDate': '2024-09-27T13:15:15.22Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46829', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46829', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: rtmutex: Drop rt_mutex::wait_lock before scheduling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Drop rt_mutex::wait_lock before scheduling\n\nrt_mutex_handle_deadlock() is called with rt_mutex::wait_lock held. In the\ngood case it returns with the lock held and in the deadlock case it emits a\nwarning and goes into an endless scheduling loop with the lock held, which\ntriggers the 'scheduling in atomic' warning.\n\nUnlock rt_mutex::wait_lock in the dead lock case before issuing the warning\nand dropping into the schedule for ever loop.\n\n[ tglx: Moved unlock before the WARN(), removed the pointless comment,\n \tmassaged changelog, added Fixes tag ]", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46829', 'https://git.kernel.org/linus/d33d26036a0274b472299d7dcdaa5fb34329f91b (6.11-rc7)', 'https://git.kernel.org/stable/c/1401da1486dc1cdbef6025fd74a3977df3a3e5d0', 'https://git.kernel.org/stable/c/432efdbe7da5ecfcbc0c2180cfdbab1441752a38', 'https://git.kernel.org/stable/c/6a976e9a47e8e5b326de671811561cab12e6fb1f', 'https://git.kernel.org/stable/c/85f03ca98e07cd0786738b56ae73740bce0ac27f', 'https://git.kernel.org/stable/c/93f44655472d9cd418293d328f9d141ca234ad83', 'https://git.kernel.org/stable/c/a92d81c9efec9280681c27a2c0a963fd0f1338e0', 'https://git.kernel.org/stable/c/d33d26036a0274b472299d7dcdaa5fb34329f91b', 'https://git.kernel.org/stable/c/f13b5afc5c4889569d84c3011ce449f61fccfb28', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46829-da70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46829', 'https://www.cve.org/CVERecord?id=CVE-2024-46829'], 'PublishedDate': '2024-09-27T13:15:15.3Z', 'LastModifiedDate': '2024-10-02T14:27:57.92Z'}, {'VulnerabilityID': 'CVE-2024-46830', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46830', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS\n\nGrab kvm->srcu when processing KVM_SET_VCPU_EVENTS, as KVM will forcibly\nleave nested VMX/SVM if SMM mode is being toggled, and leaving nested VMX\nreads guest memory.\n\nNote, kvm_vcpu_ioctl_x86_set_vcpu_events() can also be called from KVM_RUN\nvia sync_regs(), which already holds SRCU. I.e. trying to precisely use\nkvm_vcpu_srcu_read_lock() around the problematic SMM code would cause\nproblems. Acquiring SRCU isn't all that expensive, so for simplicity,\ngrab it unconditionally for KVM_SET_VCPU_EVENTS.\n\n =============================\n WARNING: suspicious RCU usage\n 6.10.0-rc7-332d2c1d713e-next-vm #552 Not tainted\n -----------------------------\n include/linux/kvm_host.h:1027 suspicious rcu_dereference_check() usage!\n\n other info that might help us debug this:\n\n rcu_scheduler_active = 2, debug_locks = 1\n 1 lock held by repro/1071:\n #0: ffff88811e424430 (&vcpu->mutex){+.+.}-{3:3}, at: kvm_vcpu_ioctl+0x7d/0x970 [kvm]\n\n stack backtrace:\n CPU: 15 PID: 1071 Comm: repro Not tainted 6.10.0-rc7-332d2c1d713e-next-vm #552\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n Call Trace:\n \n dump_stack_lvl+0x7f/0x90\n lockdep_rcu_suspicious+0x13f/0x1a0\n kvm_vcpu_gfn_to_memslot+0x168/0x190 [kvm]\n kvm_vcpu_read_guest+0x3e/0x90 [kvm]\n nested_vmx_load_msr+0x6b/0x1d0 [kvm_intel]\n load_vmcs12_host_state+0x432/0xb40 [kvm_intel]\n vmx_leave_nested+0x30/0x40 [kvm_intel]\n kvm_vcpu_ioctl_x86_set_vcpu_events+0x15d/0x2b0 [kvm]\n kvm_arch_vcpu_ioctl+0x1107/0x1750 [kvm]\n ? mark_held_locks+0x49/0x70\n ? kvm_vcpu_ioctl+0x7d/0x970 [kvm]\n ? kvm_vcpu_ioctl+0x497/0x970 [kvm]\n kvm_vcpu_ioctl+0x497/0x970 [kvm]\n ? lock_acquire+0xba/0x2d0\n ? find_held_lock+0x2b/0x80\n ? do_user_addr_fault+0x40c/0x6f0\n ? lock_release+0xb7/0x270\n __x64_sys_ioctl+0x82/0xb0\n do_syscall_64+0x6c/0x170\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x7ff11eb1b539\n ", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46830', 'https://git.kernel.org/linus/4bcdd831d9d01e0fb64faea50732b59b2ee88da1 (6.11-rc7)', 'https://git.kernel.org/stable/c/4bcdd831d9d01e0fb64faea50732b59b2ee88da1', 'https://git.kernel.org/stable/c/939375737b5a0b1bf9b1e75129054e11bc9ca65e', 'https://git.kernel.org/stable/c/ecdbe8ac86fb5538ccc623a41f88ec96c7168ab9', 'https://git.kernel.org/stable/c/fa297c33faefe51e10244e8a378837fca4963228', 'https://lore.kernel.org/linux-cve-announce/2024092751-CVE-2024-46830-deac@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46830', 'https://www.cve.org/CVERecord?id=CVE-2024-46830'], 'PublishedDate': '2024-09-27T13:15:15.38Z', 'LastModifiedDate': '2024-09-30T12:45:57.823Z'}, {'VulnerabilityID': 'CVE-2024-46831', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46831', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: microchip: vcap: Fix use-after-free error in kunit test', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: vcap: Fix use-after-free error in kunit test\n\nThis is a clear use-after-free error. We remove it, and rely on checking\nthe return code of vcap_del_rule.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46831', 'https://git.kernel.org/linus/a3c1e45156ad39f225cd7ddae0f81230a3b1e657 (6.11-rc7)', 'https://git.kernel.org/stable/c/a3c1e45156ad39f225cd7ddae0f81230a3b1e657', 'https://git.kernel.org/stable/c/b0804c286ccfcf5f5c004d5bf8a54c0508b5e86b', 'https://git.kernel.org/stable/c/f7fe95f40c85311c98913fe6ae2c56adb7f767a7', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46831-06bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46831', 'https://www.cve.org/CVERecord?id=CVE-2024-46831'], 'PublishedDate': '2024-09-27T13:15:15.457Z', 'LastModifiedDate': '2024-10-02T14:26:13.807Z'}, {'VulnerabilityID': 'CVE-2024-46832', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46832', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: cevt-r4k: Don\'t call get_c0_compare_int if timer irq is installed\n\nThis avoids warning:\n\n[ 0.118053] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:283\n\nCaused by get_c0_compare_int on secondary CPU.\n\nWe also skipped saving IRQ number to struct clock_event_device *cd as\nit\'s never used by clockevent core, as per comments it\'s only meant\nfor "non CPU local devices".', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46832', 'https://git.kernel.org/linus/50f2b98dc83de7809a5c5bf0ccf9af2e75c37c13 (6.11-rc5)', 'https://git.kernel.org/stable/c/189d3ed3b25beee26ffe2abed278208bece13f52', 'https://git.kernel.org/stable/c/32ee0520159f1e8c2d6597c19690df452c528f30', 'https://git.kernel.org/stable/c/50f2b98dc83de7809a5c5bf0ccf9af2e75c37c13', 'https://git.kernel.org/stable/c/b1d2051373bfc65371ce4ac8911ed984d0178c98', 'https://git.kernel.org/stable/c/d3ff0f98a52f0aafe35aa314d1c442f4318be3db', 'https://git.kernel.org/stable/c/e6cd871627abbb459d0ff6521d6bb9cf9d9f7522', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46832-3ad0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46832', 'https://www.cve.org/CVERecord?id=CVE-2024-46832'], 'PublishedDate': '2024-09-27T13:15:15.517Z', 'LastModifiedDate': '2024-10-09T15:51:20.7Z'}, {'VulnerabilityID': 'CVE-2024-46833', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46833', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: hns3: void array out of bound when loop tnl_num', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: void array out of bound when loop tnl_num\n\nWhen query reg inf of SSU, it loops tnl_num times. However, tnl_num comes\nfrom hardware and the length of array is a fixed value. To void array out\nof bound, make sure the loop time is not greater than the length of array', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46833', 'https://git.kernel.org/linus/86db7bfb06704ef17340eeae71c832f21cfce35c (6.11-rc4)', 'https://git.kernel.org/stable/c/86db7bfb06704ef17340eeae71c832f21cfce35c', 'https://git.kernel.org/stable/c/c33a9806dc806bcb4a31dc71fb06979219181ad4', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46833-0fa0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46833', 'https://www.cve.org/CVERecord?id=CVE-2024-46833'], 'PublishedDate': '2024-09-27T13:15:15.593Z', 'LastModifiedDate': '2024-10-09T15:54:38.123Z'}, {'VulnerabilityID': 'CVE-2024-46834', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46834', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ethtool: fail closed if we can't get max channel used in indirection tables', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: fail closed if we can\'t get max channel used in indirection tables\n\nCommit 0d1b7d6c9274 ("bnxt: fix crashes when reducing ring count with\nactive RSS contexts") proves that allowing indirection table to contain\nchannels with out of bounds IDs may lead to crashes. Currently the\nmax channel check in the core gets skipped if driver can\'t fetch\nthe indirection table or when we can\'t allocate memory.\n\nBoth of those conditions should be extremely rare but if they do\nhappen we should try to be safe and fail the channel change.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46834', 'https://git.kernel.org/linus/2899d58462ba868287d6ff3acad3675e7adf934f (6.11-rc1)', 'https://git.kernel.org/stable/c/101737d8b88dbd4be6010bac398fe810f1950036', 'https://git.kernel.org/stable/c/2899d58462ba868287d6ff3acad3675e7adf934f', 'https://lore.kernel.org/linux-cve-announce/2024092752-CVE-2024-46834-dc7b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46834', 'https://www.cve.org/CVERecord?id=CVE-2024-46834'], 'PublishedDate': '2024-09-27T13:15:15.66Z', 'LastModifiedDate': '2024-10-09T15:57:03.037Z'}, {'VulnerabilityID': 'CVE-2024-46835', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46835', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix smatch static checker warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix smatch static checker warning\n\nadev->gfx.imu.funcs could be NULL', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46835', 'https://git.kernel.org/linus/bdbdc7cecd00305dc844a361f9883d3a21022027 (6.11-rc1)', 'https://git.kernel.org/stable/c/8bc7b3ce33e64c74211ed17aec823fc4e523426a', 'https://git.kernel.org/stable/c/bdbdc7cecd00305dc844a361f9883d3a21022027', 'https://git.kernel.org/stable/c/c2056c7a840f0dbf293bc3b0d91826d001668fb0', 'https://git.kernel.org/stable/c/d40c2c3dd0395fe7fdc19bd96551e87251426d66', 'https://lore.kernel.org/linux-cve-announce/2024092753-CVE-2024-46835-4f99@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46835', 'https://www.cve.org/CVERecord?id=CVE-2024-46835'], 'PublishedDate': '2024-09-27T13:15:15.72Z', 'LastModifiedDate': '2024-10-02T14:24:18.93Z'}, {'VulnerabilityID': 'CVE-2024-46836', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46836', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: gadget: aspeed_udc: validate endpoint index for ast udc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed_udc: validate endpoint index for ast udc\n\nWe should verify the bound of the array to assure that host\nmay not manipulate the index to point past endpoint array.\n\nFound by static analysis.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46836', 'https://git.kernel.org/linus/ee0d382feb44ec0f445e2ad63786cd7f3f6a8199 (6.11-rc1)', 'https://git.kernel.org/stable/c/31bd4fab49c0adc6228848357c1b1df9395858af', 'https://git.kernel.org/stable/c/6fe9ca2ca389114c8da66e534c18273497843e8a', 'https://git.kernel.org/stable/c/b2a50ffdd1a079869a62198a8d1441355c513c7c', 'https://git.kernel.org/stable/c/ee0d382feb44ec0f445e2ad63786cd7f3f6a8199', 'https://lore.kernel.org/linux-cve-announce/2024092753-CVE-2024-46836-acff@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46836', 'https://www.cve.org/CVERecord?id=CVE-2024-46836'], 'PublishedDate': '2024-09-27T13:15:15.78Z', 'LastModifiedDate': '2024-10-09T15:47:55.187Z'}, {'VulnerabilityID': 'CVE-2024-46838', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46838', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: userfaultfd: don't BUG_ON() if khugepaged yanks our page table', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: don\'t BUG_ON() if khugepaged yanks our page table\n\nSince khugepaged was changed to allow retracting page tables in file\nmappings without holding the mmap lock, these BUG_ON()s are wrong - get\nrid of them.\n\nWe could also remove the preceding "if (unlikely(...))" block, but then we\ncould reach pte_offset_map_lock() with transhuge pages not just for file\nmappings but also for anonymous mappings - which would probably be fine\nbut I think is not necessarily expected.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46838', 'https://git.kernel.org/linus/4828d207dc5161dc7ddf9a4f6dcfd80c7dd7d20a (6.11-rc7)', 'https://git.kernel.org/stable/c/4828d207dc5161dc7ddf9a4f6dcfd80c7dd7d20a', 'https://git.kernel.org/stable/c/4a594acc12d5954cdc71d4450a386748bf3d136a', 'https://git.kernel.org/stable/c/db978287e908d48b209e374b00d847b2d785e0a9', 'https://lore.kernel.org/linux-cve-announce/2024092753-CVE-2024-46838-5fa5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46838', 'https://www.cve.org/CVERecord?id=CVE-2024-46838'], 'PublishedDate': '2024-09-27T13:15:15.92Z', 'LastModifiedDate': '2024-10-09T15:35:40.827Z'}, {'VulnerabilityID': 'CVE-2024-46840', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46840', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: clean up our handling of refs == 0 in snapshot delete', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: clean up our handling of refs == 0 in snapshot delete\n\nIn reada we BUG_ON(refs == 0), which could be unkind since we aren't\nholding a lock on the extent leaf and thus could get a transient\nincorrect answer. In walk_down_proc we also BUG_ON(refs == 0), which\ncould happen if we have extent tree corruption. Change that to return\n-EUCLEAN. In do_walk_down() we catch this case and handle it correctly,\nhowever we return -EIO, which -EUCLEAN is a more appropriate error code.\nFinally in walk_up_proc we have the same BUG_ON(refs == 0), so convert\nthat to proper error handling. Also adjust the error message so we can\nactually do something with the information.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46840', 'https://git.kernel.org/linus/b8ccef048354074a548f108e51d0557d6adfd3a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/03804641ec2d0da4fa088ad21c88e703d151ce16', 'https://git.kernel.org/stable/c/71291aa7246645ef622621934d2067400380645e', 'https://git.kernel.org/stable/c/728d4d045b628e006b48a448f3326a7194c88d32', 'https://git.kernel.org/stable/c/7d1df13bf078ffebfedd361d714ff6cee1ff01b9', 'https://git.kernel.org/stable/c/9cc887ac24b7a0598f4042ae9af6b9a33072f75b', 'https://git.kernel.org/stable/c/b8ccef048354074a548f108e51d0557d6adfd3a3', 'https://git.kernel.org/stable/c/c60676b81fab456b672796830f6d8057058f029c', 'https://git.kernel.org/stable/c/c847b28a799733b04574060ab9d00f215970627d', 'https://lore.kernel.org/linux-cve-announce/2024092754-CVE-2024-46840-fc44@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46840', 'https://www.cve.org/CVERecord?id=CVE-2024-46840'], 'PublishedDate': '2024-09-27T13:15:16.057Z', 'LastModifiedDate': '2024-10-08T18:15:07.857Z'}, {'VulnerabilityID': 'CVE-2024-46841', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46841', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc()\n\nWe handle errors here properly, ENOMEM isn't fatal, return the error.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46841', 'https://git.kernel.org/linus/a580fb2c3479d993556e1c31b237c9e5be4944a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/704c359b4093a2af650a20eaa030c435d7c30f91', 'https://git.kernel.org/stable/c/a580fb2c3479d993556e1c31b237c9e5be4944a3', 'https://lore.kernel.org/linux-cve-announce/2024092754-CVE-2024-46841-7572@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46841', 'https://www.cve.org/CVERecord?id=CVE-2024-46841'], 'PublishedDate': '2024-09-27T13:15:16.13Z', 'LastModifiedDate': '2024-10-08T18:17:07.87Z'}, {'VulnerabilityID': 'CVE-2024-46842', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46842', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info\n\nThe MBX_TIMEOUT return code is not handled in lpfc_get_sfp_info and the\nroutine unconditionally frees submitted mailbox commands regardless of\nreturn status. The issue is that for MBX_TIMEOUT cases, when firmware\nreturns SFP information at a later time, that same mailbox memory region\nreferences previously freed memory in its cmpl routine.\n\nFix by adding checks for the MBX_TIMEOUT return code. During mailbox\nresource cleanup, check the mbox flag to make sure that the wait did not\ntimeout. If the MBOX_WAKE flag is not set, then do not free the resources\nbecause it will be freed when firmware completes the mailbox at a later\ntime in its cmpl routine.\n\nAlso, increase the timeout from 30 to 60 seconds to accommodate boot\nscripts requiring longer timeouts.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46842', 'https://git.kernel.org/linus/ede596b1434b57c0b3fd5c02b326efe5c54f6e48 (6.11-rc1)', 'https://git.kernel.org/stable/c/bba47fe3b038cca3d3ebd799665ce69d6d273b58', 'https://git.kernel.org/stable/c/ede596b1434b57c0b3fd5c02b326efe5c54f6e48', 'https://lore.kernel.org/linux-cve-announce/2024092754-CVE-2024-46842-e52c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46842', 'https://www.cve.org/CVERecord?id=CVE-2024-46842'], 'PublishedDate': '2024-09-27T13:15:16.19Z', 'LastModifiedDate': '2024-10-08T18:22:24.997Z'}, {'VulnerabilityID': 'CVE-2024-46843', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46843', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: ufs: core: Remove SCSI host only if added', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Remove SCSI host only if added\n\nIf host tries to remove ufshcd driver from a UFS device it would cause a\nkernel panic if ufshcd_async_scan fails during ufshcd_probe_hba before\nadding a SCSI host with scsi_add_host and MCQ is enabled since SCSI host\nhas been defered after MCQ configuration introduced by commit 0cab4023ec7b\n("scsi: ufs: core: Defer adding host to SCSI if MCQ is supported").\n\nTo guarantee that SCSI host is removed only if it has been added, set the\nscsi_host_added flag to true after adding a SCSI host and check whether it\nis set or not before removing it.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46843', 'https://git.kernel.org/linus/7cbff570dbe8907e23bba06f6414899a0fbb2fcc (6.11-rc1)', 'https://git.kernel.org/stable/c/2f49e05d6b58d660f035a75ff96b77071b4bd5ed', 'https://git.kernel.org/stable/c/3844586e9bd9845140e1078f1e61896b576ac536', 'https://git.kernel.org/stable/c/7cbff570dbe8907e23bba06f6414899a0fbb2fcc', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46843-82c5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46843', 'https://www.cve.org/CVERecord?id=CVE-2024-46843'], 'PublishedDate': '2024-09-27T13:15:16.25Z', 'LastModifiedDate': '2024-10-08T18:23:52.423Z'}, {'VulnerabilityID': 'CVE-2024-46844', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46844', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: um: line: always fill *error_out in setup_one_line()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\num: line: always fill *error_out in setup_one_line()\n\nThe pointer isn't initialized by callers, but I have\nencountered cases where it's still printed; initialize\nit in all possible cases in setup_one_line().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-824'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46844', 'https://git.kernel.org/linus/824ac4a5edd3f7494ab1996826c4f47f8ef0f63d (6.11-rc1)', 'https://git.kernel.org/stable/c/289979d64573f43df1d0e6bc6435de63a0d69cdf', 'https://git.kernel.org/stable/c/3bedb7ce080690d0d6172db790790c1219bcbdd5', 'https://git.kernel.org/stable/c/43f782c27907f306c664b6614fd6f264ac32cce6', 'https://git.kernel.org/stable/c/824ac4a5edd3f7494ab1996826c4f47f8ef0f63d', 'https://git.kernel.org/stable/c/96301fdc2d533a196197c055af875fe33d47ef84', 'https://git.kernel.org/stable/c/c8944d449fda9f58c03bd99649b2df09948fc874', 'https://git.kernel.org/stable/c/ec5b47a370177d79ae7773858042c107e21f8ecc', 'https://git.kernel.org/stable/c/fc843d3837ebcb1c16d3768ef3eb55e25d5331f2', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46844-af64@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46844', 'https://www.cve.org/CVERecord?id=CVE-2024-46844'], 'PublishedDate': '2024-09-27T13:15:16.313Z', 'LastModifiedDate': '2024-10-02T14:22:50.533Z'}, {'VulnerabilityID': 'CVE-2024-46845', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46845', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing/timerlat: Only clear timer if a kthread exists', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Only clear timer if a kthread exists\n\nThe timerlat tracer can use user space threads to check for osnoise and\ntimer latency. If the program using this is killed via a SIGTERM, the\nthreads are shutdown one at a time and another tracing instance can start\nup resetting the threads before they are fully closed. That causes the\nhrtimer assigned to the kthread to be shutdown and freed twice when the\ndying thread finally closes the file descriptors, causing a use-after-free\nbug.\n\nOnly cancel the hrtimer if the associated thread is still around. Also add\nthe interface_lock around the resetting of the tlat_var->kthread.\n\nNote, this is just a quick fix that can be backported to stable. A real\nfix is to have a better synchronization between the shutdown of old\nthreads and the starting of new ones.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46845', 'https://git.kernel.org/linus/e6a53481da292d970d1edf0d8831121d1c5e2f0d (6.11-rc7)', 'https://git.kernel.org/stable/c/8a9d0d405159e9c796ddf771f7cff691c1a2bc1e', 'https://git.kernel.org/stable/c/8c72f0b2c45f21cb8b00fc37f79f632d7e46c2ed', 'https://git.kernel.org/stable/c/e6a53481da292d970d1edf0d8831121d1c5e2f0d', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46845-a529@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46845', 'https://www.cve.org/CVERecord?id=CVE-2024-46845'], 'PublishedDate': '2024-09-27T13:15:16.397Z', 'LastModifiedDate': '2024-10-02T14:18:32.923Z'}, {'VulnerabilityID': 'CVE-2024-46846', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: rockchip: Resolve unbalanced runtime PM / system PM handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: rockchip: Resolve unbalanced runtime PM / system PM handling\n\nCommit e882575efc77 ("spi: rockchip: Suspend and resume the bus during\nNOIRQ_SYSTEM_SLEEP_PM ops") stopped respecting runtime PM status and\nsimply disabled clocks unconditionally when suspending the system. This\ncauses problems when the device is already runtime suspended when we go\nto sleep -- in which case we double-disable clocks and produce a\nWARNing.\n\nSwitch back to pm_runtime_force_{suspend,resume}(), because that still\nseems like the right thing to do, and the aforementioned commit makes no\nexplanation why it stopped using it.\n\nAlso, refactor some of the resume() error handling, because it\'s not\nactually a good idea to re-disable clocks on failure.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46846', 'https://git.kernel.org/linus/be721b451affbecc4ba4eaac3b71cdbdcade1b1b (6.11-rc7)', 'https://git.kernel.org/stable/c/0efbad8445fbba7896402500a1473450a299a08a', 'https://git.kernel.org/stable/c/14f970a8d03d882b15b97beb83bd84ac8ba6298c', 'https://git.kernel.org/stable/c/be721b451affbecc4ba4eaac3b71cdbdcade1b1b', 'https://git.kernel.org/stable/c/d034bff62faea1a2219e0d2f3d17263265f24087', 'https://lore.kernel.org/linux-cve-announce/2024092755-CVE-2024-46846-f264@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46846', 'https://www.cve.org/CVERecord?id=CVE-2024-46846'], 'PublishedDate': '2024-09-27T13:15:16.48Z', 'LastModifiedDate': '2024-10-08T18:25:56.467Z'}, {'VulnerabilityID': 'CVE-2024-46848', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46848', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf/x86/intel: Limit the period on Haswell', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Limit the period on Haswell\n\nRunning the ltp test cve-2015-3290 concurrently reports the following\nwarnings.\n\nperfevents: irq loop stuck!\n WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174\n intel_pmu_handle_irq+0x285/0x370\n Call Trace:\n \n ? __warn+0xa4/0x220\n ? intel_pmu_handle_irq+0x285/0x370\n ? __report_bug+0x123/0x130\n ? intel_pmu_handle_irq+0x285/0x370\n ? __report_bug+0x123/0x130\n ? intel_pmu_handle_irq+0x285/0x370\n ? report_bug+0x3e/0xa0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x18/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? irq_work_claim+0x1e/0x40\n ? intel_pmu_handle_irq+0x285/0x370\n perf_event_nmi_handler+0x3d/0x60\n nmi_handle+0x104/0x330\n\nThanks to Thomas Gleixner's analysis, the issue is caused by the low\ninitial period (1) of the frequency estimation algorithm, which triggers\nthe defects of the HW, specifically erratum HSW11 and HSW143. (For the\ndetails, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)\n\nThe HSW11 requires a period larger than 100 for the INST_RETIRED.ALL\nevent, but the initial period in the freq mode is 1. The erratum is the\nsame as the BDM11, which has been supported in the kernel. A minimum\nperiod of 128 is enforced as well on HSW.\n\nHSW143 is regarding that the fixed counter 1 may overcount 32 with the\nHyper-Threading is enabled. However, based on the test, the hardware\nhas more issues than it tells. Besides the fixed counter 1, the message\n'interrupt took too long' can be observed on any counter which was armed\nwith a period < 32 and two events expired in the same NMI. A minimum\nperiod of 32 is enforced for the rest of the events.\nThe recommended workaround code of the HSW143 is not implemented.\nBecause it only addresses the issue for the fixed counter. It brings\nextra overhead through extra MSR writing. No related overcounting issue\nhas been reported so far.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46848', 'https://git.kernel.org/linus/25dfc9e357af8aed1ca79b318a73f2c59c1f0b2b (6.11-rc7)', 'https://git.kernel.org/stable/c/0eaf812aa1506704f3b78be87036860e5d0fe81d', 'https://git.kernel.org/stable/c/15210b7c8caff4929f25d049ef8404557f8ae468', 'https://git.kernel.org/stable/c/25dfc9e357af8aed1ca79b318a73f2c59c1f0b2b', 'https://git.kernel.org/stable/c/8717dc35c0e5896f4110f4b3882f7ff787a5f73d', 'https://lore.kernel.org/linux-cve-announce/2024092756-CVE-2024-46848-bbd4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46848', 'https://www.cve.org/CVERecord?id=CVE-2024-46848'], 'PublishedDate': '2024-09-27T13:15:16.657Z', 'LastModifiedDate': '2024-10-04T15:23:35.287Z'}, {'VulnerabilityID': 'CVE-2024-46849', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46849', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: meson: axg-card: fix 'use-after-free'', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: axg-card: fix 'use-after-free'\n\nBuffer 'card->dai_link' is reallocated in 'meson_card_reallocate_links()',\nso move 'pad' pointer initialization after this function when memory is\nalready reallocated.\n\nKasan bug report:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in axg_card_add_link+0x76c/0x9bc\nRead of size 8 at addr ffff000000e8b260 by task modprobe/356\n\nCPU: 0 PID: 356 Comm: modprobe Tainted: G O 6.9.12-sdkernel #1\nCall trace:\n dump_backtrace+0x94/0xec\n show_stack+0x18/0x24\n dump_stack_lvl+0x78/0x90\n print_report+0xfc/0x5c0\n kasan_report+0xb8/0xfc\n __asan_load8+0x9c/0xb8\n axg_card_add_link+0x76c/0x9bc [snd_soc_meson_axg_sound_card]\n meson_card_probe+0x344/0x3b8 [snd_soc_meson_card_utils]\n platform_probe+0x8c/0xf4\n really_probe+0x110/0x39c\n __driver_probe_device+0xb8/0x18c\n driver_probe_device+0x108/0x1d8\n __driver_attach+0xd0/0x25c\n bus_for_each_dev+0xe0/0x154\n driver_attach+0x34/0x44\n bus_add_driver+0x134/0x294\n driver_register+0xa8/0x1e8\n __platform_driver_register+0x44/0x54\n axg_card_pdrv_init+0x20/0x1000 [snd_soc_meson_axg_sound_card]\n do_one_initcall+0xdc/0x25c\n do_init_module+0x10c/0x334\n load_module+0x24c4/0x26cc\n init_module_from_file+0xd4/0x128\n __arm64_sys_finit_module+0x1f4/0x41c\n invoke_syscall+0x60/0x188\n el0_svc_common.constprop.0+0x78/0x13c\n do_el0_svc+0x30/0x40\n el0_svc+0x38/0x78\n el0t_64_sync_handler+0x100/0x12c\n el0t_64_sync+0x190/0x194", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46849', 'https://git.kernel.org/linus/4f9a71435953f941969a4f017e2357db62d85a86 (6.11)', 'https://git.kernel.org/stable/c/4f9a71435953f941969a4f017e2357db62d85a86', 'https://git.kernel.org/stable/c/5a2cc2bb81399e9ebc72560541137eb04d61dc3d', 'https://git.kernel.org/stable/c/7d318166bf55e9029d56997c3b134f4ac2ae2607', 'https://git.kernel.org/stable/c/e1a199ec31617242e1a0ea8f312341e682d0c037', 'https://git.kernel.org/stable/c/e43364f578cdc2f8083abbc0cb743ea55e827c29', 'https://git.kernel.org/stable/c/fb0530025d502cb79d2b2801b14a9d5261833f1a', 'https://lore.kernel.org/linux-cve-announce/2024092741-CVE-2024-46849-93c5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46849', 'https://www.cve.org/CVERecord?id=CVE-2024-46849'], 'PublishedDate': '2024-09-27T13:15:16.723Z', 'LastModifiedDate': '2024-10-17T14:15:07.75Z'}, {'VulnerabilityID': 'CVE-2024-46850', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46850', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()\n\ndc_state_destruct() nulls the resource context of the DC state. The pipe\ncontext passed to dcn35_set_drr() is a member of this resource context.\n\nIf dc_state_destruct() is called parallel to the IRQ processing (which\ncalls dcn35_set_drr() at some point), we can end up using already nulled\nfunction callback fields of struct stream_resource.\n\nThe logic in dcn35_set_drr() already tries to avoid this, by checking tg\nagainst NULL. But if the nulling happens exactly after the NULL check and\nbefore the next access, then we get a race.\n\nAvoid this by copying tg first to a local variable, and then use this\nvariable for all the operations. This should work, as long as nobody\nfrees the resource pool where the timing generators live.\n\n(cherry picked from commit 0607a50c004798a96e62c089a4c34c220179dcb5)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46850', 'https://git.kernel.org/linus/e835d5144f5ef78e4f8828c63e2f0d61144f283a (6.11)', 'https://git.kernel.org/stable/c/42850927656a540428e58d370b3c1599a617bac7', 'https://git.kernel.org/stable/c/e835d5144f5ef78e4f8828c63e2f0d61144f283a', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46850-186e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46850', 'https://www.cve.org/CVERecord?id=CVE-2024-46850'], 'PublishedDate': '2024-09-27T13:15:16.787Z', 'LastModifiedDate': '2024-10-04T15:30:32.11Z'}, {'VulnerabilityID': 'CVE-2024-46851', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46851', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct()\n\ndc_state_destruct() nulls the resource context of the DC state. The pipe\ncontext passed to dcn10_set_drr() is a member of this resource context.\n\nIf dc_state_destruct() is called parallel to the IRQ processing (which\ncalls dcn10_set_drr() at some point), we can end up using already nulled\nfunction callback fields of struct stream_resource.\n\nThe logic in dcn10_set_drr() already tries to avoid this, by checking tg\nagainst NULL. But if the nulling happens exactly after the NULL check and\nbefore the next access, then we get a race.\n\nAvoid this by copying tg first to a local variable, and then use this\nvariable for all the operations. This should work, as long as nobody\nfrees the resource pool where the timing generators live.\n\n(cherry picked from commit a3cc326a43bdc48fbdf53443e1027a03e309b643)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46851', 'https://git.kernel.org/linus/a7aeb03888b92304e2fc7d4d1c242f54a312561b (6.11)', 'https://git.kernel.org/stable/c/a7aeb03888b92304e2fc7d4d1c242f54a312561b', 'https://git.kernel.org/stable/c/b6ce047a81f508f5c60756db8dfb5ff486e4dad0', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46851-125b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46851', 'https://www.cve.org/CVERecord?id=CVE-2024-46851'], 'PublishedDate': '2024-09-27T13:15:16.85Z', 'LastModifiedDate': '2024-10-04T16:00:43.913Z'}, {'VulnerabilityID': 'CVE-2024-46852', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46852', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dma-buf: heaps: Fix off-by-one in CMA heap fault handler', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: heaps: Fix off-by-one in CMA heap fault handler\n\nUntil VM_DONTEXPAND was added in commit 1c1914d6e8c6 ("dma-buf: heaps:\nDon\'t track CMA dma-buf pages under RssFile") it was possible to obtain\na mapping larger than the buffer size via mremap and bypass the overflow\ncheck in dma_buf_mmap_internal. When using such a mapping to attempt to\nfault past the end of the buffer, the CMA heap fault handler also checks\nthe fault offset against the buffer size, but gets the boundary wrong by\n1. Fix the boundary check so that we don\'t read off the end of the pages\narray and insert an arbitrary page in the mapping.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-193'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46852', 'https://git.kernel.org/linus/ea5ff5d351b520524019f7ff7f9ce418de2dad87 (6.11)', 'https://git.kernel.org/stable/c/007180fcb6cc4a93211d4cc45fef3f5ccccd56ae', 'https://git.kernel.org/stable/c/79cce5e81d20fa9ad553be439d665ac3302d3c95', 'https://git.kernel.org/stable/c/84175dc5b2c932266a50c04e5ce342c30f817a2f', 'https://git.kernel.org/stable/c/e79050882b857c37634baedbdcf7c2047c24cbff', 'https://git.kernel.org/stable/c/ea5ff5d351b520524019f7ff7f9ce418de2dad87', 'https://git.kernel.org/stable/c/eb7fc8b65cea22f9038c52398c8b22849e9620ea', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46852-91a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46852', 'https://www.cve.org/CVERecord?id=CVE-2024-46852'], 'PublishedDate': '2024-09-27T13:15:16.917Z', 'LastModifiedDate': '2024-10-17T14:15:07.887Z'}, {'VulnerabilityID': 'CVE-2024-46853', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46853', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: nxp-fspi: fix the KASAN report out-of-bounds bug', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: nxp-fspi: fix the KASAN report out-of-bounds bug\n\nChange the memcpy length to fix the out-of-bounds issue when writing the\ndata that is not 4 byte aligned to TX FIFO.\n\nTo reproduce the issue, write 3 bytes data to NOR chip.\n\ndd if=3b of=/dev/mtd0\n[ 36.926103] ==================================================================\n[ 36.933409] BUG: KASAN: slab-out-of-bounds in nxp_fspi_exec_op+0x26ec/0x2838\n[ 36.940514] Read of size 4 at addr ffff00081037c2a0 by task dd/455\n[ 36.946721]\n[ 36.948235] CPU: 3 UID: 0 PID: 455 Comm: dd Not tainted 6.11.0-rc5-gc7b0e37c8434 #1070\n[ 36.956185] Hardware name: Freescale i.MX8QM MEK (DT)\n[ 36.961260] Call trace:\n[ 36.963723] dump_backtrace+0x90/0xe8\n[ 36.967414] show_stack+0x18/0x24\n[ 36.970749] dump_stack_lvl+0x78/0x90\n[ 36.974451] print_report+0x114/0x5cc\n[ 36.978151] kasan_report+0xa4/0xf0\n[ 36.981670] __asan_report_load_n_noabort+0x1c/0x28\n[ 36.986587] nxp_fspi_exec_op+0x26ec/0x2838\n[ 36.990800] spi_mem_exec_op+0x8ec/0xd30\n[ 36.994762] spi_mem_no_dirmap_read+0x190/0x1e0\n[ 36.999323] spi_mem_dirmap_write+0x238/0x32c\n[ 37.003710] spi_nor_write_data+0x220/0x374\n[ 37.007932] spi_nor_write+0x110/0x2e8\n[ 37.011711] mtd_write_oob_std+0x154/0x1f0\n[ 37.015838] mtd_write_oob+0x104/0x1d0\n[ 37.019617] mtd_write+0xb8/0x12c\n[ 37.022953] mtdchar_write+0x224/0x47c\n[ 37.026732] vfs_write+0x1e4/0x8c8\n[ 37.030163] ksys_write+0xec/0x1d0\n[ 37.033586] __arm64_sys_write+0x6c/0x9c\n[ 37.037539] invoke_syscall+0x6c/0x258\n[ 37.041327] el0_svc_common.constprop.0+0x160/0x22c\n[ 37.046244] do_el0_svc+0x44/0x5c\n[ 37.049589] el0_svc+0x38/0x78\n[ 37.052681] el0t_64_sync_handler+0x13c/0x158\n[ 37.057077] el0t_64_sync+0x190/0x194\n[ 37.060775]\n[ 37.062274] Allocated by task 455:\n[ 37.065701] kasan_save_stack+0x2c/0x54\n[ 37.069570] kasan_save_track+0x20/0x3c\n[ 37.073438] kasan_save_alloc_info+0x40/0x54\n[ 37.077736] __kasan_kmalloc+0xa0/0xb8\n[ 37.081515] __kmalloc_noprof+0x158/0x2f8\n[ 37.085563] mtd_kmalloc_up_to+0x120/0x154\n[ 37.089690] mtdchar_write+0x130/0x47c\n[ 37.093469] vfs_write+0x1e4/0x8c8\n[ 37.096901] ksys_write+0xec/0x1d0\n[ 37.100332] __arm64_sys_write+0x6c/0x9c\n[ 37.104287] invoke_syscall+0x6c/0x258\n[ 37.108064] el0_svc_common.constprop.0+0x160/0x22c\n[ 37.112972] do_el0_svc+0x44/0x5c\n[ 37.116319] el0_svc+0x38/0x78\n[ 37.119401] el0t_64_sync_handler+0x13c/0x158\n[ 37.123788] el0t_64_sync+0x190/0x194\n[ 37.127474]\n[ 37.128977] The buggy address belongs to the object at ffff00081037c2a0\n[ 37.128977] which belongs to the cache kmalloc-8 of size 8\n[ 37.141177] The buggy address is located 0 bytes inside of\n[ 37.141177] allocated 3-byte region [ffff00081037c2a0, ffff00081037c2a3)\n[ 37.153465]\n[ 37.154971] The buggy address belongs to the physical page:\n[ 37.160559] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x89037c\n[ 37.168596] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)\n[ 37.175149] page_type: 0xfdffffff(slab)\n[ 37.179021] raw: 0bfffe0000000000 ffff000800002500 dead000000000122 0000000000000000\n[ 37.186788] raw: 0000000000000000 0000000080800080 00000001fdffffff 0000000000000000\n[ 37.194553] page dumped because: kasan: bad access detected\n[ 37.200144]\n[ 37.201647] Memory state around the buggy address:\n[ 37.206460] ffff00081037c180: fa fc fc fc fa fc fc fc fa fc fc fc fa fc fc fc\n[ 37.213701] ffff00081037c200: fa fc fc fc 05 fc fc fc 03 fc fc fc 02 fc fc fc\n[ 37.220946] >ffff00081037c280: 06 fc fc fc 03 fc fc fc fc fc fc fc fc fc fc fc\n[ 37.228186] ^\n[ 37.232473] ffff00081037c300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 37.239718] ffff00081037c380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 37.246962] ==============================================================\n---truncated---', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46853', 'https://git.kernel.org/linus/2a8787c1cdc7be24fdd8953ecd1a8743a1006235 (6.11)', 'https://git.kernel.org/stable/c/09af8b0ba70072be831f3ec459f4063d570f9e24', 'https://git.kernel.org/stable/c/2a8787c1cdc7be24fdd8953ecd1a8743a1006235', 'https://git.kernel.org/stable/c/491f9646f7ac31af5fca71be1a3e5eb8aa7663ad', 'https://git.kernel.org/stable/c/609260542cf86b459c57618b8cdec8020394b7ad', 'https://git.kernel.org/stable/c/af9ca9ca3e44f48b2a191e100d452fbf850c3d87', 'https://git.kernel.org/stable/c/d1a1dfcec77c57b1181da93d11a3db1bc4eefa97', 'https://lore.kernel.org/linux-cve-announce/2024092742-CVE-2024-46853-ab04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46853', 'https://www.cve.org/CVERecord?id=CVE-2024-46853'], 'PublishedDate': '2024-09-27T13:15:16.997Z', 'LastModifiedDate': '2024-10-17T14:15:07.993Z'}, {'VulnerabilityID': 'CVE-2024-46854', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46854', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dpaa: Pad packets to ETH_ZLEN', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dpaa: Pad packets to ETH_ZLEN\n\nWhen sending packets under 60 bytes, up to three bytes of the buffer\nfollowing the data may be leaked. Avoid this by extending all packets to\nETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be\nreproduced by running\n\n\t$ ping -s 11 destination', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46854', 'https://git.kernel.org/linus/cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0 (6.11)', 'https://git.kernel.org/stable/c/1f31f51bfc8214a6deaac2920e6342cb9d019133', 'https://git.kernel.org/stable/c/34fcac26216ce17886af3eb392355b459367af1a', 'https://git.kernel.org/stable/c/38f5db5587c0ee53546b28c50ba128253181ac83', 'https://git.kernel.org/stable/c/cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0', 'https://git.kernel.org/stable/c/ce8eabc912fe9b9a62be1a5c6af5ad2196e90fc2', 'https://git.kernel.org/stable/c/f43190e33224c49e1c7ebbc25923ff400d87ec00', 'https://lore.kernel.org/linux-cve-announce/2024092743-CVE-2024-46854-3404@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46854', 'https://www.cve.org/CVERecord?id=CVE-2024-46854'], 'PublishedDate': '2024-09-27T13:15:17.063Z', 'LastModifiedDate': '2024-10-17T14:15:08.107Z'}, {'VulnerabilityID': 'CVE-2024-46855', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46855', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: nft_socket: fix sk refcount leaks', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_socket: fix sk refcount leaks\n\nWe must put 'sk' reference before returning.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46855', 'https://git.kernel.org/linus/8b26ff7af8c32cb4148b3e147c52f9e4c695209c (6.11)', 'https://git.kernel.org/stable/c/1f68e097e20d3c695281a9c6433acc37be47fe11', 'https://git.kernel.org/stable/c/33c2258bf8cb17fba9e58b111d4c4f4cf43a4896', 'https://git.kernel.org/stable/c/83e6fb59040e8964888afcaa5612cc1243736715', 'https://git.kernel.org/stable/c/8b26ff7af8c32cb4148b3e147c52f9e4c695209c', 'https://git.kernel.org/stable/c/ddc7c423c4a5386bf865474c694b48178efd311a', 'https://lore.kernel.org/linux-cve-announce/2024092743-CVE-2024-46855-4382@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46855', 'https://www.cve.org/CVERecord?id=CVE-2024-46855'], 'PublishedDate': '2024-09-27T13:15:17.133Z', 'LastModifiedDate': '2024-10-17T14:15:12.79Z'}, {'VulnerabilityID': 'CVE-2024-46857', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46857', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix bridge mode operations when there are no VFs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix bridge mode operations when there are no VFs\n\nCurrently, trying to set the bridge mode attribute when numvfs=0 leads to a\ncrash:\n\nbridge link set dev eth2 hwmode vepa\n\n[ 168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030\n[...]\n[ 168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core]\n[...]\n[ 168.976037] Call Trace:\n[ 168.976188] \n[ 168.978620] _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core]\n[ 168.979074] mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core]\n[ 168.979471] rtnl_bridge_setlink+0xe9/0x1f0\n[ 168.979714] rtnetlink_rcv_msg+0x159/0x400\n[ 168.980451] netlink_rcv_skb+0x54/0x100\n[ 168.980675] netlink_unicast+0x241/0x360\n[ 168.980918] netlink_sendmsg+0x1f6/0x430\n[ 168.981162] ____sys_sendmsg+0x3bb/0x3f0\n[ 168.982155] ___sys_sendmsg+0x88/0xd0\n[ 168.985036] __sys_sendmsg+0x59/0xa0\n[ 168.985477] do_syscall_64+0x79/0x150\n[ 168.987273] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 168.987773] RIP: 0033:0x7f8f7950f917\n\n(esw->fdb_table.legacy.vepa_fdb is null)\n\nThe bridge mode is only relevant when there are multiple functions per\nport. Therefore, prevent setting and getting this setting when there are no\nVFs.\n\nNote that after this change, there are no settings to change on the PF\ninterface using `bridge link` when there are no VFs, so the interface no\nlonger appears in the `bridge link` output.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46857', 'https://git.kernel.org/linus/b1d305abef4640af1b4f1b4774d513cd81b10cfc (6.11)', 'https://git.kernel.org/stable/c/505ae01f75f839b54329164bbfecf24cc1361b31', 'https://git.kernel.org/stable/c/52c4beb79e095e0631b5cac46ed48a2aefe51985', 'https://git.kernel.org/stable/c/65feee671e37f3b6eda0b6af28f204b5bcf7fa50', 'https://git.kernel.org/stable/c/b1d305abef4640af1b4f1b4774d513cd81b10cfc', 'https://lore.kernel.org/linux-cve-announce/2024092743-CVE-2024-46857-3bc3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46857', 'https://www.cve.org/CVERecord?id=CVE-2024-46857'], 'PublishedDate': '2024-09-27T13:15:17.277Z', 'LastModifiedDate': '2024-10-01T17:10:29.657Z'}, {'VulnerabilityID': 'CVE-2024-46858', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46858', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mptcp: pm: Fix uaf in __timer_delete_sync', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: Fix uaf in __timer_delete_sync\n\nThere are two paths to access mptcp_pm_del_add_timer, result in a race\ncondition:\n\n CPU1\t\t\t\tCPU2\n ==== ====\n net_rx_action\n napi_poll netlink_sendmsg\n __napi_poll netlink_unicast\n process_backlog netlink_unicast_kernel\n __netif_receive_skb genl_rcv\n __netif_receive_skb_one_core netlink_rcv_skb\n NF_HOOK genl_rcv_msg\n ip_local_deliver_finish genl_family_rcv_msg\n ip_protocol_deliver_rcu genl_family_rcv_msg_doit\n tcp_v4_rcv mptcp_pm_nl_flush_addrs_doit\n tcp_v4_do_rcv mptcp_nl_remove_addrs_list\n tcp_rcv_established mptcp_pm_remove_addrs_and_subflows\n tcp_data_queue remove_anno_list_by_saddr\n mptcp_incoming_options mptcp_pm_del_add_timer\n mptcp_pm_del_add_timer kfree(entry)\n\nIn remove_anno_list_by_saddr(running on CPU2), after leaving the critical\nzone protected by "pm.lock", the entry will be released, which leads to the\noccurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1).\n\nKeeping a reference to add_timer inside the lock, and calling\nsk_stop_timer_sync() with this reference, instead of "entry->add_timer".\n\nMove list_del(&entry->list) to mptcp_pm_del_add_timer and inside the pm lock,\ndo not directly access any members of the entry outside the pm lock, which\ncan avoid similar "entry->x" uaf.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46858', 'https://git.kernel.org/linus/b4cd80b0338945a94972ac3ed54f8338d2da2076 (6.11)', 'https://git.kernel.org/stable/c/0e7814b028cd50b3ff79659d23dfa9da6a1e75e1', 'https://git.kernel.org/stable/c/12134a652b0a10064844ea235173e70246eba6dc', 'https://git.kernel.org/stable/c/3554482f4691571fc4b5490c17ae26896e62171c', 'https://git.kernel.org/stable/c/6452b162549c7f9ef54655d3fb9977b9192e6e5b', 'https://git.kernel.org/stable/c/67409b358500c71632116356a0b065f112d7b707', 'https://git.kernel.org/stable/c/b4cd80b0338945a94972ac3ed54f8338d2da2076', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46858-dab6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46858', 'https://www.cve.org/CVERecord?id=CVE-2024-46858'], 'PublishedDate': '2024-09-27T13:15:17.353Z', 'LastModifiedDate': '2024-10-17T14:15:13.017Z'}, {'VulnerabilityID': 'CVE-2024-46859', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46859', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: panasonic-laptop: Fix SINF array out of bounds accesses\n\nThe panasonic laptop code in various places uses the SINF array with index\nvalues of 0 - SINF_CUR_BRIGHT(0x0d) without checking that the SINF array\nis big enough.\n\nNot all panasonic laptops have this many SINF array entries, for example\nthe Toughbook CF-18 model only has 10 SINF array entries. So it only\nsupports the AC+DC brightness entries and mute.\n\nCheck that the SINF array has a minimum size which covers all AC+DC\nbrightness entries and refuse to load if the SINF array is smaller.\n\nFor higher SINF indexes hide the sysfs attributes when the SINF array\ndoes not contain an entry for that attribute, avoiding show()/store()\naccessing the array out of bounds and add bounds checking to the probe()\nand resume() code accessing these.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46859', 'https://git.kernel.org/linus/f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4 (6.11)', 'https://git.kernel.org/stable/c/6821a82616f60aa72c5909b3e252ad97fb9f7e2a', 'https://git.kernel.org/stable/c/9291fadbd2720a869b1d2fcf82305648e2e62a16', 'https://git.kernel.org/stable/c/b38c19783286a71693c2194ed1b36665168c09c4', 'https://git.kernel.org/stable/c/b7c2f692307fe704be87ea80d7328782b33c3cef', 'https://git.kernel.org/stable/c/f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46859-e785@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46859', 'https://www.cve.org/CVERecord?id=CVE-2024-46859'], 'PublishedDate': '2024-09-27T13:15:17.43Z', 'LastModifiedDate': '2024-10-17T14:15:13.183Z'}, {'VulnerabilityID': 'CVE-2024-46860', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46860', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change\n\nWhen disabling wifi mt7921_ipv6_addr_change() is called as a notifier.\nAt this point mvif->phy is already NULL so we cannot use it here.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46860', 'https://git.kernel.org/linus/479ffee68d59c599f8aed8fa2dcc8e13e7bd13c3 (6.11-rc4)', 'https://git.kernel.org/stable/c/479ffee68d59c599f8aed8fa2dcc8e13e7bd13c3', 'https://git.kernel.org/stable/c/4bfee9346d8c17d928ef6da2b8bffab88fa2a553', 'https://git.kernel.org/stable/c/8d92bafd4c67efb692f722d73a07412b5f88c6d6', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46860-1dfc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46860', 'https://www.cve.org/CVERecord?id=CVE-2024-46860'], 'PublishedDate': '2024-09-27T13:15:17.493Z', 'LastModifiedDate': '2024-10-02T14:04:38.863Z'}, {'VulnerabilityID': 'CVE-2024-46861', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46861', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usbnet: ipheth: do not stop RX on failing RX callback', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: ipheth: do not stop RX on failing RX callback\n\nRX callbacks can fail for multiple reasons:\n\n* Payload too short\n* Payload formatted incorrecly (e.g. bad NCM framing)\n* Lack of memory\n\nNone of these should cause the driver to seize up.\n\nMake such failures non-critical and continue processing further\nincoming URBs.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46861', 'https://git.kernel.org/linus/74efed51e0a4d62f998f806c307778b47fc73395 (6.11-rc4)', 'https://git.kernel.org/stable/c/08ca800b0cd56d5e26722f68b18bbbf6840bf44b', 'https://git.kernel.org/stable/c/4d1cfa3afb8627435744ecdc6d8b58bc72ee0f4c', 'https://git.kernel.org/stable/c/74efed51e0a4d62f998f806c307778b47fc73395', 'https://lore.kernel.org/linux-cve-announce/2024092744-CVE-2024-46861-f2f9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46861', 'https://www.cve.org/CVERecord?id=CVE-2024-46861'], 'PublishedDate': '2024-09-27T13:15:17.563Z', 'LastModifiedDate': '2024-10-03T15:36:06.543Z'}, {'VulnerabilityID': 'CVE-2024-46864', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46864', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/hyperv: fix kexec crash due to VP assist page corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/hyperv: fix kexec crash due to VP assist page corruption\n\ncommit 9636be85cc5b ("x86/hyperv: Fix hyperv_pcpu_input_arg handling when\nCPUs go online/offline") introduces a new cpuhp state for hyperv\ninitialization.\n\ncpuhp_setup_state() returns the state number if state is\nCPUHP_AP_ONLINE_DYN or CPUHP_BP_PREPARE_DYN and 0 for all other states.\nFor the hyperv case, since a new cpuhp state was introduced it would\nreturn 0. However, in hv_machine_shutdown(), the cpuhp_remove_state() call\nis conditioned upon "hyperv_init_cpuhp > 0". This will never be true and\nso hv_cpu_die() won\'t be called on all CPUs. This means the VP assist page\nwon\'t be reset. When the kexec kernel tries to setup the VP assist page\nagain, the hypervisor corrupts the memory region of the old VP assist page\ncausing a panic in case the kexec kernel is using that memory elsewhere.\nThis was originally fixed in commit dfe94d4086e4 ("x86/hyperv: Fix kexec\npanic/hang issues").\n\nGet rid of hyperv_init_cpuhp entirely since we are no longer using a\ndynamic cpuhp state and use CPUHP_AP_HYPERV_ONLINE directly with\ncpuhp_remove_state().', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46864', 'https://git.kernel.org/linus/b9af6418279c4cf73ca073f8ea024992b38be8ab (6.11)', 'https://git.kernel.org/stable/c/2ae1beb3ab4f28868cc5d1541d05e1fbee3ad825', 'https://git.kernel.org/stable/c/b9af6418279c4cf73ca073f8ea024992b38be8ab', 'https://git.kernel.org/stable/c/d6f018a3b49d0a94ddbd0e479c2af6b19724e434', 'https://lore.kernel.org/linux-cve-announce/2024092745-CVE-2024-46864-0343@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46864', 'https://www.cve.org/CVERecord?id=CVE-2024-46864'], 'PublishedDate': '2024-09-27T13:15:17.747Z', 'LastModifiedDate': '2024-10-03T15:29:34.927Z'}, {'VulnerabilityID': 'CVE-2024-46866', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46866', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/client: add missing bo locking in show_meminfo()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: add missing bo locking in show_meminfo()\n\nbo_meminfo() wants to inspect bo state like tt and the ttm resource,\nhowever this state can change at any point leading to stuff like NPD and\nUAF, if the bo lock is not held. Grab the bo lock when calling\nbo_meminfo(), ensuring we drop any spinlocks first. In the case of\nobject_idr we now also need to hold a ref.\n\nv2 (MattB)\n - Also add xe_bo_assert_held()\n\n(cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46866', 'https://git.kernel.org/linus/94c4aa266111262c96c98f822d1bccc494786fee (6.11)', 'https://git.kernel.org/stable/c/94c4aa266111262c96c98f822d1bccc494786fee', 'https://git.kernel.org/stable/c/abc8feacacf8fae10eecf6fea7865e8c1fee419c', 'https://lore.kernel.org/linux-cve-announce/2024092746-CVE-2024-46866-c414@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46866', 'https://www.cve.org/CVERecord?id=CVE-2024-46866'], 'PublishedDate': '2024-09-27T13:15:17.887Z', 'LastModifiedDate': '2024-10-01T17:09:30Z'}, {'VulnerabilityID': 'CVE-2024-46867', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46867', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/client: fix deadlock in show_meminfo()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: fix deadlock in show_meminfo()\n\nThere is a real deadlock as well as sleeping in atomic() bug in here, if\nthe bo put happens to be the last ref, since bo destruction wants to\ngrab the same spinlock and sleeping locks. Fix that by dropping the ref\nusing xe_bo_put_deferred(), and moving the final commit outside of the\nlock. Dropping the lock around the put is tricky since the bo can go\nout of scope and delete itself from the list, making it difficult to\nnavigate to the next list entry.\n\n(cherry picked from commit 0083b8e6f11d7662283a267d4ce7c966812ffd8a)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46867', 'https://git.kernel.org/linus/9bd7ff293fc84792514aeafa06c5a17f05cb5f4b (6.11)', 'https://git.kernel.org/stable/c/9bd7ff293fc84792514aeafa06c5a17f05cb5f4b', 'https://git.kernel.org/stable/c/9d3de463e23bfb1ff1567a32b099b1b3e5286a48', 'https://lore.kernel.org/linux-cve-announce/2024092746-CVE-2024-46867-7fe4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46867', 'https://www.cve.org/CVERecord?id=CVE-2024-46867'], 'PublishedDate': '2024-09-27T13:15:17.937Z', 'LastModifiedDate': '2024-10-01T17:09:58.147Z'}, {'VulnerabilityID': 'CVE-2024-46868', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46868', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire()\n\nIf the __qcuefi pointer is not set, then in the original code, we would\nhold onto the lock. That means that if we tried to set it later, then\nit would cause a deadlock. Drop the lock on the error path. That's\nwhat all the callers are expecting.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46868', 'https://git.kernel.org/linus/db213b0cfe3268d8b1d382b3bcc999c687a2567f (6.11)', 'https://git.kernel.org/stable/c/8c6a5a1fc02ad1d62d06897ab330693d4d27cd03', 'https://git.kernel.org/stable/c/db213b0cfe3268d8b1d382b3bcc999c687a2567f', 'https://lore.kernel.org/linux-cve-announce/2024092746-CVE-2024-46868-f3a3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46868', 'https://www.cve.org/CVERecord?id=CVE-2024-46868'], 'PublishedDate': '2024-09-27T13:15:18.007Z', 'LastModifiedDate': '2024-10-01T17:09:12.247Z'}, {'VulnerabilityID': 'CVE-2024-46870', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46870', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Disable DMCUB timeout for DCN35', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Disable DMCUB timeout for DCN35\n\n[Why]\nDMCUB can intermittently take longer than expected to process commands.\n\nOld ASIC policy was to continue while logging a diagnostic error - which\nworks fine for ASIC without IPS, but with IPS this could lead to a race\ncondition where we attempt to access DCN state while it's inaccessible,\nleading to a system hang when the NIU port is not disabled or register\naccesses that timeout and the display configuration in an undefined\nstate.\n\n[How]\nWe need to investigate why these accesses take longer than expected, but\nfor now we should disable the timeout on DCN35 to avoid this race\ncondition. Since the waits happen only at lower interrupt levels the\nrisk of taking too long at higher IRQ and causing a system watchdog\ntimeout are minimal.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46870', 'https://git.kernel.org/stable/c/31c254c9cd4b122a10db297124f867107a696d83', 'https://git.kernel.org/stable/c/7c70e60fbf4bff1123f0e8d5cb1ae71df6164d7f', 'https://lore.kernel.org/linux-cve-announce/2024100958-CVE-2024-46870-f347@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46870', 'https://www.cve.org/CVERecord?id=CVE-2024-46870'], 'PublishedDate': '2024-10-09T14:15:07.463Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-46871', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-46871', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX\n\n[Why & How]\nIt actually exposes '6' types in enum dmub_notification_type. Not 5. Using smaller\nnumber to create array dmub_callback & dmub_thread_offload has potential to access\nitem out of array bound. Fix it.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-46871', 'https://git.kernel.org/stable/c/800a5ab673c4a61ca220cce177386723d91bdb37', 'https://git.kernel.org/stable/c/9f404b0bc2df3880758fb3c3bc7496f596f347d7', 'https://git.kernel.org/stable/c/ad28d7c3d989fc5689581664653879d664da76f0', 'https://git.kernel.org/stable/c/c592b6355b9b57b8e59fc5978ce1e14f64488a98', 'https://lore.kernel.org/linux-cve-announce/2024100958-CVE-2024-46871-15f4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-46871', 'https://www.cve.org/CVERecord?id=CVE-2024-46871'], 'PublishedDate': '2024-10-09T14:15:07.533Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47658', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47658', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: crypto: stm32/cryp - call finalize with bh disabled', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: stm32/cryp - call finalize with bh disabled\n\nThe finalize operation in interrupt mode produce a produces a spinlock\nrecursion warning. The reason is the fact that BH must be disabled\nduring this process.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47658', 'https://git.kernel.org/stable/c/56ddb9aa3b324c2d9645b5a7343e46010cf3f6ce', 'https://git.kernel.org/stable/c/5d734665cd5d93270731e0ff1dd673fec677f447', 'https://git.kernel.org/stable/c/d93a2f86b0a998aa1f0870c85a2a60a0771ef89a', 'https://lore.kernel.org/linux-cve-announce/2024100959-CVE-2024-47658-0b23@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47658', 'https://www.cve.org/CVERecord?id=CVE-2024-47658'], 'PublishedDate': '2024-10-09T14:15:07.603Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47659', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47659', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: smack: tcp: ipv4, fix incorrect labeling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: tcp: ipv4, fix incorrect labeling\n\nCurrently, Smack mirrors the label of incoming tcp/ipv4 connections:\nwhen a label 'foo' connects to a label 'bar' with tcp/ipv4,\n'foo' always gets 'foo' in returned ipv4 packets. So,\n1) returned packets are incorrectly labeled ('foo' instead of 'bar')\n2) 'bar' can write to 'foo' without being authorized to write.\n\nHere is a scenario how to see this:\n\n* Take two machines, let's call them C and S,\n with active Smack in the default state\n (no settings, no rules, no labeled hosts, only builtin labels)\n\n* At S, add Smack rule 'foo bar w'\n (labels 'foo' and 'bar' are instantiated at S at this moment)\n\n* At S, at label 'bar', launch a program\n that listens for incoming tcp/ipv4 connections\n\n* From C, at label 'foo', connect to the listener at S.\n (label 'foo' is instantiated at C at this moment)\n Connection succeedes and works.\n\n* Send some data in both directions.\n* Collect network traffic of this connection.\n\nAll packets in both directions are labeled with the CIPSO\nof the label 'foo'. Hence, label 'bar' writes to 'foo' without\nbeing authorized, and even without ever being known at C.\n\nIf anybody cares: exactly the same happens with DCCP.\n\nThis behavior 1st manifested in release 2.6.29.4 (see Fixes below)\nand it looks unintentional. At least, no explanation was provided.\n\nI changed returned packes label into the 'bar',\nto bring it into line with the Smack documentation claims.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47659', 'https://git.kernel.org/stable/c/0776bcf9cb6de46fdd94d10118de1cf9b05f83b9', 'https://git.kernel.org/stable/c/0aea09e82eafa50a373fc8a4b84c1d4734751e2c', 'https://git.kernel.org/stable/c/2fe209d0ad2e2729f7e22b9b31a86cc3ff0db550', 'https://git.kernel.org/stable/c/4be9fd15c3c88775bdf6fa37acabe6de85beebff', 'https://git.kernel.org/stable/c/5b4b304f196c070342e32a4752e1fa2e22fc0671', 'https://git.kernel.org/stable/c/a948ec993541db4ef392b555c37a1186f4d61670', 'https://git.kernel.org/stable/c/d3703fa94116fed91f64c7d1c7d284fb4369070f', 'https://git.kernel.org/stable/c/d3f56c653c65f170b172d3c23120bc64ada645d8', 'https://lore.kernel.org/linux-cve-announce/2024100959-CVE-2024-47659-03a8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47659', 'https://www.cve.org/CVERecord?id=CVE-2024-47659'], 'PublishedDate': '2024-10-09T14:15:07.66Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47660', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47660', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fsnotify: clear PARENT_WATCHED flags lazily', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: clear PARENT_WATCHED flags lazily\n\nIn some setups directories can have many (usually negative) dentries.\nHence __fsnotify_update_child_dentry_flags() function can take a\nsignificant amount of time. Since the bulk of this function happens\nunder inode->i_lock this causes a significant contention on the lock\nwhen we remove the watch from the directory as the\n__fsnotify_update_child_dentry_flags() call from fsnotify_recalc_mask()\nraces with __fsnotify_update_child_dentry_flags() calls from\n__fsnotify_parent() happening on children. This can lead upto softlockup\nreports reported by users.\n\nFix the problem by calling fsnotify_update_children_dentry_flags() to\nset PARENT_WATCHED flags only when parent starts watching children.\n\nWhen parent stops watching children, clear false positive PARENT_WATCHED\nflags lazily in __fsnotify_parent() for each accessed child.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47660', 'https://git.kernel.org/stable/c/172e422ffea20a89bfdc672741c1aad6fbb5044e', 'https://git.kernel.org/stable/c/3f3ef1d9f66b93913ce2171120d9226b55acd41d', 'https://git.kernel.org/stable/c/7ef1d2e240c32b1f337a37232d037b07e3919e1a', 'https://git.kernel.org/stable/c/d8c42405fc3507cc43ba7e4986a773c3fc633f6e', 'https://git.kernel.org/stable/c/f9a48bc3dd9099935751458a5bbbea4b7c28abc8', 'https://git.kernel.org/stable/c/fc1b1e135c3f72382f792e6c319fc088d5523ad5', 'https://lore.kernel.org/linux-cve-announce/2024100959-CVE-2024-47660-2d61@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47660', 'https://www.cve.org/CVERecord?id=CVE-2024-47660'], 'PublishedDate': '2024-10-09T14:15:07.73Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47661', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47661', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Avoid overflow from uint32_t to uint8_t', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid overflow from uint32_t to uint8_t\n\n[WHAT & HOW]\ndmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned\n0xFFFF. Fix it by changing it to uint8_t with value of 0xFF.\n\nThis fixes 2 INTEGER_OVERFLOW issues reported by Coverity.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47661', 'https://git.kernel.org/stable/c/30d1b783b6eeaf49d311a072c70d618d993d01ec', 'https://git.kernel.org/stable/c/d6b54900c564e35989cf6813e4071504fa0a90e0', 'https://lore.kernel.org/linux-cve-announce/2024100930-CVE-2024-47661-a6c1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47661', 'https://www.cve.org/CVERecord?id=CVE-2024-47661'], 'PublishedDate': '2024-10-09T15:15:15.02Z', 'LastModifiedDate': '2024-10-15T16:03:29.26Z'}, {'VulnerabilityID': 'CVE-2024-47662', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47662', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Remove register from DCN35 DMCUB diagnostic collection\n\n[Why]\nThese registers should not be read from driver and triggering the\nsecurity violation when DMCUB work times out and diagnostics are\ncollected blocks Z8 entry.\n\n[How]\nRemove the register read from DCN35.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47662', 'https://git.kernel.org/stable/c/466423c6dd8af23ebb3a69d43434d01aed0db356', 'https://git.kernel.org/stable/c/eba4b2a38ccdf074a053834509545703d6df1d57', 'https://lore.kernel.org/linux-cve-announce/2024100931-CVE-2024-47662-74f4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47662', 'https://www.cve.org/CVERecord?id=CVE-2024-47662'], 'PublishedDate': '2024-10-09T15:15:15.08Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47663', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47663', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: staging: iio: frequency: ad9834: Validate frequency parameter value', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: iio: frequency: ad9834: Validate frequency parameter value\n\nIn ad9834_write_frequency() clk_get_rate() can return 0. In such case\nad9834_calc_freqreg() call will lead to division by zero. Checking\n'if (fout > (clk_freq / 2))' doesn't protect in case of 'fout' is 0.\nad9834_write_frequency() is called from ad9834_write(), where fout is\ntaken from text buffer, which can contain any value.\n\nModify parameters checking.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47663', 'https://git.kernel.org/stable/c/0e727707a239d5c519fc9abc2f0fd913516a7e47', 'https://git.kernel.org/stable/c/3ba9abfcaa9e16bb91ed7e0e2b42e94a157a953e', 'https://git.kernel.org/stable/c/41cc91e3138fe52f8da92a81bebcd0e6cf488c53', 'https://git.kernel.org/stable/c/8961b245e8f92bccbaacfbbdf69eba60e3e7c227', 'https://git.kernel.org/stable/c/b48aa991758999d4e8f9296c5bbe388f293ef465', 'https://git.kernel.org/stable/c/d8b09a5edc4a634373158c1a405491de3c52e58a', 'https://git.kernel.org/stable/c/dc12e49f970b08d8b007b8981b97e2eb93c0e89d', 'https://lore.kernel.org/linux-cve-announce/2024100904-CVE-2024-47663-9bdc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47663', 'https://www.cve.org/CVERecord?id=CVE-2024-47663'], 'PublishedDate': '2024-10-09T15:15:15.15Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47664', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47664', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware\n\nIf the value of max_speed_hz is 0, it may cause a division by zero\nerror in hisi_calc_effective_speed().\nThe value of max_speed_hz is provided by firmware.\nFirmware is generally considered as a trusted domain. However, as\ndivision by zero errors can cause system failure, for defense measure,\nthe value of max_speed is validated here. So 0 is regarded as invalid\nand an error code is returned.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47664', 'https://git.kernel.org/stable/c/16ccaf581da4fcf1e4d66086cf37263f9a656d43', 'https://git.kernel.org/stable/c/5127c42c77de18651aa9e8e0a3ced190103b449c', 'https://git.kernel.org/stable/c/ee73a15d4a8ce8fb02d7866f7cf78fcdd16f0fcc', 'https://lore.kernel.org/linux-cve-announce/2024100904-CVE-2024-47664-f6bd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47664', 'https://www.cve.org/CVERecord?id=CVE-2024-47664'], 'PublishedDate': '2024-10-09T15:15:15.223Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47665', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47665', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup\n\nDefinitely condition dma_get_cache_alignment * defined value > 256\nduring driver initialization is not reason to BUG_ON(). Turn that to\ngraceful error out with -EINVAL.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47665', 'https://git.kernel.org/stable/c/2666085335bdfedf90d91f4071490ad3980be785', 'https://git.kernel.org/stable/c/5a022269abb22809f2a174b90f200fc4b9526058', 'https://git.kernel.org/stable/c/8a2be2f1db268ec735419e53ef04ca039fc027dc', 'https://git.kernel.org/stable/c/cacb76df247a7cd842ff29755a523b1cba6c0508', 'https://git.kernel.org/stable/c/e2d14bfda9eb5393f8a17008afe2aa7fe0a29815', 'https://lore.kernel.org/linux-cve-announce/2024100905-CVE-2024-47665-901e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47665', 'https://www.cve.org/CVERecord?id=CVE-2024-47665'], 'PublishedDate': '2024-10-09T15:15:15.29Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47666', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47666', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: pm80xx: Set phy->enable_completion only when we wait for it', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm80xx: Set phy->enable_completion only when we wait for it\n\npm8001_phy_control() populates the enable_completion pointer with a stack\naddress, sends a PHY_LINK_RESET / PHY_HARD_RESET, waits 300 ms, and\nreturns. The problem arises when a phy control response comes late. After\n300 ms the pm8001_phy_control() function returns and the passed\nenable_completion stack address is no longer valid. Late phy control\nresponse invokes complete() on a dangling enable_completion pointer which\nleads to a kernel crash.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47666', 'https://git.kernel.org/stable/c/7b1d779647afaea9185fa2f150b1721e7c1aae89', 'https://git.kernel.org/stable/c/e4f949ef1516c0d74745ee54a0f4882c1f6c7aea', 'https://git.kernel.org/stable/c/f14d3e1aa613311c744af32d75125e95fc8ffb84', 'https://lore.kernel.org/linux-cve-announce/2024100905-CVE-2024-47666-0015@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47666', 'https://www.cve.org/CVERecord?id=CVE-2024-47666'], 'PublishedDate': '2024-10-09T15:15:15.353Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47667', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47667', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)\n\nErrata #i2037 in AM65x/DRA80xM Processors Silicon Revision 1.0\n(SPRZ452D_July 2018_Revised December 2019 [1]) mentions when an\ninbound PCIe TLP spans more than two internal AXI 128-byte bursts,\nthe bus may corrupt the packet payload and the corrupt data may\ncause associated applications or the processor to hang.\n\nThe workaround for Errata #i2037 is to limit the maximum read\nrequest size and maximum payload size to 128 bytes. Add workaround\nfor Errata #i2037 here.\n\nThe errata and workaround is applicable only to AM65x SR 1.0 and\nlater versions of the silicon will have this fixed.\n\n[1] -> https://www.ti.com/lit/er/sprz452i/sprz452i.pdf', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47667', 'https://git.kernel.org/stable/c/135843c351c08df72bdd4b4ebea53c8052a76881', 'https://git.kernel.org/stable/c/576d0fb6f8d4bd4695e70eee173a1b9c7bae9572', 'https://git.kernel.org/stable/c/86f271f22bbb6391410a07e08d6ca3757fda01fa', 'https://git.kernel.org/stable/c/af218c803fe298ddf00abef331aa526b20d7ea61', 'https://git.kernel.org/stable/c/cfb006e185f64edbbdf7869eac352442bc76b8f6', 'https://git.kernel.org/stable/c/dd47051c76c8acd8cb983f01b4d1265da29cb66a', 'https://git.kernel.org/stable/c/ebbdbbc580c1695dec283d0ba6448729dc993246', 'https://lore.kernel.org/linux-cve-announce/2024100905-CVE-2024-47667-2d01@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47667', 'https://www.cve.org/CVERecord?id=CVE-2024-47667'], 'PublishedDate': '2024-10-09T15:15:15.43Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47668', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47668', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()\n\nIf we need to increase the tree depth, allocate a new node, and then\nrace with another thread that increased the tree depth before us, we'll\nstill have a preallocated node that might be used later.\n\nIf we then use that node for a new non-root node, it'll still have a\npointer to the old root instead of being zeroed - fix this by zeroing it\nin the cmpxchg failure path.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47668', 'https://git.kernel.org/stable/c/0f078f8ca93b28a34e20bd050f12cd4efeee7c0f', 'https://git.kernel.org/stable/c/0f27f4f445390cb7f73d4209cb2bf32834dc53da', 'https://git.kernel.org/stable/c/99418ec776a39609f50934720419e0b464ca2283', 'https://git.kernel.org/stable/c/ad5ee9feebc2eb8cfc76ed74a2d6e55343b0e169', 'https://git.kernel.org/stable/c/b2f11c6f3e1fc60742673b8675c95b78447f3dae', 'https://git.kernel.org/stable/c/d942e855324a60107025c116245095632476613e', 'https://git.kernel.org/stable/c/ebeff038744c498a036e7a92eb8e433ae0a386d7', 'https://lore.kernel.org/linux-cve-announce/2024100906-CVE-2024-47668-6b53@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47668', 'https://www.cve.org/CVERecord?id=CVE-2024-47668'], 'PublishedDate': '2024-10-09T15:15:15.513Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47669', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47669', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: fix state management in error path of log writing function', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix state management in error path of log writing function\n\nAfter commit a694291a6211 ("nilfs2: separate wait function from\nnilfs_segctor_write") was applied, the log writing function\nnilfs_segctor_do_construct() was able to issue I/O requests continuously\neven if user data blocks were split into multiple logs across segments,\nbut two potential flaws were introduced in its error handling.\n\nFirst, if nilfs_segctor_begin_construction() fails while creating the\nsecond or subsequent logs, the log writing function returns without\ncalling nilfs_segctor_abort_construction(), so the writeback flag set on\npages/folios will remain uncleared. This causes page cache operations to\nhang waiting for the writeback flag. For example,\ntruncate_inode_pages_final(), which is called via nilfs_evict_inode() when\nan inode is evicted from memory, will hang.\n\nSecond, the NILFS_I_COLLECTED flag set on normal inodes remain uncleared. \nAs a result, if the next log write involves checkpoint creation, that\'s\nfine, but if a partial log write is performed that does not, inodes with\nNILFS_I_COLLECTED set are erroneously removed from the "sc_dirty_files"\nlist, and their data and b-tree blocks may not be written to the device,\ncorrupting the block mapping.\n\nFix these issues by uniformly calling nilfs_segctor_abort_construction()\non failure of each step in the loop in nilfs_segctor_do_construct(),\nhaving it clean up logs and segment usages according to progress, and\ncorrecting the conditions for calling nilfs_redirty_inodes() to ensure\nthat the NILFS_I_COLLECTED flag is cleared.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47669', 'https://git.kernel.org/stable/c/036441e8438b29111fa75008f0ce305fb4e83c0a', 'https://git.kernel.org/stable/c/0a1a961bde4351dc047ffdeb2f1311ca16a700cc', 'https://git.kernel.org/stable/c/30562eff4a6dd35c4b5be9699ef61ad9f5f20a06', 'https://git.kernel.org/stable/c/3e349d7191f0688fc9808ef24fd4e4b4ef5ca876', 'https://git.kernel.org/stable/c/40a2757de2c376ef8a08d9ee9c81e77f3c750adf', 'https://git.kernel.org/stable/c/6576dd6695f2afca3f4954029ac4a64f82ba60ab', 'https://git.kernel.org/stable/c/74866c16ea2183f52925fa5d76061a1fe7f7737b', 'https://git.kernel.org/stable/c/efdde00d4a1ef10bb71e09ebc67823a3d3ad725b', 'https://lore.kernel.org/linux-cve-announce/2024100906-CVE-2024-47669-135c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47669', 'https://www.cve.org/CVERecord?id=CVE-2024-47669'], 'PublishedDate': '2024-10-09T15:15:15.59Z', 'LastModifiedDate': '2024-10-10T12:51:56.987Z'}, {'VulnerabilityID': 'CVE-2024-47670', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47670', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ocfs2: add bounds checking to ocfs2_xattr_find_entry()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: add bounds checking to ocfs2_xattr_find_entry()\n\nAdd a paranoia check to make sure it doesn't stray beyond valid memory\nregion containing ocfs2 xattr entries when scanning for a match. It will\nprevent out-of-bound access in case of crafted images.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47670', 'https://git.kernel.org/stable/c/1f6e167d6753fe3ea493cdc7f7de8d03147a4d39', 'https://git.kernel.org/stable/c/34759b7e4493d7337cbc414c132cef378c492a2c', 'https://git.kernel.org/stable/c/5bbe51eaf01a5dd6fb3f0dea81791e5dbc6dc6dd', 'https://git.kernel.org/stable/c/8e7bef408261746c160853fc27df3139659f5f77', 'https://git.kernel.org/stable/c/9b32539590a8e6400ac2f6e7cf9cbb8e08711a2f', 'https://git.kernel.org/stable/c/9e3041fecdc8f78a5900c3aa51d3d756e73264d6', 'https://lore.kernel.org/linux-cve-announce/2024100919-CVE-2024-47670-53f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47670', 'https://www.cve.org/CVERecord?id=CVE-2024-47670'], 'PublishedDate': '2024-10-09T15:15:15.673Z', 'LastModifiedDate': '2024-10-17T14:15:13.56Z'}, {'VulnerabilityID': 'CVE-2024-47671', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47671', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: USB: usbtmc: prevent kernel-usb-infoleak', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: usbtmc: prevent kernel-usb-infoleak\n\nThe syzbot reported a kernel-usb-infoleak in usbtmc_write,\nwe need to clear the structure before filling fields.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47671', 'https://git.kernel.org/stable/c/0c927dfc0b9bd177f7ab6ee59ef0c4ea06c110a7', 'https://git.kernel.org/stable/c/16e0ab9ed3ae7d19ca8ee718ba4e09d5c0f909ca', 'https://git.kernel.org/stable/c/51297ef7ad7824ad577337f273cd092e81a9fa08', 'https://git.kernel.org/stable/c/625fa77151f00c1bd00d34d60d6f2e710b3f9aad', 'https://git.kernel.org/stable/c/6c7fc36da021b13c34c572a26ba336cd102418f8', 'https://git.kernel.org/stable/c/ba6269e187aa1b1f20faf3c458831a0d6350304b', 'https://git.kernel.org/stable/c/e872738e670ddd63e19f22d0d784f0bdf26ecba5', 'https://lore.kernel.org/linux-cve-announce/2024100922-CVE-2024-47671-6c52@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47671', 'https://www.cve.org/CVERecord?id=CVE-2024-47671'], 'PublishedDate': '2024-10-09T15:15:15.753Z', 'LastModifiedDate': '2024-10-17T14:15:13.697Z'}, {'VulnerabilityID': 'CVE-2024-47672', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47672', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead\n\nThere is a WARNING in iwl_trans_wait_tx_queues_empty() (that was\nrecently converted from just a message), that can be hit if we\nwait for TX queues to become empty after firmware died. Clearly,\nwe can't expect anything from the firmware after it's declared dead.\n\nDon't call iwl_trans_wait_tx_queues_empty() in this case. While it could\nbe a good idea to stop the flow earlier, the flush functions do some\nmaintenance work that is not related to the firmware, so keep that part\nof the code running even when the firmware is not running.\n\n[edit commit message]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47672', 'https://git.kernel.org/stable/c/1afed66cb271b3e65fe9df1c9fba2bf4b1f55669', 'https://git.kernel.org/stable/c/1b0cd832c9607f41f84053b818e0b7908510a3b9', 'https://git.kernel.org/stable/c/3a84454f5204718ca5b4ad2c1f0bf2031e2403d1', 'https://git.kernel.org/stable/c/4d0a900ec470d392476c428875dbf053f8a0ae5e', 'https://git.kernel.org/stable/c/7188b7a72320367554b76d8f298417b070b05dd3', 'https://git.kernel.org/stable/c/de46b1d24f5f752b3bd8b46673c2ea4239661244', 'https://lore.kernel.org/linux-cve-announce/2024100922-CVE-2024-47672-9bef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47672', 'https://www.cve.org/CVERecord?id=CVE-2024-47672'], 'PublishedDate': '2024-10-09T15:15:15.827Z', 'LastModifiedDate': '2024-10-17T14:15:13.78Z'}, {'VulnerabilityID': 'CVE-2024-47673', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47673', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: pause TCM when the firmware is stopped\n\nNot doing so will make us send a host command to the transport while the\nfirmware is not alive, which will trigger a WARNING.\n\nbad state = 0\nWARNING: CPU: 2 PID: 17434 at drivers/net/wireless/intel/iwlwifi/iwl-trans.c:115 iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi]\nRIP: 0010:iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi]\nCall Trace:\n \n iwl_mvm_send_cmd+0x40/0xc0 [iwlmvm]\n iwl_mvm_config_scan+0x198/0x260 [iwlmvm]\n iwl_mvm_recalc_tcm+0x730/0x11d0 [iwlmvm]\n iwl_mvm_tcm_work+0x1d/0x30 [iwlmvm]\n process_one_work+0x29e/0x640\n worker_thread+0x2df/0x690\n ? rescuer_thread+0x540/0x540\n kthread+0x192/0x1e0\n ? set_kthread_struct+0x90/0x90\n ret_from_fork+0x22/0x30', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47673', 'https://git.kernel.org/stable/c/0668ebc8c2282ca1e7eb96092a347baefffb5fe7', 'https://git.kernel.org/stable/c/2c61b561baf92a2860c76c2302a62169e22c21cc', 'https://git.kernel.org/stable/c/55086c97a55d781b04a2667401c75ffde190135c', 'https://git.kernel.org/stable/c/5948a191906b54e10f02f6b7a7670243a39f99f4', 'https://git.kernel.org/stable/c/a15df5f37fa3a8b7a8ec7a339d1e897bc524e28f', 'https://lore.kernel.org/linux-cve-announce/2024100922-CVE-2024-47673-9110@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47673', 'https://www.cve.org/CVERecord?id=CVE-2024-47673'], 'PublishedDate': '2024-10-09T15:15:15.9Z', 'LastModifiedDate': '2024-10-17T14:15:13.853Z'}, {'VulnerabilityID': 'CVE-2024-47674', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-47674', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: avoid leaving partial pfn mappings around in error case', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: avoid leaving partial pfn mappings around in error case\n\nAs Jann points out, PFN mappings are special, because unlike normal\nmemory mappings, there is no lifetime information associated with the\nmapping - it is just a raw mapping of PFNs with no reference counting of\na 'struct page'.\n\nThat's all very much intentional, but it does mean that it's easy to\nmess up the cleanup in case of errors. Yes, a failed mmap() will always\neventually clean up any partial mappings, but without any explicit\nlifetime in the page table mapping itself, it's very easy to do the\nerror handling in the wrong order.\n\nIn particular, it's easy to mistakenly free the physical backing store\nbefore the page tables are actually cleaned up and (temporarily) have\nstale dangling PTE entries.\n\nTo make this situation less error-prone, just make sure that any partial\npfn mapping is torn down early, before any other error handling.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-47674', 'https://git.kernel.org/linus/79a61cc3fc0466ad2b7b89618a6157785f0293b3 (6.11)', 'https://git.kernel.org/stable/c/5b2c8b34f6d76bfbd1dd4936eb8a0fbfb9af3959', 'https://git.kernel.org/stable/c/65d0db500d7c07f0f76fc24a4d837791c4862cd2', 'https://git.kernel.org/stable/c/79a61cc3fc0466ad2b7b89618a6157785f0293b3', 'https://git.kernel.org/stable/c/954fd4c81f22c4b6ba65379a81fd252971bf4ef3', 'https://git.kernel.org/stable/c/a95a24fcaee1b892e47d5e6dcc403f713874ee80', 'https://lore.kernel.org/linux-cve-announce/2024101538-CVE-2024-47674-ba1f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-47674', 'https://www.cve.org/CVERecord?id=CVE-2024-47674'], 'PublishedDate': '2024-10-15T11:15:13.073Z', 'LastModifiedDate': '2024-10-18T14:50:02.71Z'}, {'VulnerabilityID': 'CVE-2017-0537', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-0537', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'An information disclosure vulnerability in the kernel USB gadget driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-31614969.', 'Severity': 'LOW', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N', 'V2Score': 2.6, 'V3Score': 4.7}}, 'References': ['http://www.securityfocus.com/bid/96831', 'http://www.securitytracker.com/id/1037968', 'https://android.googlesource.com/kernel/tegra.git/+/389b185cb2f17fff994dbdf8d4bac003d4b2b6b3%5E%21/#F0', 'https://lore.kernel.org/lkml/1484647168-30135-1-git-send-email-jilin@nvidia.com/#t', 'https://source.android.com/security/bulletin/2017-01-01.html', 'https://source.android.com/security/bulletin/2017-03-01', 'https://source.android.com/security/bulletin/2017-03-01.html', 'https://www.cve.org/CVERecord?id=CVE-2017-0537'], 'PublishedDate': '2017-03-08T01:59:03.127Z', 'LastModifiedDate': '2017-07-17T13:18:15.89Z'}, {'VulnerabilityID': 'CVE-2017-13165', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13165', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.', 'Severity': 'LOW', 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 4.6, 'V3Score': 7.8}}, 'References': ['https://github.com/aosp-mirror/platform_system_core/commit/15ffc53f6d57a46e3041453865311035a18e047a', 'https://source.android.com/security/bulletin/pixel/2017-12-01', 'https://www.cve.org/CVERecord?id=CVE-2017-13165'], 'PublishedDate': '2017-12-06T14:29:01.333Z', 'LastModifiedDate': '2019-10-03T00:03:26.223Z'}, {'VulnerabilityID': 'CVE-2017-13693', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2017-13693', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ACPI operand cache leak in dsutils.c', 'Description': 'The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.', 'Severity': 'LOW', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:C/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'V3Score': 3.3}}, 'References': ['http://www.securityfocus.com/bid/100502', 'https://access.redhat.com/security/cve/CVE-2017-13693', 'https://github.com/acpica/acpica/pull/295/commits/987a3b5cf7175916e2a4b6ea5b8e70f830dfe732', 'https://nvd.nist.gov/vuln/detail/CVE-2017-13693', 'https://patchwork.kernel.org/patch/9919053/', 'https://www.cve.org/CVERecord?id=CVE-2017-13693'], 'PublishedDate': '2017-08-25T08:29:00.273Z', 'LastModifiedDate': '2017-09-20T14:51:00.41Z'}, {'VulnerabilityID': 'CVE-2018-1121', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-1121', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'procps: process hiding through race condition enumerating /proc', 'Description': "procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.", 'Severity': 'LOW', 'CweIDs': ['CWE-362', 'CWE-367'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:P/A:N', 'V3Vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'V2Score': 4.3, 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L', 'V3Score': 3.9}}, 'References': ['http://seclists.org/oss-sec/2018/q2/122', 'http://www.securityfocus.com/bid/104214', 'https://access.redhat.com/security/cve/CVE-2018-1121', 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121', 'https://nvd.nist.gov/vuln/detail/CVE-2018-1121', 'https://www.cve.org/CVERecord?id=CVE-2018-1121', 'https://www.exploit-db.com/exploits/44806/', 'https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt'], 'PublishedDate': '2018-06-13T20:29:00.337Z', 'LastModifiedDate': '2020-06-30T16:15:14.393Z'}, {'VulnerabilityID': 'CVE-2018-12928', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12928', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: NULL pointer dereference in hfs_ext_read_extent in hfs.ko', 'Description': 'In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5}}, 'References': ['http://www.securityfocus.com/bid/104593', 'https://access.redhat.com/security/cve/CVE-2018-12928', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763384', 'https://groups.google.com/forum/#!msg/syzkaller-bugs/9SgQk_6tSZ4/zLhTm4r1AwAJ', 'https://lore.kernel.org/linux-fsdevel/20180418173028.GA30953@bombadil.infradead.org/', 'https://marc.info/?l=linux-fsdevel&m=152407263325766&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12928', 'https://www.cve.org/CVERecord?id=CVE-2018-12928'], 'PublishedDate': '2018-06-28T14:29:00.353Z', 'LastModifiedDate': '2018-08-21T11:55:37.35Z'}, {'VulnerabilityID': 'CVE-2018-12929', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12929', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free in ntfs_read_locked_inode in the ntfs.ko', 'Description': 'ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['http://www.securityfocus.com/bid/104588', 'https://access.redhat.com/errata/RHSA-2019:0641', 'https://access.redhat.com/security/cve/CVE-2018-12929', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403', 'https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12929', 'https://www.cve.org/CVERecord?id=CVE-2018-12929'], 'PublishedDate': '2018-06-28T14:29:00.417Z', 'LastModifiedDate': '2019-03-26T13:35:51.317Z'}, {'VulnerabilityID': 'CVE-2018-12930', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12930', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: stack-based out-of-bounds write in ntfs_end_buffer_async_read in the ntfs.ko', 'Description': 'ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 7.2, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['http://www.securityfocus.com/bid/104588', 'https://access.redhat.com/errata/RHSA-2019:0641', 'https://access.redhat.com/security/cve/CVE-2018-12930', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403', 'https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12930', 'https://www.cve.org/CVERecord?id=CVE-2018-12930'], 'PublishedDate': '2018-06-28T14:29:00.463Z', 'LastModifiedDate': '2019-03-26T13:35:37.397Z'}, {'VulnerabilityID': 'CVE-2018-12931', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-12931', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: stack-based out-of-bounds write in ntfs_attr_find in the ntfs.ko', 'Description': 'ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 7.2, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['http://www.securityfocus.com/bid/104588', 'https://access.redhat.com/errata/RHSA-2019:0641', 'https://access.redhat.com/security/cve/CVE-2018-12931', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403', 'https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2018-12931', 'https://www.cve.org/CVERecord?id=CVE-2018-12931'], 'PublishedDate': '2018-06-28T14:29:00.51Z', 'LastModifiedDate': '2019-03-26T13:35:20.957Z'}, {'VulnerabilityID': 'CVE-2019-14899', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-14899', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel', 'Description': 'A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.', 'Severity': 'LOW', 'CweIDs': ['CWE-300'], 'CVSS': {'nvd': {'V2Vector': 'AV:A/AC:M/Au:S/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 4.9, 'V3Score': 7.4}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.4}}, 'References': ['http://seclists.org/fulldisclosure/2020/Dec/32', 'http://seclists.org/fulldisclosure/2020/Jul/23', 'http://seclists.org/fulldisclosure/2020/Jul/24', 'http://seclists.org/fulldisclosure/2020/Jul/25', 'http://seclists.org/fulldisclosure/2020/Nov/20', 'http://www.openwall.com/lists/oss-security/2020/08/13/2', 'http://www.openwall.com/lists/oss-security/2020/10/07/3', 'http://www.openwall.com/lists/oss-security/2021/07/05/1', 'https://access.redhat.com/security/cve/CVE-2019-14899', 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899', 'https://nvd.nist.gov/vuln/detail/CVE-2019-14899', 'https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/', 'https://support.apple.com/kb/HT211288', 'https://support.apple.com/kb/HT211289', 'https://support.apple.com/kb/HT211290', 'https://support.apple.com/kb/HT211850', 'https://support.apple.com/kb/HT211931', 'https://www.cve.org/CVERecord?id=CVE-2019-14899', 'https://www.openwall.com/lists/oss-security/2019/12/05/1'], 'PublishedDate': '2019-12-11T15:15:14.263Z', 'LastModifiedDate': '2023-03-01T16:40:04.14Z'}, {'VulnerabilityID': 'CVE-2019-15213', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-15213', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free caused by malicious USB device in drivers/media/usb/dvb-usb/dvb-usb-init.c', 'Description': 'An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.', 'Severity': 'LOW', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 4.6}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 4.3}}, 'References': ['http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html', 'http://www.openwall.com/lists/oss-security/2019/08/20/2', 'https://access.redhat.com/security/cve/CVE-2019-15213', 'https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6cf97230cd5f36b7665099083272595c55d72be7', 'https://linux.oracle.com/cve/CVE-2019-15213.html', 'https://linux.oracle.com/errata/ELSA-2019-4872.html', 'https://lore.kernel.org/linux-media/fe983331d14442a96db3f71066ca0488a8921840.camel@decadent.org.uk/', 'https://nvd.nist.gov/vuln/detail/CVE-2019-15213', 'https://security.netapp.com/advisory/ntap-20190905-0002/', 'https://syzkaller.appspot.com/bug?id=a53c9c9dd2981bfdbfbcbc1ddbd35595eda8bced', 'https://www.cve.org/CVERecord?id=CVE-2019-15213'], 'PublishedDate': '2019-08-19T22:15:11.253Z', 'LastModifiedDate': '2023-11-09T14:44:33.733Z'}, {'VulnerabilityID': 'CVE-2019-19378', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-19378', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: out-of-bounds write in index_rbio_pages in fs/btrfs/raid56.c', 'Description': 'In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 6.8, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-19378', 'https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19378', 'https://nvd.nist.gov/vuln/detail/CVE-2019-19378', 'https://security.netapp.com/advisory/ntap-20200103-0001/', 'https://www.cve.org/CVERecord?id=CVE-2019-19378'], 'PublishedDate': '2019-11-29T17:15:11.84Z', 'LastModifiedDate': '2020-01-03T11:15:14.997Z'}, {'VulnerabilityID': 'CVE-2019-19814', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2019-19814', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: out-of-bounds write in __remove_dirty_segment in fs/f2fs/segment.c', 'Description': 'In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.', 'Severity': 'LOW', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'V2Score': 9.3, 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2019-19814', 'https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19814', 'https://nvd.nist.gov/vuln/detail/CVE-2019-19814', 'https://security.netapp.com/advisory/ntap-20200103-0001/', 'https://www.cve.org/CVERecord?id=CVE-2019-19814'], 'PublishedDate': '2019-12-17T06:15:12.843Z', 'LastModifiedDate': '2020-01-03T11:15:16.48Z'}, {'VulnerabilityID': 'CVE-2020-35501', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2020-35501', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: audit not logging access to syscall open_by_handle_at for users with CAP_DAC_READ_SEARCH capability', 'Description': 'A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem', 'Severity': 'LOW', 'CweIDs': ['CWE-863'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:P/A:N', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N', 'V2Score': 3.6, 'V3Score': 3.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 3.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2020-35501', 'https://bugzilla.redhat.com/show_bug.cgi?id=1908577', 'https://listman.redhat.com/archives/linux-audit/2018-July/msg00041.html', 'https://nvd.nist.gov/vuln/detail/CVE-2020-35501', 'https://www.cve.org/CVERecord?id=CVE-2020-35501', 'https://www.openwall.com/lists/oss-security/2021/02/18/1'], 'PublishedDate': '2022-03-30T16:15:08.673Z', 'LastModifiedDate': '2022-12-02T19:54:37.647Z'}, {'VulnerabilityID': 'CVE-2021-26934', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-26934', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'An issue was discovered in the Linux kernel 4.18 through 5.10.16, as u ...', 'Description': "An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.", 'Severity': 'LOW', 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:P/A:P', 'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V2Score': 4.6, 'V3Score': 7.8}}, 'References': ['http://xenbits.xen.org/xsa/advisory-363.html', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4GELN5E6MDR5KQBJF5M5COUUED3YFZTD/', 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOAJBVAVR6RSCUCHNXPVSNRPSFM7INMP/', 'https://nvd.nist.gov/vuln/detail/CVE-2021-26934', 'https://security.netapp.com/advisory/ntap-20210326-0001/', 'https://www.cve.org/CVERecord?id=CVE-2021-26934', 'https://www.openwall.com/lists/oss-security/2021/02/16/2', 'https://xenbits.xen.org/xsa/advisory-363.html'], 'PublishedDate': '2021-02-17T02:15:13.143Z', 'LastModifiedDate': '2023-11-07T03:31:50.59Z'}, {'VulnerabilityID': 'CVE-2022-44034', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-44034', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'Kernel: A use-after-free due to race between scr24x_open() and scr24x_remove()', 'Description': 'An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().', 'Severity': 'LOW', 'CweIDs': ['CWE-362'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-44034', 'https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b12f050c76f090cc6d0aebe0ef76fed79ec3f15', 'https://lore.kernel.org/lkml/20220916050333.GA188358%40ubuntu/', 'https://lore.kernel.org/lkml/20220916050333.GA188358@ubuntu/', 'https://lore.kernel.org/lkml/20220919101825.GA313940%40ubuntu/', 'https://lore.kernel.org/lkml/20220919101825.GA313940@ubuntu/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-44034', 'https://www.cve.org/CVERecord?id=CVE-2022-44034'], 'PublishedDate': '2022-10-30T01:15:08.937Z', 'LastModifiedDate': '2024-03-25T01:15:52.787Z'}, {'VulnerabilityID': 'CVE-2022-45884', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-45884', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free due to race condition occurring in dvb_register_device()', 'Description': 'An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.', 'Severity': 'LOW', 'CweIDs': ['CWE-362', 'CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2023:7549', 'https://access.redhat.com/security/cve/CVE-2022-45884', 'https://bugzilla.redhat.com/2148510', 'https://bugzilla.redhat.com/2148517', 'https://bugzilla.redhat.com/2151956', 'https://bugzilla.redhat.com/2154178', 'https://bugzilla.redhat.com/2224048', 'https://bugzilla.redhat.com/2240249', 'https://bugzilla.redhat.com/2241924', 'https://bugzilla.redhat.com/show_bug.cgi?id=2148510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2148517', 'https://bugzilla.redhat.com/show_bug.cgi?id=2151956', 'https://bugzilla.redhat.com/show_bug.cgi?id=2154178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2224048', 'https://bugzilla.redhat.com/show_bug.cgi?id=2240249', 'https://bugzilla.redhat.com/show_bug.cgi?id=2241924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45884', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45919', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1192', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2163', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3812', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5178', 'https://errata.almalinux.org/8/ALSA-2023-7549.html', 'https://errata.rockylinux.org/RLSA-2023:7549', 'https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=627bb528b086b4136315c25d6a447a98ea9448d3', 'https://linux.oracle.com/cve/CVE-2022-45884.html', 'https://linux.oracle.com/errata/ELSA-2023-7549.html', 'https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel%40gmail.com/', 'https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel@gmail.com/', 'https://lore.kernel.org/linux-media/20221115131822.6640-4-imv4bel%40gmail.com/', 'https://lore.kernel.org/linux-media/20221115131822.6640-4-imv4bel@gmail.com/', 'https://lore.kernel.org/linux-media/20221117045925.14297-4-imv4bel@gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-45884', 'https://security.netapp.com/advisory/ntap-20230113-0006/', 'https://www.cve.org/CVERecord?id=CVE-2022-45884'], 'PublishedDate': '2022-11-25T04:15:09.18Z', 'LastModifiedDate': '2024-03-25T01:15:52.84Z'}, {'VulnerabilityID': 'CVE-2023-33053', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-33053', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Description': 'Memory corruption in Kernel while parsing metadata.', 'Severity': 'LOW', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://git.codelinaro.org/clo/la/kernel/msm-5.4/-/commit/06426824a281c9aef5bf0c50927eae9c7431db1e', 'https://www.cve.org/CVERecord?id=CVE-2023-33053', 'https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin'], 'PublishedDate': '2023-12-05T03:15:11.707Z', 'LastModifiedDate': '2024-04-12T16:15:18.403Z'}, {'VulnerabilityID': 'CVE-2023-4010', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-4010', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: hcd: malformed USB descriptor leads to infinite loop in usb_giveback_urb()', 'Description': 'A flaw was found in the USB Host Controller Driver framework in the Linux kernel. The usb_giveback_urb function has a logic loophole in its implementation. Due to the inappropriate judgment condition of the goto statement, the function cannot return under the input of a specific malformed descriptor file, so it falls into an endless loop, resulting in a denial of service.', 'Severity': 'LOW', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-4010', 'https://bugzilla.redhat.com/show_bug.cgi?id=2227726', 'https://github.com/wanrenmi/a-usb-kernel-bug', 'https://github.com/wanrenmi/a-usb-kernel-bug/issues/1', 'https://nvd.nist.gov/vuln/detail/CVE-2023-4010', 'https://www.cve.org/CVERecord?id=CVE-2023-4010'], 'PublishedDate': '2023-07-31T17:15:10.277Z', 'LastModifiedDate': '2023-11-07T04:22:02.797Z'}, {'VulnerabilityID': 'CVE-2023-6238', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-6238', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: memory corruption via unprivileged user passthrough', 'Description': 'A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.', 'Severity': 'LOW', 'CweIDs': ['CWE-120'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-6238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2250834', 'https://lore.kernel.org/linux-nvme/20231013051458.39987-1-joshi.k@samsung.com/T/#u', 'https://lore.kernel.org/linux-nvme/20231016060519.231880-1-joshi.k@samsung.com/T/#u', 'https://nvd.nist.gov/vuln/detail/CVE-2023-6238', 'https://www.cve.org/CVERecord?id=CVE-2023-6238'], 'PublishedDate': '2023-11-21T21:15:09.273Z', 'LastModifiedDate': '2024-02-07T00:15:55.24Z'}, {'VulnerabilityID': 'CVE-2024-0564', 'PkgID': 'linux-aws-6.8-tools-6.8.0-1015@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-aws-6.8-tools-6.8.0-1015', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-0564', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: max page sharing of Kernel Samepage Merging (KSM) may cause memory deduplication', 'Description': 'A flaw was found in the Linux kernel\'s memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the unmap to merge with the victim\'s page. The unmapping time depends on whether it merges with the victim\'s page and additional physical pages are created beyond the KSM\'s "max page share". Through these operations, the attacker can leak the victim\'s page.', 'Severity': 'LOW', 'CweIDs': ['CWE-99', 'CWE-203'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-0564', 'https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1680513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2258514', 'https://link.springer.com/conference/wisa', 'https://nvd.nist.gov/vuln/detail/CVE-2024-0564', 'https://wisa.or.kr/accepted', 'https://www.cve.org/CVERecord?id=CVE-2024-0564'], 'PublishedDate': '2024-01-30T15:15:08.687Z', 'LastModifiedDate': '2024-10-16T15:15:14.11Z'}, {'VulnerabilityID': 'CVE-2024-43882', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43882', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: exec: Fix ToCToU between perm check and set-uid/gid usage', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Fix ToCToU between perm check and set-uid/gid usage\n\nWhen opening a file for exec via do_filp_open(), permission checking is\ndone against the file\'s metadata at that moment, and on success, a file\npointer is passed back. Much later in the execve() code path, the file\nmetadata (specifically mode, uid, and gid) is used to determine if/how\nto set the uid and gid. However, those values may have changed since the\npermissions check, meaning the execution may gain unintended privileges.\n\nFor example, if a file could change permissions from executable and not\nset-id:\n\n---------x 1 root root 16048 Aug 7 13:16 target\n\nto set-id and non-executable:\n\n---S------ 1 root root 16048 Aug 7 13:16 target\n\nit is possible to gain root privileges when execution should have been\ndisallowed.\n\nWhile this race condition is rare in real-world scenarios, it has been\nobserved (and proven exploitable) when package managers are updating\nthe setuid bits of installed programs. Such files start with being\nworld-executable but then are adjusted to be group-exec with a set-uid\nbit. For example, "chmod o-x,u+s target" makes "target" executable only\nby uid "root" and gid "cdrom", while also becoming setuid-root:\n\n-rwxr-xr-x 1 root cdrom 16048 Aug 7 13:16 target\n\nbecomes:\n\n-rwsr-xr-- 1 root cdrom 16048 Aug 7 13:16 target\n\nBut racing the chmod means users without group "cdrom" membership can\nget the permission to execute "target" just before the chmod, and when\nthe chmod finishes, the exec reaches brpm_fill_uid(), and performs the\nsetuid to root, violating the expressed authorization of "only cdrom\ngroup members can setuid to root".\n\nRe-check that we still have execute permissions in case the metadata\nhas changed. It would be better to keep a copy from the perm-check time,\nbut until we can do that refactoring, the least-bad option is to do a\nfull inode_permission() call (under inode lock). It is understood that\nthis is safe against dead-locks, but hardly optimal.', 'Severity': 'HIGH', 'CweIDs': ['CWE-367'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43882', 'https://git.kernel.org/linus/f50733b45d865f91db90919f8311e2127ce5a0cb (6.11-rc4)', 'https://git.kernel.org/stable/c/15469d46ba34559bfe7e3de6659115778c624759', 'https://git.kernel.org/stable/c/368f6985d46657b8b466a421dddcacd4051f7ada', 'https://git.kernel.org/stable/c/90dfbba89ad4f0d9c9744ecbb1adac4aa2ff4f3e', 'https://git.kernel.org/stable/c/9b424c5d4130d56312e2a3be17efb0928fec4d64', 'https://git.kernel.org/stable/c/d2a2a4714d80d09b0f8eb6438ab4224690b7121e', 'https://git.kernel.org/stable/c/d5c3c7e26275a2d83b894d30f7582a42853a958f', 'https://git.kernel.org/stable/c/f50733b45d865f91db90919f8311e2127ce5a0cb', 'https://git.kernel.org/stable/c/f6cfc6bcfd5e1cf76115b6450516ea4c99897ae1', 'https://linux.oracle.com/cve/CVE-2024-43882.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082152-CVE-2024-43882-4fa4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43882', 'https://www.cve.org/CVERecord?id=CVE-2024-43882'], 'PublishedDate': '2024-08-21T01:15:12.34Z', 'LastModifiedDate': '2024-09-03T13:25:39.747Z'}, {'VulnerabilityID': 'CVE-2013-7445', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2013-7445', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memory exhaustion via crafted Graphics Execution Manager (GEM) objects', 'Description': 'The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-399'], 'CVSS': {'nvd': {'V2Vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:C', 'V2Score': 7.8}, 'redhat': {'V2Vector': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'V2Score': 4.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2013-7445', 'https://bugzilla.kernel.org/show_bug.cgi?id=60533', 'https://lists.freedesktop.org/archives/dri-devel/2015-September/089778.html (potential start towards fixing)', 'https://nvd.nist.gov/vuln/detail/CVE-2013-7445', 'https://www.cve.org/CVERecord?id=CVE-2013-7445'], 'PublishedDate': '2015-10-16T01:59:00.12Z', 'LastModifiedDate': '2015-10-16T16:22:25.587Z'}, {'VulnerabilityID': 'CVE-2015-8553', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2015-8553', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'xen: non-maskable interrupts triggerable by guests (xsa120)', 'Description': 'Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:P/I:N/A:N', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N', 'V2Score': 2.1, 'V3Score': 6.5}, 'redhat': {'V2Vector': 'AV:A/AC:M/Au:S/C:N/I:N/A:C', 'V2Score': 5.2}}, 'References': ['http://thread.gmane.org/gmane.linux.kernel/1924087/focus=1930758 (regression mention)', 'http://xenbits.xen.org/xsa/advisory-120.html', 'https://access.redhat.com/security/cve/CVE-2015-8553', 'https://nvd.nist.gov/vuln/detail/CVE-2015-8553', 'https://seclists.org/bugtraq/2019/Aug/18', 'https://www.cve.org/CVERecord?id=CVE-2015-8553', 'https://www.debian.org/security/2019/dsa-4497'], 'PublishedDate': '2016-04-13T15:59:07.307Z', 'LastModifiedDate': '2019-08-13T23:15:11.203Z'}, {'VulnerabilityID': 'CVE-2016-8660', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2016-8660', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: local DoS due to a page lock order bug in the XFS seek hole/data implementation', 'Description': 'The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implementation."', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-19'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 5.5}, 'redhat': {'V2Vector': 'AV:L/AC:M/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.7, 'V3Score': 5.5}}, 'References': ['http://www.openwall.com/lists/oss-security/2016/10/13/8', 'http://www.securityfocus.com/bid/93558', 'https://access.redhat.com/security/cve/CVE-2016-8660', 'https://bugzilla.redhat.com/show_bug.cgi?id=1384851', 'https://lore.kernel.org/linux-xfs/895314622.769515.1476375930648.JavaMail.zimbra@redhat.com/', 'https://marc.info/?l=linux-fsdevel&m=147639177409294&w=2', 'https://marc.info/?l=linux-xfs&m=149498118228320&w=2', 'https://nvd.nist.gov/vuln/detail/CVE-2016-8660', 'https://www.cve.org/CVERecord?id=CVE-2016-8660'], 'PublishedDate': '2016-10-16T21:59:14.333Z', 'LastModifiedDate': '2016-11-28T20:41:02.59Z'}, {'VulnerabilityID': 'CVE-2018-17977', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2018-17977', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service', 'Description': 'The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-400'], 'CVSS': {'nvd': {'V2Vector': 'AV:L/AC:L/Au:N/C:N/I:N/A:C', 'V3Vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V2Score': 4.9, 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.9}}, 'References': ['http://www.securityfocus.com/bid/105539', 'https://access.redhat.com/security/cve/CVE-2018-17977', 'https://bugzilla.suse.com/show_bug.cgi?id=1111609', 'https://nvd.nist.gov/vuln/detail/CVE-2018-17977', 'https://www.cve.org/CVERecord?id=CVE-2018-17977', 'https://www.openwall.com/lists/oss-security/2018/10/05/5'], 'PublishedDate': '2018-10-08T17:29:00.653Z', 'LastModifiedDate': '2018-11-26T15:51:30.427Z'}, {'VulnerabilityID': 'CVE-2021-3714', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-3714', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Remote Page Deduplication Attacks', 'Description': 'A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-200'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.9}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-3714', 'https://arxiv.org/abs/2111.08553', 'https://arxiv.org/pdf/2111.08553.pdf', 'https://bugzilla.redhat.com/show_bug.cgi?id=1931327', 'https://nvd.nist.gov/vuln/detail/CVE-2021-3714', 'https://www.cve.org/CVERecord?id=CVE-2021-3714'], 'PublishedDate': '2022-08-23T16:15:09.6Z', 'LastModifiedDate': '2024-02-01T18:51:23.66Z'}, {'VulnerabilityID': 'CVE-2021-47599', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-47599', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: use latest_dev in btrfs_show_devname', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: use latest_dev in btrfs_show_devname\n\nThe test case btrfs/238 reports the warning below:\n\n WARNING: CPU: 3 PID: 481 at fs/btrfs/super.c:2509 btrfs_show_devname+0x104/0x1e8 [btrfs]\n CPU: 2 PID: 1 Comm: systemd Tainted: G W O 5.14.0-rc1-custom #72\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n Call trace:\n btrfs_show_devname+0x108/0x1b4 [btrfs]\n show_mountinfo+0x234/0x2c4\n m_show+0x28/0x34\n seq_read_iter+0x12c/0x3c4\n vfs_read+0x29c/0x2c8\n ksys_read+0x80/0xec\n __arm64_sys_read+0x28/0x34\n invoke_syscall+0x50/0xf8\n do_el0_svc+0x88/0x138\n el0_svc+0x2c/0x8c\n el0t_64_sync_handler+0x84/0xe4\n el0t_64_sync+0x198/0x19c\n\nReason:\nWhile btrfs_prepare_sprout() moves the fs_devices::devices into\nfs_devices::seed_list, the btrfs_show_devname() searches for the devices\nand found none, leading to the warning as in above.\n\nFix:\nlatest_dev is updated according to the changes to the device list.\nThat means we could use the latest_dev->name to show the device name in\n/proc/self/mounts, the pointer will be always valid as it's assigned\nbefore the device is deleted from the list in remove or replace.\nThe RCU protection is sufficient as the device structure is freed after\nsynchronization.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-47599', 'https://git.kernel.org/linus/6605fd2f394bba0a0059df2b6cfc87b0b6d393a2 (5.16-rc1)', 'https://git.kernel.org/stable/c/6605fd2f394bba0a0059df2b6cfc87b0b6d393a2', 'https://git.kernel.org/stable/c/e342c2558016ead462f376b6c6c2ac5efc17f3b1', 'https://lore.kernel.org/linux-cve-announce/2024061921-CVE-2021-47599-37b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2021-47599', 'https://www.cve.org/CVERecord?id=CVE-2021-47599'], 'PublishedDate': '2024-06-19T15:15:54.483Z', 'LastModifiedDate': '2024-06-20T12:43:25.663Z'}, {'VulnerabilityID': 'CVE-2021-47615', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2021-47615', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/mlx5: Fix releasing unallocated memory in dereg MR flow', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix releasing unallocated memory in dereg MR flow\n\nFor the case of IB_MR_TYPE_DM the mr does doesn't have a umem, even though\nit is a user MR. This causes function mlx5_free_priv_descs() to think that\nit is a kernel MR, leading to wrongly accessing mr->descs that will get\nwrong values in the union which leads to attempt to release resources that\nwere not allocated in the first place.\n\nFor example:\n DMA-API: mlx5_core 0000:08:00.1: device driver tries to free DMA memory it has not allocated [device address=0x0000000000000000] [size=0 bytes]\n WARNING: CPU: 8 PID: 1021 at kernel/dma/debug.c:961 check_unmap+0x54f/0x8b0\n RIP: 0010:check_unmap+0x54f/0x8b0\n Call Trace:\n debug_dma_unmap_page+0x57/0x60\n mlx5_free_priv_descs+0x57/0x70 [mlx5_ib]\n mlx5_ib_dereg_mr+0x1fb/0x3d0 [mlx5_ib]\n ib_dereg_mr_user+0x60/0x140 [ib_core]\n uverbs_destroy_uobject+0x59/0x210 [ib_uverbs]\n uobj_destroy+0x3f/0x80 [ib_uverbs]\n ib_uverbs_cmd_verbs+0x435/0xd10 [ib_uverbs]\n ? uverbs_finalize_object+0x50/0x50 [ib_uverbs]\n ? lock_acquire+0xc4/0x2e0\n ? lock_acquired+0x12/0x380\n ? lock_acquire+0xc4/0x2e0\n ? lock_acquire+0xc4/0x2e0\n ? ib_uverbs_ioctl+0x7c/0x140 [ib_uverbs]\n ? lock_release+0x28a/0x400\n ib_uverbs_ioctl+0xc0/0x140 [ib_uverbs]\n ? ib_uverbs_ioctl+0x7c/0x140 [ib_uverbs]\n __x64_sys_ioctl+0x7f/0xb0\n do_syscall_64+0x38/0x90\n\nFix it by reorganizing the dereg flow and mlx5_ib_mr structure:\n - Move the ib_umem field into the user MRs structure in the union as it's\n applicable only there.\n - Function mlx5_ib_dereg_mr() will now call mlx5_free_priv_descs() only\n in case there isn't udata, which indicates that this isn't a user MR.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2021-47615', 'https://git.kernel.org/linus/f0ae4afe3d35e67db042c58a52909e06262b740f (5.16-rc5)', 'https://git.kernel.org/stable/c/c44979ace49b4aede3cc7cb5542316e53a4005c9', 'https://git.kernel.org/stable/c/e3bc4d4b50cae7db08e50dbe43f771c906e97701', 'https://git.kernel.org/stable/c/f0ae4afe3d35e67db042c58a52909e06262b740f', 'https://lore.kernel.org/linux-cve-announce/2024061909-CVE-2021-47615-3c6a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2021-47615', 'https://www.cve.org/CVERecord?id=CVE-2021-47615'], 'PublishedDate': '2024-06-19T15:15:56.03Z', 'LastModifiedDate': '2024-06-20T12:43:25.663Z'}, {'VulnerabilityID': 'CVE-2022-0400', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-0400', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Out of bounds read in the smc protocol stack', 'Description': 'An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 7.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-0400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2040604', 'https://bugzilla.redhat.com/show_bug.cgi?id=2040604 (not public)', 'https://bugzilla.redhat.com/show_bug.cgi?id=2044575', 'https://nvd.nist.gov/vuln/detail/CVE-2022-0400', 'https://www.cve.org/CVERecord?id=CVE-2022-0400'], 'PublishedDate': '2022-08-29T15:15:09.423Z', 'LastModifiedDate': '2022-09-01T20:18:18.247Z'}, {'VulnerabilityID': 'CVE-2022-0480', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-0480', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion', 'Description': 'A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-0480', 'https://bugzilla.redhat.com/show_bug.cgi?id=2049700', 'https://git.kernel.org/linus/0f12156dff2862ac54235fc72703f18770769042 (5.15-rc1)', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0f12156dff2862ac54235fc72703f18770769042', 'https://github.com/kata-containers/kata-containers/issues/3373', 'https://linux.oracle.com/cve/CVE-2022-0480.html', 'https://linux.oracle.com/errata/ELSA-2024-2394.html', 'https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm%40linux-foundation.org/', 'https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm@linux-foundation.org/', 'https://nvd.nist.gov/vuln/detail/CVE-2022-0480', 'https://ubuntu.com/security/CVE-2022-0480', 'https://www.cve.org/CVERecord?id=CVE-2022-0480'], 'PublishedDate': '2022-08-29T15:15:09.477Z', 'LastModifiedDate': '2023-03-03T18:49:53.213Z'}, {'VulnerabilityID': 'CVE-2022-3238', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-3238', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously', 'Description': 'A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-415', 'CWE-459'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-3238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2127927', 'https://nvd.nist.gov/vuln/detail/CVE-2022-3238', 'https://www.cve.org/CVERecord?id=CVE-2022-3238'], 'PublishedDate': '2022-11-14T21:15:16.163Z', 'LastModifiedDate': '2022-11-17T20:24:18.537Z'}, {'VulnerabilityID': 'CVE-2022-48846', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: release rq qos structures for queue without disk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: release rq qos structures for queue without disk\n\nblkcg_init_queue() may add rq qos structures to request queue, previously\nblk_cleanup_queue() calls rq_qos_exit() to release them, but commit\n8e141f9eb803 ("block: drain file system I/O on del_gendisk")\nmoves rq_qos_exit() into del_gendisk(), so memory leak is caused\nbecause queues may not have disk, such as un-present scsi luns, nvme\nadmin queue, ...\n\nFixes the issue by adding rq_qos_exit() to blk_cleanup_queue() back.\n\nBTW, v5.18 won\'t need this patch any more since we move\nblkcg_init_queue()/blkcg_exit_queue() into disk allocation/release\nhandler, and patches have been in for-5.18/block.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48846', 'https://git.kernel.org/linus/daaca3522a8e67c46e39ef09c1d542e866f85f3b (5.17)', 'https://git.kernel.org/stable/c/60c2c8e2ef3a3ec79de8cbc80a06ca0c21df8c29', 'https://git.kernel.org/stable/c/d4ad8736ac982111bb0be8306bf19c8207f6600e', 'https://git.kernel.org/stable/c/daaca3522a8e67c46e39ef09c1d542e866f85f3b', 'https://lore.kernel.org/linux-cve-announce/2024071623-CVE-2022-48846-a1a8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48846', 'https://www.cve.org/CVERecord?id=CVE-2022-48846'], 'PublishedDate': '2024-07-16T13:15:11.883Z', 'LastModifiedDate': '2024-07-24T17:56:26.767Z'}, {'VulnerabilityID': 'CVE-2022-48929', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2022-48929', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids.', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix crash due to out of bounds access into reg2btf_ids.\n\nWhen commit e6ac2450d6de ("bpf: Support bpf program calling kernel function") added\nkfunc support, it defined reg2btf_ids as a cheap way to translate the verifier\nreg type to the appropriate btf_vmlinux BTF ID, however\ncommit c25b2ae13603 ("bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL")\nmoved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after\nthe base register types, and defined other variants using type flag\ncomposition. However, now, the direct usage of reg->type to index into\nreg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to\nout of bounds access and kernel crash on dereference of bad pointer.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-125'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2022-48929', 'https://git.kernel.org/linus/45ce4b4f9009102cd9f581196d480a59208690c1 (5.17-rc6)', 'https://git.kernel.org/stable/c/45ce4b4f9009102cd9f581196d480a59208690c1', 'https://git.kernel.org/stable/c/8c39925e98d498b9531343066ef82ae39e41adae', 'https://git.kernel.org/stable/c/f0ce1bc9e0235dd7412240be493d7ea65ed9eadc', 'https://lore.kernel.org/linux-cve-announce/2024082222-CVE-2022-48929-857d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2022-48929', 'https://www.cve.org/CVERecord?id=CVE-2022-48929'], 'PublishedDate': '2024-08-22T04:15:15.773Z', 'LastModifiedDate': '2024-08-23T02:00:22.653Z'}, {'VulnerabilityID': 'CVE-2023-0030', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-0030', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Use after Free in nvkm_vmm_pfn_map', 'Description': 'A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-0030', 'https://bugzilla.redhat.com/show_bug.cgi?id=2157270', 'https://git.kernel.org/linus/729eba3355674f2d9524629b73683ba1d1cd3f10 (5.0-rc1)', 'https://github.com/torvalds/linux/commit/729eba3355674f2d9524629b73683ba1d1cd3f10', 'https://lore.kernel.org/all/20221230072758.443644-1-zyytlz.wz@163.com/', 'https://lore.kernel.org/all/63d485b2.170a0220.4af4c.d54f@mx.google.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-0030', 'https://security.netapp.com/advisory/ntap-20230413-0010/', 'https://www.cve.org/CVERecord?id=CVE-2023-0030'], 'PublishedDate': '2023-03-08T23:15:10.963Z', 'LastModifiedDate': '2023-04-13T17:15:09.433Z'}, {'VulnerabilityID': 'CVE-2023-0160', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-0160', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: possibility of deadlock in libbpf function sock_hash_delete_elem', 'Description': 'A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667', 'CWE-833'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-0160', 'https://bugzilla.redhat.com/show_bug.cgi?id=2159764', 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ed17aa92dc56', 'https://lore.kernel.org/all/20230406122622.109978-1-liuxin350@huawei.com/', 'https://lore.kernel.org/all/CABcoxUayum5oOqFMMqAeWuS8+EzojquSOSyDA3J_2omY=2EeAg@mail.gmail.com/', 'https://lore.kernel.org/bpf/000000000000f1db9605f939720e@google.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-0160', 'https://www.cve.org/CVERecord?id=CVE-2023-0160'], 'PublishedDate': '2023-07-18T17:15:11.313Z', 'LastModifiedDate': '2023-11-07T03:59:46.343Z'}, {'VulnerabilityID': 'CVE-2023-1193', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-1193', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: use-after-free in setup_async_work()', 'Description': 'A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 6.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-1193', 'https://bugzilla.redhat.com/show_bug.cgi?id=2154177', 'https://lkml.kernel.org/linux-cifs/20230401084951.6085-2-linkinjeon@kernel.org/T/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-1193', 'https://www.cve.org/CVERecord?id=CVE-2023-1193'], 'PublishedDate': '2023-11-01T20:15:08.663Z', 'LastModifiedDate': '2023-11-09T15:13:51.737Z'}, {'VulnerabilityID': 'CVE-2023-26242', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-26242', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the ...', 'Description': 'afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://bugzilla.suse.com/show_bug.cgi?id=1208518', 'https://lore.kernel.org/all/20230206054326.89323-1-k1rh4.lee@gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-26242', 'https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee%40gmail.com', 'https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee@gmail.com/', 'https://security.netapp.com/advisory/ntap-20230406-0002/', 'https://www.cve.org/CVERecord?id=CVE-2023-26242'], 'PublishedDate': '2023-02-21T01:15:11.423Z', 'LastModifiedDate': '2024-03-25T01:15:53.57Z'}, {'VulnerabilityID': 'CVE-2023-31082', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-31082', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sleeping function called from an invalid context in gsmld_write', 'Description': 'An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-763'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-31082', 'https://bugzilla.suse.com/show_bug.cgi?id=1210781', 'https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A%40mail.gmail.com/', 'https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A@mail.gmail.com/', 'https://nvd.nist.gov/vuln/detail/CVE-2023-31082', 'https://security.netapp.com/advisory/ntap-20230929-0003/', 'https://www.cve.org/CVERecord?id=CVE-2023-31082'], 'PublishedDate': '2023-04-24T06:15:07.783Z', 'LastModifiedDate': '2024-08-02T15:16:00.853Z'}, {'VulnerabilityID': 'CVE-2023-52879', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52879', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Have trace_event_file have ref counters', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have trace_event_file have ref counters\n\nThe following can crash the kernel:\n\n # cd /sys/kernel/tracing\n # echo \'p:sched schedule\' > kprobe_events\n # exec 5>>events/kprobes/sched/enable\n # > kprobe_events\n # exec 5>&-\n\nThe above commands:\n\n 1. Change directory to the tracefs directory\n 2. Create a kprobe event (doesn\'t matter what one)\n 3. Open bash file descriptor 5 on the enable file of the kprobe event\n 4. Delete the kprobe event (removes the files too)\n 5. Close the bash file descriptor 5\n\nThe above causes a crash!\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 6 PID: 877 Comm: bash Not tainted 6.5.0-rc4-test-00008-g2c6b6b1029d4-dirty #186\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\n RIP: 0010:tracing_release_file_tr+0xc/0x50\n\nWhat happens here is that the kprobe event creates a trace_event_file\n"file" descriptor that represents the file in tracefs to the event. It\nmaintains state of the event (is it enabled for the given instance?).\nOpening the "enable" file gets a reference to the event "file" descriptor\nvia the open file descriptor. When the kprobe event is deleted, the file is\nalso deleted from the tracefs system which also frees the event "file"\ndescriptor.\n\nBut as the tracefs file is still opened by user space, it will not be\ntotally removed until the final dput() is called on it. But this is not\ntrue with the event "file" descriptor that is already freed. If the user\ndoes a write to or simply closes the file descriptor it will reference the\nevent "file" descriptor that was just freed, causing a use-after-free bug.\n\nTo solve this, add a ref count to the event "file" descriptor as well as a\nnew flag called "FREED". The "file" will not be freed until the last\nreference is released. But the FREE flag will be set when the event is\nremoved to prevent any more modifications to that event from happening,\neven if there\'s still a reference to the event "file" descriptor.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-52879', 'https://git.kernel.org/linus/bb32500fb9b78215e4ef6ee8b4345c5f5d7eafb4 (6.7-rc1)', 'https://git.kernel.org/stable/c/2c9de867ca285c397cd71af703763fe416265706', 'https://git.kernel.org/stable/c/2fa74d29fc1899c237d51bf9a6e132ea5c488976', 'https://git.kernel.org/stable/c/9034c87d61be8cff989017740a91701ac8195a1d', 'https://git.kernel.org/stable/c/961c4511c7578d6b8f39118be919016ec3db1c1e', 'https://git.kernel.org/stable/c/a98172e36e5f1b3d29ad71fade2d611cfcc2fe6f', 'https://git.kernel.org/stable/c/bb32500fb9b78215e4ef6ee8b4345c5f5d7eafb4', 'https://git.kernel.org/stable/c/cbc7c29dff0fa18162f2a3889d82eeefd67305e0', 'https://lore.kernel.org/linux-cve-announce/2024052122-CVE-2023-52879-fa4d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52879', 'https://www.cve.org/CVERecord?id=CVE-2023-52879'], 'PublishedDate': '2024-05-21T16:15:24.53Z', 'LastModifiedDate': '2024-05-21T16:53:56.55Z'}, {'VulnerabilityID': 'CVE-2023-52889', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2023-52889', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: apparmor: Fix null pointer deref when receiving skb during sock creation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: Fix null pointer deref when receiving skb during sock creation\n\nThe panic below is observed when receiving ICMP packets with secmark set\nwhile an ICMP raw socket is being created. SK_CTX(sk)->label is updated\nin apparmor_socket_post_create(), but the packet is delivered to the\nsocket before that, causing the null pointer dereference.\nDrop the packet if label context is not set.\n\n BUG: kernel NULL pointer dereference, address: 000000000000004c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 PID: 407 Comm: a.out Not tainted 6.4.12-arch1-1 #1 3e6fa2753a2d75925c34ecb78e22e85a65d083df\n Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 05/28/2020\n RIP: 0010:aa_label_next_confined+0xb/0x40\n Code: 00 00 48 89 ef e8 d5 25 0c 00 e9 66 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 89 f0 <8b> 77 4c 39 c6 7e 1f 48 63 d0 48 8d 14 d7 eb 0b 83 c0 01 48 83 c2\n RSP: 0018:ffffa92940003b08 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 000000000000000e\n RDX: ffffa92940003be8 RSI: 0000000000000000 RDI: 0000000000000000\n RBP: ffff8b57471e7800 R08: ffff8b574c642400 R09: 0000000000000002\n R10: ffffffffbd820eeb R11: ffffffffbeb7ff00 R12: ffff8b574c642400\n R13: 0000000000000001 R14: 0000000000000001 R15: 0000000000000000\n FS: 00007fb092ea7640(0000) GS:ffff8b577bc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000004c CR3: 00000001020f2005 CR4: 00000000007706f0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? aa_label_next_confined+0xb/0x40\n apparmor_secmark_check+0xec/0x330\n security_sock_rcv_skb+0x35/0x50\n sk_filter_trim_cap+0x47/0x250\n sock_queue_rcv_skb_reason+0x20/0x60\n raw_rcv+0x13c/0x210\n raw_local_deliver+0x1f3/0x250\n ip_protocol_deliver_rcu+0x4f/0x2f0\n ip_local_deliver_finish+0x76/0xa0\n __netif_receive_skb_one_core+0x89/0xa0\n netif_receive_skb+0x119/0x170\n ? __netdev_alloc_skb+0x3d/0x140\n vmxnet3_rq_rx_complete+0xb23/0x1010 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a]\n vmxnet3_poll_rx_only+0x36/0xb0 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a]\n __napi_poll+0x28/0x1b0\n net_rx_action+0x2a4/0x380\n __do_softirq+0xd1/0x2c8\n __irq_exit_rcu+0xbb/0xf0\n common_interrupt+0x86/0xa0\n \n \n asm_common_interrupt+0x26/0x40\n RIP: 0010:apparmor_socket_post_create+0xb/0x200\n Code: 08 48 85 ff 75 a1 eb b1 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 <55> 48 89 fd 53 45 85 c0 0f 84 b2 00 00 00 48 8b 1d 80 56 3f 02 48\n RSP: 0018:ffffa92940ce7e50 EFLAGS: 00000286\n RAX: ffffffffbc756440 RBX: 0000000000000000 RCX: 0000000000000001\n RDX: 0000000000000003 RSI: 0000000000000002 RDI: ffff8b574eaab740\n RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff8b57444cec70 R11: 0000000000000000 R12: 0000000000000003\n R13: 0000000000000002 R14: ffff8b574eaab740 R15: ffffffffbd8e4748\n ? __pfx_apparmor_socket_post_create+0x10/0x10\n security_socket_post_create+0x4b/0x80\n __sock_create+0x176/0x1f0\n __sys_socket+0x89/0x100\n __x64_sys_socket+0x17/0x20\n do_syscall_64+0x5d/0x90\n ? do_syscall_64+0x6c/0x90\n ? do_syscall_64+0x6c/0x90\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2023-52889', 'https://git.kernel.org/linus/fce09ea314505a52f2436397608fa0a5d0934fb1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0abe35bc48d4ec80424b1f4b3560c0e082cbd5c1', 'https://git.kernel.org/stable/c/290a6b88e8c19b6636ed1acc733d1458206f7697', 'https://git.kernel.org/stable/c/347dcb84a4874b5fb375092c08d8cc4069b94f81', 'https://git.kernel.org/stable/c/46c17ead5b7389e22e7dc9903fd0ba865d05bda2', 'https://git.kernel.org/stable/c/6c920754f62cefc63fccdc38a062c7c3452e2961', 'https://git.kernel.org/stable/c/ead2ad1d9f045f26fdce3ef1644913b3a6cd38f2', 'https://git.kernel.org/stable/c/fce09ea314505a52f2436397608fa0a5d0934fb1', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2023-52889-cdd0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2023-52889', 'https://www.cve.org/CVERecord?id=CVE-2023-52889'], 'PublishedDate': '2024-08-17T09:15:07.073Z', 'LastModifiedDate': '2024-08-19T21:19:16.97Z'}, {'VulnerabilityID': 'CVE-2024-26713', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-26713', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: powerpc/pseries/iommu: Fix iommu initialisation during DLPAR add', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: Fix iommu initialisation during DLPAR add\n\nWhen a PCI device is dynamically added, the kernel oopses with a NULL\npointer dereference:\n\n BUG: Kernel NULL pointer dereference on read at 0x00000030\n Faulting instruction address: 0xc0000000006bbe5c\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: rpadlpar_io rpaphp rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs xsk_diag bonding nft_compat nf_tables nfnetlink rfkill binfmt_misc dm_multipath rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi ib_ipoib rdma_cm iw_cm ib_cm mlx5_ib ib_uverbs ib_core pseries_rng drm drm_panel_orientation_quirks xfs libcrc32c mlx5_core mlxfw sd_mod t10_pi sg tls ibmvscsi ibmveth scsi_transport_srp vmx_crypto pseries_wdt psample dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 17 PID: 2685 Comm: drmgr Not tainted 6.7.0-203405+ #66\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c0000000006bbe5c LR: c000000000a13e68 CTR: c0000000000579f8\n REGS: c00000009924f240 TRAP: 0300 Not tainted (6.7.0-203405+)\n MSR: 8000000000009033 CR: 24002220 XER: 20040006\n CFAR: c000000000a13e64 DAR: 0000000000000030 DSISR: 40000000 IRQMASK: 0\n ...\n NIP sysfs_add_link_to_group+0x34/0x94\n LR iommu_device_link+0x5c/0x118\n Call Trace:\n iommu_init_device+0x26c/0x318 (unreliable)\n iommu_device_link+0x5c/0x118\n iommu_init_device+0xa8/0x318\n iommu_probe_device+0xc0/0x134\n iommu_bus_notifier+0x44/0x104\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n bus_notify+0x50/0x7c\n device_add+0x640/0x918\n pci_device_add+0x23c/0x298\n of_create_pci_dev+0x400/0x884\n of_scan_pci_dev+0x124/0x1b0\n __of_scan_bus+0x78/0x18c\n pcibios_scan_phb+0x2a4/0x3b0\n init_phb_dynamic+0xb8/0x110\n dlpar_add_slot+0x170/0x3b8 [rpadlpar_io]\n add_slot_store.part.0+0xb4/0x130 [rpadlpar_io]\n kobj_attr_store+0x2c/0x48\n sysfs_kf_write+0x64/0x78\n kernfs_fop_write_iter+0x1b0/0x290\n vfs_write+0x350/0x4a0\n ksys_write+0x84/0x140\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nCommit a940904443e4 ("powerpc/iommu: Add iommu_ops to report capabilities\nand allow blocking domains") broke DLPAR add of PCI devices.\n\nThe above added iommu_device structure to pci_controller. During\nsystem boot, PCI devices are discovered and this newly added iommu_device\nstructure is initialized by a call to iommu_device_register().\n\nDuring DLPAR add of a PCI device, a new pci_controller structure is\nallocated but there are no calls made to iommu_device_register()\ninterface.\n\nFix is to register the iommu device during DLPAR add as well.\n\n[mpe: Trim oops and tweak some change log wording]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-26713', 'https://git.kernel.org/linus/ed8b94f6e0acd652ce69bd69d678a0c769172df8 (6.8-rc5)', 'https://git.kernel.org/stable/c/9978d5b744e0227afe19e3bcb4c5f75442dde753', 'https://git.kernel.org/stable/c/d4f762d6403f7419de90d7749fa83dd92ffb0e1d', 'https://git.kernel.org/stable/c/ed8b94f6e0acd652ce69bd69d678a0c769172df8', 'https://lore.kernel.org/linux-cve-announce/2024040342-CVE-2024-26713-1b52@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-26713', 'https://www.cve.org/CVERecord?id=CVE-2024-26713'], 'PublishedDate': '2024-04-03T15:15:53.647Z', 'LastModifiedDate': '2024-04-03T17:24:18.15Z'}, {'VulnerabilityID': 'CVE-2024-27025', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-27025', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nbd: null check for nla_nest_start', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: null check for nla_nest_start\n\nnla_nest_start() may fail and return NULL. Insert a check and set errno\nbased on other call sites within the same source code.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:5102', 'https://access.redhat.com/security/cve/CVE-2024-27025', 'https://bugzilla.redhat.com/2263879', 'https://bugzilla.redhat.com/2265645', 'https://bugzilla.redhat.com/2265797', 'https://bugzilla.redhat.com/2266341', 'https://bugzilla.redhat.com/2266347', 'https://bugzilla.redhat.com/2266497', 'https://bugzilla.redhat.com/2267787', 'https://bugzilla.redhat.com/2268118', 'https://bugzilla.redhat.com/2269070', 'https://bugzilla.redhat.com/2269211', 'https://bugzilla.redhat.com/2270084', 'https://bugzilla.redhat.com/2270100', 'https://bugzilla.redhat.com/2271686', 'https://bugzilla.redhat.com/2271688', 'https://bugzilla.redhat.com/2272782', 'https://bugzilla.redhat.com/2272795', 'https://bugzilla.redhat.com/2273109', 'https://bugzilla.redhat.com/2273174', 'https://bugzilla.redhat.com/2273236', 'https://bugzilla.redhat.com/2273242', 'https://bugzilla.redhat.com/2273247', 'https://bugzilla.redhat.com/2273268', 'https://bugzilla.redhat.com/2273427', 'https://bugzilla.redhat.com/2273654', 'https://bugzilla.redhat.com/2275565', 'https://bugzilla.redhat.com/2275573', 'https://bugzilla.redhat.com/2275580', 'https://bugzilla.redhat.com/2275694', 'https://bugzilla.redhat.com/2275711', 'https://bugzilla.redhat.com/2275748', 'https://bugzilla.redhat.com/2275761', 'https://bugzilla.redhat.com/2275928', 'https://bugzilla.redhat.com/2277166', 'https://bugzilla.redhat.com/2277238', 'https://bugzilla.redhat.com/2277840', 'https://bugzilla.redhat.com/2278176', 'https://bugzilla.redhat.com/2278178', 'https://bugzilla.redhat.com/2278182', 'https://bugzilla.redhat.com/2278218', 'https://bugzilla.redhat.com/2278256', 'https://bugzilla.redhat.com/2278258', 'https://bugzilla.redhat.com/2278277', 'https://bugzilla.redhat.com/2278279', 'https://bugzilla.redhat.com/2278380', 'https://bugzilla.redhat.com/2278484', 'https://bugzilla.redhat.com/2278515', 'https://bugzilla.redhat.com/2278535', 'https://bugzilla.redhat.com/2278539', 'https://bugzilla.redhat.com/2278989', 'https://bugzilla.redhat.com/2280440', 'https://bugzilla.redhat.com/2281054', 'https://bugzilla.redhat.com/2281133', 'https://bugzilla.redhat.com/2281149', 'https://bugzilla.redhat.com/2281207', 'https://bugzilla.redhat.com/2281215', 'https://bugzilla.redhat.com/2281221', 'https://bugzilla.redhat.com/2281235', 'https://bugzilla.redhat.com/2281268', 'https://bugzilla.redhat.com/2281326', 'https://bugzilla.redhat.com/2281360', 'https://bugzilla.redhat.com/2281510', 'https://bugzilla.redhat.com/2281519', 'https://bugzilla.redhat.com/2281636', 'https://bugzilla.redhat.com/2281641', 'https://bugzilla.redhat.com/2281664', 'https://bugzilla.redhat.com/2281667', 'https://bugzilla.redhat.com/2281672', 'https://bugzilla.redhat.com/2281675', 'https://bugzilla.redhat.com/2281682', 'https://bugzilla.redhat.com/2281725', 'https://bugzilla.redhat.com/2281752', 'https://bugzilla.redhat.com/2281758', 'https://bugzilla.redhat.com/2281819', 'https://bugzilla.redhat.com/2281821', 'https://bugzilla.redhat.com/2281833', 'https://bugzilla.redhat.com/2281938', 'https://bugzilla.redhat.com/2281949', 'https://bugzilla.redhat.com/2281968', 'https://bugzilla.redhat.com/2281989', 'https://bugzilla.redhat.com/2282328', 'https://bugzilla.redhat.com/2282373', 'https://bugzilla.redhat.com/2282479', 'https://bugzilla.redhat.com/2282553', 'https://bugzilla.redhat.com/2282615', 'https://bugzilla.redhat.com/2282623', 'https://bugzilla.redhat.com/2282640', 'https://bugzilla.redhat.com/2282642', 'https://bugzilla.redhat.com/2282645', 'https://bugzilla.redhat.com/2282717', 'https://bugzilla.redhat.com/2282719', 'https://bugzilla.redhat.com/2282727', 'https://bugzilla.redhat.com/2282742', 'https://bugzilla.redhat.com/2282743', 'https://bugzilla.redhat.com/2282744', 'https://bugzilla.redhat.com/2282759', 'https://bugzilla.redhat.com/2282763', 'https://bugzilla.redhat.com/2282766', 'https://bugzilla.redhat.com/2282772', 'https://bugzilla.redhat.com/2282780', 'https://bugzilla.redhat.com/2282887', 'https://bugzilla.redhat.com/2282896', 'https://bugzilla.redhat.com/2282923', 'https://bugzilla.redhat.com/2282925', 'https://bugzilla.redhat.com/2282950', 'https://bugzilla.redhat.com/2283401', 'https://bugzilla.redhat.com/2283894', 'https://bugzilla.redhat.com/2284400', 'https://bugzilla.redhat.com/2284417', 'https://bugzilla.redhat.com/2284421', 'https://bugzilla.redhat.com/2284474', 'https://bugzilla.redhat.com/2284477', 'https://bugzilla.redhat.com/2284488', 'https://bugzilla.redhat.com/2284496', 'https://bugzilla.redhat.com/2284500', 'https://bugzilla.redhat.com/2284513', 'https://bugzilla.redhat.com/2284519', 'https://bugzilla.redhat.com/2284539', 'https://bugzilla.redhat.com/2284541', 'https://bugzilla.redhat.com/2284556', 'https://bugzilla.redhat.com/2284571', 'https://bugzilla.redhat.com/2284590', 'https://bugzilla.redhat.com/2284625', 'https://bugzilla.redhat.com/2290408', 'https://bugzilla.redhat.com/2292331', 'https://bugzilla.redhat.com/2293078', 'https://bugzilla.redhat.com/2293250', 'https://bugzilla.redhat.com/2293276', 'https://bugzilla.redhat.com/2293312', 'https://bugzilla.redhat.com/2293316', 'https://bugzilla.redhat.com/2293348', 'https://bugzilla.redhat.com/2293371', 'https://bugzilla.redhat.com/2293383', 'https://bugzilla.redhat.com/2293418', 'https://bugzilla.redhat.com/2293420', 'https://bugzilla.redhat.com/2293444', 'https://bugzilla.redhat.com/2293461', 'https://bugzilla.redhat.com/2293653', 'https://bugzilla.redhat.com/2293657', 'https://bugzilla.redhat.com/2293684', 'https://bugzilla.redhat.com/2293687', 'https://bugzilla.redhat.com/2293700', 'https://bugzilla.redhat.com/2293711', 'https://bugzilla.redhat.com/2294274', 'https://bugzilla.redhat.com/2295914', 'https://bugzilla.redhat.com/2296067', 'https://bugzilla.redhat.com/2297056', 'https://bugzilla.redhat.com/2297474', 'https://bugzilla.redhat.com/2297511', 'https://bugzilla.redhat.com/2298108', 'https://bugzilla.redhat.com/show_bug.cgi?id=2263879', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265650', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265797', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266341', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266347', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266497', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266594', 'https://bugzilla.redhat.com/show_bug.cgi?id=2267787', 'https://bugzilla.redhat.com/show_bug.cgi?id=2268118', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269070', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269211', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270084', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270100', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271686', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271688', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272782', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272795', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273109', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273117', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273174', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273242', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273247', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273427', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273654', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275565', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275573', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275580', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275694', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275748', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275761', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275928', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277840', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278176', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278182', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278218', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278256', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278258', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278277', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278279', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278380', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278484', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278515', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278535', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2280440', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281054', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281133', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281149', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281189', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281190', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281207', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281215', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281221', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281235', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281326', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281360', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281636', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281641', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281664', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281667', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281675', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281682', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281725', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281752', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281758', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281819', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281821', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281833', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281938', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281949', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281968', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282328', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282373', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282479', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282553', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282615', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282623', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282640', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282642', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282690', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282717', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282719', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282727', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282742', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282743', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282759', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282763', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282766', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282772', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282780', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282887', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282896', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282923', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282925', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282950', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283401', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283894', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284417', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284421', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284465', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284477', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284488', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284496', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284500', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284541', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284556', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284571', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284590', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284625', 'https://bugzilla.redhat.com/show_bug.cgi?id=2290408', 'https://bugzilla.redhat.com/show_bug.cgi?id=2292331', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293078', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293250', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293276', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293312', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293316', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293348', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293367', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293371', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293383', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293418', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293420', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293444', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293461', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293653', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293657', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293684', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293687', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2294274', 'https://bugzilla.redhat.com/show_bug.cgi?id=2295914', 'https://bugzilla.redhat.com/show_bug.cgi?id=2296067', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297056', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297558', 'https://bugzilla.redhat.com/show_bug.cgi?id=2298108', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47018', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47257', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47304', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47373', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47408', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47468', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47491', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47548', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47579', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48743', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48747', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52451', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52463', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52469', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52471', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52486', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52530', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52619', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52622', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52623', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52648', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52653', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52662', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52679', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52707', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52730', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52756', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52762', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52764', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52775', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52777', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52784', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52791', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52796', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52803', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52811', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52832', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52845', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52864', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2201', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25739', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26586', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26614', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26640', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26686', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26698', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26704', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26772', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26773', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26802', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26837', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26840', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26843', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26852', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26870', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26878', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26908', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26961', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27011', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27019', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27065', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27388', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27395', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27434', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31076', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33621', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35790', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35801', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35807', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35814', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35824', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35876', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35893', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35897', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35899', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35900', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35910', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35912', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35930', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35937', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35938', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35952', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36000', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36005', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36006', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36016', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36017', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36270', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36489', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36917', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36929', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36933', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36941', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36945', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36950', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36954', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36971', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36978', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36979', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38538', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38555', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38573', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38575', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38596', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38598', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38615', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38627', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39276', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39472', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39476', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39487', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39502', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40974', 'https://errata.almalinux.org/8/ALSA-2024-5102.html', 'https://errata.rockylinux.org/RLSA-2024:5101', 'https://git.kernel.org/linus/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d (6.9-rc1)', 'https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d', 'https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19e', 'https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dced', 'https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8', 'https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797', 'https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983', 'https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596a', 'https://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcf', 'https://linux.oracle.com/cve/CVE-2024-27025.html', 'https://linux.oracle.com/errata/ELSA-2024-5101.html', 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'https://lore.kernel.org/linux-cve-announce/2024050107-CVE-2024-27025-babd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-27025', 'https://www.cve.org/CVERecord?id=CVE-2024-27025'], 'PublishedDate': '2024-05-01T13:15:48.89Z', 'LastModifiedDate': '2024-06-25T22:15:28.24Z'}, {'VulnerabilityID': 'CVE-2024-35928', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35928', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()\n\nThis ensures that the memory mapped by ioremap for adev->rmmio, is\nproperly handled in amdgpu_device_init(). If the function exits early\ndue to an error, the memory is unmapped. If the function completes\nsuccessfully, the memory remains mapped.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/amdgpu_device.c:4337 amdgpu_device_init() warn: 'adev->rmmio' from ioremap() not released on lines: 4035,4045,4051,4058,4068,4337", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35928', 'https://git.kernel.org/linus/eb4f139888f636614dab3bcce97ff61cefc4b3a7 (6.9-rc1)', 'https://git.kernel.org/stable/c/14ac934db851642ea8cd1bd4121c788a8899ef69', 'https://git.kernel.org/stable/c/aa665c3a2aca2ffe31b9645bda278e96dfc3b55c', 'https://git.kernel.org/stable/c/c5f9fe2c1e5023fa096189a8bfba6420aa035587', 'https://git.kernel.org/stable/c/eb4f139888f636614dab3bcce97ff61cefc4b3a7', 'https://lore.kernel.org/linux-cve-announce/2024051915-CVE-2024-35928-ead3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35928', 'https://www.cve.org/CVERecord?id=CVE-2024-35928'], 'PublishedDate': '2024-05-19T11:15:48.93Z', 'LastModifiedDate': '2024-05-20T13:00:04.957Z'}, {'VulnerabilityID': 'CVE-2024-35948', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35948', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bcachefs: Check for journal entries overruning end of sb clean section', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: Check for journal entries overruning end of sb clean section\n\nFix a missing bounds check in superblock validation.\n\nNote that we don't yet have repair code for this case - repair code for\nindividual items is generally low priority, since the whole superblock\nis checksummed, validated prior to write, and we have backups.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-400'], 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35948', 'https://git.kernel.org/linus/fcdbc1d7a4b638e5d5668de461f320386f3002aa (6.9-rc6)', 'https://git.kernel.org/stable/c/fcdbc1d7a4b638e5d5668de461f320386f3002aa', 'https://lore.kernel.org/linux-cve-announce/2024052043-CVE-2024-35948-a92f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35948', 'https://www.cve.org/CVERecord?id=CVE-2024-35948'], 'PublishedDate': '2024-05-20T10:15:09.44Z', 'LastModifiedDate': '2024-07-03T02:02:27.897Z'}, {'VulnerabilityID': 'CVE-2024-35995', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-35995', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Use access_width over bit_width for system memory accesses\n\nTo align with ACPI 6.3+, since bit_width can be any 8-bit value, it\ncannot be depended on to be always on a clean 8b boundary. This was\nuncovered on the Cobalt 100 platform.\n\nSError Interrupt on CPU26, code 0xbe000011 -- SError\n CPU: 26 PID: 1510 Comm: systemd-udevd Not tainted 5.15.2.1-13 #1\n Hardware name: MICROSOFT CORPORATION, BIOS MICROSOFT CORPORATION\n pstate: 62400009 (nZCv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)\n pc : cppc_get_perf_caps+0xec/0x410\n lr : cppc_get_perf_caps+0xe8/0x410\n sp : ffff8000155ab730\n x29: ffff8000155ab730 x28: ffff0080139d0038 x27: ffff0080139d0078\n x26: 0000000000000000 x25: ffff0080139d0058 x24: 00000000ffffffff\n x23: ffff0080139d0298 x22: ffff0080139d0278 x21: 0000000000000000\n x20: ffff00802b251910 x19: ffff0080139d0000 x18: ffffffffffffffff\n x17: 0000000000000000 x16: ffffdc7e111bad04 x15: ffff00802b251008\n x14: ffffffffffffffff x13: ffff013f1fd63300 x12: 0000000000000006\n x11: ffffdc7e128f4420 x10: 0000000000000000 x9 : ffffdc7e111badec\n x8 : ffff00802b251980 x7 : 0000000000000000 x6 : ffff0080139d0028\n x5 : 0000000000000000 x4 : ffff0080139d0018 x3 : 00000000ffffffff\n x2 : 0000000000000008 x1 : ffff8000155ab7a0 x0 : 0000000000000000\n Kernel panic - not syncing: Asynchronous SError Interrupt\n CPU: 26 PID: 1510 Comm: systemd-udevd Not tainted\n5.15.2.1-13 #1\n Hardware name: MICROSOFT CORPORATION, BIOS MICROSOFT CORPORATION\n Call trace:\n dump_backtrace+0x0/0x1e0\n show_stack+0x24/0x30\n dump_stack_lvl+0x8c/0xb8\n dump_stack+0x18/0x34\n panic+0x16c/0x384\n add_taint+0x0/0xc0\n arm64_serror_panic+0x7c/0x90\n arm64_is_fatal_ras_serror+0x34/0xa4\n do_serror+0x50/0x6c\n el1h_64_error_handler+0x40/0x74\n el1h_64_error+0x7c/0x80\n cppc_get_perf_caps+0xec/0x410\n cppc_cpufreq_cpu_init+0x74/0x400 [cppc_cpufreq]\n cpufreq_online+0x2dc/0xa30\n cpufreq_add_dev+0xc0/0xd4\n subsys_interface_register+0x134/0x14c\n cpufreq_register_driver+0x1b0/0x354\n cppc_cpufreq_init+0x1a8/0x1000 [cppc_cpufreq]\n do_one_initcall+0x50/0x250\n do_init_module+0x60/0x27c\n load_module+0x2300/0x2570\n __do_sys_finit_module+0xa8/0x114\n __arm64_sys_finit_module+0x2c/0x3c\n invoke_syscall+0x78/0x100\n el0_svc_common.constprop.0+0x180/0x1a0\n do_el0_svc+0x84/0xa0\n el0_svc+0x2c/0xc0\n el0t_64_sync_handler+0xa4/0x12c\n el0t_64_sync+0x1a4/0x1a8\n\nInstead, use access_width to determine the size and use the offset and\nwidth to shift and mask the bits to read/write out. Make sure to add a\ncheck for system memory since pcc redefines the access_width to\nsubspace id.\n\nIf access_width is not set, then fall back to using bit_width.\n\n[ rjw: Subject and changelog edits, comment adjustments ]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-35995', 'https://git.kernel.org/linus/2f4a4d63a193be6fd530d180bb13c3592052904c (6.9-rc1)', 'https://git.kernel.org/stable/c/01fc53be672acae37e611c80cc0b4f3939584de3', 'https://git.kernel.org/stable/c/1b890ae474d19800a6be1696df7fb4d9a41676e4', 'https://git.kernel.org/stable/c/2f4a4d63a193be6fd530d180bb13c3592052904c', 'https://git.kernel.org/stable/c/4949affd5288b867cdf115f5b08d6166b2027f87', 'https://git.kernel.org/stable/c/6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1', 'https://git.kernel.org/stable/c/6dfd79ed04c578f1d9a9a41ba5b2015cf9f03fc3', 'https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2', 'https://lore.kernel.org/linux-cve-announce/2024052021-CVE-2024-35995-abbc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-35995', 'https://www.cve.org/CVERecord?id=CVE-2024-35995'], 'PublishedDate': '2024-05-20T10:15:13.597Z', 'LastModifiedDate': '2024-05-20T13:00:04.957Z'}, {'VulnerabilityID': 'CVE-2024-36885', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-36885', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()\n\nCurrently, enabling SG_DEBUG in the kernel will cause nouveau to hit a\nBUG() on startup:\n\n kernel BUG at include/linux/scatterlist.h:187!\n invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 7 PID: 930 Comm: (udev-worker) Not tainted 6.9.0-rc3Lyude-Test+ #30\n Hardware name: MSI MS-7A39/A320M GAMING PRO (MS-7A39), BIOS 1.I0 01/22/2019\n RIP: 0010:sg_init_one+0x85/0xa0\n Code: 69 88 32 01 83 e1 03 f6 c3 03 75 20 a8 01 75 1e 48 09 cb 41 89 54\n 24 08 49 89 1c 24 41 89 6c 24 0c 5b 5d 41 5c e9 7b b9 88 00 <0f> 0b 0f 0b\n 0f 0b 48 8b 05 5e 46 9a 01 eb b2 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffa776017bf6a0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffffa77600d87000 RCX: 000000000000002b\n RDX: 0000000000000001 RSI: 0000000000000000 RDI: ffffa77680d87000\n RBP: 000000000000e000 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff98f4c46aa508 R11: 0000000000000000 R12: ffff98f4c46aa508\n R13: ffff98f4c46aa008 R14: ffffa77600d4a000 R15: ffffa77600d4a018\n FS: 00007feeb5aae980(0000) GS:ffff98f5c4dc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f22cb9a4520 CR3: 00000001043ba000 CR4: 00000000003506f0\n Call Trace:\n \n ? die+0x36/0x90\n ? do_trap+0xdd/0x100\n ? sg_init_one+0x85/0xa0\n ? do_error_trap+0x65/0x80\n ? sg_init_one+0x85/0xa0\n ? exc_invalid_op+0x50/0x70\n ? sg_init_one+0x85/0xa0\n ? asm_exc_invalid_op+0x1a/0x20\n ? sg_init_one+0x85/0xa0\n nvkm_firmware_ctor+0x14a/0x250 [nouveau]\n nvkm_falcon_fw_ctor+0x42/0x70 [nouveau]\n ga102_gsp_booter_ctor+0xb4/0x1a0 [nouveau]\n r535_gsp_oneinit+0xb3/0x15f0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? nvkm_udevice_new+0x95/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? ktime_get+0x47/0xb0\n ? srso_return_thunk+0x5/0x5f\n nvkm_subdev_oneinit_+0x4f/0x120 [nouveau]\n nvkm_subdev_init_+0x39/0x140 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n nvkm_subdev_init+0x44/0x90 [nouveau]\n nvkm_device_init+0x166/0x2e0 [nouveau]\n nvkm_udevice_init+0x47/0x70 [nouveau]\n nvkm_object_init+0x41/0x1c0 [nouveau]\n nvkm_ioctl_new+0x16a/0x290 [nouveau]\n ? __pfx_nvkm_client_child_new+0x10/0x10 [nouveau]\n ? __pfx_nvkm_udevice_new+0x10/0x10 [nouveau]\n nvkm_ioctl+0x126/0x290 [nouveau]\n nvif_object_ctor+0x112/0x190 [nouveau]\n nvif_device_ctor+0x23/0x60 [nouveau]\n nouveau_cli_init+0x164/0x640 [nouveau]\n nouveau_drm_device_init+0x97/0x9e0 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n ? pci_update_current_state+0x72/0xb0\n ? srso_return_thunk+0x5/0x5f\n nouveau_drm_probe+0x12c/0x280 [nouveau]\n ? srso_return_thunk+0x5/0x5f\n local_pci_probe+0x45/0xa0\n pci_device_probe+0xc7/0x270\n really_probe+0xe6/0x3a0\n __driver_probe_device+0x87/0x160\n driver_probe_device+0x1f/0xc0\n __driver_attach+0xec/0x1f0\n ? __pfx___driver_attach+0x10/0x10\n bus_for_each_dev+0x88/0xd0\n bus_add_driver+0x116/0x220\n driver_register+0x59/0x100\n ? __pfx_nouveau_drm_init+0x10/0x10 [nouveau]\n do_one_initcall+0x5b/0x320\n do_init_module+0x60/0x250\n init_module_from_file+0x86/0xc0\n idempotent_init_module+0x120/0x2b0\n __x64_sys_finit_module+0x5e/0xb0\n do_syscall_64+0x83/0x160\n ? srso_return_thunk+0x5/0x5f\n entry_SYSCALL_64_after_hwframe+0x71/0x79\n RIP: 0033:0x7feeb5cc20cd\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89\n f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0\n ff ff 73 01 c3 48 8b 0d 1b cd 0c 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffcf220b2c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n RAX: ffffffffffffffda RBX: 000055fdd2916aa0 RCX: 00007feeb5cc20cd\n RDX: 0000000000000000 RSI: 000055fdd29161e0 RDI: 0000000000000035\n RBP: 00007ffcf220b380 R08: 00007feeb5d8fb20 R09: 00007ffcf220b310\n R10: 000055fdd2909dc0 R11: 0000000000000246 R12: 000055\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-36885', 'https://git.kernel.org/linus/52a6947bf576b97ff8e14bb0a31c5eaf2d0d96e2 (6.9-rc7)', 'https://git.kernel.org/stable/c/1a88c18da464db0ba8ea25196d0a06490f65322e', 'https://git.kernel.org/stable/c/52a6947bf576b97ff8e14bb0a31c5eaf2d0d96e2', 'https://git.kernel.org/stable/c/e05af009302893f39b072811a68fa4a196284c75', 'https://lore.kernel.org/linux-cve-announce/2024053032-CVE-2024-36885-cb0b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-36885', 'https://www.cve.org/CVERecord?id=CVE-2024-36885'], 'PublishedDate': '2024-05-30T16:15:12.067Z', 'LastModifiedDate': '2024-05-30T18:18:58.87Z'}, {'VulnerabilityID': 'CVE-2024-36970', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-36970', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: iwlwifi: Use request_module_nowait', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: Use request_module_nowait\n\nThis appears to work around a deadlock regression that came in\nwith the LED merge in 6.9.\n\nThe deadlock happens on my system with 24 iwlwifi radios, so maybe\nit something like all worker threads are busy and some work that needs\nto complete cannot complete.\n\n[also remove unnecessary "load_module" var and now-wrong comment]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-36970', 'https://git.kernel.org/linus/3d913719df14c28c4d3819e7e6d150760222bda4 (6.10-rc1)', 'https://git.kernel.org/stable/c/3d913719df14c28c4d3819e7e6d150760222bda4', 'https://git.kernel.org/stable/c/d20013259539e2fde2deeac85354851097afdf9e', 'https://lore.kernel.org/linux-cve-announce/2024060855-CVE-2024-36970-2eb9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-36970', 'https://www.cve.org/CVERecord?id=CVE-2024-36970'], 'PublishedDate': '2024-06-08T13:15:58.26Z', 'LastModifiedDate': '2024-06-10T02:52:08.267Z'}, {'VulnerabilityID': 'CVE-2024-38581', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-38581', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/mes: fix use-after-free issue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/mes: fix use-after-free issue\n\nDelete fence fallback timer to fix the ramdom\nuse-after-free issue.\n\nv2: move to amdgpu_mes.c', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-38581', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/948255282074d9367e01908b3f5dcf8c10fc9c3d (6.9-rc6)', 'https://git.kernel.org/stable/c/0f98c144c15c8fc0f3176c994bd4e727ef718a5c', 'https://git.kernel.org/stable/c/39cfce75168c11421d70b8c0c65f6133edccb82a', 'https://git.kernel.org/stable/c/70b1bf6d9edc8692d241f59a65f073aec6d501de', 'https://git.kernel.org/stable/c/948255282074d9367e01908b3f5dcf8c10fc9c3d', 'https://linux.oracle.com/cve/CVE-2024-38581.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024061948-CVE-2024-38581-592d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-38581', 'https://www.cve.org/CVERecord?id=CVE-2024-38581'], 'PublishedDate': '2024-06-19T14:15:18.15Z', 'LastModifiedDate': '2024-08-01T20:12:00.623Z'}, {'VulnerabilityID': 'CVE-2024-38608', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-38608', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Fix netif state handling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix netif state handling\n\nmlx5e_suspend cleans resources only if netif_device_present() returns\ntrue. However, mlx5e_resume changes the state of netif, via\nmlx5e_nic_enable, only if reg_state == NETREG_REGISTERED.\nIn the below case, the above leads to NULL-ptr Oops[1] and memory\nleaks:\n\nmlx5e_probe\n _mlx5e_resume\n mlx5e_attach_netdev\n mlx5e_nic_enable <-- netdev not reg, not calling netif_device_attach()\n register_netdev <-- failed for some reason.\nERROR_FLOW:\n _mlx5e_suspend <-- netif_device_present return false, resources aren't freed :(\n\nHence, clean resources in this case as well.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0010 [#1] SMP\nCPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at0xffffffffffffffd6.\nRSP: 0018:ffff888178aaf758 EFLAGS: 00010246\nCall Trace:\n \n ? __die+0x20/0x60\n ? page_fault_oops+0x14c/0x3c0\n ? exc_page_fault+0x75/0x140\n ? asm_exc_page_fault+0x22/0x30\n notifier_call_chain+0x35/0xb0\n blocking_notifier_call_chain+0x3d/0x60\n mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core]\n mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core]\n mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib]\n mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib]\n __mlx5_ib_add+0x34/0xd0 [mlx5_ib]\n mlx5r_probe+0xe1/0x210 [mlx5_ib]\n ? auxiliary_match_id+0x6a/0x90\n auxiliary_bus_probe+0x38/0x80\n ? driver_sysfs_add+0x51/0x80\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n bus_probe_device+0x86/0xa0\n device_add+0x637/0x840\n __auxiliary_device_add+0x3b/0xa0\n add_adev+0xc9/0x140 [mlx5_core]\n mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core]\n mlx5_register_device+0x53/0xa0 [mlx5_core]\n mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core]\n mlx5_init_one+0x3b/0x60 [mlx5_core]\n probe_one+0x44c/0x730 [mlx5_core]\n local_pci_probe+0x3e/0x90\n pci_device_probe+0xbf/0x210\n ? kernfs_create_link+0x5d/0xa0\n ? sysfs_do_create_link_sd+0x60/0xc0\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n pci_bus_add_device+0x54/0x80\n pci_iov_add_virtfn+0x2e6/0x320\n sriov_enable+0x208/0x420\n mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core]\n sriov_numvfs_store+0xae/0x1a0\n kernfs_fop_write_iter+0x10c/0x1a0\n vfs_write+0x291/0x3c0\n ksys_write+0x5f/0xe0\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n CR2: 0000000000000000\n ---[ end trace 0000000000000000 ]---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-38608', 'https://git.kernel.org/linus/3d5918477f94e4c2f064567875c475468e264644 (6.10-rc1)', 'https://git.kernel.org/stable/c/3d5918477f94e4c2f064567875c475468e264644', 'https://git.kernel.org/stable/c/f7e6cfb864a53af71c5cc904f1cc22215d68f5c6', 'https://linux.oracle.com/cve/CVE-2024-38608.html', 'https://linux.oracle.com/errata/ELSA-2024-5928.html', 'https://lore.kernel.org/linux-cve-announce/2024061920-CVE-2024-38608-4068@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-38608', 'https://www.cve.org/CVERecord?id=CVE-2024-38608'], 'PublishedDate': '2024-06-19T14:15:20.737Z', 'LastModifiedDate': '2024-08-27T15:58:56.9Z'}, {'VulnerabilityID': 'CVE-2024-39293', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-39293', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "xsk: Support redirect to any socket bound to the same umem"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "xsk: Support redirect to any socket bound to the same umem"\n\nThis reverts commit 2863d665ea41282379f108e4da6c8a2366ba66db.\n\nThis patch introduced a potential kernel crash when multiple napi instances\nredirect to the same AF_XDP socket. By removing the queue_index check, it is\npossible for multiple napi instances to access the Rx ring at the same time,\nwhich will result in a corrupted ring state which can lead to a crash when\nflushing the rings in __xsk_flush(). This can happen when the linked list of\nsockets to flush gets corrupted by concurrent accesses. A quick and small fix\nis not possible, so let us revert this for now.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-39293', 'https://git.kernel.org/linus/7fcf26b315bbb728036da0862de6b335da83dff2 (6.10-rc3)', 'https://git.kernel.org/stable/c/19cb40b1064566ea09538289bfcf5bc7ecb9b6f5', 'https://git.kernel.org/stable/c/7fcf26b315bbb728036da0862de6b335da83dff2', 'https://lore.kernel.org/linux-cve-announce/2024062548-CVE-2024-39293-d42a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-39293', 'https://www.cve.org/CVERecord?id=CVE-2024-39293'], 'PublishedDate': '2024-06-25T15:15:13.993Z', 'LastModifiedDate': '2024-06-25T18:50:42.04Z'}, {'VulnerabilityID': 'CVE-2024-39472', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-39472', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix log recovery buffer allocation for the legacy h_size fixup\n\nCommit a70f9fe52daa ("xfs: detect and handle invalid iclog size set by\nmkfs") added a fixup for incorrect h_size values used for the initial\numount record in old xfsprogs versions. Later commit 0c771b99d6c9\n("xfs: clean up calculation of LR header blocks") cleaned up the log\nreover buffer calculation, but stoped using the fixed up h_size value\nto size the log recovery buffer, which can lead to an out of bounds\naccess when the incorrect h_size does not come from the old mkfs\ntool, but a fuzzer.\n\nFix this by open coding xlog_logrec_hblks and taking the fixed h_size\ninto account for this calculation.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:5102', 'https://access.redhat.com/security/cve/CVE-2024-39472', 'https://bugzilla.redhat.com/2263879', 'https://bugzilla.redhat.com/2265645', 'https://bugzilla.redhat.com/2265797', 'https://bugzilla.redhat.com/2266341', 'https://bugzilla.redhat.com/2266347', 'https://bugzilla.redhat.com/2266497', 'https://bugzilla.redhat.com/2267787', 'https://bugzilla.redhat.com/2268118', 'https://bugzilla.redhat.com/2269070', 'https://bugzilla.redhat.com/2269211', 'https://bugzilla.redhat.com/2270084', 'https://bugzilla.redhat.com/2270100', 'https://bugzilla.redhat.com/2271686', 'https://bugzilla.redhat.com/2271688', 'https://bugzilla.redhat.com/2272782', 'https://bugzilla.redhat.com/2272795', 'https://bugzilla.redhat.com/2273109', 'https://bugzilla.redhat.com/2273174', 'https://bugzilla.redhat.com/2273236', 'https://bugzilla.redhat.com/2273242', 'https://bugzilla.redhat.com/2273247', 'https://bugzilla.redhat.com/2273268', 'https://bugzilla.redhat.com/2273427', 'https://bugzilla.redhat.com/2273654', 'https://bugzilla.redhat.com/2275565', 'https://bugzilla.redhat.com/2275573', 'https://bugzilla.redhat.com/2275580', 'https://bugzilla.redhat.com/2275694', 'https://bugzilla.redhat.com/2275711', 'https://bugzilla.redhat.com/2275748', 'https://bugzilla.redhat.com/2275761', 'https://bugzilla.redhat.com/2275928', 'https://bugzilla.redhat.com/2277166', 'https://bugzilla.redhat.com/2277238', 'https://bugzilla.redhat.com/2277840', 'https://bugzilla.redhat.com/2278176', 'https://bugzilla.redhat.com/2278178', 'https://bugzilla.redhat.com/2278182', 'https://bugzilla.redhat.com/2278218', 'https://bugzilla.redhat.com/2278256', 'https://bugzilla.redhat.com/2278258', 'https://bugzilla.redhat.com/2278277', 'https://bugzilla.redhat.com/2278279', 'https://bugzilla.redhat.com/2278380', 'https://bugzilla.redhat.com/2278484', 'https://bugzilla.redhat.com/2278515', 'https://bugzilla.redhat.com/2278535', 'https://bugzilla.redhat.com/2278539', 'https://bugzilla.redhat.com/2278989', 'https://bugzilla.redhat.com/2280440', 'https://bugzilla.redhat.com/2281054', 'https://bugzilla.redhat.com/2281133', 'https://bugzilla.redhat.com/2281149', 'https://bugzilla.redhat.com/2281207', 'https://bugzilla.redhat.com/2281215', 'https://bugzilla.redhat.com/2281221', 'https://bugzilla.redhat.com/2281235', 'https://bugzilla.redhat.com/2281268', 'https://bugzilla.redhat.com/2281326', 'https://bugzilla.redhat.com/2281360', 'https://bugzilla.redhat.com/2281510', 'https://bugzilla.redhat.com/2281519', 'https://bugzilla.redhat.com/2281636', 'https://bugzilla.redhat.com/2281641', 'https://bugzilla.redhat.com/2281664', 'https://bugzilla.redhat.com/2281667', 'https://bugzilla.redhat.com/2281672', 'https://bugzilla.redhat.com/2281675', 'https://bugzilla.redhat.com/2281682', 'https://bugzilla.redhat.com/2281725', 'https://bugzilla.redhat.com/2281752', 'https://bugzilla.redhat.com/2281758', 'https://bugzilla.redhat.com/2281819', 'https://bugzilla.redhat.com/2281821', 'https://bugzilla.redhat.com/2281833', 'https://bugzilla.redhat.com/2281938', 'https://bugzilla.redhat.com/2281949', 'https://bugzilla.redhat.com/2281968', 'https://bugzilla.redhat.com/2281989', 'https://bugzilla.redhat.com/2282328', 'https://bugzilla.redhat.com/2282373', 'https://bugzilla.redhat.com/2282479', 'https://bugzilla.redhat.com/2282553', 'https://bugzilla.redhat.com/2282615', 'https://bugzilla.redhat.com/2282623', 'https://bugzilla.redhat.com/2282640', 'https://bugzilla.redhat.com/2282642', 'https://bugzilla.redhat.com/2282645', 'https://bugzilla.redhat.com/2282717', 'https://bugzilla.redhat.com/2282719', 'https://bugzilla.redhat.com/2282727', 'https://bugzilla.redhat.com/2282742', 'https://bugzilla.redhat.com/2282743', 'https://bugzilla.redhat.com/2282744', 'https://bugzilla.redhat.com/2282759', 'https://bugzilla.redhat.com/2282763', 'https://bugzilla.redhat.com/2282766', 'https://bugzilla.redhat.com/2282772', 'https://bugzilla.redhat.com/2282780', 'https://bugzilla.redhat.com/2282887', 'https://bugzilla.redhat.com/2282896', 'https://bugzilla.redhat.com/2282923', 'https://bugzilla.redhat.com/2282925', 'https://bugzilla.redhat.com/2282950', 'https://bugzilla.redhat.com/2283401', 'https://bugzilla.redhat.com/2283894', 'https://bugzilla.redhat.com/2284400', 'https://bugzilla.redhat.com/2284417', 'https://bugzilla.redhat.com/2284421', 'https://bugzilla.redhat.com/2284474', 'https://bugzilla.redhat.com/2284477', 'https://bugzilla.redhat.com/2284488', 'https://bugzilla.redhat.com/2284496', 'https://bugzilla.redhat.com/2284500', 'https://bugzilla.redhat.com/2284513', 'https://bugzilla.redhat.com/2284519', 'https://bugzilla.redhat.com/2284539', 'https://bugzilla.redhat.com/2284541', 'https://bugzilla.redhat.com/2284556', 'https://bugzilla.redhat.com/2284571', 'https://bugzilla.redhat.com/2284590', 'https://bugzilla.redhat.com/2284625', 'https://bugzilla.redhat.com/2290408', 'https://bugzilla.redhat.com/2292331', 'https://bugzilla.redhat.com/2293078', 'https://bugzilla.redhat.com/2293250', 'https://bugzilla.redhat.com/2293276', 'https://bugzilla.redhat.com/2293312', 'https://bugzilla.redhat.com/2293316', 'https://bugzilla.redhat.com/2293348', 'https://bugzilla.redhat.com/2293371', 'https://bugzilla.redhat.com/2293383', 'https://bugzilla.redhat.com/2293418', 'https://bugzilla.redhat.com/2293420', 'https://bugzilla.redhat.com/2293444', 'https://bugzilla.redhat.com/2293461', 'https://bugzilla.redhat.com/2293653', 'https://bugzilla.redhat.com/2293657', 'https://bugzilla.redhat.com/2293684', 'https://bugzilla.redhat.com/2293687', 'https://bugzilla.redhat.com/2293700', 'https://bugzilla.redhat.com/2293711', 'https://bugzilla.redhat.com/2294274', 'https://bugzilla.redhat.com/2295914', 'https://bugzilla.redhat.com/2296067', 'https://bugzilla.redhat.com/2297056', 'https://bugzilla.redhat.com/2297474', 'https://bugzilla.redhat.com/2297511', 'https://bugzilla.redhat.com/2298108', 'https://bugzilla.redhat.com/show_bug.cgi?id=2263879', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265650', 'https://bugzilla.redhat.com/show_bug.cgi?id=2265797', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266341', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266347', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266497', 'https://bugzilla.redhat.com/show_bug.cgi?id=2266594', 'https://bugzilla.redhat.com/show_bug.cgi?id=2267787', 'https://bugzilla.redhat.com/show_bug.cgi?id=2268118', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269070', 'https://bugzilla.redhat.com/show_bug.cgi?id=2269211', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270084', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270100', 'https://bugzilla.redhat.com/show_bug.cgi?id=2270700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271686', 'https://bugzilla.redhat.com/show_bug.cgi?id=2271688', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272782', 'https://bugzilla.redhat.com/show_bug.cgi?id=2272795', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273109', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273117', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273174', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273236', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273242', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273247', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273427', 'https://bugzilla.redhat.com/show_bug.cgi?id=2273654', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275565', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275573', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275580', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275694', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275748', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275761', 'https://bugzilla.redhat.com/show_bug.cgi?id=2275928', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277166', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277238', 'https://bugzilla.redhat.com/show_bug.cgi?id=2277840', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278176', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278178', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278182', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278218', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278256', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278258', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278277', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278279', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278380', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278484', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278515', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278535', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2278989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2280440', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281054', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281133', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281149', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281189', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281190', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281207', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281215', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281221', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281235', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281268', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281326', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281360', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281510', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281636', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281641', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281664', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281667', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281672', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281675', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281682', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281725', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281752', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281758', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281819', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281821', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281833', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281938', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281949', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281968', 'https://bugzilla.redhat.com/show_bug.cgi?id=2281989', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282328', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282373', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282479', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282553', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282615', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282623', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282640', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282642', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282645', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282690', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282717', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282719', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282727', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282742', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282743', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282744', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282759', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282763', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282766', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282772', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282780', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282887', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282896', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282923', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282925', 'https://bugzilla.redhat.com/show_bug.cgi?id=2282950', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283401', 'https://bugzilla.redhat.com/show_bug.cgi?id=2283894', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284400', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284417', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284421', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284465', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284477', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284488', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284496', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284500', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284513', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284519', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284539', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284541', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284556', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284571', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284590', 'https://bugzilla.redhat.com/show_bug.cgi?id=2284625', 'https://bugzilla.redhat.com/show_bug.cgi?id=2290408', 'https://bugzilla.redhat.com/show_bug.cgi?id=2292331', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293078', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293250', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293276', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293312', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293316', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293348', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293367', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293371', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293383', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293418', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293420', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293444', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293461', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293653', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293657', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293684', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293687', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293700', 'https://bugzilla.redhat.com/show_bug.cgi?id=2293711', 'https://bugzilla.redhat.com/show_bug.cgi?id=2294274', 'https://bugzilla.redhat.com/show_bug.cgi?id=2295914', 'https://bugzilla.redhat.com/show_bug.cgi?id=2296067', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297056', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297474', 'https://bugzilla.redhat.com/show_bug.cgi?id=2297558', 'https://bugzilla.redhat.com/show_bug.cgi?id=2298108', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47018', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47257', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47304', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47373', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47408', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47468', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47491', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47548', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47579', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48743', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48747', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52451', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52463', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52469', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52471', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52486', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52530', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52619', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52622', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52623', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52648', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52653', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52662', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52679', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52707', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52730', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52756', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52762', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52764', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52775', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52777', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52784', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52791', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52796', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52803', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52811', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52832', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52845', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52864', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2201', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25739', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26586', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26614', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26640', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26669', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26686', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26698', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26704', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26740', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26772', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26773', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26802', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26837', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26840', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26843', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26852', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26870', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26878', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26908', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26961', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27011', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27019', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27065', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27388', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27395', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27434', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31076', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33621', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35790', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35801', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35807', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35810', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35814', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35823', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35824', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35847', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35876', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35893', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35897', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35899', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35900', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35910', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35912', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35924', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35925', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35930', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35937', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35938', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35952', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36000', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36005', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36006', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36010', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36016', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36017', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36020', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36025', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36270', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36489', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36896', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36904', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36917', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36921', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36929', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36933', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36940', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36941', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36945', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36950', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36954', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36971', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36978', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36979', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38538', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38555', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38573', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38575', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38596', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38598', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38615', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38627', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39276', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39472', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39476', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39487', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39502', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40927', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40974', 'https://errata.almalinux.org/8/ALSA-2024-5102.html', 'https://errata.rockylinux.org/RLSA-2024:5101', 'https://git.kernel.org/linus/45cf976008ddef4a9c9a30310c9b4fb2a9a6602a (6.10-rc1)', 'https://git.kernel.org/stable/c/45cf976008ddef4a9c9a30310c9b4fb2a9a6602a', 'https://git.kernel.org/stable/c/57835c0e7152e36b03875dd6c56dfeed685c1b1f', 'https://git.kernel.org/stable/c/c2389c074973aa94e34992e7f66dac0de37595b5', 'https://git.kernel.org/stable/c/f754591b17d0ee91c2b45fe9509d0cdc420527cb', 'https://linux.oracle.com/cve/CVE-2024-39472.html', 'https://linux.oracle.com/errata/ELSA-2024-5101.html', 'https://lore.kernel.org/linux-cve-announce/2024070512-CVE-2024-39472-f977@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-39472', 'https://www.cve.org/CVERecord?id=CVE-2024-39472'], 'PublishedDate': '2024-07-05T07:15:10.02Z', 'LastModifiedDate': '2024-08-19T05:15:06.543Z'}, {'VulnerabilityID': 'CVE-2024-41008', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41008', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: change vm->task_info handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: change vm->task_info handling\n\nThis patch changes the handling and lifecycle of vm->task_info object.\nThe major changes are:\n- vm->task_info is a dynamically allocated ptr now, and its uasge is\n reference counted.\n- introducing two new helper funcs for task_info lifecycle management\n - amdgpu_vm_get_task_info: reference counts up task_info before\n returning this info\n - amdgpu_vm_put_task_info: reference counts down task_info\n- last put to task_info() frees task_info from the vm.\n\nThis patch also does logistical changes required for existing usage\nof vm->task_info.\n\nV2: Do not block all the prints when task_info not found (Felix)\n\nV3: Fixed review comments from Felix\n - Fix wrong indentation\n - No debug message for -ENOMEM\n - Add NULL check for task_info\n - Do not duplicate the debug messages (ti vs no ti)\n - Get first reference of task_info in vm_init(), put last\n in vm_fini()\n\nV4: Fixed review comments from Felix\n - fix double reference increment in create_task_info\n - change amdgpu_vm_get_task_info_pasid\n - additional changes in amdgpu_gem.c while porting', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41008', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c (6.9-rc1)', 'https://git.kernel.org/stable/c/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c', 'https://linux.oracle.com/cve/CVE-2024-41008.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/20240716080357.2696435-2-lee@kernel.org/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41008', 'https://www.cve.org/CVERecord?id=CVE-2024-41008'], 'PublishedDate': '2024-07-16T08:15:02.24Z', 'LastModifiedDate': '2024-07-16T13:43:58.773Z'}, {'VulnerabilityID': 'CVE-2024-41009', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41009', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix overrunning reservations in ringbuf', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix overrunning reservations in ringbuf\n\nThe BPF ring buffer internally is implemented as a power-of-2 sized circular\nbuffer, with two logical and ever-increasing counters: consumer_pos is the\nconsumer counter to show which logical position the consumer consumed the\ndata, and producer_pos which is the producer counter denoting the amount of\ndata reserved by all producers.\n\nEach time a record is reserved, the producer that "owns" the record will\nsuccessfully advance producer counter. In user space each time a record is\nread, the consumer of the data advanced the consumer counter once it finished\nprocessing. Both counters are stored in separate pages so that from user\nspace, the producer counter is read-only and the consumer counter is read-write.\n\nOne aspect that simplifies and thus speeds up the implementation of both\nproducers and consumers is how the data area is mapped twice contiguously\nback-to-back in the virtual memory, allowing to not take any special measures\nfor samples that have to wrap around at the end of the circular buffer data\narea, because the next page after the last data page would be first data page\nagain, and thus the sample will still appear completely contiguous in virtual\nmemory.\n\nEach record has a struct bpf_ringbuf_hdr { u32 len; u32 pg_off; } header for\nbook-keeping the length and offset, and is inaccessible to the BPF program.\nHelpers like bpf_ringbuf_reserve() return `(void *)hdr + BPF_RINGBUF_HDR_SZ`\nfor the BPF program to use. Bing-Jhong and Muhammad reported that it is however\npossible to make a second allocated memory chunk overlapping with the first\nchunk and as a result, the BPF program is now able to edit first chunk\'s\nheader.\n\nFor example, consider the creation of a BPF_MAP_TYPE_RINGBUF map with size\nof 0x4000. Next, the consumer_pos is modified to 0x3000 /before/ a call to\nbpf_ringbuf_reserve() is made. This will allocate a chunk A, which is in\n[0x0,0x3008], and the BPF program is able to edit [0x8,0x3008]. Now, lets\nallocate a chunk B with size 0x3000. This will succeed because consumer_pos\nwas edited ahead of time to pass the `new_prod_pos - cons_pos > rb->mask`\ncheck. Chunk B will be in range [0x3008,0x6010], and the BPF program is able\nto edit [0x3010,0x6010]. Due to the ring buffer memory layout mentioned\nearlier, the ranges [0x0,0x4000] and [0x4000,0x8000] point to the same data\npages. This means that chunk B at [0x4000,0x4008] is chunk A\'s header.\nbpf_ringbuf_submit() / bpf_ringbuf_discard() use the header\'s pg_off to then\nlocate the bpf_ringbuf itself via bpf_ringbuf_restore_from_rec(). Once chunk\nB modified chunk A\'s header, then bpf_ringbuf_commit() refers to the wrong\npage and could cause a crash.\n\nFix it by calculating the oldest pending_pos and check whether the range\nfrom the oldest outstanding record to the newest would span beyond the ring\nbuffer size. If that is the case, then reject the request. We\'ve tested with\nthe ring buffer benchmark in BPF selftests (./benchs/run_bench_ringbufs.sh)\nbefore/after the fix and while it seems a bit slower on some benchmarks, it\nis still not significantly enough to matter.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41009', 'https://git.kernel.org/linus/cfa1a2329a691ffd991fcf7248a57d752e712881 (6.10-rc6)', 'https://git.kernel.org/stable/c/0f98f40eb1ed52af8b81f61901b6c0289ff59de4', 'https://git.kernel.org/stable/c/47416c852f2a04d348ea66ee451cbdcf8119f225', 'https://git.kernel.org/stable/c/511804ab701c0503b72eac08217eabfd366ba069', 'https://git.kernel.org/stable/c/be35504b959f2749bab280f4671e8df96dcf836f', 'https://git.kernel.org/stable/c/cfa1a2329a691ffd991fcf7248a57d752e712881', 'https://git.kernel.org/stable/c/d1b9df0435bc61e0b44f578846516df8ef476686', 'https://lore.kernel.org/linux-cve-announce/2024071715-CVE-2024-41009-cac5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41009', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-41009'], 'PublishedDate': '2024-07-17T07:15:01.973Z', 'LastModifiedDate': '2024-07-29T07:15:04.56Z'}, {'VulnerabilityID': 'CVE-2024-41013', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41013', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: don't walk off the end of a directory data block', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't walk off the end of a directory data block\n\nThis adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry\nto make sure don't stray beyond valid memory region. Before patching, the\nloop simply checks that the start offset of the dup and dep is within the\nrange. So in a crafted image, if last entry is xfs_dir2_data_unused, we\ncan change dup->length to dup->length-1 and leave 1 byte of space. In the\nnext traversal, this space will be considered as dup or dep. We may\nencounter an out of bound read when accessing the fixed members.\n\nIn the patch, we make sure that the remaining bytes large enough to hold\nan unused entry before accessing xfs_dir2_data_unused and\nxfs_dir2_data_unused is XFS_DIR2_DATA_ALIGN byte aligned. We also make\nsure that the remaining bytes large enough to hold a dirent with a\nsingle-byte name before accessing xfs_dir2_data_entry.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41013', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/0c7fcdb6d06cdf8b19b57c17605215b06afa864a (6.11-rc1)', 'https://git.kernel.org/stable/c/0c7fcdb6d06cdf8b19b57c17605215b06afa864a', 'https://linux.oracle.com/cve/CVE-2024-41013.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024072908-CVE-2024-41013-2996@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41013', 'https://www.cve.org/CVERecord?id=CVE-2024-41013'], 'PublishedDate': '2024-07-29T07:15:05.43Z', 'LastModifiedDate': '2024-07-29T14:12:08.783Z'}, {'VulnerabilityID': 'CVE-2024-41014', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41014', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xfs: add bounds checking to xlog_recover_process_data', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: add bounds checking to xlog_recover_process_data\n\nThere is a lack of verification of the space occupied by fixed members\nof xlog_op_header in the xlog_recover_process_data.\n\nWe can create a crafted image to trigger an out of bounds read by\nfollowing these steps:\n 1) Mount an image of xfs, and do some file operations to leave records\n 2) Before umounting, copy the image for subsequent steps to simulate\n abnormal exit. Because umount will ensure that tail_blk and\n head_blk are the same, which will result in the inability to enter\n xlog_recover_process_data\n 3) Write a tool to parse and modify the copied image in step 2\n 4) Make the end of the xlog_op_header entries only 1 byte away from\n xlog_rec_header->h_size\n 5) xlog_rec_header->h_num_logops++\n 6) Modify xlog_rec_header->h_crc\n\nFix:\nAdd a check to make sure there is sufficient space to access fixed members\nof xlog_op_header.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-41014', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/fb63435b7c7dc112b1ae1baea5486e0a6e27b196 (6.11-rc1)', 'https://git.kernel.org/stable/c/fb63435b7c7dc112b1ae1baea5486e0a6e27b196', 'https://linux.oracle.com/cve/CVE-2024-41014.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41014-9186@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41014', 'https://www.cve.org/CVERecord?id=CVE-2024-41014'], 'PublishedDate': '2024-07-29T07:15:05.81Z', 'LastModifiedDate': '2024-07-29T14:12:08.783Z'}, {'VulnerabilityID': 'CVE-2024-41016', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41016', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()\n\nxattr in ocfs2 maybe 'non-indexed', which saved with additional space\nrequested. It's better to check if the memory is out of bound before\nmemcmp, although this possibility mainly comes from crafted poisonous\nimages.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41016', 'https://git.kernel.org/linus/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 (6.11-rc1)', 'https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637', 'https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262', 'https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e', 'https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e', 'https://git.kernel.org/stable/c/cfb926051fab19b10d1e65976211f364aa820180', 'https://git.kernel.org/stable/c/e4ffea01adf3323c821b6f37e9577d2d400adbaa', 'https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41016-fcf9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41016', 'https://www.cve.org/CVERecord?id=CVE-2024-41016'], 'PublishedDate': '2024-07-29T07:15:06.293Z', 'LastModifiedDate': '2024-10-17T14:15:07.01Z'}, {'VulnerabilityID': 'CVE-2024-41024', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-41024', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: misc: fastrpc: Restrict untrusted app to attach to privileged PD', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Restrict untrusted app to attach to privileged PD\n\nUntrusted application with access to only non-secure fastrpc device\nnode can attach to root_pd or static PDs if it can make the respective\ninit request. This can cause problems as the untrusted application\ncan send bad requests to root_pd or static PDs. Add changes to reject\nattach to privileged PDs if the request is being made using non-secure\nfastrpc device node.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-41024', 'https://git.kernel.org/linus/bab2f5e8fd5d2f759db26b78d9db57412888f187 (6.10)', 'https://git.kernel.org/stable/c/2eb973ee4770a26d9b5e292b58ad29822d321c7f', 'https://git.kernel.org/stable/c/5e305b5986dc52122a9368a1461f0c13e1de3fd6', 'https://git.kernel.org/stable/c/bab2f5e8fd5d2f759db26b78d9db57412888f187', 'https://git.kernel.org/stable/c/c69fd8afacebfdf2f8a1ee1ea7e0723786529874', 'https://git.kernel.org/stable/c/ea13bd807f1cef1af375d999980a9b9794c789b6', 'https://lore.kernel.org/all/20240628114501.14310-7-srinivas.kandagatla@linaro.org/', 'https://lore.kernel.org/linux-cve-announce/2024072919-CVE-2024-41024-be39@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-41024', 'https://www.cve.org/CVERecord?id=CVE-2024-41024'], 'PublishedDate': '2024-07-29T15:15:11.27Z', 'LastModifiedDate': '2024-08-29T17:15:07.913Z'}, {'VulnerabilityID': 'CVE-2024-42107', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42107', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: ice: Don't process extts if PTP is disabled", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Don't process extts if PTP is disabled\n\nThe ice_ptp_extts_event() function can race with ice_ptp_release() and\nresult in a NULL pointer dereference which leads to a kernel panic.\n\nPanic occurs because the ice_ptp_extts_event() function calls\nptp_clock_event() with a NULL pointer. The ice driver has already\nreleased the PTP clock by the time the interrupt for the next external\ntimestamp event occurs.\n\nTo fix this, modify the ice_ptp_extts_event() function to check the\nPTP state and bail early if PTP is not ready.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42107', 'https://git.kernel.org/linus/996422e3230e41468f652d754fefd1bdbcd4604e (6.10-rc7)', 'https://git.kernel.org/stable/c/1c4e524811918600683b1ea87a5e0fc2db64fa9b', 'https://git.kernel.org/stable/c/996422e3230e41468f652d754fefd1bdbcd4604e', 'https://lore.kernel.org/linux-cve-announce/2024073020-CVE-2024-42107-65cc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42107', 'https://www.cve.org/CVERecord?id=CVE-2024-42107'], 'PublishedDate': '2024-07-30T08:15:03.22Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42116', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42116', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: igc: fix a log entry using uninitialized netdev', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nigc: fix a log entry using uninitialized netdev\n\nDuring successful probe, igc logs this:\n\n[ 5.133667] igc 0000:01:00.0 (unnamed net_device) (uninitialized): PHC added\n ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe reason is that igc_ptp_init() is called very early, even before\nregister_netdev() has been called. So the netdev_info() call works\non a partially uninitialized netdev.\n\nFix this by calling igc_ptp_init() after register_netdev(), right\nafter the media autosense check, just as in igb. Add a comment,\njust as in igb.\n\nNow the log message is fine:\n\n[ 5.200987] igc 0000:01:00.0 eth0: PHC added', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42116', 'https://git.kernel.org/linus/86167183a17e03ec77198897975e9fdfbd53cb0b (6.10-rc1)', 'https://git.kernel.org/stable/c/86167183a17e03ec77198897975e9fdfbd53cb0b', 'https://git.kernel.org/stable/c/96839f3f588236593de36465f142b0126267f8b6', 'https://git.kernel.org/stable/c/98c8958980e829f023a490b9a9816ca1fe2f8b79', 'https://git.kernel.org/stable/c/991f036cabc3d13e886a37faeea1b6800181fdda', 'https://git.kernel.org/stable/c/d478ec838cf2b1e1051a8709cfc744fe1c03110f', 'https://linux.oracle.com/cve/CVE-2024-42116.html', 'https://linux.oracle.com/errata/ELSA-2024-12618.html', 'https://lore.kernel.org/linux-cve-announce/2024073023-CVE-2024-42116-b420@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42116', 'https://www.cve.org/CVERecord?id=CVE-2024-42116'], 'PublishedDate': '2024-07-30T08:15:03.95Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42122', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42122', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add NULL pointer check for kzalloc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL pointer check for kzalloc\n\n[Why & How]\nCheck return pointer of kzalloc before using it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42122', 'https://git.kernel.org/linus/8e65a1b7118acf6af96449e1e66b7adbc9396912 (6.10-rc1)', 'https://git.kernel.org/stable/c/062edd612fcd300f0f79a36fca5b8b6a5e2fce70', 'https://git.kernel.org/stable/c/8e65a1b7118acf6af96449e1e66b7adbc9396912', 'https://lore.kernel.org/linux-cve-announce/2024073025-CVE-2024-42122-2f70@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42122', 'https://www.cve.org/CVERecord?id=CVE-2024-42122'], 'PublishedDate': '2024-07-30T08:15:04.43Z', 'LastModifiedDate': '2024-09-16T13:49:27.837Z'}, {'VulnerabilityID': 'CVE-2024-42125', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42125', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw89: fw: scan offload prohibit all 6 GHz channel if no 6 GHz sband', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fw: scan offload prohibit all 6 GHz channel if no 6 GHz sband\n\nWe have some policy via BIOS to block uses of 6 GHz. In this case, 6 GHz\nsband will be NULL even if it is WiFi 7 chip. So, add NULL handling here\nto avoid crash.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42125', 'https://git.kernel.org/linus/bb38626f3f97e16e6d368a9ff6daf320f3fe31d9 (6.10-rc1)', 'https://git.kernel.org/stable/c/bb38626f3f97e16e6d368a9ff6daf320f3fe31d9', 'https://git.kernel.org/stable/c/ce4ba62f8bc5195a9a0d49c6235a9c99e619cadc', 'https://lore.kernel.org/linux-cve-announce/2024073026-CVE-2024-42125-b515@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42125', 'https://www.cve.org/CVERecord?id=CVE-2024-42125'], 'PublishedDate': '2024-07-30T08:15:04.667Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42139', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42139', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Fix improper extts handling', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix improper extts handling\n\nExtts events are disabled and enabled by the application ts2phc.\nHowever, in case where the driver is removed when the application is\nrunning, a specific extts event remains enabled and can cause a kernel\ncrash.\nAs a side effect, when the driver is reloaded and application is started\nagain, remaining extts event for the channel from a previous run will\nkeep firing and the message "extts on unexpected channel" might be\nprinted to the user.\n\nTo avoid that, extts events shall be disabled when PTP is released.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42139', 'https://git.kernel.org/linus/00d3b4f54582d4e4a02cda5886bb336eeab268cc (6.10-rc7)', 'https://git.kernel.org/stable/c/00d3b4f54582d4e4a02cda5886bb336eeab268cc', 'https://git.kernel.org/stable/c/9f69b31ae9e25dec27ad31fbc64dd99af16ee3d3', 'https://lore.kernel.org/linux-cve-announce/2024073030-CVE-2024-42139-f8ef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42139', 'https://www.cve.org/CVERecord?id=CVE-2024-42139'], 'PublishedDate': '2024-07-30T08:15:05.757Z', 'LastModifiedDate': '2024-07-30T13:32:45.943Z'}, {'VulnerabilityID': 'CVE-2024-42154', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42154', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tcp_metrics: validate source addr length', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_metrics: validate source addr length\n\nI don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4\nis at least 4 bytes long, and the policy doesn't have an entry\nfor this attribute at all (neither does it for IPv6 but v6 is\nmanually validated).", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.4}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42154', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/66be40e622e177316ae81717aa30057ba9e61dff (6.10-rc7)', 'https://git.kernel.org/stable/c/19d997b59fa1fd7a02e770ee0881c0652b9c32c9', 'https://git.kernel.org/stable/c/2a2e79dbe2236a1289412d2044994f7ab419b44c', 'https://git.kernel.org/stable/c/31f03bb04146c1c6df6c03e9f45401f5f5a985d3', 'https://git.kernel.org/stable/c/3d550dd5418729a6e77fe7721d27adea7152e321', 'https://git.kernel.org/stable/c/66be40e622e177316ae81717aa30057ba9e61dff', 'https://git.kernel.org/stable/c/8c2debdd170e395934ac0e039748576dfde14e99', 'https://git.kernel.org/stable/c/cdffc358717e436bb67122bb82c1a2a26e050f98', 'https://git.kernel.org/stable/c/ef7c428b425beeb52b894e16f1c4b629d6cebfb6', 'https://linux.oracle.com/cve/CVE-2024-42154.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024073034-CVE-2024-42154-cf82@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42154', 'https://ubuntu.com/security/notices/USN-7003-1', 'https://ubuntu.com/security/notices/USN-7003-2', 'https://ubuntu.com/security/notices/USN-7003-3', 'https://ubuntu.com/security/notices/USN-7003-4', 'https://ubuntu.com/security/notices/USN-7003-5', 'https://ubuntu.com/security/notices/USN-7006-1', 'https://ubuntu.com/security/notices/USN-7007-1', 'https://ubuntu.com/security/notices/USN-7007-2', 'https://ubuntu.com/security/notices/USN-7007-3', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://ubuntu.com/security/notices/USN-7019-1', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://ubuntu.com/security/notices/USN-7039-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42154'], 'PublishedDate': '2024-07-30T08:15:06.933Z', 'LastModifiedDate': '2024-10-01T19:32:18.31Z'}, {'VulnerabilityID': 'CVE-2024-42159', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42159', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: mpi3mr: Sanitise num_phys', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Sanitise num_phys\n\nInformation is stored in mr_sas_port->phy_mask, values larger then size of\nthis field shouldn't be allowed.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42159', 'https://git.kernel.org/linus/3668651def2c1622904e58b0280ee93121f2b10b (6.10-rc1)', 'https://git.kernel.org/stable/c/3668651def2c1622904e58b0280ee93121f2b10b', 'https://git.kernel.org/stable/c/586b41060113ae43032ec6c4a16d518cef5da6e0', 'https://git.kernel.org/stable/c/b869ec89d2ee923d46608b76e54c006680c9b4df', 'https://git.kernel.org/stable/c/c8707901b53a48106d7501bdbd0350cefaefa4cf', 'https://linux.oracle.com/cve/CVE-2024-42159.html', 'https://linux.oracle.com/errata/ELSA-2024-12682.html', 'https://lore.kernel.org/linux-cve-announce/2024073036-CVE-2024-42159-c19e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42159', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42159'], 'PublishedDate': '2024-07-30T08:15:07.3Z', 'LastModifiedDate': '2024-08-02T14:29:46.24Z'}, {'VulnerabilityID': 'CVE-2024-42160', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42160', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: check validation of fault attrs in f2fs_build_fault_attr()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: check validation of fault attrs in f2fs_build_fault_attr()\n\n- It missed to check validation of fault attrs in parse_options(),\nlet's fix to add check condition in f2fs_build_fault_attr().\n- Use f2fs_build_fault_attr() in __sbi_store() to clean up code.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42160', 'https://git.kernel.org/linus/4ed886b187f47447ad559619c48c086f432d2b77 (6.10-rc1)', 'https://git.kernel.org/stable/c/44958ca9e400f57bd0478115519ffc350fcee61e', 'https://git.kernel.org/stable/c/4ed886b187f47447ad559619c48c086f432d2b77', 'https://git.kernel.org/stable/c/bc84dd2c33e0c10fd90d60f0cfc0bfb504d4692d', 'https://git.kernel.org/stable/c/ecb641f424d6d1f055d149a15b892edcc92c504b', 'https://lore.kernel.org/linux-cve-announce/2024073036-CVE-2024-42160-c733@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42160', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7022-1', 'https://ubuntu.com/security/notices/USN-7022-2', 'https://ubuntu.com/security/notices/USN-7022-3', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42160'], 'PublishedDate': '2024-07-30T08:15:07.37Z', 'LastModifiedDate': '2024-08-02T14:29:26.33Z'}, {'VulnerabilityID': 'CVE-2024-42224', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42224', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: dsa: mv88e6xxx: Correct check for empty list', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Correct check for empty list\n\nSince commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO\nbusses") mv88e6xxx_default_mdio_bus() has checked that the\nreturn value of list_first_entry() is non-NULL.\n\nThis appears to be intended to guard against the list chip->mdios being\nempty. However, it is not the correct check as the implementation of\nlist_first_entry is not designed to return NULL for empty lists.\n\nInstead, use list_first_entry_or_null() which does return NULL if the\nlist is empty.\n\nFlagged by Smatch.\nCompile tested only.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 6.1}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42224', 'https://git.kernel.org/linus/4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b (6.10-rc1)', 'https://git.kernel.org/stable/c/2a2fe25a103cef73cde356e6d09da10f607e93f5', 'https://git.kernel.org/stable/c/3bf8d70e1455f87856640c3433b3660a31001618', 'https://git.kernel.org/stable/c/3f25b5f1635449036692a44b771f39f772190c1d', 'https://git.kernel.org/stable/c/47d28dde172696031c880c5778633cdca30394ee', 'https://git.kernel.org/stable/c/4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b', 'https://git.kernel.org/stable/c/8c2c3cca816d074c75a2801d1ca0dea7b0148114', 'https://git.kernel.org/stable/c/aa03f591ef31ba603a4a99d05d25a0f21ab1cd89', 'https://git.kernel.org/stable/c/f75625db838ade28f032dacd0f0c8baca42ecde4', 'https://linux.oracle.com/cve/CVE-2024-42224.html', 'https://linux.oracle.com/errata/ELSA-2024-12779.html', 'https://lore.kernel.org/linux-cve-announce/2024073037-CVE-2024-42224-863a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42224', 'https://ubuntu.com/security/notices/USN-7003-1', 'https://ubuntu.com/security/notices/USN-7003-2', 'https://ubuntu.com/security/notices/USN-7003-3', 'https://ubuntu.com/security/notices/USN-7003-4', 'https://ubuntu.com/security/notices/USN-7003-5', 'https://ubuntu.com/security/notices/USN-7006-1', 'https://ubuntu.com/security/notices/USN-7007-1', 'https://ubuntu.com/security/notices/USN-7007-2', 'https://ubuntu.com/security/notices/USN-7007-3', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://ubuntu.com/security/notices/USN-7019-1', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42224'], 'PublishedDate': '2024-07-30T08:15:07.667Z', 'LastModifiedDate': '2024-09-25T15:55:09.027Z'}, {'VulnerabilityID': 'CVE-2024-42228', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'FixedVersion': '6.8.0-1016.17~22.04.2', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42228', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc\n\nInitialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001.\nV2: To really improve the handling we would actually\n need to have a separate value of 0xffffffff.(Christian)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 6.3}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42228', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/88a9a467c548d0b3c7761b4fd54a68e70f9c0944 (6.10-rc1)', 'https://git.kernel.org/stable/c/3b505759447637dcccb50cbd98ec6f8d2a04fc46', 'https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef', 'https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944', 'https://git.kernel.org/stable/c/9ee1534ecdd5b4c013064663502d7fde824d2144', 'https://git.kernel.org/stable/c/d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8', 'https://git.kernel.org/stable/c/da6a85d197888067e8d38b5d22c986b5b5cab712', 'https://git.kernel.org/stable/c/df02642c21c984303fe34c3f7d72965792fb1a15', 'https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440', 'https://linux.oracle.com/cve/CVE-2024-42228.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024073038-CVE-2024-42228-86f5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42228', 'https://ubuntu.com/security/notices/USN-7020-1', 'https://ubuntu.com/security/notices/USN-7020-2', 'https://ubuntu.com/security/notices/USN-7020-3', 'https://ubuntu.com/security/notices/USN-7020-4', 'https://ubuntu.com/security/notices/USN-7021-1', 'https://ubuntu.com/security/notices/USN-7021-2', 'https://ubuntu.com/security/notices/USN-7021-3', 'https://ubuntu.com/security/notices/USN-7021-4', 'https://ubuntu.com/security/notices/USN-7022-1', 'https://ubuntu.com/security/notices/USN-7022-2', 'https://ubuntu.com/security/notices/USN-7022-3', 'https://ubuntu.com/security/notices/USN-7028-1', 'https://ubuntu.com/security/notices/USN-7028-2', 'https://ubuntu.com/security/notices/USN-7029-1', 'https://ubuntu.com/security/notices/USN-7039-1', 'https://www.cve.org/CVERecord?id=CVE-2024-42228'], 'PublishedDate': '2024-07-30T08:15:07.96Z', 'LastModifiedDate': '2024-09-04T12:15:04.577Z'}, {'VulnerabilityID': 'CVE-2024-42258', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42258', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines\n\nYves-Alexis Perez reported commit 4ef9ad19e176 ("mm: huge_memory: don\'t\nforce huge page alignment on 32 bit") didn\'t work for x86_32 [1]. It is\nbecause x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT.\n\n!CONFIG_64BIT should cover all 32 bit machines.\n\n[1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42258', 'https://git.kernel.org/linus/d9592025000b3cf26c742f3505da7b83aedc26d5 (6.11-rc1)', 'https://git.kernel.org/stable/c/7e1f4efb8d6140b2ec79bf760c43e1fc186e8dfc', 'https://git.kernel.org/stable/c/89f2914dd4b47d2fad3deef0d700f9526d98d11f', 'https://git.kernel.org/stable/c/a5c399fe433a115e9d3693169b5f357f3194af0a', 'https://git.kernel.org/stable/c/d9592025000b3cf26c742f3505da7b83aedc26d5', 'https://lore.kernel.org/linux-cve-announce/2024081216-CVE-2024-42258-e3f3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42258', 'https://www.cve.org/CVERecord?id=CVE-2024-42258'], 'PublishedDate': '2024-08-12T15:15:20.983Z', 'LastModifiedDate': '2024-08-14T14:15:27.727Z'}, {'VulnerabilityID': 'CVE-2024-42259', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42259', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/i915/gem: Fix Virtual Memory mapping boundaries calculation', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix Virtual Memory mapping boundaries calculation\n\nCalculating the size of the mapped area as the lesser value\nbetween the requested size and the actual size does not consider\nthe partial mapping offset. This can cause page fault access.\n\nFix the calculation of the starting and ending addresses, the\ntotal size is now deduced from the difference between the end and\nstart addresses.\n\nAdditionally, the calculations have been rewritten in a clearer\nand more understandable form.\n\n[Joonas: Add Requires: tag]\nRequires: 60a2066c5005 ("drm/i915/gem: Adjust vma offset for framebuffer mmap offset")\n(cherry picked from commit 97b6784753da06d9d40232328efc5c5367e53417)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-131'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42259', 'https://git.kernel.org/linus/8bdd9ef7e9b1b2a73e394712b72b22055e0e26c3 (6.11-rc3)', 'https://git.kernel.org/stable/c/3e06073d24807f04b4694108a8474decb7b99e60', 'https://git.kernel.org/stable/c/4b09513ce93b3dcb590baaaff2ce96f2d098312d', 'https://git.kernel.org/stable/c/50111a8098fb9ade621eeff82228a997d42732ab', 'https://git.kernel.org/stable/c/8bdd9ef7e9b1b2a73e394712b72b22055e0e26c3', 'https://git.kernel.org/stable/c/911f8055f175c82775d0fd8cedcd0b75413f4ba7', 'https://git.kernel.org/stable/c/a256d019eaf044864c7e50312f0a65b323c24f39', 'https://git.kernel.org/stable/c/e8a68aa842d3f8dd04a46b9d632e5f67fde1da9b', 'https://git.kernel.org/stable/c/ead9289a51ea82eb5b27029fcf4c34b2dd60cf06', 'https://linux.oracle.com/cve/CVE-2024-42259.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081452-CVE-2024-42259-4cef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42259', 'https://project-zero.issues.chromium.org/issues/42451707', 'https://www.cve.org/CVERecord?id=CVE-2024-42259'], 'PublishedDate': '2024-08-14T15:15:31.673Z', 'LastModifiedDate': '2024-09-25T01:15:42.137Z'}, {'VulnerabilityID': 'CVE-2024-42260', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42260', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Validate passed in drm syncobj handles in the performance extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Validate passed in drm syncobj handles in the performance extension\n\nIf userspace provides an unknown or invalid handle anywhere in the handle\narray the rest of the driver will not handle that well.\n\nFix it by checking handle was looked up successfully or otherwise fail the\nextension by jumping into the existing unwind.\n\n(cherry picked from commit a546b7e4d73c23838d7e4d2c92882b3ca902d213)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42260', 'https://git.kernel.org/linus/4ecc24a84d7e0254efd150ec23e0b89638386516 (6.11-rc2)', 'https://git.kernel.org/stable/c/4ecc24a84d7e0254efd150ec23e0b89638386516', 'https://git.kernel.org/stable/c/5d4aa25f47cd05e9eeac272906588728588605dd', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-42260-0ce0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42260', 'https://www.cve.org/CVERecord?id=CVE-2024-42260'], 'PublishedDate': '2024-08-17T09:15:07.53Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42261', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42261', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Validate passed in drm syncobj handles in the timestamp extension\n\nIf userspace provides an unknown or invalid handle anywhere in the handle\narray the rest of the driver will not handle that well.\n\nFix it by checking handle was looked up successfully or otherwise fail the\nextension by jumping into the existing unwind.\n\n(cherry picked from commit 8d1276d1b8f738c3afe1457d4dff5cc66fc848a3)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42261', 'https://git.kernel.org/linus/023d22e8bb0cdd6900382ad1ed06df3b6c2ea791 (6.11-rc2)', 'https://git.kernel.org/stable/c/023d22e8bb0cdd6900382ad1ed06df3b6c2ea791', 'https://git.kernel.org/stable/c/5c56f104edd02a537e9327dc543574e55713e1d7', 'https://lore.kernel.org/linux-cve-announce/2024081736-CVE-2024-42261-f6a2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42261', 'https://www.cve.org/CVERecord?id=CVE-2024-42261'], 'PublishedDate': '2024-08-17T09:15:07.6Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42262', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42262', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix potential memory leak in the performance extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix potential memory leak in the performance extension\n\nIf fetching of userspace memory fails during the main loop, all drm sync\nobjs looked up until that point will be leaked because of the missing\ndrm_syncobj_put.\n\nFix it by exporting and using a common cleanup helper.\n\n(cherry picked from commit 484de39fa5f5b7bd0c5f2e2c5265167250ef7501)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42262', 'https://git.kernel.org/linus/32df4abc44f24dbec239d43e2b26d5768c5d1a78 (6.11-rc2)', 'https://git.kernel.org/stable/c/32df4abc44f24dbec239d43e2b26d5768c5d1a78', 'https://git.kernel.org/stable/c/ad5fdc48f7a63b8a98493c667505fe4d3864ae21', 'https://lore.kernel.org/linux-cve-announce/2024081736-CVE-2024-42262-7156@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42262', 'https://www.cve.org/CVERecord?id=CVE-2024-42262'], 'PublishedDate': '2024-08-17T09:15:07.68Z', 'LastModifiedDate': '2024-08-19T20:05:15.407Z'}, {'VulnerabilityID': 'CVE-2024-42263', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42263', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Fix potential memory leak in the timestamp extension', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix potential memory leak in the timestamp extension\n\nIf fetching of userspace memory fails during the main loop, all drm sync\nobjs looked up until that point will be leaked because of the missing\ndrm_syncobj_put.\n\nFix it by exporting and using a common cleanup helper.\n\n(cherry picked from commit 753ce4fea62182c77e1691ab4f9022008f25b62e)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42263', 'https://git.kernel.org/linus/0e50fcc20bd87584840266e8004f9064a8985b4f (6.11-rc2)', 'https://git.kernel.org/stable/c/0e50fcc20bd87584840266e8004f9064a8985b4f', 'https://git.kernel.org/stable/c/9b5033ee2c5af6d1135a403df32d219ab57e55f9', 'https://lore.kernel.org/linux-cve-announce/2024081737-CVE-2024-42263-31b3@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42263', 'https://www.cve.org/CVERecord?id=CVE-2024-42263'], 'PublishedDate': '2024-08-17T09:15:07.77Z', 'LastModifiedDate': '2024-08-19T20:41:11.24Z'}, {'VulnerabilityID': 'CVE-2024-42264', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42264', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/v3d: Prevent out of bounds access in performance query extensions', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Prevent out of bounds access in performance query extensions\n\nCheck that the number of perfmons userspace is passing in the copy and\nreset extensions is not greater than the internal kernel storage where\nthe ids will be copied into.\n\n(cherry picked from commit f32b5128d2c440368b5bf3a7a356823e235caabb)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42264', 'https://git.kernel.org/linus/6ce9efd12ae81cf46bf44eb0348594558dfbb9d2 (6.11-rc2)', 'https://git.kernel.org/stable/c/6ce9efd12ae81cf46bf44eb0348594558dfbb9d2', 'https://git.kernel.org/stable/c/73ad583bd4938bf37d2709fc36901eb6f22f2722', 'https://lore.kernel.org/linux-cve-announce/2024081737-CVE-2024-42264-5d23@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42264', 'https://www.cve.org/CVERecord?id=CVE-2024-42264'], 'PublishedDate': '2024-08-17T09:15:07.833Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42267', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42267', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv/mm: Add handling for VM_FAULT_SIGSEGV in mm_fault_error()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/mm: Add handling for VM_FAULT_SIGSEGV in mm_fault_error()\n\nHandle VM_FAULT_SIGSEGV in the page fault path so that we correctly\nkill the process and we don't BUG() the kernel.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42267', 'https://git.kernel.org/linus/0c710050c47d45eb77b28c271cddefc5c785cb40 (6.11-rc2)', 'https://git.kernel.org/stable/c/0c710050c47d45eb77b28c271cddefc5c785cb40', 'https://git.kernel.org/stable/c/20dbdebc5580cd472a310d56a6e252275ee4c864', 'https://git.kernel.org/stable/c/59be4a167782d68e21068a761b90b01fadc09146', 'https://git.kernel.org/stable/c/917f598209f3f5e4ab175d5079d8aeb523e58b1f', 'https://git.kernel.org/stable/c/d4e7db757e2d7f4c407a007e92c98477eab215d2', 'https://git.kernel.org/stable/c/d7ccf2ca772bfe33e2c53ef80fa20d2d87eb6144', 'https://lore.kernel.org/linux-cve-announce/2024081738-CVE-2024-42267-9f79@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42267', 'https://www.cve.org/CVERecord?id=CVE-2024-42267'], 'PublishedDate': '2024-08-17T09:15:08.047Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42268', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42268', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Fix missing lock on sync reset reload', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix missing lock on sync reset reload\n\nOn sync reset reload work, when remote host updates devlink on reload\nactions performed on that host, it misses taking devlink lock before\ncalling devlink_remote_reload_actions_performed() which results in\ntriggering lock assert like the following:\n\nWARNING: CPU: 4 PID: 1164 at net/devlink/core.c:261 devl_assert_locked+0x3e/0x50\n…\n CPU: 4 PID: 1164 Comm: kworker/u96:6 Tainted: G S W 6.10.0-rc2+ #116\n Hardware name: Supermicro SYS-2028TP-DECTR/X10DRT-PT, BIOS 2.0 12/18/2015\n Workqueue: mlx5_fw_reset_events mlx5_sync_reset_reload_work [mlx5_core]\n RIP: 0010:devl_assert_locked+0x3e/0x50\n…\n Call Trace:\n \n ? __warn+0xa4/0x210\n ? devl_assert_locked+0x3e/0x50\n ? report_bug+0x160/0x280\n ? handle_bug+0x3f/0x80\n ? exc_invalid_op+0x17/0x40\n ? asm_exc_invalid_op+0x1a/0x20\n ? devl_assert_locked+0x3e/0x50\n devlink_notify+0x88/0x2b0\n ? mlx5_attach_device+0x20c/0x230 [mlx5_core]\n ? __pfx_devlink_notify+0x10/0x10\n ? process_one_work+0x4b6/0xbb0\n process_one_work+0x4b6/0xbb0\n[…]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42268', 'https://git.kernel.org/linus/572f9caa9e7295f8c8822e4122c7ae8f1c412ff9 (6.11-rc2)', 'https://git.kernel.org/stable/c/091268f3c27a5b6d7858a3bb2a0dbcc9cd26ddb5', 'https://git.kernel.org/stable/c/572f9caa9e7295f8c8822e4122c7ae8f1c412ff9', 'https://git.kernel.org/stable/c/5d07d1d40aabfd61bab21115639bd4f641db6002', 'https://git.kernel.org/stable/c/98884e89c90d077f6fe6ba18e6cf6f914642f04e', 'https://lore.kernel.org/linux-cve-announce/2024081738-CVE-2024-42268-2084@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42268', 'https://www.cve.org/CVERecord?id=CVE-2024-42268'], 'PublishedDate': '2024-08-17T09:15:08.11Z', 'LastModifiedDate': '2024-08-19T20:52:49.323Z'}, {'VulnerabilityID': 'CVE-2024-42269', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42269', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().\n\nip6table_nat_table_init() accesses net->gen->ptr[ip6table_nat_net_ops.id],\nbut the function is exposed to user space before the entry is allocated\nvia register_pernet_subsys().\n\nLet's call register_pernet_subsys() before xt_register_template().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42269', 'https://git.kernel.org/linus/c22921df777de5606f1047b1345b8d22ef1c0b34 (6.11-rc2)', 'https://git.kernel.org/stable/c/419ee6274c5153b89c4393c1946faa4c3cad4f9e', 'https://git.kernel.org/stable/c/87dba44e9471b79b255d0736858a897332db9226', 'https://git.kernel.org/stable/c/91b6df6611b7edb28676c4f63f90c56c30d3e601', 'https://git.kernel.org/stable/c/c22921df777de5606f1047b1345b8d22ef1c0b34', 'https://git.kernel.org/stable/c/e85b9b6a87be4cb3710082038b677e97f2389003', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42269-7d0a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42269', 'https://www.cve.org/CVERecord?id=CVE-2024-42269'], 'PublishedDate': '2024-08-17T09:15:08.177Z', 'LastModifiedDate': '2024-08-19T20:53:51.717Z'}, {'VulnerabilityID': 'CVE-2024-42270', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42270', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().\n\nWe had a report that iptables-restore sometimes triggered null-ptr-deref\nat boot time. [0]\n\nThe problem is that iptable_nat_table_init() is exposed to user space\nbefore the kernel fully initialises netns.\n\nIn the small race window, a user could call iptable_nat_table_init()\nthat accesses net_generic(net, iptable_nat_net_id), which is available\nonly after registering iptable_nat_net_ops.\n\nLet's call register_pernet_subsys() before xt_register_template().\n\n[0]:\nbpfilter: Loaded bpfilter_umh pid 11702\nStarted bpfilter\nBUG: kernel NULL pointer dereference, address: 0000000000000013\n PF: supervisor write access in kernel mode\n PF: error_code(0x0002) - not-present page\nPGD 0 P4D 0\nPREEMPT SMP NOPTI\nCPU: 2 PID: 11879 Comm: iptables-restor Not tainted 6.1.92-99.174.amzn2023.x86_64 #1\nHardware name: Amazon EC2 c6i.4xlarge/, BIOS 1.0 10/16/2017\nRIP: 0010:iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat\nCode: 10 4c 89 f6 48 89 ef e8 0b 19 bb ff 41 89 c4 85 c0 75 38 41 83 c7 01 49 83 c6 28 41 83 ff 04 75 dc 48 8b 44 24 08 48 8b 0c 24 <48> 89 08 4c 89 ef e8 a2 3b a2 cf 48 83 c4 10 44 89 e0 5b 5d 41 5c\nRSP: 0018:ffffbef902843cd0 EFLAGS: 00010246\nRAX: 0000000000000013 RBX: ffff9f4b052caa20 RCX: ffff9f4b20988d80\nRDX: 0000000000000000 RSI: 0000000000000064 RDI: ffffffffc04201c0\nRBP: ffff9f4b29394000 R08: ffff9f4b07f77258 R09: ffff9f4b07f77240\nR10: 0000000000000000 R11: ffff9f4b09635388 R12: 0000000000000000\nR13: ffff9f4b1a3c6c00 R14: ffff9f4b20988e20 R15: 0000000000000004\nFS: 00007f6284340000(0000) GS:ffff9f51fe280000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000013 CR3: 00000001d10a6005 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? xt_find_table_lock (net/netfilter/x_tables.c:1259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? page_fault_oops (arch/x86/mm/fault.c:727)\n ? exc_page_fault (./arch/x86/include/asm/irqflags.h:40 ./arch/x86/include/asm/irqflags.h:75 arch/x86/mm/fault.c:1470 arch/x86/mm/fault.c:1518)\n ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570)\n ? iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat\n xt_find_table_lock (net/netfilter/x_tables.c:1259)\n xt_request_find_table_lock (net/netfilter/x_tables.c:1287)\n get_info (net/ipv4/netfilter/ip_tables.c:965)\n ? security_capable (security/security.c:809 (discriminator 13))\n ? ns_capable (kernel/capability.c:376 kernel/capability.c:397)\n ? do_ipt_get_ctl (net/ipv4/netfilter/ip_tables.c:1656)\n ? bpfilter_send_req (net/bpfilter/bpfilter_kern.c:52) bpfilter\n nf_getsockopt (net/netfilter/nf_sockopt.c:116)\n ip_getsockopt (net/ipv4/ip_sockglue.c:1827)\n __sys_getsockopt (net/socket.c:2327)\n __x64_sys_getsockopt (net/socket.c:2342 net/socket.c:2339 net/socket.c:2339)\n do_syscall_64 (arch/x86/entry/common.c:51 arch/x86/entry/common.c:81)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\nRIP: 0033:0x7f62844685ee\nCode: 48 8b 0d 45 28 0f 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 37 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 09\nRSP: 002b:00007ffd1f83d638 EFLAGS: 00000246 ORIG_RAX: 0000000000000037\nRAX: ffffffffffffffda RBX: 00007ffd1f83d680 RCX: 00007f62844685ee\nRDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000004\nRBP: 0000000000000004 R08: 00007ffd1f83d670 R09: 0000558798ffa2a0\nR10: 00007ffd1f83d680 R11: 0000000000000246 R12: 00007ffd1f83e3b2\nR13: 00007f6284\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42270', 'https://git.kernel.org/linus/5830aa863981d43560748aa93589c0695191d95d (6.11-rc2)', 'https://git.kernel.org/stable/c/08ed888b69a22647153fe2bec55b7cd0a46102cc', 'https://git.kernel.org/stable/c/5830aa863981d43560748aa93589c0695191d95d', 'https://git.kernel.org/stable/c/70014b73d7539fcbb6b4ff5f37368d7241d8e626', 'https://git.kernel.org/stable/c/95590a4929027769af35b153645c0ab6fd22b29b', 'https://git.kernel.org/stable/c/b98ddb65fa1674b0e6b52de8af9103b63f51b643', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42270-c752@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42270', 'https://ubuntu.com/security/notices/USN-7004-1', 'https://ubuntu.com/security/notices/USN-7009-1', 'https://ubuntu.com/security/notices/USN-7009-2', 'https://www.cve.org/CVERecord?id=CVE-2024-42270'], 'PublishedDate': '2024-08-17T09:15:08.24Z', 'LastModifiedDate': '2024-08-19T20:01:09.52Z'}, {'VulnerabilityID': 'CVE-2024-42272', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42272', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched: act_ct: take care of padding in struct zones_ht_key', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched: act_ct: take care of padding in struct zones_ht_key\n\nBlamed commit increased lookup key size from 2 bytes to 16 bytes,\nbecause zones_ht_key got a struct net pointer.\n\nMake sure rhashtable_lookup() is not using the padding bytes\nwhich are not initialized.\n\n BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline]\n BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline]\n BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329\n rht_ptr_rcu include/linux/rhashtable.h:376 [inline]\n __rhashtable_lookup include/linux/rhashtable.h:607 [inline]\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329\n tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408\n tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425\n tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488\n tcf_action_add net/sched/act_api.c:2061 [inline]\n tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118\n rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647\n netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550\n rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665\n netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]\n netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357\n netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n ____sys_sendmsg+0x877/0xb60 net/socket.c:2597\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651\n __sys_sendmsg net/socket.c:2680 [inline]\n __do_sys_sendmsg net/socket.c:2689 [inline]\n __se_sys_sendmsg net/socket.c:2687 [inline]\n __x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2687\n x64_sys_call+0x2dd6/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable key created at:\n tcf_ct_flow_table_get+0x4a/0x2260 net/sched/act_ct.c:324\n tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42272', 'https://git.kernel.org/linus/2191a54f63225b548fd8346be3611c3219a24738 (6.11-rc2)', 'https://git.kernel.org/stable/c/2191a54f63225b548fd8346be3611c3219a24738', 'https://git.kernel.org/stable/c/3a5b68869dbe14f1157c6a24ac71923db060eeab', 'https://git.kernel.org/stable/c/3ddefcb8f75e312535e2e7d5fef9932019ba60f2', 'https://git.kernel.org/stable/c/7c03ab555eb1ba26c77fd7c25bdf44a0ac23edee', 'https://git.kernel.org/stable/c/d06daf0ad645d9225a3ff6958dd82e1f3988fa64', 'https://git.kernel.org/stable/c/d7cc186d0973afce0e1237c37f7512c01981fb79', 'https://linux.oracle.com/cve/CVE-2024-42272.html', 'https://linux.oracle.com/errata/ELSA-2024-8162.html', 'https://lore.kernel.org/linux-cve-announce/2024081739-CVE-2024-42272-c687@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42272', 'https://www.cve.org/CVERecord?id=CVE-2024-42272'], 'PublishedDate': '2024-08-17T09:15:08.37Z', 'LastModifiedDate': '2024-09-30T13:40:21.843Z'}, {'VulnerabilityID': 'CVE-2024-42273', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42273', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid\n\nmkdir /mnt/test/comp\nf2fs_io setflags compression /mnt/test/comp\ndd if=/dev/zero of=/mnt/test/comp/testfile bs=16k count=1\ntruncate --size 13 /mnt/test/comp/testfile\n\nIn the above scenario, we can get a BUG_ON.\n kernel BUG at fs/f2fs/segment.c:3589!\n Call Trace:\n do_write_page+0x78/0x390 [f2fs]\n f2fs_outplace_write_data+0x62/0xb0 [f2fs]\n f2fs_do_write_data_page+0x275/0x740 [f2fs]\n f2fs_write_single_data_page+0x1dc/0x8f0 [f2fs]\n f2fs_write_multi_pages+0x1e5/0xae0 [f2fs]\n f2fs_write_cache_pages+0xab1/0xc60 [f2fs]\n f2fs_write_data_pages+0x2d8/0x330 [f2fs]\n do_writepages+0xcf/0x270\n __writeback_single_inode+0x44/0x350\n writeback_sb_inodes+0x242/0x530\n __writeback_inodes_wb+0x54/0xf0\n wb_writeback+0x192/0x310\n wb_workfn+0x30d/0x400\n\nThe reason is we gave CURSEG_ALL_DATA_ATGC to COMPR_ADDR where the\npage was set the gcing flag by set_cluster_dirty().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42273', 'https://git.kernel.org/linus/8cb1f4080dd91c6e6b01dbea013a3f42341cb6a1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0cd106612396656d6f1ca17ef192c6759bb60791', 'https://git.kernel.org/stable/c/4239571c5db46a42f723b8fa8394039187c34439', 'https://git.kernel.org/stable/c/5fd057160ab240dd816ae09b625395d54c297de1', 'https://git.kernel.org/stable/c/8cb1f4080dd91c6e6b01dbea013a3f42341cb6a1', 'https://lore.kernel.org/linux-cve-announce/2024081740-CVE-2024-42273-9b87@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42273', 'https://www.cve.org/CVERecord?id=CVE-2024-42273'], 'PublishedDate': '2024-08-17T09:15:08.45Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42274', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42274', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Revert "ALSA: firewire-lib: operate for period elapse event in process context"', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "ALSA: firewire-lib: operate for period elapse event in process context"\n\nCommit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period elapse event\nin process context") removed the process context workqueue from\namdtp_domain_stream_pcm_pointer() and update_pcm_pointers() to remove\nits overhead.\n\nWith RME Fireface 800, this lead to a regression since\nKernels 5.14.0, causing an AB/BA deadlock competition for the\nsubstream lock with eventual system freeze under ALSA operation:\n\nthread 0:\n * (lock A) acquire substream lock by\n\tsnd_pcm_stream_lock_irq() in\n\tsnd_pcm_status64()\n * (lock B) wait for tasklet to finish by calling\n \ttasklet_unlock_spin_wait() in\n\ttasklet_disable_in_atomic() in\n\tohci_flush_iso_completions() of ohci.c\n\nthread 1:\n * (lock B) enter tasklet\n * (lock A) attempt to acquire substream lock,\n \twaiting for it to be released:\n\tsnd_pcm_stream_lock_irqsave() in\n \tsnd_pcm_period_elapsed() in\n\tupdate_pcm_pointers() in\n\tprocess_ctx_payloads() in\n\tprocess_rx_packets() of amdtp-stream.c\n\n? tasklet_unlock_spin_wait\n \n \nohci_flush_iso_completions firewire_ohci\namdtp_domain_stream_pcm_pointer snd_firewire_lib\nsnd_pcm_update_hw_ptr0 snd_pcm\nsnd_pcm_status64 snd_pcm\n\n? native_queued_spin_lock_slowpath\n \n \n_raw_spin_lock_irqsave\nsnd_pcm_period_elapsed snd_pcm\nprocess_rx_packets snd_firewire_lib\nirq_target_callback snd_firewire_lib\nhandle_it_packet firewire_ohci\ncontext_tasklet firewire_ohci\n\nRestore the process context work queue to prevent deadlock\nAB/BA deadlock competition for ALSA substream lock of\nsnd_pcm_stream_lock_irq() in snd_pcm_status64()\nand snd_pcm_stream_lock_irqsave() in snd_pcm_period_elapsed().\n\nrevert commit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period\nelapse event in process context")\n\nReplace inline description to prevent future deadlock.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42274', 'https://git.kernel.org/linus/3dab73ab925a51ab05543b491bf17463a48ca323 (6.11-rc2)', 'https://git.kernel.org/stable/c/36c255db5a25edd42d1aca48e38b8e95ee5fd9ef', 'https://git.kernel.org/stable/c/3dab73ab925a51ab05543b491bf17463a48ca323', 'https://git.kernel.org/stable/c/7c07220cf634002f93a87ca2252a32766850f2d1', 'https://git.kernel.org/stable/c/b239a37d68e8bc59f9516444da222841e3b13ba9', 'https://git.kernel.org/stable/c/f5043e69aeb2786f32e84132817a007a6430aa7d', 'https://lore.kernel.org/linux-cve-announce/2024081740-CVE-2024-42274-9dc6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42274', 'https://www.cve.org/CVERecord?id=CVE-2024-42274'], 'PublishedDate': '2024-08-17T09:15:08.53Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42276', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42276', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme-pci: add missing condition check for existence of mapped data', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: add missing condition check for existence of mapped data\n\nnvme_map_data() is called when request has physical segments, hence\nthe nvme_unmap_data() should have same condition to avoid dereference.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42276', 'https://git.kernel.org/linus/c31fad1470389666ac7169fe43aa65bf5b7e2cfd (6.11-rc1)', 'https://git.kernel.org/stable/c/3f8ec1d6b0ebd8268307d52be8301973fa5a01ec', 'https://git.kernel.org/stable/c/70100fe721840bf6d8e5abd25b8bffe4d2e049b7', 'https://git.kernel.org/stable/c/77848b379e9f85a08048a2c8b3b4a7e8396f5f83', 'https://git.kernel.org/stable/c/7cc1f4cd90a00b6191cb8cda2d1302fdce59361c', 'https://git.kernel.org/stable/c/be23ae63080e0bf9e246ab20207200bca6585eba', 'https://git.kernel.org/stable/c/c31fad1470389666ac7169fe43aa65bf5b7e2cfd', 'https://git.kernel.org/stable/c/d135c3352f7c947a922da93c8e763ee6bc208b64', 'https://linux.oracle.com/cve/CVE-2024-42276.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081741-CVE-2024-42276-cb0a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42276', 'https://www.cve.org/CVERecord?id=CVE-2024-42276'], 'PublishedDate': '2024-08-17T09:15:08.673Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42277', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42277', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu: sprd: Avoid NULL deref in sprd_iommu_hw_en\n\nIn sprd_iommu_cleanup() before calling function sprd_iommu_hw_en()\ndom->sdev is equal to NULL, which leads to null dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42277', 'https://git.kernel.org/linus/630482ee0653decf9e2482ac6181897eb6cde5b8 (6.11-rc1)', 'https://git.kernel.org/stable/c/630482ee0653decf9e2482ac6181897eb6cde5b8', 'https://git.kernel.org/stable/c/8c79ceb4ecf823e6ec10fee6febb0fca3de79922', 'https://git.kernel.org/stable/c/b62841e49a2b7938f6fdeaaf93fb57e4eb880bdb', 'https://git.kernel.org/stable/c/d5fe884ce28c5005f8582c35333c195a168f841c', 'https://git.kernel.org/stable/c/dfe90030a0cfa26dca4cb6510de28920e5ad22fb', 'https://lore.kernel.org/linux-cve-announce/2024081741-CVE-2024-42277-997a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42277', 'https://www.cve.org/CVERecord?id=CVE-2024-42277'], 'PublishedDate': '2024-08-17T09:15:08.75Z', 'LastModifiedDate': '2024-09-10T18:46:21.62Z'}, {'VulnerabilityID': 'CVE-2024-42278', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42278', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: TAS2781: Fix tasdev_load_calibrated_data()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: TAS2781: Fix tasdev_load_calibrated_data()\n\nThis function has a reversed if statement so it's either a no-op or it\nleads to a NULL dereference.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42278', 'https://git.kernel.org/linus/92c78222168e9035a9bfb8841c2e56ce23e51f73 (6.11-rc1)', 'https://git.kernel.org/stable/c/51be301d29d674ff328dfcf23705851f326f35b3', 'https://git.kernel.org/stable/c/6d98741dbd1309a6f2d7cffbb10a8f036ec3ca06', 'https://git.kernel.org/stable/c/92c78222168e9035a9bfb8841c2e56ce23e51f73', 'https://lore.kernel.org/linux-cve-announce/2024081742-CVE-2024-42278-e639@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42278', 'https://www.cve.org/CVERecord?id=CVE-2024-42278'], 'PublishedDate': '2024-08-17T09:15:08.813Z', 'LastModifiedDate': '2024-09-30T12:53:36.42Z'}, {'VulnerabilityID': 'CVE-2024-42279', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42279', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: spi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer\n\nWhile transmitting with rx_len == 0, the RX FIFO is not going to be\nemptied in the interrupt handler. A subsequent transfer could then\nread crap from the previous transfer out of the RX FIFO into the\nstart RX buffer. The core provides a register that will empty the RX and\nTX FIFOs, so do that before each transfer.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L', 'V3Score': 5.8}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42279', 'https://git.kernel.org/linus/9cf71eb0faef4bff01df4264841b8465382d7927 (6.11-rc1)', 'https://git.kernel.org/stable/c/3feda3677e8bbe833c3a62a4091377a08f015b80', 'https://git.kernel.org/stable/c/45e03d35229b680b79dfea1103a1f2f07d0b5d75', 'https://git.kernel.org/stable/c/9cf71eb0faef4bff01df4264841b8465382d7927', 'https://lore.kernel.org/linux-cve-announce/2024081742-CVE-2024-42279-91b0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42279', 'https://www.cve.org/CVERecord?id=CVE-2024-42279'], 'PublishedDate': '2024-08-17T09:15:08.88Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42281', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42281', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix a segment issue when downgrading gso_size', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a segment issue when downgrading gso_size\n\nLinearize the skb when downgrading gso_size because it may trigger a\nBUG_ON() later when the skb is segmented as described in [1,2].', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42281', 'https://git.kernel.org/linus/fa5ef655615a01533035c6139248c5b33aa27028 (6.11-rc1)', 'https://git.kernel.org/stable/c/11ec79f5c7f74261874744039bc1551023edd6b2', 'https://git.kernel.org/stable/c/a689f5eb13a90f892a088865478b3cd39f53d5dc', 'https://git.kernel.org/stable/c/c3496314c53e7e82ddb544c825defc3e8c0e45cf', 'https://git.kernel.org/stable/c/dda518dea60d556a2d171c0122ca7d9fdb7d473a', 'https://git.kernel.org/stable/c/ec4eea14d75f7b0491194dd413f540dd19b8c733', 'https://git.kernel.org/stable/c/f6bb8c90cab97a3e03f8d30e3069efe6a742e0be', 'https://git.kernel.org/stable/c/fa5ef655615a01533035c6139248c5b33aa27028', 'https://linux.oracle.com/cve/CVE-2024-42281.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42281-780b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42281', 'https://www.cve.org/CVERecord?id=CVE-2024-42281'], 'PublishedDate': '2024-08-17T09:15:09.013Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42283', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42283', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: nexthop: Initialize all fields in dumped nexthops', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nexthop: Initialize all fields in dumped nexthops\n\nstruct nexthop_grp contains two reserved fields that are not initialized by\nnla_put_nh_group(), and carry garbage. This can be observed e.g. with\nstrace (edited for clarity):\n\n # ip nexthop add id 1 dev lo\n # ip nexthop add id 101 group 1\n # strace -e recvmsg ip nexthop get id 101\n ...\n recvmsg(... [{nla_len=12, nla_type=NHA_GROUP},\n [{id=1, weight=0, resvd1=0x69, resvd2=0x67}]] ...) = 52\n\nThe fields are reserved and therefore not currently used. But as they are, they\nleak kernel memory, and the fact they are not just zero complicates repurposing\nof the fields for new ends. Initialize the full structure.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42283', 'https://git.kernel.org/linus/6d745cd0e9720282cd291d36b9db528aea18add2 (6.11-rc1)', 'https://git.kernel.org/stable/c/1377de719652d868f5317ba8398b7e74c5f0430b', 'https://git.kernel.org/stable/c/5cc4d71dda2dd4f1520f40e634a527022e48ccd8', 'https://git.kernel.org/stable/c/6d745cd0e9720282cd291d36b9db528aea18add2', 'https://git.kernel.org/stable/c/7704460acd7f5d35eb07c52500987dc9b95313fb', 'https://git.kernel.org/stable/c/9e8f558a3afe99ce51a642ce0d3637ddc2b5d5d0', 'https://git.kernel.org/stable/c/a13d3864b76ac87085ec530b2ff8e37482a63a96', 'https://git.kernel.org/stable/c/fd06cb4a5fc7bda3dea31712618a62af72a1c6cb', 'https://linux.oracle.com/cve/CVE-2024-42283.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42283-15a5@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42283', 'https://www.cve.org/CVERecord?id=CVE-2024-42283'], 'PublishedDate': '2024-08-17T09:15:09.163Z', 'LastModifiedDate': '2024-08-19T19:54:33.213Z'}, {'VulnerabilityID': 'CVE-2024-42284', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42284', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Return non-zero value from tipc_udp_addr2str() on error\n\ntipc_udp_addr2str() should return non-zero value if the UDP media\naddress is invalid. Otherwise, a buffer overflow access can occur in\ntipc_media_addr_printf(). Fix this by returning 1 on an invalid UDP\nmedia address.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-754'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 7.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42284', 'https://git.kernel.org/linus/fa96c6baef1b5385e2f0c0677b32b3839e716076 (6.11-rc1)', 'https://git.kernel.org/stable/c/253405541be2f15ffebdeac2f4cf4b7e9144d12f', 'https://git.kernel.org/stable/c/2abe350db1aa599eeebc6892237d0bce0f1de62a', 'https://git.kernel.org/stable/c/5eea127675450583680c8170358bcba43227bd69', 'https://git.kernel.org/stable/c/728734352743a78b4c5a7285b282127696a4a813', 'https://git.kernel.org/stable/c/76ddf84a52f0d8ec3f5db6ccce08faf202a17d28', 'https://git.kernel.org/stable/c/7ec3335dd89c8d169e9650e4bac64fde71fdf15b', 'https://git.kernel.org/stable/c/aa38bf74899de07cf70b50cd17f8ad45fb6654c8', 'https://git.kernel.org/stable/c/fa96c6baef1b5385e2f0c0677b32b3839e716076', 'https://linux.oracle.com/cve/CVE-2024-42284.html', 'https://linux.oracle.com/errata/ELSA-2024-8162.html', 'https://lore.kernel.org/linux-cve-announce/2024081743-CVE-2024-42284-bbfa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42284', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-42284'], 'PublishedDate': '2024-08-17T09:15:09.233Z', 'LastModifiedDate': '2024-08-19T19:47:55.623Z'}, {'VulnerabilityID': 'CVE-2024-42285', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42285', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/iwcm: Fix a use-after-free related to destroying CM IDs\n\niw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with\nan existing struct iw_cm_id (cm_id) as follows:\n\n conn_id->cm_id.iw = cm_id;\n cm_id->context = conn_id;\n cm_id->cm_handler = cma_iw_handler;\n\nrdma_destroy_id() frees both the cm_id and the struct rdma_id_private. Make\nsure that cm_work_handler() does not trigger a use-after-free by only\nfreeing of the struct rdma_id_private after all pending work has finished.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42285', 'https://git.kernel.org/linus/aee2424246f9f1dadc33faa78990c1e2eb7826e4 (6.11-rc1)', 'https://git.kernel.org/stable/c/557d035fe88d78dd51664f4dc0e1896c04c97cf6', 'https://git.kernel.org/stable/c/7f25f296fc9bd0435be14e89bf657cd615a23574', 'https://git.kernel.org/stable/c/94ee7ff99b87435ec63211f632918dc7f44dac79', 'https://git.kernel.org/stable/c/aee2424246f9f1dadc33faa78990c1e2eb7826e4', 'https://git.kernel.org/stable/c/d91d253c87fd1efece521ff2612078a35af673c6', 'https://git.kernel.org/stable/c/dc8074b8901caabb97c2d353abd6b4e7fa5a59a5', 'https://git.kernel.org/stable/c/ee39384ee787e86e9db4efb843818ef0ea9cb8ae', 'https://git.kernel.org/stable/c/ff5bbbdee08287d75d72e65b72a2b76d9637892a', 'https://linux.oracle.com/cve/CVE-2024-42285.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42285-37ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42285', 'https://www.cve.org/CVERecord?id=CVE-2024-42285'], 'PublishedDate': '2024-08-17T09:15:09.3Z', 'LastModifiedDate': '2024-08-19T19:45:41.59Z'}, {'VulnerabilityID': 'CVE-2024-42286', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42286', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: validate nvme_local_port correctly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: validate nvme_local_port correctly\n\nThe driver load failed with error message,\n\nqla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef\n\nand with a kernel crash,\n\n\tBUG: unable to handle kernel NULL pointer dereference at 0000000000000070\n\tWorkqueue: events_unbound qla_register_fcport_fn [qla2xxx]\n\tRIP: 0010:nvme_fc_register_remoteport+0x16/0x430 [nvme_fc]\n\tRSP: 0018:ffffaaa040eb3d98 EFLAGS: 00010282\n\tRAX: 0000000000000000 RBX: ffff9dfb46b78c00 RCX: 0000000000000000\n\tRDX: ffff9dfb46b78da8 RSI: ffffaaa040eb3e08 RDI: 0000000000000000\n\tRBP: ffff9dfb612a0a58 R08: ffffffffaf1d6270 R09: 3a34303a30303030\n\tR10: 34303a303030305b R11: 2078787832616c71 R12: ffff9dfb46b78dd4\n\tR13: ffff9dfb46b78c24 R14: ffff9dfb41525300 R15: ffff9dfb46b78da8\n\tFS: 0000000000000000(0000) GS:ffff9dfc67c00000(0000) knlGS:0000000000000000\n\tCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n\tCR2: 0000000000000070 CR3: 000000018da10004 CR4: 00000000000206f0\n\tCall Trace:\n\tqla_nvme_register_remote+0xeb/0x1f0 [qla2xxx]\n\t? qla2x00_dfs_create_rport+0x231/0x270 [qla2xxx]\n\tqla2x00_update_fcport+0x2a1/0x3c0 [qla2xxx]\n\tqla_register_fcport_fn+0x54/0xc0 [qla2xxx]\n\nExit the qla_nvme_register_remote() function when qla_nvme_register_hba()\nfails and correctly validate nvme_local_port.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42286', 'https://git.kernel.org/linus/eb1d4ce2609584eeb7694866f34d4b213caa3af9 (6.11-rc1)', 'https://git.kernel.org/stable/c/3eac973eb5cb2b874b3918f924798afc5affd46b', 'https://git.kernel.org/stable/c/549aac9655320c9b245a24271b204668c5d40430', 'https://git.kernel.org/stable/c/7cec2c3bfe84539c415f5e16f989228eba1d2f1e', 'https://git.kernel.org/stable/c/a3ab508a4853a9f5ae25a7816a4889f09938f63c', 'https://git.kernel.org/stable/c/cde43031df533751b4ead37d173922feee2f550f', 'https://git.kernel.org/stable/c/e1f010844443c389bc552884ac5cfa47de34d54c', 'https://git.kernel.org/stable/c/eb1d4ce2609584eeb7694866f34d4b213caa3af9', 'https://git.kernel.org/stable/c/f6be298cc1042f24d521197af29c7c4eb95af4d5', 'https://linux.oracle.com/cve/CVE-2024-42286.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42286-e856@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42286', 'https://www.cve.org/CVERecord?id=CVE-2024-42286'], 'PublishedDate': '2024-08-17T09:15:09.38Z', 'LastModifiedDate': '2024-09-10T19:02:12.36Z'}, {'VulnerabilityID': 'CVE-2024-42287', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42287', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: Complete command early within lock', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Complete command early within lock\n\nA crash was observed while performing NPIV and FW reset,\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 1 PREEMPT_RT SMP NOPTI\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffc90026f47b88 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000002\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8881041130d0\n RBP: ffff8881041130d0 R08: 0000000000000000 R09: 0000000000000034\n R10: ffffc90026f47c48 R11: 0000000000000031 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8881565e4a20 R15: 0000000000000000\n FS: 00007f4c69ed3d00(0000) GS:ffff889faac80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000000288a50002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die_body+0x1a/0x60\n ? page_fault_oops+0x16f/0x4a0\n ? do_user_addr_fault+0x174/0x7f0\n ? exc_page_fault+0x69/0x1a0\n ? asm_exc_page_fault+0x22/0x30\n ? dma_direct_unmap_sg+0x51/0x1e0\n ? preempt_count_sub+0x96/0xe0\n qla2xxx_qpair_sp_free_dma+0x29f/0x3b0 [qla2xxx]\n qla2xxx_qpair_sp_compl+0x60/0x80 [qla2xxx]\n __qla2x00_abort_all_cmds+0xa2/0x450 [qla2xxx]\n\nThe command completion was done early while aborting the commands in driver\nunload path but outside lock to avoid the WARN_ON condition of performing\ndma_free_attr within the lock. However this caused race condition while\ncommand completion via multiple paths causing system crash.\n\nHence complete the command early in unload path but within the lock to\navoid race condition.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42287', 'https://git.kernel.org/linus/4475afa2646d3fec176fc4d011d3879b26cb26e3 (6.11-rc1)', 'https://git.kernel.org/stable/c/314efe3f87949a568f512f05df20bf47b81cf232', 'https://git.kernel.org/stable/c/36fdc5319c4d0ec8b8938ec4769764098a246bfb', 'https://git.kernel.org/stable/c/4475afa2646d3fec176fc4d011d3879b26cb26e3', 'https://git.kernel.org/stable/c/57ba7563712227647f82a92547e82c96cd350553', 'https://git.kernel.org/stable/c/814f4a53cc86f7ea8b501bfb1723f24fd29ef5ee', 'https://git.kernel.org/stable/c/9117337b04d789bd08fdd9854a40bec2815cd3f6', 'https://git.kernel.org/stable/c/af46649304b0c9cede4ccfc2be2561ce8ed6a2ea', 'https://linux.oracle.com/cve/CVE-2024-42287.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081744-CVE-2024-42287-d635@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42287', 'https://www.cve.org/CVERecord?id=CVE-2024-42287'], 'PublishedDate': '2024-08-17T09:15:09.453Z', 'LastModifiedDate': '2024-09-10T19:05:07.67Z'}, {'VulnerabilityID': 'CVE-2024-42288', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42288', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: Fix for possible memory corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix for possible memory corruption\n\nInit Control Block is dereferenced incorrectly. Correctly dereference ICB', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42288', 'https://git.kernel.org/linus/c03d740152f78e86945a75b2ad541bf972fab92a (6.11-rc1)', 'https://git.kernel.org/stable/c/2a15b59a2c5afac89696e44acf5bbfc0599c6c5e', 'https://git.kernel.org/stable/c/571d7f2a08836698c2fb0d792236424575b9829b', 'https://git.kernel.org/stable/c/8192c533e89d9fb69b2490398939236b78cda79b', 'https://git.kernel.org/stable/c/87db8d7b7520e99de71791260989f06f9c94953d', 'https://git.kernel.org/stable/c/b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce', 'https://git.kernel.org/stable/c/c03d740152f78e86945a75b2ad541bf972fab92a', 'https://git.kernel.org/stable/c/dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb', 'https://linux.oracle.com/cve/CVE-2024-42288.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42288-c59b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42288', 'https://www.cve.org/CVERecord?id=CVE-2024-42288'], 'PublishedDate': '2024-08-17T09:15:09.523Z', 'LastModifiedDate': '2024-09-05T17:38:38.383Z'}, {'VulnerabilityID': 'CVE-2024-42289', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42289', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: qla2xxx: During vport delete send async logout explicitly', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: During vport delete send async logout explicitly\n\nDuring vport delete, it is observed that during unload we hit a crash\nbecause of stale entries in outstanding command array. For all these stale\nI/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but\nI/Os could not complete while vport delete is in process of deleting.\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n Workqueue: qla2xxx_wq qla_do_work [qla2xxx]\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0\n RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8\n R10: ffff8ce378aac8a0 R11: ffffa1e1e150f9d8 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8ce378aac9c8 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8d217f000000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000002089acc000 CR4: 0000000000350ee0\n Call Trace:\n \n qla2xxx_qpair_sp_free_dma+0x417/0x4e0\n ? qla2xxx_qpair_sp_compl+0x10d/0x1a0\n ? qla2x00_status_entry+0x768/0x2830\n ? newidle_balance+0x2f0/0x430\n ? dequeue_entity+0x100/0x3c0\n ? qla24xx_process_response_queue+0x6a1/0x19e0\n ? __schedule+0x2d5/0x1140\n ? qla_do_work+0x47/0x60\n ? process_one_work+0x267/0x440\n ? process_one_work+0x440/0x440\n ? worker_thread+0x2d/0x3d0\n ? process_one_work+0x440/0x440\n ? kthread+0x156/0x180\n ? set_kthread_struct+0x50/0x50\n ? ret_from_fork+0x22/0x30\n \n\nSend out async logout explicitly for all the ports during vport delete.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42289', 'https://git.kernel.org/linus/76f480d7c717368f29a3870f7d64471ce0ff8fb2 (6.11-rc1)', 'https://git.kernel.org/stable/c/086489256696eb774654a5410e86381c346356fe', 'https://git.kernel.org/stable/c/171ac4b495f9473bc134356a00095b47e6409e52', 'https://git.kernel.org/stable/c/76f480d7c717368f29a3870f7d64471ce0ff8fb2', 'https://git.kernel.org/stable/c/87c25fcb95aafabb6a4914239f4ab41b07a4f9b7', 'https://git.kernel.org/stable/c/b12c54e51ba83c1fbc619d35083d7872e42ecdef', 'https://git.kernel.org/stable/c/b35d6d5a2f38605cddea7d5c64cded894fbe8ede', 'https://git.kernel.org/stable/c/d28a2075bb530489715a3b011e1dd8765ba20313', 'https://git.kernel.org/stable/c/e5ed6a26ffdec0c91cf0b6138afbd675c00ad5fc', 'https://linux.oracle.com/cve/CVE-2024-42289.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42289-fe68@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42289', 'https://www.cve.org/CVERecord?id=CVE-2024-42289'], 'PublishedDate': '2024-08-17T09:15:09.59Z', 'LastModifiedDate': '2024-09-05T17:37:49.057Z'}, {'VulnerabilityID': 'CVE-2024-42290', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42290', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: irqchip/imx-irqsteer: Handle runtime power management correctly', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/imx-irqsteer: Handle runtime power management correctly\n\nThe power domain is automatically activated from clk_prepare(). However, on\ncertain platforms like i.MX8QM and i.MX8QXP, the power-on handling invokes\nsleeping functions, which triggers the 'scheduling while atomic' bug in the\ncontext switch path during device probing:\n\n BUG: scheduling while atomic: kworker/u13:1/48/0x00000002\n Call trace:\n __schedule_bug+0x54/0x6c\n __schedule+0x7f0/0xa94\n schedule+0x5c/0xc4\n schedule_preempt_disabled+0x24/0x40\n __mutex_lock.constprop.0+0x2c0/0x540\n __mutex_lock_slowpath+0x14/0x20\n mutex_lock+0x48/0x54\n clk_prepare_lock+0x44/0xa0\n clk_prepare+0x20/0x44\n imx_irqsteer_resume+0x28/0xe0\n pm_generic_runtime_resume+0x2c/0x44\n __genpd_runtime_resume+0x30/0x80\n genpd_runtime_resume+0xc8/0x2c0\n __rpm_callback+0x48/0x1d8\n rpm_callback+0x6c/0x78\n rpm_resume+0x490/0x6b4\n __pm_runtime_resume+0x50/0x94\n irq_chip_pm_get+0x2c/0xa0\n __irq_do_set_handler+0x178/0x24c\n irq_set_chained_handler_and_data+0x60/0xa4\n mxc_gpio_probe+0x160/0x4b0\n\nCure this by implementing the irq_bus_lock/sync_unlock() interrupt chip\ncallbacks and handle power management in them as they are invoked from\nnon-atomic context.\n\n[ tglx: Rewrote change log, added Fixes tag ]", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42290', 'https://git.kernel.org/linus/33b1c47d1fc0b5f06a393bb915db85baacba18ea (6.11-rc1)', 'https://git.kernel.org/stable/c/21bd3f9e7f924cd2fc892a484e7a50c7e1847565', 'https://git.kernel.org/stable/c/33b1c47d1fc0b5f06a393bb915db85baacba18ea', 'https://git.kernel.org/stable/c/3a2884a44e5cda192df1b28e9925661f79f599a1', 'https://git.kernel.org/stable/c/58c56735facb225a5c46fa4b8bbbe7f31d1cb894', 'https://git.kernel.org/stable/c/a590e8dea3df2639921f874d763be961dd74e8f9', 'https://git.kernel.org/stable/c/f8ae38f1dfe652779c7c613facbc257cec00ac44', 'https://git.kernel.org/stable/c/fa1803401e1c360efe6342fb41d161cc51748a11', 'https://linux.oracle.com/cve/CVE-2024-42290.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081745-CVE-2024-42290-c966@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42290', 'https://www.cve.org/CVERecord?id=CVE-2024-42290'], 'PublishedDate': '2024-08-17T09:15:09.663Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42291', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42291', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ice: Add a per-VF limit on number of FDIR filters', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add a per-VF limit on number of FDIR filters\n\nWhile the iavf driver adds a s/w limit (128) on the number of FDIR\nfilters that the VF can request, a malicious VF driver can request more\nthan that and exhaust the resources for other VFs.\n\nAdd a similar limit in ice.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42291', 'https://git.kernel.org/linus/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97 (6.11-rc1)', 'https://git.kernel.org/stable/c/292081c4e7f575a79017d5cbe1a0ec042783976f', 'https://git.kernel.org/stable/c/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97', 'https://git.kernel.org/stable/c/8e02cd98a6e24389d476e28436d41e620ed8e559', 'https://git.kernel.org/stable/c/d62389073a5b937413e2d1bc1da06ccff5103c0c', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42291-6f31@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42291', 'https://www.cve.org/CVERecord?id=CVE-2024-42291'], 'PublishedDate': '2024-08-17T09:15:09.73Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42292', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42292', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kobject_uevent: Fix OOB access within zap_modalias_env()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkobject_uevent: Fix OOB access within zap_modalias_env()\n\nzap_modalias_env() wrongly calculates size of memory block to move, so\nwill cause OOB memory access issue if variable MODALIAS is not the last\none within its @env parameter, fixed by correcting size to memmove.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42292', 'https://git.kernel.org/linus/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc (6.11-rc1)', 'https://git.kernel.org/stable/c/57fe01d3d04276875c7e3a6dc763517fc05b8762', 'https://git.kernel.org/stable/c/648d5490460d38436640da0812bf7f6351c150d2', 'https://git.kernel.org/stable/c/68d63ace80b76395e7935687ecdb86421adc2168', 'https://git.kernel.org/stable/c/81a15d28f32af01493ae8c5457e0d55314a4167d', 'https://git.kernel.org/stable/c/b59a5e86a3934f1b6a5bd1368902dbc79bdecc90', 'https://git.kernel.org/stable/c/c5ee8adc8d98a49703320d13878ba2b923b142f5', 'https://git.kernel.org/stable/c/d4663536754defff75ff1eca0aaebc41da165a8d', 'https://git.kernel.org/stable/c/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc', 'https://linux.oracle.com/cve/CVE-2024-42292.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42292-5387@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42292', 'https://www.cve.org/CVERecord?id=CVE-2024-42292'], 'PublishedDate': '2024-08-17T09:15:09.797Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42294', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42294', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: fix deadlock between sd_remove & sd_release', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix deadlock between sd_remove & sd_release\n\nOur test report the following hung task:\n\n[ 2538.459400] INFO: task "kworker/0:0":7 blocked for more than 188 seconds.\n[ 2538.459427] Call trace:\n[ 2538.459430] __switch_to+0x174/0x338\n[ 2538.459436] __schedule+0x628/0x9c4\n[ 2538.459442] schedule+0x7c/0xe8\n[ 2538.459447] schedule_preempt_disabled+0x24/0x40\n[ 2538.459453] __mutex_lock+0x3ec/0xf04\n[ 2538.459456] __mutex_lock_slowpath+0x14/0x24\n[ 2538.459459] mutex_lock+0x30/0xd8\n[ 2538.459462] del_gendisk+0xdc/0x350\n[ 2538.459466] sd_remove+0x30/0x60\n[ 2538.459470] device_release_driver_internal+0x1c4/0x2c4\n[ 2538.459474] device_release_driver+0x18/0x28\n[ 2538.459478] bus_remove_device+0x15c/0x174\n[ 2538.459483] device_del+0x1d0/0x358\n[ 2538.459488] __scsi_remove_device+0xa8/0x198\n[ 2538.459493] scsi_forget_host+0x50/0x70\n[ 2538.459497] scsi_remove_host+0x80/0x180\n[ 2538.459502] usb_stor_disconnect+0x68/0xf4\n[ 2538.459506] usb_unbind_interface+0xd4/0x280\n[ 2538.459510] device_release_driver_internal+0x1c4/0x2c4\n[ 2538.459514] device_release_driver+0x18/0x28\n[ 2538.459518] bus_remove_device+0x15c/0x174\n[ 2538.459523] device_del+0x1d0/0x358\n[ 2538.459528] usb_disable_device+0x84/0x194\n[ 2538.459532] usb_disconnect+0xec/0x300\n[ 2538.459537] hub_event+0xb80/0x1870\n[ 2538.459541] process_scheduled_works+0x248/0x4dc\n[ 2538.459545] worker_thread+0x244/0x334\n[ 2538.459549] kthread+0x114/0x1bc\n\n[ 2538.461001] INFO: task "fsck.":15415 blocked for more than 188 seconds.\n[ 2538.461014] Call trace:\n[ 2538.461016] __switch_to+0x174/0x338\n[ 2538.461021] __schedule+0x628/0x9c4\n[ 2538.461025] schedule+0x7c/0xe8\n[ 2538.461030] blk_queue_enter+0xc4/0x160\n[ 2538.461034] blk_mq_alloc_request+0x120/0x1d4\n[ 2538.461037] scsi_execute_cmd+0x7c/0x23c\n[ 2538.461040] ioctl_internal_command+0x5c/0x164\n[ 2538.461046] scsi_set_medium_removal+0x5c/0xb0\n[ 2538.461051] sd_release+0x50/0x94\n[ 2538.461054] blkdev_put+0x190/0x28c\n[ 2538.461058] blkdev_release+0x28/0x40\n[ 2538.461063] __fput+0xf8/0x2a8\n[ 2538.461066] __fput_sync+0x28/0x5c\n[ 2538.461070] __arm64_sys_close+0x84/0xe8\n[ 2538.461073] invoke_syscall+0x58/0x114\n[ 2538.461078] el0_svc_common+0xac/0xe0\n[ 2538.461082] do_el0_svc+0x1c/0x28\n[ 2538.461087] el0_svc+0x38/0x68\n[ 2538.461090] el0t_64_sync_handler+0x68/0xbc\n[ 2538.461093] el0t_64_sync+0x1a8/0x1ac\n\n T1:\t\t\t\tT2:\n sd_remove\n del_gendisk\n __blk_mark_disk_dead\n blk_freeze_queue_start\n ++q->mq_freeze_depth\n \t\t\t\tbdev_release\n \t\t\t\tmutex_lock(&disk->open_mutex)\n \t\t\t\tsd_release\n \t\t\t\tscsi_execute_cmd\n \t\t\t\tblk_queue_enter\n \t\t\t\twait_event(!q->mq_freeze_depth)\n mutex_lock(&disk->open_mutex)\n\nSCSI does not set GD_OWNS_QUEUE, so QUEUE_FLAG_DYING is not set in\nthis scenario. This is a classic ABBA deadlock. To fix the deadlock,\nmake sure we don\'t try to acquire disk->open_mutex after freezing\nthe queue.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42294', 'https://git.kernel.org/stable/c/5a5625a83eac91fdff1d5f0202ecfc45a31983c9', 'https://git.kernel.org/stable/c/7e04da2dc7013af50ed3a2beb698d5168d1e594b', 'https://git.kernel.org/stable/c/f5418f48a93b69ed9e6a2281eee06b412f14a544', 'https://lore.kernel.org/linux-cve-announce/2024081746-CVE-2024-42294-0145@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42294', 'https://www.cve.org/CVERecord?id=CVE-2024-42294'], 'PublishedDate': '2024-08-17T09:15:09.947Z', 'LastModifiedDate': '2024-08-19T19:43:22.46Z'}, {'VulnerabilityID': 'CVE-2024-42295', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42295', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nilfs2: handle inconsistent state in nilfs_btnode_create_block()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: handle inconsistent state in nilfs_btnode_create_block()\n\nSyzbot reported that a buffer state inconsistency was detected in\nnilfs_btnode_create_block(), triggering a kernel bug.\n\nIt is not appropriate to treat this inconsistency as a bug; it can occur\nif the argument block address (the buffer index of the newly created\nblock) is a virtual block number and has been reallocated due to\ncorruption of the bitmap used to manage its allocation state.\n\nSo, modify nilfs_btnode_create_block() and its callers to treat it as a\npossible filesystem error, rather than triggering a kernel bug.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42295', 'https://git.kernel.org/linus/4811f7af6090e8f5a398fbdd766f903ef6c0d787 (6.11-rc1)', 'https://git.kernel.org/stable/c/012be828a118bf496e666ef1fc47fc0e7358ada2', 'https://git.kernel.org/stable/c/02b87e6334a38c65eef49848d3f1ac422f0b2a44', 'https://git.kernel.org/stable/c/19cce46238ffe3546e44b9c74057103ff8b24c62', 'https://git.kernel.org/stable/c/366c3f688dd0288cbe38af1d3a886b5c62372e4a', 'https://git.kernel.org/stable/c/4811f7af6090e8f5a398fbdd766f903ef6c0d787', 'https://git.kernel.org/stable/c/5f0a6800b8aec1b453c7fe4c44fcaac5ffe9d52e', 'https://git.kernel.org/stable/c/be56dfc9be0604291267c07b0e27a69a6bda4899', 'https://git.kernel.org/stable/c/e34191cce3ee63dfa5fb241904aaf2a042d5b6d8', 'https://linux.oracle.com/cve/CVE-2024-42295.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42295-4f43@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42295', 'https://www.cve.org/CVERecord?id=CVE-2024-42295'], 'PublishedDate': '2024-08-17T09:15:10.017Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42296', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42296', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix return value of f2fs_convert_inline_inode()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix return value of f2fs_convert_inline_inode()\n\nIf device is readonly, make f2fs_convert_inline_inode()\nreturn EROFS instead of zero, otherwise it may trigger\npanic during writeback of inline inode's dirty page as\nbelow:\n\n f2fs_write_single_data_page+0xbb6/0x1e90 fs/f2fs/data.c:2888\n f2fs_write_cache_pages fs/f2fs/data.c:3187 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3342 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3369\n do_writepages+0x359/0x870 mm/page-writeback.c:2634\n filemap_fdatawrite_wbc+0x125/0x180 mm/filemap.c:397\n __filemap_fdatawrite_range mm/filemap.c:430 [inline]\n file_write_and_wait_range+0x1aa/0x290 mm/filemap.c:788\n f2fs_do_sync_file+0x68a/0x1ae0 fs/f2fs/file.c:276\n generic_write_sync include/linux/fs.h:2806 [inline]\n f2fs_file_write_iter+0x7bd/0x24e0 fs/f2fs/file.c:4977\n call_write_iter include/linux/fs.h:2114 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xa72/0xc90 fs/read_write.c:590\n ksys_write+0x1a0/0x2c0 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42296', 'https://git.kernel.org/linus/a8eb3de28e7a365690c61161e7a07a4fc7c60bbf (6.11-rc1)', 'https://git.kernel.org/stable/c/077f0e24b27c4b44841593c7edbd1993be9eecb5', 'https://git.kernel.org/stable/c/1e7725814361c8c008d131db195cef8274ff26b8', 'https://git.kernel.org/stable/c/47a8ddcdcaccd9b891db4574795e46a33a121ac2', 'https://git.kernel.org/stable/c/70f5ef5f33c333cfb286116fa3af74ac9bc84f1b', 'https://git.kernel.org/stable/c/a8eb3de28e7a365690c61161e7a07a4fc7c60bbf', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42296-3f50@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42296', 'https://www.cve.org/CVERecord?id=CVE-2024-42296'], 'PublishedDate': '2024-08-17T09:15:10.08Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42297', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42297', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: f2fs: fix to don't dirty inode for readonly filesystem", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to don't dirty inode for readonly filesystem\n\nsyzbot reports f2fs bug as below:\n\nkernel BUG at fs/f2fs/inode.c:933!\nRIP: 0010:f2fs_evict_inode+0x1576/0x1590 fs/f2fs/inode.c:933\nCall Trace:\n evict+0x2a4/0x620 fs/inode.c:664\n dispose_list fs/inode.c:697 [inline]\n evict_inodes+0x5f8/0x690 fs/inode.c:747\n generic_shutdown_super+0x9d/0x2c0 fs/super.c:675\n kill_block_super+0x44/0x90 fs/super.c:1667\n kill_f2fs_super+0x303/0x3b0 fs/f2fs/super.c:4894\n deactivate_locked_super+0xc1/0x130 fs/super.c:484\n cleanup_mnt+0x426/0x4c0 fs/namespace.c:1256\n task_work_run+0x24a/0x300 kernel/task_work.c:180\n ptrace_notify+0x2cd/0x380 kernel/signal.c:2399\n ptrace_report_syscall include/linux/ptrace.h:411 [inline]\n ptrace_report_syscall_exit include/linux/ptrace.h:473 [inline]\n syscall_exit_work kernel/entry/common.c:251 [inline]\n syscall_exit_to_user_mode_prepare kernel/entry/common.c:278 [inline]\n __syscall_exit_to_user_mode_work kernel/entry/common.c:283 [inline]\n syscall_exit_to_user_mode+0x15c/0x280 kernel/entry/common.c:296\n do_syscall_64+0x50/0x110 arch/x86/entry/common.c:88\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nThe root cause is:\n- do_sys_open\n - f2fs_lookup\n - __f2fs_find_entry\n - f2fs_i_depth_write\n - f2fs_mark_inode_dirty_sync\n - f2fs_dirty_inode\n - set_inode_flag(inode, FI_DIRTY_INODE)\n\n- umount\n - kill_f2fs_super\n - kill_block_super\n - generic_shutdown_super\n - sync_filesystem\n : sb is readonly, skip sync_filesystem()\n - evict_inodes\n - iput\n - f2fs_evict_inode\n - f2fs_bug_on(sbi, is_inode_flag_set(inode, FI_DIRTY_INODE))\n : trigger kernel panic\n\nWhen we try to repair i_current_depth in readonly filesystem, let's\nskip dirty inode to avoid panic in later f2fs_evict_inode().", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42297', 'https://git.kernel.org/linus/192b8fb8d1c8ca3c87366ebbef599fa80bb626b8 (6.11-rc1)', 'https://git.kernel.org/stable/c/192b8fb8d1c8ca3c87366ebbef599fa80bb626b8', 'https://git.kernel.org/stable/c/2434344559f6743efb3ac15d11af9a0db9543bd3', 'https://git.kernel.org/stable/c/2d2916516577f2239b3377d9e8d12da5e6ccdfcf', 'https://git.kernel.org/stable/c/54162974aea37a8cae00742470a78c7f6bd6f915', 'https://git.kernel.org/stable/c/54bc4e88447e385c4d4ffa85d93e0dce628fcfa6', 'https://git.kernel.org/stable/c/9ce8135accf103f7333af472709125878704fdd4', 'https://git.kernel.org/stable/c/e62ff092a42f4a1bae3b310cf46673b4f3aac3b5', 'https://git.kernel.org/stable/c/ec56571b4b146a1cfbedab49d5fcaf19fe8bf4f1', 'https://linux.oracle.com/cve/CVE-2024-42297.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081747-CVE-2024-42297-fcec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42297', 'https://www.cve.org/CVERecord?id=CVE-2024-42297'], 'PublishedDate': '2024-08-17T09:15:10.147Z', 'LastModifiedDate': '2024-09-30T13:41:26.463Z'}, {'VulnerabilityID': 'CVE-2024-42298', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42298', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value\n\ndevm_kasprintf() can return a NULL pointer on failure but this returned\nvalue is not checked.\n\nFix this lack and check the returned value.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42298', 'https://git.kernel.org/linus/e62599902327d27687693f6e5253a5d56583db58 (6.11-rc1)', 'https://git.kernel.org/stable/c/af466037fa2b263e8ea5c47285513d2487e17d90', 'https://git.kernel.org/stable/c/b4205dfcfe96182118e54343954827eda51b2135', 'https://git.kernel.org/stable/c/e62599902327d27687693f6e5253a5d56583db58', 'https://lore.kernel.org/linux-cve-announce/2024081748-CVE-2024-42298-d6a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42298', 'https://www.cve.org/CVERecord?id=CVE-2024-42298'], 'PublishedDate': '2024-08-17T09:15:10.23Z', 'LastModifiedDate': '2024-09-10T18:42:19.607Z'}, {'VulnerabilityID': 'CVE-2024-42299', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42299', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fs/ntfs3: Update log->page_{mask,bits} if log->page_size changed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Update log->page_{mask,bits} if log->page_size changed\n\nIf an NTFS file system is mounted to another system with different\nPAGE_SIZE from the original system, log->page_size will change in\nlog_replay(), but log->page_{mask,bits} don\'t change correspondingly.\nThis will cause a panic because "u32 bytes = log->page_size - page_off"\nwill get a negative value in the later read_log_page().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42299', 'https://git.kernel.org/linus/2fef55d8f78383c8e6d6d4c014b9597375132696 (6.11-rc1)', 'https://git.kernel.org/stable/c/0484adcb5fbcadd9ba0fd4485c42630f72e97da9', 'https://git.kernel.org/stable/c/0a4ae2644e2a3b3b219aad9639fb2b0691d08420', 'https://git.kernel.org/stable/c/2cac0df3324b5e287d8020bc0708f7d2dec88a6f', 'https://git.kernel.org/stable/c/2fef55d8f78383c8e6d6d4c014b9597375132696', 'https://git.kernel.org/stable/c/b90ceffdc975502bc085ce8e79c6adeff05f9521', 'https://lore.kernel.org/linux-cve-announce/2024081748-CVE-2024-42299-a588@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42299', 'https://www.cve.org/CVERecord?id=CVE-2024-42299'], 'PublishedDate': '2024-08-17T09:15:10.293Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42301', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42301', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dev/parport: fix the array out-of-bounds risk', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndev/parport: fix the array out-of-bounds risk\n\nFixed array out-of-bounds issues caused by sprintf\nby replacing it with snprintf for safer data copying,\nensuring the destination buffer is not overflowed.\n\nBelow is the stack trace I encountered during the actual issue:\n\n[ 66.575408s] [pid:5118,cpu4,QThread,4]Kernel panic - not syncing: stack-protector:\nKernel stack is corrupted in: do_hardware_base_addr+0xcc/0xd0 [parport]\n[ 66.575408s] [pid:5118,cpu4,QThread,5]CPU: 4 PID: 5118 Comm:\nQThread Tainted: G S W O 5.10.97-arm64-desktop #7100.57021.2\n[ 66.575439s] [pid:5118,cpu4,QThread,6]TGID: 5087 Comm: EFileApp\n[ 66.575439s] [pid:5118,cpu4,QThread,7]Hardware name: HUAWEI HUAWEI QingYun\nPGUX-W515x-B081/SP1PANGUXM, BIOS 1.00.07 04/29/2024\n[ 66.575439s] [pid:5118,cpu4,QThread,8]Call trace:\n[ 66.575469s] [pid:5118,cpu4,QThread,9] dump_backtrace+0x0/0x1c0\n[ 66.575469s] [pid:5118,cpu4,QThread,0] show_stack+0x14/0x20\n[ 66.575469s] [pid:5118,cpu4,QThread,1] dump_stack+0xd4/0x10c\n[ 66.575500s] [pid:5118,cpu4,QThread,2] panic+0x1d8/0x3bc\n[ 66.575500s] [pid:5118,cpu4,QThread,3] __stack_chk_fail+0x2c/0x38\n[ 66.575500s] [pid:5118,cpu4,QThread,4] do_hardware_base_addr+0xcc/0xd0 [parport]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42301', 'https://git.kernel.org/linus/ab11dac93d2d568d151b1918d7b84c2d02bacbd5 (6.11-rc1)', 'https://git.kernel.org/stable/c/166a0bddcc27de41fe13f861c8348e8e53e988c8', 'https://git.kernel.org/stable/c/47b3dce100778001cd76f7e9188944b5cb27a76d', 'https://git.kernel.org/stable/c/7789a1d6792af410aa9b39a1eb237ed24fa2170a', 'https://git.kernel.org/stable/c/7f4da759092a1a6ce35fb085182d02de8cc4cc84', 'https://git.kernel.org/stable/c/a44f88f7576bc1916d8d6293f5c62fbe7cbe03e0', 'https://git.kernel.org/stable/c/ab11dac93d2d568d151b1918d7b84c2d02bacbd5', 'https://git.kernel.org/stable/c/b579ea3516c371ecf59d073772bc45dfd28c8a0e', 'https://git.kernel.org/stable/c/c719b393374d3763e64900ee19aaed767d5a08d6', 'https://linux.oracle.com/cve/CVE-2024-42301.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42301-4026@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42301', 'https://www.cve.org/CVERecord?id=CVE-2024-42301'], 'PublishedDate': '2024-08-17T09:15:10.423Z', 'LastModifiedDate': '2024-08-22T16:31:18.667Z'}, {'VulnerabilityID': 'CVE-2024-42302', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42302', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/DPC: Fix use-after-free on concurrent DPC and hot-removal\n\nKeith reports a use-after-free when a DPC event occurs concurrently to\nhot-removal of the same portion of the hierarchy:\n\nThe dpc_handler() awaits readiness of the secondary bus below the\nDownstream Port where the DPC event occurred. To do so, it polls the\nconfig space of the first child device on the secondary bus. If that\nchild device is concurrently removed, accesses to its struct pci_dev\ncause the kernel to oops.\n\nThat\'s because pci_bridge_wait_for_secondary_bus() neglects to hold a\nreference on the child device. Before v6.3, the function was only\ncalled on resume from system sleep or on runtime resume. Holding a\nreference wasn\'t necessary back then because the pciehp IRQ thread\ncould never run concurrently. (On resume from system sleep, IRQs are\nnot enabled until after the resume_noirq phase. And runtime resume is\nalways awaited before a PCI device is removed.)\n\nHowever starting with v6.3, pci_bridge_wait_for_secondary_bus() is also\ncalled on a DPC event. Commit 53b54ad074de ("PCI/DPC: Await readiness\nof secondary bus after reset"), which introduced that, failed to\nappreciate that pci_bridge_wait_for_secondary_bus() now needs to hold a\nreference on the child device because dpc_handler() and pciehp may\nindeed run concurrently. The commit was backported to v5.10+ stable\nkernels, so that\'s the oldest one affected.\n\nAdd the missing reference acquisition.\n\nAbridged stack trace:\n\n BUG: unable to handle page fault for address: 00000000091400c0\n CPU: 15 PID: 2464 Comm: irq/53-pcie-dpc 6.9.0\n RIP: pci_bus_read_config_dword+0x17/0x50\n pci_dev_wait()\n pci_bridge_wait_for_secondary_bus()\n dpc_reset_link()\n pcie_do_recovery()\n dpc_handler()', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42302', 'https://git.kernel.org/linus/11a1f4bc47362700fcbde717292158873fb847ed (6.11-rc1)', 'https://git.kernel.org/stable/c/11a1f4bc47362700fcbde717292158873fb847ed', 'https://git.kernel.org/stable/c/2c111413f38ca5cf87557cab89f6d82b0e3433e7', 'https://git.kernel.org/stable/c/2cc8973bdc4d6c928ebe38b88090a2cdfe81f42f', 'https://git.kernel.org/stable/c/b16f3ea1db47a6766a9f1169244cf1fc287a7c62', 'https://git.kernel.org/stable/c/c52f9e1a9eb40f13993142c331a6cfd334d4b91d', 'https://git.kernel.org/stable/c/f63df70b439bb8331358a306541893bf415bf1da', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42302-c0d9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42302', 'https://www.cve.org/CVERecord?id=CVE-2024-42302'], 'PublishedDate': '2024-08-17T09:15:10.487Z', 'LastModifiedDate': '2024-08-22T16:37:26.237Z'}, {'VulnerabilityID': 'CVE-2024-42303', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42303', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: imx-pxp: Fix ERR_PTR dereference in pxp_probe()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: imx-pxp: Fix ERR_PTR dereference in pxp_probe()\n\ndevm_regmap_init_mmio() can fail, add a check and bail out in case of\nerror.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42303', 'https://git.kernel.org/linus/57e9ce68ae98551da9c161aaab12b41fe8601856 (6.11-rc1)', 'https://git.kernel.org/stable/c/358bc85269d6a359fea597ef9fbb429cd3626e08', 'https://git.kernel.org/stable/c/57e9ce68ae98551da9c161aaab12b41fe8601856', 'https://git.kernel.org/stable/c/5ab6ac4e9e165b0fe8a326308218337007224f05', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42303-4d12@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42303', 'https://www.cve.org/CVERecord?id=CVE-2024-42303'], 'PublishedDate': '2024-08-17T09:15:10.56Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42304', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42304', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: make sure the first directory block is not a hole', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: make sure the first directory block is not a hole\n\nThe syzbot constructs a directory that has no dirblock but is non-inline,\ni.e. the first directory block is a hole. And no errors are reported when\ncreating files in this directory in the following flow.\n\n ext4_mknod\n ...\n ext4_add_entry\n // Read block 0\n ext4_read_dirblock(dir, block, DIRENT)\n bh = ext4_bread(NULL, inode, block, 0)\n if (!bh && (type == INDEX || type == DIRENT_HTREE))\n // The first directory block is a hole\n // But type == DIRENT, so no error is reported.\n\nAfter that, we get a directory block without '.' and '..' but with a valid\ndentry. This may cause some code that relies on dot or dotdot (such as\nmake_indexed_dir()) to crash.\n\nTherefore when ext4_read_dirblock() finds that the first directory block\nis a hole report that the filesystem is corrupted and return an error to\navoid loading corrupted data from disk causing something bad.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42304', 'https://git.kernel.org/linus/f9ca51596bbfd0f9c386dd1c613c394c78d9e5e6 (6.11-rc1)', 'https://git.kernel.org/stable/c/299bc6ffa57e04e74c6cce866d6c0741fb4897a1', 'https://git.kernel.org/stable/c/9771e3d8365ae1dd5e8846a204cb9af14e3e656a', 'https://git.kernel.org/stable/c/b609753cbbd38f8c0affd4956c0af178348523ac', 'https://git.kernel.org/stable/c/c3893d9de8ee153baac56d127d844103488133b5', 'https://git.kernel.org/stable/c/d81d7e347d1f1f48a5634607d39eb90c161c8afe', 'https://git.kernel.org/stable/c/de2a011a13a46468a6e8259db58b1b62071fe136', 'https://git.kernel.org/stable/c/e02f9941e8c011aa3eafa799def6a134ce06bcfa', 'https://git.kernel.org/stable/c/f9ca51596bbfd0f9c386dd1c613c394c78d9e5e6', 'https://linux.oracle.com/cve/CVE-2024-42304.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081749-CVE-2024-42304-d0e4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42304', 'https://www.cve.org/CVERecord?id=CVE-2024-42304'], 'PublishedDate': '2024-08-17T09:15:10.617Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42305', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42305', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: check dot and dotdot of dx_root before making dir indexed', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: check dot and dotdot of dx_root before making dir indexed\n\nSyzbot reports a issue as follows:\n============================================\nBUG: unable to handle page fault for address: ffffed11022e24fe\nPGD 23ffee067 P4D 23ffee067 PUD 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 0 PID: 5079 Comm: syz-executor306 Not tainted 6.10.0-rc5-g55027e689933 #0\nCall Trace:\n \n make_indexed_dir+0xdaf/0x13c0 fs/ext4/namei.c:2341\n ext4_add_entry+0x222a/0x25d0 fs/ext4/namei.c:2451\n ext4_rename fs/ext4/namei.c:3936 [inline]\n ext4_rename2+0x26e5/0x4370 fs/ext4/namei.c:4214\n[...]\n============================================\n\nThe immediate cause of this problem is that there is only one valid dentry\nfor the block to be split during do_split, so split==0 results in out of\nbounds accesses to the map triggering the issue.\n\n do_split\n unsigned split\n dx_make_map\n count = 1\n split = count/2 = 0;\n continued = hash2 == map[split - 1].hash;\n ---> map[4294967295]\n\nThe maximum length of a filename is 255 and the minimum block size is 1024,\nso it is always guaranteed that the number of entries is greater than or\nequal to 2 when do_split() is called.\n\nBut syzbot's crafted image has no dot and dotdot in dir, and the dentry\ndistribution in dirblock is as follows:\n\n bus dentry1 hole dentry2 free\n|xx--|xx-------------|...............|xx-------------|...............|\n0 12 (8+248)=256 268 256 524 (8+256)=264 788 236 1024\n\nSo when renaming dentry1 increases its name_len length by 1, neither hole\nnor free is sufficient to hold the new dentry, and make_indexed_dir() is\ncalled.\n\nIn make_indexed_dir() it is assumed that the first two entries of the\ndirblock must be dot and dotdot, so bus and dentry1 are left in dx_root\nbecause they are treated as dot and dotdot, and only dentry2 is moved\nto the new leaf block. That's why count is equal to 1.\n\nTherefore add the ext4_check_dx_root() helper function to add more sanity\nchecks to dot and dotdot before starting the conversion to avoid the above\nissue.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42305', 'https://git.kernel.org/linus/50ea741def587a64e08879ce6c6a30131f7111e7 (6.11-rc1)', 'https://git.kernel.org/stable/c/19e13b4d7f0303186fcc891aba8d0de7c8fdbda8', 'https://git.kernel.org/stable/c/42d420517072028fb0eb852c358056b7717ba5aa', 'https://git.kernel.org/stable/c/50ea741def587a64e08879ce6c6a30131f7111e7', 'https://git.kernel.org/stable/c/8afe06ed3be7a874b3cd82ef5f8959aca8d6429a', 'https://git.kernel.org/stable/c/9d241b7a39af192d1bb422714a458982c7cc67a2', 'https://git.kernel.org/stable/c/abb411ac991810c0bcbe51c2e76d2502bf611b5c', 'https://git.kernel.org/stable/c/b80575ffa98b5bb3a5d4d392bfe4c2e03e9557db', 'https://git.kernel.org/stable/c/cdd345321699042ece4a9d2e70754d2397d378c5', 'https://linux.oracle.com/cve/CVE-2024-42305.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42305-94ed@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42305', 'https://www.cve.org/CVERecord?id=CVE-2024-42305'], 'PublishedDate': '2024-08-17T09:15:10.69Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42306', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42306', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Avoid using corrupted block bitmap buffer', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid using corrupted block bitmap buffer\n\nWhen the filesystem block bitmap is corrupted, we detect the corruption\nwhile loading the bitmap and fail the allocation with error. However the\nnext allocation from the same bitmap will notice the bitmap buffer is\nalready loaded and tries to allocate from the bitmap with mixed results\n(depending on the exact nature of the bitmap corruption). Fix the\nproblem by using BH_verified bit to indicate whether the bitmap is valid\nor not.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42306', 'https://git.kernel.org/linus/a90d4471146de21745980cba51ce88e7926bcc4f (6.11-rc1)', 'https://git.kernel.org/stable/c/2199e157a465aaf98294d3932797ecd7fce942d5', 'https://git.kernel.org/stable/c/271cab2ca00652bc984e269cf1208699a1e09cdd', 'https://git.kernel.org/stable/c/57053b3bcf3403b80db6f65aba284d7dfe7326af', 'https://git.kernel.org/stable/c/6a43e3c210df6c5f00570f4be49a897677dbcb64', 'https://git.kernel.org/stable/c/8ca170c39eca7cad6e0cfeb24e351d8f8eddcd65', 'https://git.kernel.org/stable/c/a90d4471146de21745980cba51ce88e7926bcc4f', 'https://git.kernel.org/stable/c/cae9e59cc41683408b70b9ab569f8654866ba914', 'https://linux.oracle.com/cve/CVE-2024-42306.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42306-647c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42306', 'https://www.cve.org/CVERecord?id=CVE-2024-42306'], 'PublishedDate': '2024-08-17T09:15:10.777Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42307', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42307', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential null pointer use in destroy_workqueue in init_cifs error path\n\nDan Carpenter reported a Smack static checker warning:\n fs/smb/client/cifsfs.c:1981 init_cifs()\n error: we previously assumed 'serverclose_wq' could be null (see line 1895)\n\nThe patch which introduced the serverclose workqueue used the wrong\noredering in error paths in init_cifs() for freeing it on errors.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42307', 'https://git.kernel.org/linus/193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2 (6.11-rc1)', 'https://git.kernel.org/stable/c/160235efb4f9b55212dedff5de0094c606c4b303', 'https://git.kernel.org/stable/c/193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2', 'https://git.kernel.org/stable/c/3739d711246d8fbc95ff73dbdace9741cdce4777', 'https://git.kernel.org/stable/c/6018971710fdc7739f8655c1540832b4bb903671', 'https://lore.kernel.org/linux-cve-announce/2024081750-CVE-2024-42307-7c2c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42307', 'https://www.cve.org/CVERecord?id=CVE-2024-42307'], 'PublishedDate': '2024-08-17T09:15:10.843Z', 'LastModifiedDate': '2024-09-05T17:49:58.257Z'}, {'VulnerabilityID': 'CVE-2024-42308', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42308', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Check for NULL pointer', 'Description': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42308', 'https://git.kernel.org/linus/4ab68e168ae1695f7c04fae98930740aaf7c50fa (6.11-rc1)', 'https://git.kernel.org/stable/c/185616085b12e651cdfd11ef00d1449f54552d89', 'https://git.kernel.org/stable/c/4ab68e168ae1695f7c04fae98930740aaf7c50fa', 'https://git.kernel.org/stable/c/4ccd37085976ea5d3c499b1e6d0b3f4deaf2cd5a', 'https://git.kernel.org/stable/c/6b5ed0648213e9355cc78f4a264d9afe8536d692', 'https://git.kernel.org/stable/c/71dbf95359347c2ecc5a6dfc02783fcfccb2e9fb', 'https://git.kernel.org/stable/c/9ce89824ff04d261fc855e0ca6e6025251d9fa40', 'https://git.kernel.org/stable/c/f068494430d15b5fc551ac928de9dac7e5e27602', 'https://linux.oracle.com/cve/CVE-2024-42308.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42308-562d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42308', 'https://www.cve.org/CVERecord?id=CVE-2024-42308'], 'PublishedDate': '2024-08-17T09:15:10.92Z', 'LastModifiedDate': '2024-10-09T14:15:05.227Z'}, {'VulnerabilityID': 'CVE-2024-42309', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42309', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes\n\nIn psb_intel_lvds_get_modes(), the return value of drm_mode_duplicate() is\nassigned to mode, which will lead to a possible NULL pointer dereference\non failure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42309', 'https://git.kernel.org/linus/2df7aac81070987b0f052985856aa325a38debf6 (6.11-rc1)', 'https://git.kernel.org/stable/c/13b5f3ee94bdbdc4b5f40582aab62977905aedee', 'https://git.kernel.org/stable/c/2df7aac81070987b0f052985856aa325a38debf6', 'https://git.kernel.org/stable/c/46d2ef272957879cbe30a884574320e7f7d78692', 'https://git.kernel.org/stable/c/475a5b3b7c8edf6e583a9eb59cf28ea770602e14', 'https://git.kernel.org/stable/c/6735d02ead7dd3adf74eb8b70aebd09e0ce78ec9', 'https://git.kernel.org/stable/c/7e52c62ff029f95005915c0a11863b5fb5185c8c', 'https://git.kernel.org/stable/c/d6ad202f73f8edba0cbc0065aa57a79ffe8fdcdc', 'https://git.kernel.org/stable/c/f70ffeca546452d1acd3a70ada56ecb2f3e7f811', 'https://linux.oracle.com/cve/CVE-2024-42309.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42309-9560@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42309', 'https://www.cve.org/CVERecord?id=CVE-2024-42309'], 'PublishedDate': '2024-08-17T09:15:10.987Z', 'LastModifiedDate': '2024-08-22T16:01:29.287Z'}, {'VulnerabilityID': 'CVE-2024-42310', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42310', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes\n\nIn cdv_intel_lvds_get_modes(), the return value of drm_mode_duplicate()\nis assigned to mode, which will lead to a NULL pointer dereference on\nfailure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42310', 'https://git.kernel.org/linus/cb520c3f366c77e8d69e4e2e2781a8ce48d98e79 (6.11-rc1)', 'https://git.kernel.org/stable/c/08f45102c81ad8bc9f85f7a25e9f64e128edb87d', 'https://git.kernel.org/stable/c/2d209b2f862f6b8bff549ede541590a8d119da23', 'https://git.kernel.org/stable/c/977ee4fe895e1729cd36cc26916bbb10084713d6', 'https://git.kernel.org/stable/c/a658ae2173ab74667c009e2550455e6de5b33ddc', 'https://git.kernel.org/stable/c/b6ac46a00188cde50ffba233e6efb366354a1de5', 'https://git.kernel.org/stable/c/cb520c3f366c77e8d69e4e2e2781a8ce48d98e79', 'https://git.kernel.org/stable/c/e74eb5e8089427c8c49e0dd5067e5f39ce3a4d56', 'https://git.kernel.org/stable/c/f392c36cebf4c1d6997a4cc2c0f205254acef42a', 'https://linux.oracle.com/cve/CVE-2024-42310.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081751-CVE-2024-42310-58b0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42310', 'https://www.cve.org/CVERecord?id=CVE-2024-42310'], 'PublishedDate': '2024-08-17T09:15:11.067Z', 'LastModifiedDate': '2024-08-22T16:01:46.263Z'}, {'VulnerabilityID': 'CVE-2024-42311', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42311', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()\n\nSyzbot reports uninitialized value access issue as below:\n\nloop0: detected capacity change from 0 to 64\n=====================================================\nBUG: KMSAN: uninit-value in hfs_revalidate_dentry+0x307/0x3f0 fs/hfs/sysdep.c:30\n hfs_revalidate_dentry+0x307/0x3f0 fs/hfs/sysdep.c:30\n d_revalidate fs/namei.c:862 [inline]\n lookup_fast+0x89e/0x8e0 fs/namei.c:1649\n walk_component fs/namei.c:2001 [inline]\n link_path_walk+0x817/0x1480 fs/namei.c:2332\n path_lookupat+0xd9/0x6f0 fs/namei.c:2485\n filename_lookup+0x22e/0x740 fs/namei.c:2515\n user_path_at_empty+0x8b/0x390 fs/namei.c:2924\n user_path_at include/linux/namei.h:57 [inline]\n do_mount fs/namespace.c:3689 [inline]\n __do_sys_mount fs/namespace.c:3898 [inline]\n __se_sys_mount+0x66b/0x810 fs/namespace.c:3875\n __x64_sys_mount+0xe4/0x140 fs/namespace.c:3875\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nBUG: KMSAN: uninit-value in hfs_ext_read_extent fs/hfs/extent.c:196 [inline]\nBUG: KMSAN: uninit-value in hfs_get_block+0x92d/0x1620 fs/hfs/extent.c:366\n hfs_ext_read_extent fs/hfs/extent.c:196 [inline]\n hfs_get_block+0x92d/0x1620 fs/hfs/extent.c:366\n block_read_full_folio+0x4ff/0x11b0 fs/buffer.c:2271\n hfs_read_folio+0x55/0x60 fs/hfs/inode.c:39\n filemap_read_folio+0x148/0x4f0 mm/filemap.c:2426\n do_read_cache_folio+0x7c8/0xd90 mm/filemap.c:3553\n do_read_cache_page mm/filemap.c:3595 [inline]\n read_cache_page+0xfb/0x2f0 mm/filemap.c:3604\n read_mapping_page include/linux/pagemap.h:755 [inline]\n hfs_btree_open+0x928/0x1ae0 fs/hfs/btree.c:78\n hfs_mdb_get+0x260c/0x3000 fs/hfs/mdb.c:204\n hfs_fill_super+0x1fb1/0x2790 fs/hfs/super.c:406\n mount_bdev+0x628/0x920 fs/super.c:1359\n hfs_mount+0xcd/0xe0 fs/hfs/super.c:456\n legacy_get_tree+0x167/0x2e0 fs/fs_context.c:610\n vfs_get_tree+0xdc/0x5d0 fs/super.c:1489\n do_new_mount+0x7a9/0x16f0 fs/namespace.c:3145\n path_mount+0xf98/0x26a0 fs/namespace.c:3475\n do_mount fs/namespace.c:3488 [inline]\n __do_sys_mount fs/namespace.c:3697 [inline]\n __se_sys_mount+0x919/0x9e0 fs/namespace.c:3674\n __ia32_sys_mount+0x15b/0x1b0 fs/namespace.c:3674\n do_syscall_32_irqs_on arch/x86/entry/common.c:112 [inline]\n __do_fast_syscall_32+0xa2/0x100 arch/x86/entry/common.c:178\n do_fast_syscall_32+0x37/0x80 arch/x86/entry/common.c:203\n do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:246\n entry_SYSENTER_compat_after_hwframe+0x70/0x82\n\nUninit was created at:\n __alloc_pages+0x9a6/0xe00 mm/page_alloc.c:4590\n __alloc_pages_node include/linux/gfp.h:238 [inline]\n alloc_pages_node include/linux/gfp.h:261 [inline]\n alloc_slab_page mm/slub.c:2190 [inline]\n allocate_slab mm/slub.c:2354 [inline]\n new_slab+0x2d7/0x1400 mm/slub.c:2407\n ___slab_alloc+0x16b5/0x3970 mm/slub.c:3540\n __slab_alloc mm/slub.c:3625 [inline]\n __slab_alloc_node mm/slub.c:3678 [inline]\n slab_alloc_node mm/slub.c:3850 [inline]\n kmem_cache_alloc_lru+0x64d/0xb30 mm/slub.c:3879\n alloc_inode_sb include/linux/fs.h:3018 [inline]\n hfs_alloc_inode+0x5a/0xc0 fs/hfs/super.c:165\n alloc_inode+0x83/0x440 fs/inode.c:260\n new_inode_pseudo fs/inode.c:1005 [inline]\n new_inode+0x38/0x4f0 fs/inode.c:1031\n hfs_new_inode+0x61/0x1010 fs/hfs/inode.c:186\n hfs_mkdir+0x54/0x250 fs/hfs/dir.c:228\n vfs_mkdir+0x49a/0x700 fs/namei.c:4126\n do_mkdirat+0x529/0x810 fs/namei.c:4149\n __do_sys_mkdirat fs/namei.c:4164 [inline]\n __se_sys_mkdirat fs/namei.c:4162 [inline]\n __x64_sys_mkdirat+0xc8/0x120 fs/namei.c:4162\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nIt missed to initialize .tz_secondswest, .cached_start and .cached_blocks\nfields in struct hfs_inode_info after hfs_alloc_inode(), fix it.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-908'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42311', 'https://git.kernel.org/linus/26a2ed107929a855155429b11e1293b83e6b2a8b (6.11-rc1)', 'https://git.kernel.org/stable/c/10f7163bfb5f8b4e0c9c05a939f20b8540e33c65', 'https://git.kernel.org/stable/c/26a2ed107929a855155429b11e1293b83e6b2a8b', 'https://git.kernel.org/stable/c/4a52861cd76e79f1a593beb23d096523eb9732c2', 'https://git.kernel.org/stable/c/58d83fc160505a7009c39dec64effaac5129b971', 'https://git.kernel.org/stable/c/9c4e40b9b731220f9464975e49da75496e3865c4', 'https://git.kernel.org/stable/c/d3493d6f0dfb1ab5225b62faa77732983f2187a1', 'https://git.kernel.org/stable/c/d55aae5c1730d6b70d5d8eaff00113cd34772ea3', 'https://git.kernel.org/stable/c/f7316b2b2f11cf0c6de917beee8d3de728be24db', 'https://linux.oracle.com/cve/CVE-2024-42311.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42311-f825@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42311', 'https://www.cve.org/CVERecord?id=CVE-2024-42311'], 'PublishedDate': '2024-08-17T09:15:11.147Z', 'LastModifiedDate': '2024-09-03T17:38:24.21Z'}, {'VulnerabilityID': 'CVE-2024-42312', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42312', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sysctl: always initialize i_uid/i_gid', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsysctl: always initialize i_uid/i_gid\n\nAlways initialize i_uid/i_gid inside the sysfs core so set_ownership()\ncan safely skip setting them.\n\nCommit 5ec27ec735ba ("fs/proc/proc_sysctl.c: fix the default values of\ni_uid/i_gid on /proc/sys inodes.") added defaults for i_uid/i_gid when\nset_ownership() was not implemented. It also missed adjusting\nnet_ctl_set_ownership() to use the same default values in case the\ncomputation of a better value failed.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42312', 'https://git.kernel.org/linus/98ca62ba9e2be5863c7d069f84f7166b45a5b2f4 (6.11-rc1)', 'https://git.kernel.org/stable/c/1deae34db9f4f8e0e03f891be2e2e15c15c8ac05', 'https://git.kernel.org/stable/c/34a86adea1f2b3c3f9d864c8cce09dca644601ab', 'https://git.kernel.org/stable/c/98ca62ba9e2be5863c7d069f84f7166b45a5b2f4', 'https://git.kernel.org/stable/c/b2591c89a6e2858796111138c38fcb6851aa1955', 'https://git.kernel.org/stable/c/c7e2f43d182f5dde473389dbb39f16c9f0d64536', 'https://git.kernel.org/stable/c/ffde3af4b29bf97d62d82e1d45275587e10a991a', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42312-bddc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42312', 'https://www.cve.org/CVERecord?id=CVE-2024-42312'], 'PublishedDate': '2024-08-17T09:15:11.24Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42313', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42313', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: venus: fix use after free in vdec_close', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: fix use after free in vdec_close\n\nThere appears to be a possible use after free with vdec_close().\nThe firmware will add buffer release work to the work queue through\nHFI callbacks as a normal part of decoding. Randomly closing the\ndecoder device from userspace during normal decoding can incur\na read after free for inst.\n\nFix it by cancelling the work in vdec_close.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42313', 'https://git.kernel.org/linus/a0157b5aa34eb43ec4c5510f9c260bbb03be937e (6.11-rc1)', 'https://git.kernel.org/stable/c/4c9d235630d35db762b85a4149bbb0be9d504c36', 'https://git.kernel.org/stable/c/66fa52edd32cdbb675f0803b3c4da10ea19b6635', 'https://git.kernel.org/stable/c/6a96041659e834dc0b172dda4b2df512d63920c2', 'https://git.kernel.org/stable/c/72aff311194c8ceda934f24fd6f250b8827d7567', 'https://git.kernel.org/stable/c/a0157b5aa34eb43ec4c5510f9c260bbb03be937e', 'https://git.kernel.org/stable/c/ad8cf035baf29467158e0550c7a42b7bb43d1db6', 'https://git.kernel.org/stable/c/da55685247f409bf7f976cc66ba2104df75d8dad', 'https://git.kernel.org/stable/c/f8e9a63b982a8345470c225679af4ba86e4a7282', 'https://linux.oracle.com/cve/CVE-2024-42313.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42313-09b9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42313', 'https://www.cve.org/CVERecord?id=CVE-2024-42313'], 'PublishedDate': '2024-08-17T09:15:11.32Z', 'LastModifiedDate': '2024-08-22T16:01:59.467Z'}, {'VulnerabilityID': 'CVE-2024-42314', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42314', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: btrfs: fix extent map use-after-free when adding pages to compressed bio', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix extent map use-after-free when adding pages to compressed bio\n\nAt add_ra_bio_pages() we are accessing the extent map to calculate\n'add_size' after we dropped our reference on the extent map, resulting\nin a use-after-free. Fix this by computing 'add_size' before dropping our\nextent map reference.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42314', 'https://git.kernel.org/linus/8e7860543a94784d744c7ce34b78a2e11beefa5c (6.11-rc1)', 'https://git.kernel.org/stable/c/8e7860543a94784d744c7ce34b78a2e11beefa5c', 'https://git.kernel.org/stable/c/b7859ff398b6b656e1689daa860eb34837b4bb89', 'https://git.kernel.org/stable/c/c1cc3326e27b0bd7a2806b40bc48e49afaf951e7', 'https://git.kernel.org/stable/c/c205565e0f2f439f278a4a94ee97b67ef7b56ae8', 'https://lore.kernel.org/linux-cve-announce/2024081752-CVE-2024-42314-de1f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42314', 'https://www.cve.org/CVERecord?id=CVE-2024-42314'], 'PublishedDate': '2024-08-17T09:15:11.397Z', 'LastModifiedDate': '2024-09-04T12:15:04.723Z'}, {'VulnerabilityID': 'CVE-2024-42315', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42315', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: exfat: fix potential deadlock on __exfat_get_dentry_set', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix potential deadlock on __exfat_get_dentry_set\n\nWhen accessing a file with more entries than ES_MAX_ENTRY_NUM, the bh-array\nis allocated in __exfat_get_entry_set. The problem is that the bh-array is\nallocated with GFP_KERNEL. It does not make sense. In the following cases,\na deadlock for sbi->s_lock between the two processes may occur.\n\n CPU0 CPU1\n ---- ----\n kswapd\n balance_pgdat\n lock(fs_reclaim)\n exfat_iterate\n lock(&sbi->s_lock)\n exfat_readdir\n exfat_get_uniname_from_ext_entry\n exfat_get_dentry_set\n __exfat_get_dentry_set\n kmalloc_array\n ...\n lock(fs_reclaim)\n ...\n evict\n exfat_evict_inode\n lock(&sbi->s_lock)\n\nTo fix this, let's allocate bh-array with GFP_NOFS.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42315', 'https://git.kernel.org/linus/89fc548767a2155231128cb98726d6d2ea1256c9 (6.11-rc1)', 'https://git.kernel.org/stable/c/1d1970493c289e3f44b9ec847ed26a5dbdf56a62', 'https://git.kernel.org/stable/c/89fc548767a2155231128cb98726d6d2ea1256c9', 'https://git.kernel.org/stable/c/a7ac198f8dba791e3144c4da48a5a9b95773ee4b', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42315-a707@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42315', 'https://www.cve.org/CVERecord?id=CVE-2024-42315'], 'PublishedDate': '2024-08-17T09:15:11.47Z', 'LastModifiedDate': '2024-08-22T15:51:03.077Z'}, {'VulnerabilityID': 'CVE-2024-42316', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42316', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/mglru: fix div-by-zero in vmpressure_calc_level()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mglru: fix div-by-zero in vmpressure_calc_level()\n\nevict_folios() uses a second pass to reclaim folios that have gone through\npage writeback and become clean before it finishes the first pass, since\nfolio_rotate_reclaimable() cannot handle those folios due to the\nisolation.\n\nThe second pass tries to avoid potential double counting by deducting\nscan_control->nr_scanned. However, this can result in underflow of\nnr_scanned, under a condition where shrink_folio_list() does not increment\nnr_scanned, i.e., when folio_trylock() fails.\n\nThe underflow can cause the divisor, i.e., scale=scanned+reclaimed in\nvmpressure_calc_level(), to become zero, resulting in the following crash:\n\n [exception RIP: vmpressure_work_fn+101]\n process_one_work at ffffffffa3313f2b\n\nSince scan_control->nr_scanned has no established semantics, the potential\ndouble counting has minimal risks. Therefore, fix the problem by not\ndeducting scan_control->nr_scanned in evict_folios().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42316', 'https://git.kernel.org/linus/8b671fe1a879923ecfb72dda6caf01460dd885ef (6.11-rc1)', 'https://git.kernel.org/stable/c/8b671fe1a879923ecfb72dda6caf01460dd885ef', 'https://git.kernel.org/stable/c/8de7bf77f21068a5f602bb1e59adbc5ab533509d', 'https://git.kernel.org/stable/c/a39e38be632f0e1c908d70d1c9cd071c03faf895', 'https://git.kernel.org/stable/c/d6510f234c7d117790397f9bb150816b0a954a04', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42316-8b49@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42316', 'https://www.cve.org/CVERecord?id=CVE-2024-42316'], 'PublishedDate': '2024-08-17T09:15:11.547Z', 'LastModifiedDate': '2024-08-22T15:52:38.52Z'}, {'VulnerabilityID': 'CVE-2024-42317', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42317', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm/huge_memory: avoid PMD-size page cache if needed', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: avoid PMD-size page cache if needed\n\nxarray can\'t support arbitrary page cache size. the largest and supported\npage cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71\n("mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray"). However,\nit\'s possible to have 512MB page cache in the huge memory\'s collapsing\npath on ARM64 system whose base page size is 64KB. 512MB page cache is\nbreaking the limitation and a warning is raised when the xarray entry is\nsplit as shown in the following example.\n\n[root@dhcp-10-26-1-207 ~]# cat /proc/1/smaps | grep KernelPageSize\nKernelPageSize: 64 kB\n[root@dhcp-10-26-1-207 ~]# cat /tmp/test.c\n :\nint main(int argc, char **argv)\n{\n\tconst char *filename = TEST_XFS_FILENAME;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret = 0;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stdout, "System with 64KB base page size is required!\\n");\n\t\treturn -EPERM;\n\t}\n\n\tsystem("echo 0 > /sys/devices/virtual/bdi/253:0/read_ahead_kb");\n\tsystem("echo 1 > /proc/sys/vm/drop_caches");\n\n\t/* Open the xfs file */\n\tfd = open(filename, O_RDONLY);\n\tassert(fd > 0);\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE, PROT_READ, MAP_SHARED, fd, 0);\n\tassert(buf != (void *)-1);\n\tfprintf(stdout, "mapped buffer at 0x%p\\n", buf);\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_NOHUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_READ);\n\tassert(ret == 0);\n\n\t/* Collapse VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_COLLAPSE);\n\tif (ret) {\n\t\tfprintf(stdout, "Error %d to madvise(MADV_COLLAPSE)\\n", errno);\n\t\tgoto out;\n\t}\n\n\t/* Split xarray entry. Write permission is needed */\n\tmunmap(buf, TEST_MEM_SIZE);\n\tbuf = (void *)-1;\n\tclose(fd);\n\tfd = open(filename, O_RDWR);\n\tassert(fd > 0);\n\tfallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n \t\t TEST_MEM_SIZE - pgsize, pgsize);\nout:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn ret;\n}\n\n[root@dhcp-10-26-1-207 ~]# gcc /tmp/test.c -o /tmp/test\n[root@dhcp-10-26-1-207 ~]# /tmp/test\n ------------[ cut here ]------------\n WARNING: CPU: 25 PID: 7560 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\n Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\\n nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\\n nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\n ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse \\\n xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 virtio_net \\\n sha1_ce net_failover virtio_blk virtio_console failover dimlib virtio_mmio\n CPU: 25 PID: 7560 Comm: test Kdump: loaded Not tainted 6.10.0-rc7-gavin+ #9\n Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\n pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : xas_split_alloc+0xf8/0x128\n lr : split_huge_page_to_list_to_order+0x1c4/0x780\n sp : ffff8000ac32f660\n x29: ffff8000ac32f660 x28: ffff0000e0969eb0 x27: ffff8000ac32f6c0\n x26: 0000000000000c40 x25: ffff0000e0969eb0 x24: 000000000000000d\n x23: ffff8000ac32f6c0 x22: ffffffdfc0700000 x21: 0000000000000000\n x20: 0000000000000000 x19: ffffffdfc0700000 x18: 0000000000000000\n x17: 0000000000000000 x16: ffffd5f3708ffc70 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: ffffffffffffffc0 x10: 0000000000000040 x9 : ffffd5f3708e692c\n x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff0000e0969eb8\n x5 : ffffd5f37289e378 x4 : 0000000000000000 x3 : 0000000000000c40\n x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\n Call trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x780\n truncate_inode_partial_folio+0xdc/0x160\n truncate_inode_pages_range+0x1b4/0x4a8\n truncate_pagecache_range+0x84/0xa\n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42317', 'https://git.kernel.org/linus/d659b715e94ac039803d7601505d3473393fc0be (6.11-rc1)', 'https://git.kernel.org/stable/c/d659b715e94ac039803d7601505d3473393fc0be', 'https://git.kernel.org/stable/c/e60f62f75c99740a28e2bf7e6044086033012a16', 'https://lore.kernel.org/linux-cve-announce/2024081753-CVE-2024-42317-cf87@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42317', 'https://www.cve.org/CVERecord?id=CVE-2024-42317'], 'PublishedDate': '2024-08-17T09:15:11.633Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42318', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42318', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: landlock: Don't lose track of restrictions on cred_transfer', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Don't lose track of restrictions on cred_transfer\n\nWhen a process' cred struct is replaced, this _almost_ always invokes\nthe cred_prepare LSM hook; but in one special case (when\nKEYCTL_SESSION_TO_PARENT updates the parent's credentials), the\ncred_transfer LSM hook is used instead. Landlock only implements the\ncred_prepare hook, not cred_transfer, so KEYCTL_SESSION_TO_PARENT causes\nall information on Landlock restrictions to be lost.\n\nThis basically means that a process with the ability to use the fork()\nand keyctl() syscalls can get rid of all Landlock restrictions on\nitself.\n\nFix it by adding a cred_transfer hook that does the same thing as the\nexisting cred_prepare hook. (Implemented by having hook_cred_prepare()\ncall hook_cred_transfer() so that the two functions are less likely to\naccidentally diverge in the future.)", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42318', 'https://bugs.chromium.org/p/project-zero/issues/detail?id=2566', 'https://git.kernel.org/linus/39705a6c29f8a2b93cf5b99528a55366c50014d1 (6.11-rc1)', 'https://git.kernel.org/stable/c/0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c', 'https://git.kernel.org/stable/c/16896914bace82d7811c62f3b6d5320132384f49', 'https://git.kernel.org/stable/c/39705a6c29f8a2b93cf5b99528a55366c50014d1', 'https://git.kernel.org/stable/c/916c648323fa53b89eedb34a0988ddaf01406117', 'https://git.kernel.org/stable/c/b14cc2cf313bd29056fadbc8ecd7f957cf5791ff', 'https://lore.kernel.org/all/20240817.shahka3Ee1iy@digikod.net/', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42318-f0c9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42318', 'https://www.cve.org/CVERecord?id=CVE-2024-42318', 'https://www.openwall.com/lists/oss-security/2024/08/17/2'], 'PublishedDate': '2024-08-17T09:15:11.7Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42319', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42319', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()\n\nWhen mtk-cmdq unbinds, a WARN_ON message with condition\npm_runtime_get_sync() < 0 occurs.\n\nAccording to the call tracei below:\n cmdq_mbox_shutdown\n mbox_free_channel\n mbox_controller_unregister\n __devm_mbox_controller_unregister\n ...\n\nThe root cause can be deduced to be calling pm_runtime_get_sync() after\ncalling pm_runtime_disable() as observed below:\n1. CMDQ driver uses devm_mbox_controller_register() in cmdq_probe()\n to bind the cmdq device to the mbox_controller, so\n devm_mbox_controller_unregister() will automatically unregister\n the device bound to the mailbox controller when the device-managed\n resource is removed. That means devm_mbox_controller_unregister()\n and cmdq_mbox_shoutdown() will be called after cmdq_remove().\n2. CMDQ driver also uses devm_pm_runtime_enable() in cmdq_probe() after\n devm_mbox_controller_register(), so that devm_pm_runtime_disable()\n will be called after cmdq_remove(), but before\n devm_mbox_controller_unregister().\n\nTo fix this problem, cmdq_probe() needs to move\ndevm_mbox_controller_register() after devm_pm_runtime_enable() to make\ndevm_pm_runtime_disable() be called after\ndevm_mbox_controller_unregister().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42319', 'https://git.kernel.org/linus/a8bd68e4329f9a0ad1b878733e0f80be6a971649 (6.11-rc1)', 'https://git.kernel.org/stable/c/11fa625b45faf0649118b9deaf2d31c86ac41911', 'https://git.kernel.org/stable/c/a8bd68e4329f9a0ad1b878733e0f80be6a971649', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42319-ec7c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42319', 'https://www.cve.org/CVERecord?id=CVE-2024-42319'], 'PublishedDate': '2024-08-17T09:15:11.767Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42320', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42320', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: s390/dasd: fix error checks in dasd_copy_pair_store()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix error checks in dasd_copy_pair_store()\n\ndasd_add_busid() can return an error via ERR_PTR() if an allocation\nfails. However, two callsites in dasd_copy_pair_store() do not check\nthe result, potentially resulting in a NULL pointer dereference. Fix\nthis by checking the result with IS_ERR() and returning the error up\nthe stack.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42320', 'https://git.kernel.org/linus/8e64d2356cbc800b4cd0e3e614797f76bcf0cdb8 (6.11-rc1)', 'https://git.kernel.org/stable/c/68d4c3722290ad300c295fb3435e835d200d5cb2', 'https://git.kernel.org/stable/c/8e64d2356cbc800b4cd0e3e614797f76bcf0cdb8', 'https://git.kernel.org/stable/c/cc8b7284d5076722e0b8062373b68d8e47c3bace', 'https://git.kernel.org/stable/c/e511167e65d332d07b3c7a3d5a741ee9c19a8c27', 'https://lore.kernel.org/linux-cve-announce/2024081754-CVE-2024-42320-cdea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42320', 'https://www.cve.org/CVERecord?id=CVE-2024-42320'], 'PublishedDate': '2024-08-17T09:15:11.833Z', 'LastModifiedDate': '2024-09-30T12:54:12.897Z'}, {'VulnerabilityID': 'CVE-2024-42321', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42321', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: flow_dissector: use DEBUG_NET_WARN_ON_ONCE', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: flow_dissector: use DEBUG_NET_WARN_ON_ONCE\n\nThe following splat is easy to reproduce upstream as well as in -stable\nkernels. Florian Westphal provided the following commit:\n\n d1dab4f71d37 ("net: add and use __skb_get_hash_symmetric_net")\n\nbut this complementary fix has been also suggested by Willem de Bruijn\nand it can be easily backported to -stable kernel which consists in\nusing DEBUG_NET_WARN_ON_ONCE instead to silence the following splat\ngiven __skb_get_hash() is used by the nftables tracing infrastructure to\nto identify packets in traces.\n\n[69133.561393] ------------[ cut here ]------------\n[69133.561404] WARNING: CPU: 0 PID: 43576 at net/core/flow_dissector.c:1104 __skb_flow_dissect+0x134f/\n[...]\n[69133.561944] CPU: 0 PID: 43576 Comm: socat Not tainted 6.10.0-rc7+ #379\n[69133.561959] RIP: 0010:__skb_flow_dissect+0x134f/0x2ad0\n[69133.561970] Code: 83 f9 04 0f 84 b3 00 00 00 45 85 c9 0f 84 aa 00 00 00 41 83 f9 02 0f 84 81 fc ff\nff 44 0f b7 b4 24 80 00 00 00 e9 8b f9 ff ff <0f> 0b e9 20 f3 ff ff 41 f6 c6 20 0f 84 e4 ef ff ff 48 8d 7b 12 e8\n[69133.561979] RSP: 0018:ffffc90000006fc0 EFLAGS: 00010246\n[69133.561988] RAX: 0000000000000000 RBX: ffffffff82f33e20 RCX: ffffffff81ab7e19\n[69133.561994] RDX: dffffc0000000000 RSI: ffffc90000007388 RDI: ffff888103a1b418\n[69133.562001] RBP: ffffc90000007310 R08: 0000000000000000 R09: 0000000000000000\n[69133.562007] R10: ffffc90000007388 R11: ffffffff810cface R12: ffff888103a1b400\n[69133.562013] R13: 0000000000000000 R14: ffffffff82f33e2a R15: ffffffff82f33e28\n[69133.562020] FS: 00007f40f7131740(0000) GS:ffff888390800000(0000) knlGS:0000000000000000\n[69133.562027] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[69133.562033] CR2: 00007f40f7346ee0 CR3: 000000015d200001 CR4: 00000000001706f0\n[69133.562040] Call Trace:\n[69133.562044] \n[69133.562049] ? __warn+0x9f/0x1a0\n[ 1211.841384] ? __skb_flow_dissect+0x107e/0x2860\n[...]\n[ 1211.841496] ? bpf_flow_dissect+0x160/0x160\n[ 1211.841753] __skb_get_hash+0x97/0x280\n[ 1211.841765] ? __skb_get_hash_symmetric+0x230/0x230\n[ 1211.841776] ? mod_find+0xbf/0xe0\n[ 1211.841786] ? get_stack_info_noinstr+0x12/0xe0\n[ 1211.841798] ? bpf_ksym_find+0x56/0xe0\n[ 1211.841807] ? __rcu_read_unlock+0x2a/0x70\n[ 1211.841819] nft_trace_init+0x1b9/0x1c0 [nf_tables]\n[ 1211.841895] ? nft_trace_notify+0x830/0x830 [nf_tables]\n[ 1211.841964] ? get_stack_info+0x2b/0x80\n[ 1211.841975] ? nft_do_chain_arp+0x80/0x80 [nf_tables]\n[ 1211.842044] nft_do_chain+0x79c/0x850 [nf_tables]', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-42321', 'https://git.kernel.org/linus/120f1c857a73e52132e473dee89b340440cb692b (6.11-rc1)', 'https://git.kernel.org/stable/c/120f1c857a73e52132e473dee89b340440cb692b', 'https://git.kernel.org/stable/c/4afbac11f2f629d1e62817c4e210bdfaa7521107', 'https://git.kernel.org/stable/c/c5d21aabf1b31a79f228508af33aee83456bc1b0', 'https://git.kernel.org/stable/c/eb03d9826aa646577342a952d658d4598381c035', 'https://lore.kernel.org/linux-cve-announce/2024081755-CVE-2024-42321-4b46@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42321', 'https://www.cve.org/CVERecord?id=CVE-2024-42321'], 'PublishedDate': '2024-08-17T09:15:11.917Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-42322', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-42322', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ipvs: properly dereference pe in ip_vs_add_service', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: properly dereference pe in ip_vs_add_service\n\nUse pe directly to resolve sparse warning:\n\n net/netfilter/ipvs/ip_vs_ctl.c:1471:27: warning: dereference of noderef expression', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-42322', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/cbd070a4ae62f119058973f6d2c984e325bce6e7 (6.11-rc1)', 'https://git.kernel.org/stable/c/3dd428039e06e1967ce294e2cd6342825aaaad77', 'https://git.kernel.org/stable/c/c420cd5d5bc6797f3a8824e7d74f38f0c286fca5', 'https://git.kernel.org/stable/c/cbd070a4ae62f119058973f6d2c984e325bce6e7', 'https://linux.oracle.com/cve/CVE-2024-42322.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024081755-CVE-2024-42322-e2ef@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-42322', 'https://www.cve.org/CVERecord?id=CVE-2024-42322'], 'PublishedDate': '2024-08-17T09:15:11.977Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43817', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43817', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: missing check virtio', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: missing check virtio\n\nTwo missing check in virtio_net_hdr_to_skb() allowed syzbot\nto crash kernels again\n\n1. After the skb_segment function the buffer may become non-linear\n(nr_frags != 0), but since the SKBTX_SHARED_FRAG flag is not set anywhere\nthe __skb_linearize function will not be executed, then the buffer will\nremain non-linear. Then the condition (offset >= skb_headlen(skb))\nbecomes true, which causes WARN_ON_ONCE in skb_checksum_help.\n\n2. The struct sk_buff and struct virtio_net_hdr members must be\nmathematically related.\n(gso_size) must be greater than (needed) otherwise WARN_ON_ONCE.\n(remainder) must be greater than (needed) otherwise WARN_ON_ONCE.\n(remainder) may be 0 if division is without remainder.\n\noffset+2 (4191) > skb_headlen() (1116)\nWARNING: CPU: 1 PID: 5084 at net/core/dev.c:3303 skb_checksum_help+0x5e2/0x740 net/core/dev.c:3303\nModules linked in:\nCPU: 1 PID: 5084 Comm: syz-executor336 Not tainted 6.7.0-rc3-syzkaller-00014-gdf60cee26a2e #0\nHardware name: Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023\nRIP: 0010:skb_checksum_help+0x5e2/0x740 net/core/dev.c:3303\nCode: 89 e8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 52 01 00 00 44 89 e2 2b 53 74 4c 89 ee 48 c7 c7 40 57 e9 8b e8 af 8f dd f8 90 <0f> 0b 90 90 e9 87 fe ff ff e8 40 0f 6e f9 e9 4b fa ff ff 48 89 ef\nRSP: 0018:ffffc90003a9f338 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff888025125780 RCX: ffffffff814db209\nRDX: ffff888015393b80 RSI: ffffffff814db216 RDI: 0000000000000001\nRBP: ffff8880251257f4 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000001 R12: 000000000000045c\nR13: 000000000000105f R14: ffff8880251257f0 R15: 000000000000105d\nFS: 0000555555c24380(0000) GS:ffff8880b9900000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000002000f000 CR3: 0000000023151000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ip_do_fragment+0xa1b/0x18b0 net/ipv4/ip_output.c:777\n ip_fragment.constprop.0+0x161/0x230 net/ipv4/ip_output.c:584\n ip_finish_output_gso net/ipv4/ip_output.c:286 [inline]\n __ip_finish_output net/ipv4/ip_output.c:308 [inline]\n __ip_finish_output+0x49c/0x650 net/ipv4/ip_output.c:295\n ip_finish_output+0x31/0x310 net/ipv4/ip_output.c:323\n NF_HOOK_COND include/linux/netfilter.h:303 [inline]\n ip_output+0x13b/0x2a0 net/ipv4/ip_output.c:433\n dst_output include/net/dst.h:451 [inline]\n ip_local_out+0xaf/0x1a0 net/ipv4/ip_output.c:129\n iptunnel_xmit+0x5b4/0x9b0 net/ipv4/ip_tunnel_core.c:82\n ipip6_tunnel_xmit net/ipv6/sit.c:1034 [inline]\n sit_tunnel_xmit+0xed2/0x28f0 net/ipv6/sit.c:1076\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3545 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3561\n __dev_queue_xmit+0x7c1/0x3d60 net/core/dev.c:4346\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n packet_xmit+0x257/0x380 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3087 [inline]\n packet_sendmsg+0x24ca/0x5240 net/packet/af_packet.c:3119\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0xd5/0x180 net/socket.c:745\n __sys_sendto+0x255/0x340 net/socket.c:2190\n __do_sys_sendto net/socket.c:2202 [inline]\n __se_sys_sendto net/socket.c:2198 [inline]\n __x64_sys_sendto+0xe0/0x1b0 net/socket.c:2198\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x40/0x110 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43817', 'https://git.kernel.org/linus/e269d79c7d35aa3808b1f3c1737d63dab504ddc8 (6.11-rc1)', 'https://git.kernel.org/stable/c/27874ca77bd2b05a3779c7b3a5c75d8dd7f0b40f', 'https://git.kernel.org/stable/c/5b1997487a3f3373b0f580c8a20b56c1b64b0775', 'https://git.kernel.org/stable/c/90d41ebe0cd4635f6410471efc1dd71b33e894cf', 'https://git.kernel.org/stable/c/e269d79c7d35aa3808b1f3c1737d63dab504ddc8', 'https://git.kernel.org/stable/c/e9164903b8b303c34723177b02fe91e49e3c4cd7', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43817-2e95@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43817', 'https://www.cve.org/CVERecord?id=CVE-2024-43817'], 'PublishedDate': '2024-08-17T10:15:08.01Z', 'LastModifiedDate': '2024-09-03T17:41:46.407Z'}, {'VulnerabilityID': 'CVE-2024-43818', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43818', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ASoC: amd: Adjust error handling in case of absent codec device', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: Adjust error handling in case of absent codec device\n\nacpi_get_first_physical_node() can return NULL in several cases (no such\ndevice, ACPI table error, reference count drop to 0, etc).\nExisting check just emit error message, but doesn't perform return.\nThen this NULL pointer is passed to devm_acpi_dev_add_driver_gpios()\nwhere it is dereferenced.\n\nAdjust this error handling by adding error code return.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43818', 'https://git.kernel.org/linus/5080808c3339de2220c602ab7c7fa23dc6c1a5a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/1ba9856cf7f6492b47c1edf853137f320d583db5', 'https://git.kernel.org/stable/c/5080808c3339de2220c602ab7c7fa23dc6c1a5a3', 'https://git.kernel.org/stable/c/99b642dac24f6d09ba3ebf1d690be8aefff86164', 'https://git.kernel.org/stable/c/b1173d64edd276c957b6d09e1f971c85b38f1519', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43818-71ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43818', 'https://www.cve.org/CVERecord?id=CVE-2024-43818'], 'PublishedDate': '2024-08-17T10:15:08.08Z', 'LastModifiedDate': '2024-09-03T17:45:30Z'}, {'VulnerabilityID': 'CVE-2024-43819', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43819', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kvm: s390: Reject memory region operations for ucontrol VMs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkvm: s390: Reject memory region operations for ucontrol VMs\n\nThis change rejects the KVM_SET_USER_MEMORY_REGION and\nKVM_SET_USER_MEMORY_REGION2 ioctls when called on a ucontrol VM.\nThis is necessary since ucontrol VMs have kvm->arch.gmap set to 0 and\nwould thus result in a null pointer dereference further in.\nMemory management needs to be performed in userspace and using the\nioctls KVM_S390_UCAS_MAP and KVM_S390_UCAS_UNMAP.\n\nAlso improve s390 specific documentation for KVM_SET_USER_MEMORY_REGION\nand KVM_SET_USER_MEMORY_REGION2.\n\n[frankja@linux.ibm.com: commit message spelling fix, subject prefix fix]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43819', 'https://git.kernel.org/linus/7816e58967d0e6cadce05c8540b47ed027dc2499 (6.11-rc1)', 'https://git.kernel.org/stable/c/49c9945c054df4c22008e2bf87ca74d3e2507aa6', 'https://git.kernel.org/stable/c/7816e58967d0e6cadce05c8540b47ed027dc2499', 'https://lore.kernel.org/linux-cve-announce/2024081723-CVE-2024-43819-88ce@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43819', 'https://www.cve.org/CVERecord?id=CVE-2024-43819'], 'PublishedDate': '2024-08-17T10:15:08.147Z', 'LastModifiedDate': '2024-09-03T17:47:10.54Z'}, {'VulnerabilityID': 'CVE-2024-43820', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43820', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume\n\nrm-raid devices will occasionally trigger the following warning when\nbeing resumed after a table load because DM_RECOVERY_RUNNING is set:\n\nWARNING: CPU: 7 PID: 5660 at drivers/md/dm-raid.c:4105 raid_resume+0xee/0x100 [dm_raid]\n\nThe failing check is:\nWARN_ON_ONCE(test_bit(MD_RECOVERY_RUNNING, &mddev->recovery));\n\nThis check is designed to make sure that the sync thread isn't\nregistered, but md_check_recovery can set MD_RECOVERY_RUNNING without\nthe sync_thread ever getting registered. Instead of checking if\nMD_RECOVERY_RUNNING is set, check if sync_thread is non-NULL.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43820', 'https://git.kernel.org/linus/3199a34bfaf7561410e0be1e33a61eba870768fc (6.11-rc1)', 'https://git.kernel.org/stable/c/3199a34bfaf7561410e0be1e33a61eba870768fc', 'https://git.kernel.org/stable/c/a5c15a78c0e1631b7df822b56e8b6424e4d1ca3e', 'https://lore.kernel.org/linux-cve-announce/2024081724-CVE-2024-43820-1bd6@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43820', 'https://www.cve.org/CVERecord?id=CVE-2024-43820'], 'PublishedDate': '2024-08-17T10:15:08.207Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43821', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43821', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: lpfc: Fix a possible null pointer dereference', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix a possible null pointer dereference\n\nIn function lpfc_xcvr_data_show, the memory allocation with kmalloc might\nfail, thereby making rdp_context a null pointer. In the following context\nand functions that use this pointer, there are dereferencing operations,\nleading to null pointer dereference.\n\nTo fix this issue, a null pointer check should be added. If it is null,\nuse scnprintf to notify the user and return len.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43821', 'https://git.kernel.org/linus/5e0bf3e8aec2cbc51123f84b29aaacbd91fc56fa (6.11-rc1)', 'https://git.kernel.org/stable/c/45b2a23e00d448a9e6d1f371ca3a4d4b073fe78c', 'https://git.kernel.org/stable/c/57600a7dd2b52c904f7c8d2cac0fd8c23868e680', 'https://git.kernel.org/stable/c/5e0bf3e8aec2cbc51123f84b29aaacbd91fc56fa', 'https://lore.kernel.org/linux-cve-announce/2024081724-CVE-2024-43821-6ffc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43821', 'https://www.cve.org/CVERecord?id=CVE-2024-43821'], 'PublishedDate': '2024-08-17T10:15:08.277Z', 'LastModifiedDate': '2024-09-03T17:49:54.28Z'}, {'VulnerabilityID': 'CVE-2024-43823', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43823', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()\n\nIf IORESOURCE_MEM is not provided in Device Tree due to\nany error, resource_list_first_type() will return NULL and\npci_parse_request_of_pci_ranges() will just emit a warning.\n\nThis will cause a NULL pointer dereference. Fix this bug by adding NULL\nreturn check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43823', 'https://git.kernel.org/linus/a231707a91f323af1e5d9f1722055ec2fc1c7775 (6.11-rc1)', 'https://git.kernel.org/stable/c/0a6f1b5fe8ef8268aaa069035639968ceeea0a23', 'https://git.kernel.org/stable/c/a231707a91f323af1e5d9f1722055ec2fc1c7775', 'https://git.kernel.org/stable/c/bbba48ad67c53feea05936ea1e029dcca8057506', 'https://git.kernel.org/stable/c/dbcdd1863ba2ec9b76ec131df25d797709e05597', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43823-4bdd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43823', 'https://www.cve.org/CVERecord?id=CVE-2024-43823'], 'PublishedDate': '2024-08-17T10:15:08.4Z', 'LastModifiedDate': '2024-09-03T17:49:03.91Z'}, {'VulnerabilityID': 'CVE-2024-43824', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43824', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: pci-epf-test: Make use of cached \'epc_features\' in pci_epf_test_core_init()\n\nInstead of getting the epc_features from pci_epc_get_features() API, use\nthe cached pci_epf_test::epc_features value to avoid the NULL check. Since\nthe NULL check is already performed in pci_epf_test_bind(), having one more\ncheck in pci_epf_test_core_init() is redundant and it is not possible to\nhit the NULL pointer dereference.\n\nAlso with commit a01e7214bef9 ("PCI: endpoint: Remove "core_init_notifier"\nflag"), \'epc_features\' got dereferenced without the NULL check, leading to\nthe following false positive Smatch warning:\n\n drivers/pci/endpoint/functions/pci-epf-test.c:784 pci_epf_test_core_init() error: we previously assumed \'epc_features\' could be null (see line 747)\n\nThus, remove the redundant NULL check and also use the epc_features::\n{msix_capable/msi_capable} flags directly to avoid local variables.\n\n[kwilczynski: commit log]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43824', 'https://git.kernel.org/linus/5a5095a8bd1bd349cce1c879e5e44407a34dda8a (6.11-rc1)', 'https://git.kernel.org/stable/c/5a5095a8bd1bd349cce1c879e5e44407a34dda8a', 'https://git.kernel.org/stable/c/af4ad016abb1632ff7ee598a6037952b495e5b80', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43824-fc04@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43824', 'https://www.cve.org/CVERecord?id=CVE-2024-43824'], 'PublishedDate': '2024-08-17T10:15:08.477Z', 'LastModifiedDate': '2024-09-03T17:48:39.16Z'}, {'VulnerabilityID': 'CVE-2024-43825', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43825', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: iio: Fix the sorting functionality in iio_gts_build_avail_time_table', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: Fix the sorting functionality in iio_gts_build_avail_time_table\n\nThe sorting in iio_gts_build_avail_time_table is not working as intended.\nIt could result in an out-of-bounds access when the time is zero.\n\nHere are more details:\n\n1. When the gts->itime_table[i].time_us is zero, e.g., the time\nsequence is `3, 0, 1`, the inner for-loop will not terminate and do\nout-of-bound writes. This is because once `times[j] > new`, the value\n`new` will be added in the current position and the `times[j]` will be\nmoved to `j+1` position, which makes the if-condition always hold.\nMeanwhile, idx will be added one, making the loop keep running without\ntermination and out-of-bound write.\n2. If none of the gts->itime_table[i].time_us is zero, the elements\nwill just be copied without being sorted as described in the comment\n"Sort times from all tables to one and remove duplicates".\n\nFor more details, please refer to\nhttps://lore.kernel.org/all/6dd0d822-046c-4dd2-9532-79d7ab96ec05@gmail.com.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 5.2}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43825', 'https://git.kernel.org/linus/5acc3f971a01be48d5ff4252d8f9cdb87998cdfb (6.11-rc1)', 'https://git.kernel.org/stable/c/31ff8464ef540785344994986a010031410f9ff3', 'https://git.kernel.org/stable/c/5acc3f971a01be48d5ff4252d8f9cdb87998cdfb', 'https://git.kernel.org/stable/c/b5046de32fd1532c3f67065197fc1da82f0b5193', 'https://lore.kernel.org/linux-cve-announce/2024081725-CVE-2024-43825-20fc@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43825', 'https://www.cve.org/CVERecord?id=CVE-2024-43825'], 'PublishedDate': '2024-08-17T10:15:08.533Z', 'LastModifiedDate': '2024-09-30T13:53:21.44Z'}, {'VulnerabilityID': 'CVE-2024-43826', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43826', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nfs: pass explicit offset/count to trace events', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: pass explicit offset/count to trace events\n\nnfs_folio_length is unsafe to use without having the folio locked and a\ncheck for a NULL ->f_mapping that protects against truncations and can\nlead to kernel crashes. E.g. when running xfstests generic/065 with\nall nfs trace points enabled.\n\nFollow the model of the XFS trace points and pass in an explіcit offset\nand length. This has the additional benefit that these values can\nbe more accurate as some of the users touch partial folio ranges.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43826', 'https://git.kernel.org/linus/fada32ed6dbc748f447c8d050a961b75d946055a (6.11-rc1)', 'https://git.kernel.org/stable/c/387e6e9d110250946df4d4ebef9c2def5c7a4722', 'https://git.kernel.org/stable/c/fada32ed6dbc748f447c8d050a961b75d946055a', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43826-2a5f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43826', 'https://www.cve.org/CVERecord?id=CVE-2024-43826'], 'PublishedDate': '2024-08-17T10:15:08.593Z', 'LastModifiedDate': '2024-09-12T18:15:09.137Z'}, {'VulnerabilityID': 'CVE-2024-43827', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43827', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null check before access structs', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check before access structs\n\nIn enable_phantom_plane, we should better check null pointer before\naccessing various structs.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43827', 'https://git.kernel.org/linus/c96140000915b610d86f941450e15ca552de154a (6.11-rc1)', 'https://git.kernel.org/stable/c/081ff4c0ef1884ae55f7adb8944efd22e22d8724', 'https://git.kernel.org/stable/c/c96140000915b610d86f941450e15ca552de154a', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43827-6486@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43827', 'https://www.cve.org/CVERecord?id=CVE-2024-43827'], 'PublishedDate': '2024-08-17T10:15:08.653Z', 'LastModifiedDate': '2024-09-30T12:51:34.97Z'}, {'VulnerabilityID': 'CVE-2024-43828', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43828', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: fix infinite loop when replaying fast_commit', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix infinite loop when replaying fast_commit\n\nWhen doing fast_commit replay an infinite loop may occur due to an\nuninitialized extent_status struct. ext4_ext_determine_insert_hole() does\nnot detect the replay and calls ext4_es_find_extent_range(), which will\nreturn immediately without initializing the 'es' variable.\n\nBecause 'es' contains garbage, an integer overflow may happen causing an\ninfinite loop in this function, easily reproducible using fstest generic/039.\n\nThis commit fixes this issue by unconditionally initializing the structure\nin function ext4_es_find_extent_range().\n\nThanks to Zhang Yi, for figuring out the real problem!", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-835'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43828', 'https://git.kernel.org/linus/907c3fe532253a6ef4eb9c4d67efb71fab58c706 (6.11-rc1)', 'https://git.kernel.org/stable/c/0619f7750f2b178a1309808832ab20d85e0ad121', 'https://git.kernel.org/stable/c/181e63cd595c688194e07332f9944b3a63193de2', 'https://git.kernel.org/stable/c/5ed0496e383cb6de120e56991385dce70bbb87c1', 'https://git.kernel.org/stable/c/81f819c537d29932e4b9267f02411cbc8b355178', 'https://git.kernel.org/stable/c/907c3fe532253a6ef4eb9c4d67efb71fab58c706', 'https://git.kernel.org/stable/c/c6e67df64783e99a657ef2b8c834ba2bf54c539c', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43828-6bcb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43828', 'https://www.cve.org/CVERecord?id=CVE-2024-43828'], 'PublishedDate': '2024-08-17T10:15:08.72Z', 'LastModifiedDate': '2024-08-22T15:41:50.87Z'}, {'VulnerabilityID': 'CVE-2024-43829', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43829', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/qxl: Add check for drm_cvt_mode', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/qxl: Add check for drm_cvt_mode\n\nAdd check for the return value of drm_cvt_mode() and return the error if\nit fails in order to avoid NULL pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43829', 'https://git.kernel.org/linus/7bd09a2db0f617377027a2bb0b9179e6959edff3 (6.11-rc1)', 'https://git.kernel.org/stable/c/3efe34f95b1ac8c138a46b14ce75956db0d6ee7c', 'https://git.kernel.org/stable/c/4b1f303bdeceac049e56e4b20eb5280bd9e02f4f', 'https://git.kernel.org/stable/c/4e87f592a46bb804d8f833da6ce702ae4b55053f', 'https://git.kernel.org/stable/c/62ef8d7816c8e4a6088275553818b9afc0ffaa03', 'https://git.kernel.org/stable/c/7bd09a2db0f617377027a2bb0b9179e6959edff3', 'https://git.kernel.org/stable/c/d4c57354a06cb4a77998ff8aa40af89eee30e07b', 'https://git.kernel.org/stable/c/f28b353c0c6c7831a70ccca881bf2db5e6785cdd', 'https://linux.oracle.com/cve/CVE-2024-43829.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081726-CVE-2024-43829-72cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43829', 'https://www.cve.org/CVERecord?id=CVE-2024-43829'], 'PublishedDate': '2024-08-17T10:15:08.787Z', 'LastModifiedDate': '2024-09-30T12:51:56.77Z'}, {'VulnerabilityID': 'CVE-2024-43830', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43830', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: leds: trigger: Unregister sysfs attributes before calling deactivate()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nleds: trigger: Unregister sysfs attributes before calling deactivate()\n\nTriggers which have trigger specific sysfs attributes typically store\nrelated data in trigger-data allocated by the activate() callback and\nfreed by the deactivate() callback.\n\nCalling device_remove_groups() after calling deactivate() leaves a window\nwhere the sysfs attributes show/store functions could be called after\ndeactivation and then operate on the just freed trigger-data.\n\nMove the device_remove_groups() call to before deactivate() to close\nthis race window.\n\nThis also makes the deactivation path properly do things in reverse order\nof the activation path which calls the activate() callback before calling\ndevice_add_groups().', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7000', 'https://access.redhat.com/security/cve/CVE-2024-43830', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2265838', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2270103', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275558', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282648', 'https://bugzilla.redhat.com/2282669', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282764', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284511', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284630', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293414', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300381', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300439', 'https://bugzilla.redhat.com/2300440', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300709', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301543', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305410', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2305488', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7000.html', 'https://git.kernel.org/linus/c0dc9adf9474ecb7106e60e5472577375aedaed3 (6.11-rc1)', 'https://git.kernel.org/stable/c/0788a6f3523d3686a9eed5ea1e6fcce6841277b2', 'https://git.kernel.org/stable/c/09c1583f0e10c918855d6e7540a79461a353e5d6', 'https://git.kernel.org/stable/c/3fb6a9d67cfd812a547ac73ec02e1077c26c640d', 'https://git.kernel.org/stable/c/734ba6437e80dfc780e9ee9d95f912392d12b5ea', 'https://git.kernel.org/stable/c/c0dc9adf9474ecb7106e60e5472577375aedaed3', 'https://git.kernel.org/stable/c/c3b7a650c8717aa89df318364609c86cbc040156', 'https://git.kernel.org/stable/c/cb8aa9d2a4c8a15d6a43ccf901ef3d094aa60374', 'https://git.kernel.org/stable/c/d1415125b701ef13370e2761f691ec632a5eb93a', 'https://linux.oracle.com/cve/CVE-2024-43830.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43830-3b85@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43830', 'https://www.cve.org/CVERecord?id=CVE-2024-43830'], 'PublishedDate': '2024-08-17T10:15:08.857Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43831', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43831', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: mediatek: vcodec: Handle invalid decoder vsi', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: Handle invalid decoder vsi\n\nHandle an invalid decoder vsi in vpu_dec_init to ensure the decoder vsi\nis valid for future use.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43831', 'https://git.kernel.org/linus/59d438f8e02ca641c58d77e1feffa000ff809e9f (6.11-rc1)', 'https://git.kernel.org/stable/c/1c109f23b271a02b9bb195c173fab41e3285a8db', 'https://git.kernel.org/stable/c/59d438f8e02ca641c58d77e1feffa000ff809e9f', 'https://git.kernel.org/stable/c/cdf05ae76198c513836bde4eb55f099c44773280', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43831-b13e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43831', 'https://www.cve.org/CVERecord?id=CVE-2024-43831'], 'PublishedDate': '2024-08-17T10:15:08.917Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43832', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43832', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: s390/uv: Don't call folio_wait_writeback() without a folio reference", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/uv: Don't call folio_wait_writeback() without a folio reference\n\nfolio_wait_writeback() requires that no spinlocks are held and that\na folio reference is held, as documented. After we dropped the PTL, the\nfolio could get freed concurrently. So grab a temporary reference.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43832', 'https://git.kernel.org/linus/3f29f6537f54d74e64bac0a390fb2e26da25800d (6.11-rc1)', 'https://git.kernel.org/stable/c/1a1eb2f3fc453dcd52726d13e863938561489cb7', 'https://git.kernel.org/stable/c/3f29f6537f54d74e64bac0a390fb2e26da25800d', 'https://git.kernel.org/stable/c/8736604ef53359a718c246087cd21dcec232d2fb', 'https://git.kernel.org/stable/c/b21aba72aadd94bdac275deab021fc84d6c72b16', 'https://lore.kernel.org/linux-cve-announce/2024081727-CVE-2024-43832-7746@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43832', 'https://www.cve.org/CVERecord?id=CVE-2024-43832'], 'PublishedDate': '2024-08-17T10:15:08.98Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43833', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43833', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: v4l: async: Fix NULL pointer dereference in adding ancillary links', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l: async: Fix NULL pointer dereference in adding ancillary links\n\nIn v4l2_async_create_ancillary_links(), ancillary links are created for\nlens and flash sub-devices. These are sub-device to sub-device links and\nif the async notifier is related to a V4L2 device, the source sub-device\nof the ancillary link is NULL, leading to a NULL pointer dereference.\nCheck the notifier's sd field is non-NULL in\nv4l2_async_create_ancillary_links().\n\n[Sakari Ailus: Reword the subject and commit messages slightly.]", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43833', 'https://git.kernel.org/linus/9b4667ea67854f0b116fe22ad11ef5628c5b5b5f (6.11-rc1)', 'https://git.kernel.org/stable/c/249212ceb4187783af3801c57b92a5a25d410621', 'https://git.kernel.org/stable/c/9b4667ea67854f0b116fe22ad11ef5628c5b5b5f', 'https://git.kernel.org/stable/c/b87e28050d9b0959de24574d587825cfab2f13fb', 'https://git.kernel.org/stable/c/fe0f92fd5320b393e44ca210805e653ea90cc982', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43833-4e73@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43833', 'https://www.cve.org/CVERecord?id=CVE-2024-43833'], 'PublishedDate': '2024-08-17T10:15:09.04Z', 'LastModifiedDate': '2024-08-22T15:42:46.827Z'}, {'VulnerabilityID': 'CVE-2024-43834', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43834', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xdp: fix invalid wait context of page_pool_destroy()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix invalid wait context of page_pool_destroy()\n\nIf the driver uses a page pool, it creates a page pool with\npage_pool_create().\nThe reference count of page pool is 1 as default.\nA page pool will be destroyed only when a reference count reaches 0.\npage_pool_destroy() is used to destroy page pool, it decreases a\nreference count.\nWhen a page pool is destroyed, ->disconnect() is called, which is\nmem_allocator_disconnect().\nThis function internally acquires mutex_lock().\n\nIf the driver uses XDP, it registers a memory model with\nxdp_rxq_info_reg_mem_model().\nThe xdp_rxq_info_reg_mem_model() internally increases a page pool\nreference count if a memory model is a page pool.\nNow the reference count is 2.\n\nTo destroy a page pool, the driver should call both page_pool_destroy()\nand xdp_unreg_mem_model().\nThe xdp_unreg_mem_model() internally calls page_pool_destroy().\nOnly page_pool_destroy() decreases a reference count.\n\nIf a driver calls page_pool_destroy() then xdp_unreg_mem_model(), we\nwill face an invalid wait context warning.\nBecause xdp_unreg_mem_model() calls page_pool_destroy() with\nrcu_read_lock().\nThe page_pool_destroy() internally acquires mutex_lock().\n\nSplat looks like:\n=============================\n[ BUG: Invalid wait context ]\n6.10.0-rc6+ #4 Tainted: G W\n-----------------------------\nethtool/1806 is trying to lock:\nffffffff90387b90 (mem_id_lock){+.+.}-{4:4}, at: mem_allocator_disconnect+0x73/0x150\nother info that might help us debug this:\ncontext-{5:5}\n3 locks held by ethtool/1806:\nstack backtrace:\nCPU: 0 PID: 1806 Comm: ethtool Tainted: G W 6.10.0-rc6+ #4 f916f41f172891c800f2fed\nHardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021\nCall Trace:\n\ndump_stack_lvl+0x7e/0xc0\n__lock_acquire+0x1681/0x4de0\n? _printk+0x64/0xe0\n? __pfx_mark_lock.part.0+0x10/0x10\n? __pfx___lock_acquire+0x10/0x10\nlock_acquire+0x1b3/0x580\n? mem_allocator_disconnect+0x73/0x150\n? __wake_up_klogd.part.0+0x16/0xc0\n? __pfx_lock_acquire+0x10/0x10\n? dump_stack_lvl+0x91/0xc0\n__mutex_lock+0x15c/0x1690\n? mem_allocator_disconnect+0x73/0x150\n? __pfx_prb_read_valid+0x10/0x10\n? mem_allocator_disconnect+0x73/0x150\n? __pfx_llist_add_batch+0x10/0x10\n? console_unlock+0x193/0x1b0\n? lockdep_hardirqs_on+0xbe/0x140\n? __pfx___mutex_lock+0x10/0x10\n? tick_nohz_tick_stopped+0x16/0x90\n? __irq_work_queue_local+0x1e5/0x330\n? irq_work_queue+0x39/0x50\n? __wake_up_klogd.part.0+0x79/0xc0\n? mem_allocator_disconnect+0x73/0x150\nmem_allocator_disconnect+0x73/0x150\n? __pfx_mem_allocator_disconnect+0x10/0x10\n? mark_held_locks+0xa5/0xf0\n? rcu_is_watching+0x11/0xb0\npage_pool_release+0x36e/0x6d0\npage_pool_destroy+0xd7/0x440\nxdp_unreg_mem_model+0x1a7/0x2a0\n? __pfx_xdp_unreg_mem_model+0x10/0x10\n? kfree+0x125/0x370\n? bnxt_free_ring.isra.0+0x2eb/0x500\n? bnxt_free_mem+0x5ac/0x2500\nxdp_rxq_info_unreg+0x4a/0xd0\nbnxt_free_mem+0x1356/0x2500\nbnxt_close_nic+0xf0/0x3b0\n? __pfx_bnxt_close_nic+0x10/0x10\n? ethnl_parse_bit+0x2c6/0x6d0\n? __pfx___nla_validate_parse+0x10/0x10\n? __pfx_ethnl_parse_bit+0x10/0x10\nbnxt_set_features+0x2a8/0x3e0\n__netdev_update_features+0x4dc/0x1370\n? ethnl_parse_bitset+0x4ff/0x750\n? __pfx_ethnl_parse_bitset+0x10/0x10\n? __pfx___netdev_update_features+0x10/0x10\n? mark_held_locks+0xa5/0xf0\n? _raw_spin_unlock_irqrestore+0x42/0x70\n? __pm_runtime_resume+0x7d/0x110\nethnl_set_features+0x32d/0xa20\n\nTo fix this problem, it uses rhashtable_lookup_fast() instead of\nrhashtable_lookup() with rcu_read_lock().\nUsing xa without rcu_read_lock() here is safe.\nxa is freed by __xdp_mem_allocator_rcu_free() and this is called by\ncall_rcu() of mem_xa_remove().\nThe mem_xa_remove() is called by page_pool_destroy() if a reference\ncount reaches 0.\nThe xa is already protected by the reference count mechanism well in the\ncontrol plane.\nSo removing rcu_read_lock() for page_pool_destroy() is safe.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43834', 'https://git.kernel.org/linus/59a931c5b732ca5fc2ca727f5a72aeabaafa85ec (6.11-rc1)', 'https://git.kernel.org/stable/c/12144069209eec7f2090ce9afa15acdcc2c2a537', 'https://git.kernel.org/stable/c/3fc1be360b99baeea15cdee3cf94252cd3a72d26', 'https://git.kernel.org/stable/c/59a931c5b732ca5fc2ca727f5a72aeabaafa85ec', 'https://git.kernel.org/stable/c/6c390ef198aa69795427a5cb5fd7cb4bc7e6cd7a', 'https://git.kernel.org/stable/c/be9d08ff102df3ac4f66e826ea935cf3af63a4bd', 'https://git.kernel.org/stable/c/bf0ce5aa5f2525ed1b921ba36de96e458e77f482', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43834-0140@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43834', 'https://www.cve.org/CVERecord?id=CVE-2024-43834'], 'PublishedDate': '2024-08-17T10:15:09.113Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43835', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43835', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: virtio_net: Fix napi_skb_cache_put warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Fix napi_skb_cache_put warning\n\nAfter the commit bdacf3e34945 ("net: Use nested-BH locking for\nnapi_alloc_cache.") was merged, the following warning began to appear:\n\n\t WARNING: CPU: 5 PID: 1 at net/core/skbuff.c:1451 napi_skb_cache_put+0x82/0x4b0\n\n\t __warn+0x12f/0x340\n\t napi_skb_cache_put+0x82/0x4b0\n\t napi_skb_cache_put+0x82/0x4b0\n\t report_bug+0x165/0x370\n\t handle_bug+0x3d/0x80\n\t exc_invalid_op+0x1a/0x50\n\t asm_exc_invalid_op+0x1a/0x20\n\t __free_old_xmit+0x1c8/0x510\n\t napi_skb_cache_put+0x82/0x4b0\n\t __free_old_xmit+0x1c8/0x510\n\t __free_old_xmit+0x1c8/0x510\n\t __pfx___free_old_xmit+0x10/0x10\n\nThe issue arises because virtio is assuming it\'s running in NAPI context\neven when it\'s not, such as in the netpoll case.\n\nTo resolve this, modify virtnet_poll_tx() to only set NAPI when budget\nis available. Same for virtnet_poll_cleantx(), which always assumed that\nit was in a NAPI context.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43835', 'https://git.kernel.org/linus/f8321fa75102246d7415a6af441872f6637c93ab (6.11-rc1)', 'https://git.kernel.org/stable/c/19ac6f29bf64304ef04630c8ab56ecd2059d7aa1', 'https://git.kernel.org/stable/c/468a729b78895893d0e580ceea49bed8ada2a2bd', 'https://git.kernel.org/stable/c/6b5325f2457521bbece29499970c0117a648c620', 'https://git.kernel.org/stable/c/842a97b5e44f0c8a9fc356fe976e0e13ddcf7783', 'https://git.kernel.org/stable/c/cc7340f18e45886121c131227985d64ef666012f', 'https://git.kernel.org/stable/c/d3af435e8ace119e58d8e21d3d2d6a4e7c4a4baa', 'https://git.kernel.org/stable/c/f5e9a22d19bb98a7e86034db85eb295e94187caa', 'https://git.kernel.org/stable/c/f8321fa75102246d7415a6af441872f6637c93ab', 'https://lore.kernel.org/linux-cve-announce/2024081728-CVE-2024-43835-5f11@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43835', 'https://www.cve.org/CVERecord?id=CVE-2024-43835'], 'PublishedDate': '2024-08-17T10:15:09.183Z', 'LastModifiedDate': '2024-09-12T12:15:48.653Z'}, {'VulnerabilityID': 'CVE-2024-43837', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43837', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT\n\nWhen loading a EXT program without specifying `attr->attach_prog_fd`,\nthe `prog->aux->dst_prog` will be null. At this time, calling\nresolve_prog_type() anywhere will result in a null pointer dereference.\n\nExample stack trace:\n\n[ 8.107863] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004\n[ 8.108262] Mem abort info:\n[ 8.108384] ESR = 0x0000000096000004\n[ 8.108547] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 8.108722] SET = 0, FnV = 0\n[ 8.108827] EA = 0, S1PTW = 0\n[ 8.108939] FSC = 0x04: level 0 translation fault\n[ 8.109102] Data abort info:\n[ 8.109203] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 8.109399] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 8.109614] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 8.109836] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101354000\n[ 8.110011] [0000000000000004] pgd=0000000000000000, p4d=0000000000000000\n[ 8.112624] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 8.112783] Modules linked in:\n[ 8.113120] CPU: 0 PID: 99 Comm: may_access_dire Not tainted 6.10.0-rc3-next-20240613-dirty #1\n[ 8.113230] Hardware name: linux,dummy-virt (DT)\n[ 8.113390] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 8.113429] pc : may_access_direct_pkt_data+0x24/0xa0\n[ 8.113746] lr : add_subprog_and_kfunc+0x634/0x8e8\n[ 8.113798] sp : ffff80008283b9f0\n[ 8.113813] x29: ffff80008283b9f0 x28: ffff800082795048 x27: 0000000000000001\n[ 8.113881] x26: ffff0000c0bb2600 x25: 0000000000000000 x24: 0000000000000000\n[ 8.113897] x23: ffff0000c1134000 x22: 000000000001864f x21: ffff0000c1138000\n[ 8.113912] x20: 0000000000000001 x19: ffff0000c12b8000 x18: ffffffffffffffff\n[ 8.113929] x17: 0000000000000000 x16: 0000000000000000 x15: 0720072007200720\n[ 8.113944] x14: 0720072007200720 x13: 0720072007200720 x12: 0720072007200720\n[ 8.113958] x11: 0720072007200720 x10: 0000000000f9fca4 x9 : ffff80008021f4e4\n[ 8.113991] x8 : 0101010101010101 x7 : 746f72705f6d656d x6 : 000000001e0e0f5f\n[ 8.114006] x5 : 000000000001864f x4 : ffff0000c12b8000 x3 : 000000000000001c\n[ 8.114020] x2 : 0000000000000002 x1 : 0000000000000000 x0 : 0000000000000000\n[ 8.114126] Call trace:\n[ 8.114159] may_access_direct_pkt_data+0x24/0xa0\n[ 8.114202] bpf_check+0x3bc/0x28c0\n[ 8.114214] bpf_prog_load+0x658/0xa58\n[ 8.114227] __sys_bpf+0xc50/0x2250\n[ 8.114240] __arm64_sys_bpf+0x28/0x40\n[ 8.114254] invoke_syscall.constprop.0+0x54/0xf0\n[ 8.114273] do_el0_svc+0x4c/0xd8\n[ 8.114289] el0_svc+0x3c/0x140\n[ 8.114305] el0t_64_sync_handler+0x134/0x150\n[ 8.114331] el0t_64_sync+0x168/0x170\n[ 8.114477] Code: 7100707f 54000081 f9401c00 f9403800 (b9400403)\n[ 8.118672] ---[ end trace 0000000000000000 ]---\n\nOne way to fix it is by forcing `attach_prog_fd` non-empty when\nbpf_prog_load(). But this will lead to `libbpf_probe_bpf_prog_type`\nAPI broken which use verifier log to probe prog type and will log\nnothing if we reject invalid EXT prog before bpf_check().\n\nAnother way is by adding null check in resolve_prog_type().\n\nThe issue was introduced by commit 4a9c7bbe2ed4 ("bpf: Resolve to\nprog->aux->dst_prog->type only for BPF_PROG_TYPE_EXT") which wanted\nto correct type resolution for BPF_PROG_TYPE_TRACING programs. Before\nthat, the type resolution of BPF_PROG_TYPE_EXT prog actually follows\nthe logic below:\n\n prog->aux->dst_prog ? prog->aux->dst_prog->type : prog->type;\n\nIt implies that when EXT program is not yet attached to `dst_prog`,\nthe prog type should be EXT itself. This code worked fine in the past.\nSo just keep using it.\n\nFix this by returning `prog->type` for BPF_PROG_TYPE_EXT if `dst_prog`\nis not present in resolve_prog_type().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43837', 'https://git.kernel.org/linus/f7866c35873377313ff94398f17d425b28b71de1 (6.11-rc1)', 'https://git.kernel.org/stable/c/9d40fd516aeae6779e3c84c6b96700ca76285847', 'https://git.kernel.org/stable/c/b29a880bb145e1f1c1df5ab88ed26b1495ff9f09', 'https://git.kernel.org/stable/c/f7866c35873377313ff94398f17d425b28b71de1', 'https://git.kernel.org/stable/c/fcac5feb06f31ee4c88bca9bf98d8bc3ca7d2615', 'https://lore.kernel.org/linux-cve-announce/2024081729-CVE-2024-43837-63d2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43837', 'https://www.cve.org/CVERecord?id=CVE-2024-43837'], 'PublishedDate': '2024-08-17T10:15:09.32Z', 'LastModifiedDate': '2024-08-22T15:44:03.417Z'}, {'VulnerabilityID': 'CVE-2024-43839', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43839', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: bna: adjust 'name' buf size of bna_tcb and bna_ccb structures", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbna: adjust 'name' buf size of bna_tcb and bna_ccb structures\n\nTo have enough space to write all possible sprintf() args. Currently\n'name' size is 16, but the first '%s' specifier may already need at\nleast 16 characters, since 'bnad->netdev->name' is used there.\n\nFor '%d' specifiers, assume that they require:\n * 1 char for 'tx_id + tx_info->tcb[i]->id' sum, BNAD_MAX_TXQ_PER_TX is 8\n * 2 chars for 'rx_id + rx_info->rx_ctrl[i].ccb->id', BNAD_MAX_RXP_PER_RX\n is 16\n\nAnd replace sprintf with snprintf.\n\nDetected using the static analysis tool - Svace.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 6.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43839', 'https://git.kernel.org/linus/c9741a03dc8e491e57b95fba0058ab46b7e506da (6.11-rc1)', 'https://git.kernel.org/stable/c/6ce46045f9b90d952602e2c0b8886cfadf860bf1', 'https://git.kernel.org/stable/c/6d20c4044ab4d0e6a99aa35853e66f0aed5589e3', 'https://git.kernel.org/stable/c/ab748dd10d8742561f2980fea08ffb4f0cacfdef', 'https://git.kernel.org/stable/c/b0ff0cd0847b03c0a0abe20cfa900eabcfcb9e43', 'https://git.kernel.org/stable/c/c90b1cd7758fd4839909e838ae195d19f8065d76', 'https://git.kernel.org/stable/c/c9741a03dc8e491e57b95fba0058ab46b7e506da', 'https://git.kernel.org/stable/c/e0f48f51d55fb187400e9787192eda09fa200ff5', 'https://git.kernel.org/stable/c/f121740f69eda4da2de9a20a6687a13593e72540', 'https://linux.oracle.com/cve/CVE-2024-43839.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081729-CVE-2024-43839-ea03@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43839', 'https://www.cve.org/CVERecord?id=CVE-2024-43839'], 'PublishedDate': '2024-08-17T10:15:09.447Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43840', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43840', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG\n\nWhen BPF_TRAMP_F_CALL_ORIG is set, the trampoline calls\n__bpf_tramp_enter() and __bpf_tramp_exit() functions, passing them\nthe struct bpf_tramp_image *im pointer as an argument in R0.\n\nThe trampoline generation code uses emit_addr_mov_i64() to emit\ninstructions for moving the bpf_tramp_image address into R0, but\nemit_addr_mov_i64() assumes the address to be in the vmalloc() space\nand uses only 48 bits. Because bpf_tramp_image is allocated using\nkzalloc(), its address can use more than 48-bits, in this case the\ntrampoline will pass an invalid address to __bpf_tramp_enter/exit()\ncausing a kernel crash.\n\nFix this by using emit_a64_mov_i64() in place of emit_addr_mov_i64()\nas it can work with addresses that are greater than 48-bits.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43840', 'https://git.kernel.org/linus/19d3c179a37730caf600a97fed3794feac2b197b (6.11-rc1)', 'https://git.kernel.org/stable/c/19d3c179a37730caf600a97fed3794feac2b197b', 'https://git.kernel.org/stable/c/6d218fcc707d6b2c3616b6cd24b948fd4825cfec', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43840-69cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43840', 'https://www.cve.org/CVERecord?id=CVE-2024-43840'], 'PublishedDate': '2024-08-17T10:15:09.517Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43841', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43841', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: virt_wifi: avoid reporting connection success with wrong SSID', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: avoid reporting connection success with wrong SSID\n\nWhen user issues a connection with a different SSID than the one\nvirt_wifi has advertised, the __cfg80211_connect_result() will\ntrigger the warning: WARN_ON(bss_not_found).\n\nThe issue is because the connection code in virt_wifi does not\ncheck the SSID from user space (it only checks the BSSID), and\nvirt_wifi will call cfg80211_connect_result() with WLAN_STATUS_SUCCESS\neven if the SSID is different from the one virt_wifi has advertised.\nEventually cfg80211 won't be able to find the cfg80211_bss and generate\nthe warning.\n\nFixed it by checking the SSID (from user space) in the connection code.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43841', 'https://git.kernel.org/linus/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7 (6.11-rc1)', 'https://git.kernel.org/stable/c/05c4488a0e446c6ccde9f22b573950665e1cd414', 'https://git.kernel.org/stable/c/36e92b5edc8e0daa18e9325674313802ce3fbc29', 'https://git.kernel.org/stable/c/416d3c1538df005195721a200b0371d39636e05d', 'https://git.kernel.org/stable/c/93e898a264b4e0a475552ba9f99a016eb43ef942', 'https://git.kernel.org/stable/c/994fc2164a03200c3bf42fb45b3d49d9d6d33a4d', 'https://git.kernel.org/stable/c/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7', 'https://git.kernel.org/stable/c/d3cc85a10abc8eae48988336cdd3689ab92581b3', 'https://linux.oracle.com/cve/CVE-2024-43841.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43841-8143@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43841', 'https://www.cve.org/CVERecord?id=CVE-2024-43841'], 'PublishedDate': '2024-08-17T10:15:09.58Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43842', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43842', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()\n\nIn rtw89_sta_info_get_iter() \'status->he_gi\' is compared to array size.\nBut then \'rate->he_gi\' is used as array index instead of \'status->he_gi\'.\nThis can lead to go beyond array boundaries in case of \'rate->he_gi\' is\nnot equal to \'status->he_gi\' and is bigger than array size. Looks like\n"copy-paste" mistake.\n\nFix this mistake by replacing \'rate->he_gi\' with \'status->he_gi\'.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-129'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43842', 'https://git.kernel.org/linus/85099c7ce4f9e64c66aa397cd9a37473637ab891 (6.11-rc1)', 'https://git.kernel.org/stable/c/7a0edc3d83aff3a48813d78c9cad9daf38decc74', 'https://git.kernel.org/stable/c/85099c7ce4f9e64c66aa397cd9a37473637ab891', 'https://git.kernel.org/stable/c/96ae4de5bc4c8ba39fd072369398f59495b73f58', 'https://git.kernel.org/stable/c/a2a095c08b95372d6d0c5819b77f071af5e75366', 'https://lore.kernel.org/linux-cve-announce/2024081730-CVE-2024-43842-31e7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43842', 'https://www.cve.org/CVERecord?id=CVE-2024-43842'], 'PublishedDate': '2024-08-17T10:15:09.647Z', 'LastModifiedDate': '2024-09-30T13:55:17.007Z'}, {'VulnerabilityID': 'CVE-2024-43843', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43843', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv, bpf: Fix out-of-bounds issue when preparing trampoline image', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix out-of-bounds issue when preparing trampoline image\n\nWe get the size of the trampoline image during the dry run phase and\nallocate memory based on that size. The allocated image will then be\npopulated with instructions during the real patch phase. But after\ncommit 26ef208c209a ("bpf: Use arch_bpf_trampoline_size"), the `im`\nargument is inconsistent in the dry run and real patch phase. This may\ncause emit_imm in RV64 to generate a different number of instructions\nwhen generating the \'im\' address, potentially causing out-of-bounds\nissues. Let\'s emit the maximum number of instructions for the "im"\naddress during dry run to fix this problem.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43843', 'https://git.kernel.org/linus/9f1e16fb1fc9826001c69e0551d51fbbcd2d74e9 (6.11-rc1)', 'https://git.kernel.org/stable/c/3e6a1b1b179abb643ec3560c02bc3082bc92285f', 'https://git.kernel.org/stable/c/9f1e16fb1fc9826001c69e0551d51fbbcd2d74e9', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43843-e436@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43843', 'https://www.cve.org/CVERecord?id=CVE-2024-43843'], 'PublishedDate': '2024-08-17T10:15:09.707Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43844', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43844', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi rtw89 wow: fix GTK offload H2C skbuff issue', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: wow: fix GTK offload H2C skbuff issue\n\nWe mistakenly put skb too large and that may exceed skb->end.\nTherefore, we fix it.\n\nskbuff: skb_over_panic: text:ffffffffc09e9a9d len:416 put:204 head:ffff8fba04eca780 data:ffff8fba04eca7e0 tail:0x200 end:0x140 dev:\n------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:192!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 4747 Comm: kworker/u4:44 Tainted: G O 6.6.30-02659-gc18865c4dfbd #1 86547039b47e46935493f615ee31d0b2d711d35e\nHardware name: HP Meep/Meep, BIOS Google_Meep.11297.262.0 03/18/2021\nWorkqueue: events_unbound async_run_entry_fn\nRIP: 0010:skb_panic+0x5d/0x60\nCode: c6 63 8b 8f bb 4c 0f 45 f6 48 c7 c7 4d 89 8b bb 48 89 ce 44 89 d1 41 56 53 41 53 ff b0 c8 00 00 00 e8 27 5f 23 00 48 83 c4 20 <0f> 0b 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44\nRSP: 0018:ffffaa700144bad0 EFLAGS: 00010282\nRAX: 0000000000000089 RBX: 0000000000000140 RCX: 14432c5aad26c900\nRDX: 0000000000000000 RSI: 00000000ffffdfff RDI: 0000000000000001\nRBP: ffffaa700144bae0 R08: 0000000000000000 R09: ffffaa700144b920\nR10: 00000000ffffdfff R11: ffffffffbc28fbc0 R12: ffff8fba4e57a010\nR13: 0000000000000000 R14: ffffffffbb8f8b63 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff8fba7bd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007999c4ad1000 CR3: 000000015503a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? __die_body+0x1f/0x70\n ? die+0x3d/0x60\n ? do_trap+0xa4/0x110\n ? skb_panic+0x5d/0x60\n ? do_error_trap+0x6d/0x90\n ? skb_panic+0x5d/0x60\n ? handle_invalid_op+0x30/0x40\n ? skb_panic+0x5d/0x60\n ? exc_invalid_op+0x3c/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_panic+0x5d/0x60\n skb_put+0x49/0x50\n rtw89_fw_h2c_wow_gtk_ofld+0xbd/0x220 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_wow_resume+0x31f/0x540 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_ops_resume+0x2b/0xa0 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n ieee80211_reconfig+0x84/0x13e0 [mac80211 818a894e3b77da6298269c59ed7cdff065a4ed52]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? dev_printk_emit+0x51/0x70\n ? _dev_info+0x6e/0x90\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n wiphy_resume+0x89/0x180 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n dpm_run_callback+0x3c/0x140\n device_resume+0x1f9/0x3c0\n ? __pfx_dpm_watchdog_handler+0x10/0x10\n async_resume+0x1d/0x30\n async_run_entry_fn+0x29/0xd0\n process_scheduled_works+0x1d8/0x3d0\n worker_thread+0x1fc/0x2f0\n kthread+0xed/0x110\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x38/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \nModules linked in: ccm 8021q r8153_ecm cdc_ether usbnet r8152 mii dm_integrity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmalloc uinput rfcomm cmac algif_hash rtw89_8922ae(O) algif_skcipher rtw89_8922a(O) af_alg rtw89_pci(O) rtw89_core(O) btusb(O) snd_soc_sst_bxt_da7219_max98357a btbcm(O) snd_soc_hdac_hdmi btintel(O) snd_soc_intel_hda_dsp_common snd_sof_probes btrtl(O) btmtk(O) snd_hda_codec_hdmi snd_soc_dmic uvcvideo videobuf2_vmalloc uvc videobuf2_memops videobuf2_v4l2 videobuf2_common snd_sof_pci_intel_apl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda soundwire_intel soundwire_generic_allocation snd_sof_intel_hda_mlink soundwire_cadence snd_sof_pci snd_sof_xtensa_dsp mac80211 snd_soc_acpi_intel_match snd_soc_acpi snd_sof snd_sof_utils soundwire_bus snd_soc_max98357a snd_soc_avs snd_soc_hda_codec snd_hda_ext_core snd_intel_dspcfg snd_intel_sdw_acpi snd_soc_da7219 snd_hda_codec snd_hwdep snd_hda_core veth ip6table_nat xt_MASQUERADE xt_cgroup fuse bluetooth ecdh_generic\n cfg80211 ecc\ngsmi: Log Shutdown \n---truncated---', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43844', 'https://git.kernel.org/linus/dda364c345913fe03ddbe4d5ae14a2754c100296 (6.11-rc1)', 'https://git.kernel.org/stable/c/dda364c345913fe03ddbe4d5ae14a2754c100296', 'https://git.kernel.org/stable/c/ef0d9d2f0dc1133db3d3a1c5167190c6627146b2', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43844-97ea@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43844', 'https://www.cve.org/CVERecord?id=CVE-2024-43844'], 'PublishedDate': '2024-08-17T10:15:09.763Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43845', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43845', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: udf: Fix bogus checksum computation in udf_rename()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix bogus checksum computation in udf_rename()\n\nSyzbot reports uninitialized memory access in udf_rename() when updating\nchecksum of '..' directory entry of a moved directory. This is indeed\ntrue as we pass on-stack diriter.fi to the udf_update_tag() and because\nthat has only struct fileIdentDesc included in it and not the impUse or\nname fields, the checksumming function is going to checksum random stack\ncontents beyond the end of the structure. This is actually harmless\nbecause the following udf_fiiter_write_fi() will recompute the checksum\nfrom on-disk buffers where everything is properly included. So all that\nis needed is just removing the bogus calculation.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 3.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43845', 'https://git.kernel.org/linus/27ab33854873e6fb958cb074681a0107cc2ecc4c (6.11-rc1)', 'https://git.kernel.org/stable/c/27ab33854873e6fb958cb074681a0107cc2ecc4c', 'https://git.kernel.org/stable/c/40d7b3ed52449d36143bab8d3e70926aa61a60f4', 'https://git.kernel.org/stable/c/c996b570305e7a6910c2ce4cdcd4c22757ffe241', 'https://git.kernel.org/stable/c/fe2ead240c31e8d158713beca9d0681a6e6a53ab', 'https://lore.kernel.org/linux-cve-announce/2024081731-CVE-2024-43845-a85d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43845', 'https://www.cve.org/CVERecord?id=CVE-2024-43845'], 'PublishedDate': '2024-08-17T10:15:09.837Z', 'LastModifiedDate': '2024-08-29T17:15:08.397Z'}, {'VulnerabilityID': 'CVE-2024-43846', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43846', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: lib: objagg: Fix general protection fault', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlib: objagg: Fix general protection fault\n\nThe library supports aggregation of objects into other objects only if\nthe parent object does not have a parent itself. That is, nesting is not\nsupported.\n\nAggregation happens in two cases: Without and with hints, where hints\nare a pre-computed recommendation on how to aggregate the provided\nobjects.\n\nNesting is not possible in the first case due to a check that prevents\nit, but in the second case there is no check because the assumption is\nthat nesting cannot happen when creating objects based on hints. The\nviolation of this assumption leads to various warnings and eventually to\na general protection fault [1].\n\nBefore fixing the root cause, error out when nesting happens and warn.\n\n[1]\ngeneral protection fault, probably for non-canonical address 0xdead000000000d90: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 1083 Comm: kworker/1:9 Tainted: G W 6.9.0-rc6-custom-gd9b4f1cca7fb #7\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:mlxsw_sp_acl_erp_bf_insert+0x25/0x80\n[...]\nCall Trace:\n \n mlxsw_sp_acl_atcam_entry_add+0x256/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370\n worker_thread+0x2cb/0x3e0\n kthread+0xd0/0x100\n ret_from_fork+0x34/0x50\n ret_from_fork_asm+0x1a/0x30\n ', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43846', 'https://git.kernel.org/linus/b4a3a89fffcdf09702b1f161b914e52abca1894d (6.11-rc1)', 'https://git.kernel.org/stable/c/1936fa05a180834c3b52e0439a6bddc07814d3eb', 'https://git.kernel.org/stable/c/22ae17a267f4812861f0c644186c3421ff97dbfc', 'https://git.kernel.org/stable/c/499f742fed42e74f1321f4b12ca196a66a2b49fc', 'https://git.kernel.org/stable/c/565213e005557eb6cc4e42189d26eb300e02f170', 'https://git.kernel.org/stable/c/5adc61d29bbb461d7f7c2b48dceaa90ecd182eb7', 'https://git.kernel.org/stable/c/8161263362154cbebfbf4808097b956a6a8cb98a', 'https://git.kernel.org/stable/c/b4a3a89fffcdf09702b1f161b914e52abca1894d', 'https://linux.oracle.com/cve/CVE-2024-43846.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43846-2bd0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43846', 'https://www.cve.org/CVERecord?id=CVE-2024-43846'], 'PublishedDate': '2024-08-17T10:15:09.9Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43847', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43847', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: fix invalid memory access while processing fragmented packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix invalid memory access while processing fragmented packets\n\nThe monitor ring and the reo reinject ring share the same ring mask index.\nWhen the driver receives an interrupt for the reo reinject ring, the\nmonitor ring is also processed, leading to invalid memory access. Since\nmonitor support is not yet enabled in ath12k, the ring mask for the monitor\nring should be removed.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 2.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43847', 'https://git.kernel.org/linus/073f9f249eecd64ab9d59c91c4a23cfdcc02afe4 (6.11-rc1)', 'https://git.kernel.org/stable/c/073f9f249eecd64ab9d59c91c4a23cfdcc02afe4', 'https://git.kernel.org/stable/c/36fc66a7d9ca3e5c6eac25362cac63f83df8bed6', 'https://git.kernel.org/stable/c/8126f82dab7bd8b2e04799342b19fff0a1fd8575', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43847-6828@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43847', 'https://www.cve.org/CVERecord?id=CVE-2024-43847'], 'PublishedDate': '2024-08-17T10:15:09.963Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43849', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43849', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: pdr: protect locator_addr with the main mutex', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: pdr: protect locator_addr with the main mutex\n\nIf the service locator server is restarted fast enough, the PDR can\nrewrite locator_addr fields concurrently. Protect them by placing\nmodification of those fields under the main pdr->lock.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43849', 'https://git.kernel.org/linus/107924c14e3ddd85119ca43c26a4ee1056fa9b84 (6.11-rc1)', 'https://git.kernel.org/stable/c/107924c14e3ddd85119ca43c26a4ee1056fa9b84', 'https://git.kernel.org/stable/c/3e815626d73e05152a8142f6e44aecc4133e6e08', 'https://git.kernel.org/stable/c/475a77fb3f0e1d527f56c60b79f5879661df5b80', 'https://git.kernel.org/stable/c/8543269567e2fb3d976a8255c5e348aed14f98bc', 'https://git.kernel.org/stable/c/d0870c4847e77a49c2f91bb2a8e0fa3c1f8dea5c', 'https://git.kernel.org/stable/c/eab05737ee22216250fe20d27f5a596da5ea6eb7', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43849-fef0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43849', 'https://www.cve.org/CVERecord?id=CVE-2024-43849'], 'PublishedDate': '2024-08-17T10:15:10.093Z', 'LastModifiedDate': '2024-08-19T12:59:59.177Z'}, {'VulnerabilityID': 'CVE-2024-43850', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43850', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: soc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove\n\nThe following warning is seen during bwmon_remove due to refcount\nimbalance, fix this by releasing the OPPs after use.\n\nLogs:\nWARNING: at drivers/opp/core.c:1640 _opp_table_kref_release+0x150/0x158\nHardware name: Qualcomm Technologies, Inc. X1E80100 CRD (DT)\n...\nCall trace:\n_opp_table_kref_release+0x150/0x158\ndev_pm_opp_remove_table+0x100/0x1b4\ndevm_pm_opp_of_table_release+0x10/0x1c\ndevm_action_release+0x14/0x20\ndevres_release_all+0xa4/0x104\ndevice_unbind_cleanup+0x18/0x60\ndevice_release_driver_internal+0x1ec/0x228\ndriver_detach+0x50/0x98\nbus_remove_driver+0x6c/0xbc\ndriver_unregister+0x30/0x60\nplatform_driver_unregister+0x14/0x20\nbwmon_driver_exit+0x18/0x524 [icc_bwmon]\n__arm64_sys_delete_module+0x184/0x264\ninvoke_syscall+0x48/0x118\nel0_svc_common.constprop.0+0xc8/0xe8\ndo_el0_svc+0x20/0x2c\nel0_svc+0x34/0xdc\nel0t_64_sync_handler+0x13c/0x158\nel0t_64_sync+0x190/0x194\n--[ end trace 0000000000000000 ]---', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43850', 'https://git.kernel.org/linus/24086640ab39396eb1a92d1cb1cd2f31b2677c52 (6.11-rc1)', 'https://git.kernel.org/stable/c/24086640ab39396eb1a92d1cb1cd2f31b2677c52', 'https://git.kernel.org/stable/c/4100d4d019f8e140be1d4d3a9d8d93c1285f5d1c', 'https://git.kernel.org/stable/c/aad41f4c169bcb800ae88123799bdf8cdec3d366', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43850-4eec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43850', 'https://www.cve.org/CVERecord?id=CVE-2024-43850'], 'PublishedDate': '2024-08-17T10:15:10.157Z', 'LastModifiedDate': '2024-09-30T13:57:33.4Z'}, {'VulnerabilityID': 'CVE-2024-43852', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43852', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: hwmon: (ltc2991) re-order conditions to fix off by one bug', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ltc2991) re-order conditions to fix off by one bug\n\nLTC2991_T_INT_CH_NR is 4. The st->temp_en[] array has LTC2991_MAX_CHANNEL\n(4) elements. Thus if "channel" is equal to LTC2991_T_INT_CH_NR then we\nhave read one element beyond the end of the array. Flip the conditions\naround so that we check if "channel" is valid before using it as an array\nindex.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-193'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43852', 'https://git.kernel.org/linus/99bf7c2eccff82760fa23ce967cc67c8c219c6a6 (6.11-rc1)', 'https://git.kernel.org/stable/c/99bf7c2eccff82760fa23ce967cc67c8c219c6a6', 'https://git.kernel.org/stable/c/c180311c0a520692e2d0e9ca44dcd6c2ff1b41c4', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43852-61e2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43852', 'https://www.cve.org/CVERecord?id=CVE-2024-43852'], 'PublishedDate': '2024-08-17T10:15:10.31Z', 'LastModifiedDate': '2024-08-20T19:32:55.747Z'}, {'VulnerabilityID': 'CVE-2024-43853', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43853', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: cgroup/cpuset: Prevent UAF in proc_cpuset_show()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: Prevent UAF in proc_cpuset_show()\n\nAn UAF can happen when /proc/cpuset is read as reported in [1].\n\nThis can be reproduced by the following methods:\n1.add an mdelay(1000) before acquiring the cgroup_lock In the\n cgroup_path_ns function.\n2.$cat /proc//cpuset repeatly.\n3.$mount -t cgroup -o cpuset cpuset /sys/fs/cgroup/cpuset/\n$umount /sys/fs/cgroup/cpuset/ repeatly.\n\nThe race that cause this bug can be shown as below:\n\n(umount)\t\t|\t(cat /proc//cpuset)\ncss_release\t\t|\tproc_cpuset_show\ncss_release_work_fn\t|\tcss = task_get_css(tsk, cpuset_cgrp_id);\ncss_free_rwork_fn\t|\tcgroup_path_ns(css->cgroup, ...);\ncgroup_destroy_root\t|\tmutex_lock(&cgroup_mutex);\nrebind_subsystems\t|\ncgroup_free_root \t|\n\t\t\t|\t// cgrp was freed, UAF\n\t\t\t|\tcgroup_path_ns_locked(cgrp,..);\n\nWhen the cpuset is initialized, the root node top_cpuset.css.cgrp\nwill point to &cgrp_dfl_root.cgrp. In cgroup v1, the mount operation will\nallocate cgroup_root, and top_cpuset.css.cgrp will point to the allocated\n&cgroup_root.cgrp. When the umount operation is executed,\ntop_cpuset.css.cgrp will be rebound to &cgrp_dfl_root.cgrp.\n\nThe problem is that when rebinding to cgrp_dfl_root, there are cases\nwhere the cgroup_root allocated by setting up the root for cgroup v1\nis cached. This could lead to a Use-After-Free (UAF) if it is\nsubsequently freed. The descendant cgroups of cgroup v1 can only be\nfreed after the css is released. However, the css of the root will never\nbe released, yet the cgroup_root should be freed when it is unmounted.\nThis means that obtaining a reference to the css of the root does\nnot guarantee that css.cgrp->root will not be freed.\n\nFix this problem by using rcu_read_lock in proc_cpuset_show().\nAs cgroup_root is kfree_rcu after commit d23b5c577715\n("cgroup: Make operations on the cgroup root_list RCU safe"),\ncss->cgroup won\'t be freed during the critical section.\nTo call cgroup_path_ns_locked, css_set_lock is needed, so it is safe to\nreplace task_get_css with task_css.\n\n[1] https://syzkaller.appspot.com/bug?extid=9b1ff7be974a403aa4cd', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43853', 'https://git.kernel.org/linus/1be59c97c83ccd67a519d8a49486b3a8a73ca28a (6.11-rc1)', 'https://git.kernel.org/stable/c/10aeaa47e4aa2432f29b3e5376df96d7dac5537a', 'https://git.kernel.org/stable/c/1be59c97c83ccd67a519d8a49486b3a8a73ca28a', 'https://git.kernel.org/stable/c/27d6dbdc6485d68075a0ebf8544d6425c1ed84bb', 'https://git.kernel.org/stable/c/29a8d4e02fd4840028c38ceb1536cc8f82a257d4', 'https://git.kernel.org/stable/c/29ac1d238b3bf126af36037df80d7ecc4822341e', 'https://git.kernel.org/stable/c/4e8d6ac8fc9f843e940ab7389db8136634e07989', 'https://git.kernel.org/stable/c/688325078a8b5badd6e07ae22b27cd04e9947aec', 'https://git.kernel.org/stable/c/96226fbed566f3f686f53a489a29846f2d538080', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43853-da5b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43853', 'https://www.cve.org/CVERecord?id=CVE-2024-43853'], 'PublishedDate': '2024-08-17T10:15:10.383Z', 'LastModifiedDate': '2024-09-04T12:15:04.827Z'}, {'VulnerabilityID': 'CVE-2024-43854', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43854', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: block: initialize integrity buffer to zero before writing it to media', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: initialize integrity buffer to zero before writing it to media\n\nMetadata added by bio_integrity_prep is using plain kmalloc, which leads\nto random kernel memory being written media. For PI metadata this is\nlimited to the app tag that isn't used by kernel generated metadata,\nbut for non-PI metadata the entire buffer leaks kernel memory.\n\nFix this by adding the __GFP_ZERO flag to allocations for writes.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43854', 'https://git.kernel.org/linus/899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f (6.11-rc1)', 'https://git.kernel.org/stable/c/129f95948a96105c1fad8e612c9097763e88ac5f', 'https://git.kernel.org/stable/c/23a19655fb56f241e592041156dfb1c6d04da644', 'https://git.kernel.org/stable/c/3fd11fe4f20756b4c0847f755a64cd96f8c6a005', 'https://git.kernel.org/stable/c/899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f', 'https://git.kernel.org/stable/c/9f4af4cf08f9a0329ade3d938f55d2220c40d0a6', 'https://git.kernel.org/stable/c/cf6b45ea7a8df0f61bded1dc4a8561ac6ad143d2', 'https://git.kernel.org/stable/c/d418313bd8f55c079a7da12651951b489a638ac1', 'https://git.kernel.org/stable/c/ebc0e91ba76dc6544fff9f5b66408b1982806a00', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43854-5586@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43854', 'https://www.cve.org/CVERecord?id=CVE-2024-43854'], 'PublishedDate': '2024-08-17T10:15:10.447Z', 'LastModifiedDate': '2024-09-12T12:15:49.423Z'}, {'VulnerabilityID': 'CVE-2024-43856', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43856', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: dma: fix call order in dmam_free_coherent', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndma: fix call order in dmam_free_coherent\n\ndmam_free_coherent() frees a DMA allocation, which makes the\nfreed vaddr available for reuse, then calls devres_destroy()\nto remove and free the data structure used to track the DMA\nallocation. Between the two calls, it is possible for a\nconcurrent task to make an allocation with the same vaddr\nand add it to the devres list.\n\nIf this happens, there will be two entries in the devres list\nwith the same vaddr and devres_destroy() can free the wrong\nentry, triggering the WARN_ON() in dmam_match.\n\nFix by destroying the devres entry before freeing the DMA\nallocation.\n\n kokonut //net/encryption\n http://sponge2/b9145fe6-0f72-4325-ac2f-a84d81075b03', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-770'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43856', 'https://git.kernel.org/linus/28e8b7406d3a1f5329a03aa25a43aa28e087cb20 (6.11-rc1)', 'https://git.kernel.org/stable/c/1fe97f68fce1ba24bf823bfb0eb0956003473130', 'https://git.kernel.org/stable/c/22094f5f52e7bc16c5bf9613365049383650b02e', 'https://git.kernel.org/stable/c/257193083e8f43907e99ea633820fc2b3bcd24c7', 'https://git.kernel.org/stable/c/28e8b7406d3a1f5329a03aa25a43aa28e087cb20', 'https://git.kernel.org/stable/c/2f7bbdc744f2e7051d1cb47c8e082162df1923c9', 'https://git.kernel.org/stable/c/87b34c8c94e29fa01d744e5147697f592998d954', 'https://git.kernel.org/stable/c/f993a4baf6b622232e4c190d34c220179e5d61eb', 'https://git.kernel.org/stable/c/fe2d246080f035e0af5793cb79067ba125e4fb63', 'https://linux.oracle.com/cve/CVE-2024-43856.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081732-CVE-2024-43856-9087@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43856', 'https://www.cve.org/CVERecord?id=CVE-2024-43856'], 'PublishedDate': '2024-08-17T10:15:10.613Z', 'LastModifiedDate': '2024-08-22T17:57:08.64Z'}, {'VulnerabilityID': 'CVE-2024-43857', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43857', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix null reference error when checking end of zone', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix null reference error when checking end of zone\n\nThis patch fixes a potentially null pointer being accessed by\nis_end_zone_blkaddr() that checks the last block of a zone\nwhen f2fs is mounted as a single device.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43857', 'https://git.kernel.org/linus/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38 (6.11-rc1)', 'https://git.kernel.org/stable/c/381cbe85592c78fbaeb3e770e3e9f3bfa3e67efb', 'https://git.kernel.org/stable/c/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43857-b71b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43857', 'https://www.cve.org/CVERecord?id=CVE-2024-43857'], 'PublishedDate': '2024-08-17T10:15:10.687Z', 'LastModifiedDate': '2024-08-22T17:38:21.003Z'}, {'VulnerabilityID': 'CVE-2024-43859', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43859', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to truncate preallocated blocks in f2fs_file_open()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to truncate preallocated blocks in f2fs_file_open()\n\nchenyuwen reports a f2fs bug as below:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000011\n fscrypt_set_bio_crypt_ctx+0x78/0x1e8\n f2fs_grab_read_bio+0x78/0x208\n f2fs_submit_page_read+0x44/0x154\n f2fs_get_read_data_page+0x288/0x5f4\n f2fs_get_lock_data_page+0x60/0x190\n truncate_partial_data_page+0x108/0x4fc\n f2fs_do_truncate_blocks+0x344/0x5f0\n f2fs_truncate_blocks+0x6c/0x134\n f2fs_truncate+0xd8/0x200\n f2fs_iget+0x20c/0x5ac\n do_garbage_collect+0x5d0/0xf6c\n f2fs_gc+0x22c/0x6a4\n f2fs_disable_checkpoint+0xc8/0x310\n f2fs_fill_super+0x14bc/0x1764\n mount_bdev+0x1b4/0x21c\n f2fs_mount+0x20/0x30\n legacy_get_tree+0x50/0xbc\n vfs_get_tree+0x5c/0x1b0\n do_new_mount+0x298/0x4cc\n path_mount+0x33c/0x5fc\n __arm64_sys_mount+0xcc/0x15c\n invoke_syscall+0x60/0x150\n el0_svc_common+0xb8/0xf8\n do_el0_svc+0x28/0xa0\n el0_svc+0x24/0x84\n el0t_64_sync_handler+0x88/0xec\n\nIt is because inode.i_crypt_info is not initialized during below path:\n- mount\n - f2fs_fill_super\n - f2fs_disable_checkpoint\n - f2fs_gc\n - f2fs_iget\n - f2fs_truncate\n\nSo, let's relocate truncation of preallocated blocks to f2fs_file_open(),\nafter fscrypt_file_open().", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43859', 'https://git.kernel.org/linus/298b1e4182d657c3e388adcc29477904e9600ed5 (6.11-rc1)', 'https://git.kernel.org/stable/c/298b1e4182d657c3e388adcc29477904e9600ed5', 'https://git.kernel.org/stable/c/3ba0ae885215b325605ff7ebf6de12ac2adf204d', 'https://git.kernel.org/stable/c/5f04969136db674f133781626e0b692c5f2bf2f0', 'https://git.kernel.org/stable/c/f44a25a8bfe0c15d33244539696cd9119cf44d18', 'https://lore.kernel.org/linux-cve-announce/2024081733-CVE-2024-43859-62b4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43859', 'https://www.cve.org/CVERecord?id=CVE-2024-43859'], 'PublishedDate': '2024-08-17T10:15:10.817Z', 'LastModifiedDate': '2024-09-08T08:15:12.96Z'}, {'VulnerabilityID': 'CVE-2024-43860', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43860', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: remoteproc: imx_rproc: Skip over memory region when node value is NULL', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: imx_rproc: Skip over memory region when node value is NULL\n\nIn imx_rproc_addr_init() "nph = of_count_phandle_with_args()" just counts\nnumber of phandles. But phandles may be empty. So of_parse_phandle() in\nthe parsing loop (0 < a < nph) may return NULL which is later dereferenced.\nAdjust this issue by adding NULL-return check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[Fixed title to fit within the prescribed 70-75 charcters]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43860', 'https://git.kernel.org/linus/2fa26ca8b786888673689ccc9da6094150939982 (6.11-rc1)', 'https://git.kernel.org/stable/c/2fa26ca8b786888673689ccc9da6094150939982', 'https://git.kernel.org/stable/c/4e13b7c23988c0a13fdca92e94296a3bc2ff9f21', 'https://git.kernel.org/stable/c/6884fd0283e0831be153fb8d82d9eda8a55acaaa', 'https://git.kernel.org/stable/c/6b50462b473fdccdc0dfad73001147e40ff19a66', 'https://git.kernel.org/stable/c/6c9ea3547fad252fe9ae5d3ed7e066e2085bf3a2', 'https://git.kernel.org/stable/c/84beb7738459cac0ff9f8a7c4654b8ff82a702c0', 'https://git.kernel.org/stable/c/9a17cf8b2ce483fa75258bc2cdcf628f24bcf5f8', 'https://git.kernel.org/stable/c/c877a5f5268d4ab8224b9c9fbce3d746e4e72bc9', 'https://linux.oracle.com/cve/CVE-2024-43860.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024081734-CVE-2024-43860-d72f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43860', 'https://www.cve.org/CVERecord?id=CVE-2024-43860'], 'PublishedDate': '2024-08-17T10:15:10.887Z', 'LastModifiedDate': '2024-08-22T17:08:15.097Z'}, {'VulnerabilityID': 'CVE-2024-43861', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43861', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: usb: qmi_wwan: fix memory leak for not ip packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: qmi_wwan: fix memory leak for not ip packets\n\nFree the unused skb when not ip packets arrive.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43861', 'https://git.kernel.org/linus/7ab107544b777c3bd7feb9fe447367d8edd5b202 (6.11-rc3)', 'https://git.kernel.org/stable/c/37c093449704017870604994ba9b813cdb9475a4', 'https://git.kernel.org/stable/c/3c90a69533b5bba73401ef884d033ea49ee99662', 'https://git.kernel.org/stable/c/7ab107544b777c3bd7feb9fe447367d8edd5b202', 'https://git.kernel.org/stable/c/c4251a3deccad852b27e60625f31fba6cc14372f', 'https://git.kernel.org/stable/c/c6c5b91424fafc0f83852d961c10c7e43a001882', 'https://git.kernel.org/stable/c/da518cc9b64df391795d9952aed551e0f782e446', 'https://git.kernel.org/stable/c/e87f52225e04a7001bf55bbd7a330fa4252327b5', 'https://git.kernel.org/stable/c/f2c353227de14b0289298ffc3ba92058c4768384', 'https://linux.oracle.com/cve/CVE-2024-43861.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43861-1958@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43861', 'https://www.cve.org/CVERecord?id=CVE-2024-43861'], 'PublishedDate': '2024-08-20T22:15:04.917Z', 'LastModifiedDate': '2024-09-03T13:45:12.667Z'}, {'VulnerabilityID': 'CVE-2024-43863', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43863', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/vmwgfx: Fix a deadlock in dma buf fence polling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix a deadlock in dma buf fence polling\n\nIntroduce a version of the fence ops that on release doesn't remove\nthe fence from the pending list, and thus doesn't require a lock to\nfix poll->fence wait->fence unref deadlocks.\n\nvmwgfx overwrites the wait callback to iterate over the list of all\nfences and update their status, to do that it holds a lock to prevent\nthe list modifcations from other threads. The fence destroy callback\nboth deletes the fence and removes it from the list of pending\nfences, for which it holds a lock.\n\ndma buf polling cb unrefs a fence after it's been signaled: so the poll\ncalls the wait, which signals the fences, which are being destroyed.\nThe destruction tries to acquire the lock on the pending fences list\nwhich it can never get because it's held by the wait from which it\nwas called.\n\nOld bug, but not a lot of userspace apps were using dma-buf polling\ninterfaces. Fix those, in particular this fixes KDE stalls/deadlock.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43863', 'https://git.kernel.org/linus/e58337100721f3cc0c7424a18730e4f39844934f (6.11-rc2)', 'https://git.kernel.org/stable/c/3b933b16c996af8adb6bc1b5748a63dfb41a82bc', 'https://git.kernel.org/stable/c/9e20d028d8d1deb1e7fed18f22ffc01669cf3237', 'https://git.kernel.org/stable/c/a8943969f9ead2fd3044fc826140a21622ef830e', 'https://git.kernel.org/stable/c/c98ab18b9f315ff977c2c65d7c71298ef98be8e3', 'https://git.kernel.org/stable/c/e58337100721f3cc0c7424a18730e4f39844934f', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43863-9124@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43863', 'https://www.cve.org/CVERecord?id=CVE-2024-43863'], 'PublishedDate': '2024-08-21T00:15:04.847Z', 'LastModifiedDate': '2024-09-03T13:42:44.727Z'}, {'VulnerabilityID': 'CVE-2024-43864', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43864', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5e: Fix CT entry update leaks of modify header context', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix CT entry update leaks of modify header context\n\nThe cited commit allocates a new modify header to replace the old\none when updating CT entry. But if failed to allocate a new one, eg.\nexceed the max number firmware can support, modify header will be\nan error pointer that will trigger a panic when deallocating it. And\nthe old modify header point is copied to old attr. When the old\nattr is freed, the old modify header is lost.\n\nFix it by restoring the old attr to attr when failed to allocate a\nnew modify header context. So when the CT entry is freed, the right\nmodify header context will be freed. And the panic of accessing\nerror pointer is also fixed.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43864', 'https://git.kernel.org/linus/025f2b85a5e5a46df14ecf162c3c80a957a36d0b (6.11-rc2)', 'https://git.kernel.org/stable/c/025f2b85a5e5a46df14ecf162c3c80a957a36d0b', 'https://git.kernel.org/stable/c/89064d09c56b44c668509bf793c410484f63f5ad', 'https://git.kernel.org/stable/c/daab2cc17b6b6ab158566bba037e9551fd432b59', 'https://lore.kernel.org/linux-cve-announce/2024082156-CVE-2024-43864-81ad@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43864', 'https://www.cve.org/CVERecord?id=CVE-2024-43864'], 'PublishedDate': '2024-08-21T00:15:04.91Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43866', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43866', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/mlx5: Always drain health in shutdown callback', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Always drain health in shutdown callback\n\nThere is no point in recovery during device shutdown. if health\nwork started need to wait for it to avoid races and NULL pointer\naccess.\n\nHence, drain health WQ on shutdown callback.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43866', 'https://git.kernel.org/linus/1b75da22ed1e6171e261bc9265370162553d5393 (6.11-rc2)', 'https://git.kernel.org/stable/c/1b75da22ed1e6171e261bc9265370162553d5393', 'https://git.kernel.org/stable/c/5005e2e159b300c1b8c6820a1e13a62eb0127b9b', 'https://git.kernel.org/stable/c/6048dec754554a1303d632be6042d3feb3295285', 'https://git.kernel.org/stable/c/6b6c2ebd83f2bf97e8f221479372aaca97a4a9b2', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43866-66ed@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43866', 'https://www.cve.org/CVERecord?id=CVE-2024-43866'], 'PublishedDate': '2024-08-21T00:15:05.023Z', 'LastModifiedDate': '2024-10-17T14:15:07.297Z'}, {'VulnerabilityID': 'CVE-2024-43867', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43867', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/nouveau: prime: fix refcount underflow', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: prime: fix refcount underflow\n\nCalling nouveau_bo_ref() on a nouveau_bo without initializing it (and\nhence the backing ttm_bo) leads to a refcount underflow.\n\nInstead of calling nouveau_bo_ref() in the unwind path of\ndrm_gem_object_init(), clean things up manually.\n\n(cherry picked from commit 1b93f3e89d03cfc576636e195466a0d728ad8de5)', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43867', 'https://git.kernel.org/linus/a9bf3efc33f1fbf88787a277f7349459283c9b95 (6.11-rc2)', 'https://git.kernel.org/stable/c/16998763c62bb465ebc409d0373b9cdcef1a61a6', 'https://git.kernel.org/stable/c/2a1b327d57a8ac080977633a18999f032d7e9e3f', 'https://git.kernel.org/stable/c/3bcb8bba72ce89667fa863054956267c450c47ef', 'https://git.kernel.org/stable/c/906372e753c5027a1dc88743843b6aa2ad1aaecf', 'https://git.kernel.org/stable/c/a9bf3efc33f1fbf88787a277f7349459283c9b95', 'https://git.kernel.org/stable/c/ebebba4d357b6c67f96776a48ddbaf0060fa4c10', 'https://git.kernel.org/stable/c/f23cd66933fe76b84d8e282e5606b4d99068c320', 'https://linux.oracle.com/cve/CVE-2024-43867.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43867-0620@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43867', 'https://www.cve.org/CVERecord?id=CVE-2024-43867'], 'PublishedDate': '2024-08-21T00:15:05.087Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43868', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43868', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: riscv/purgatory: align riscv_kernel_entry', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/purgatory: align riscv_kernel_entry\n\nWhen alignment handling is delegated to the kernel, everything must be\nword-aligned in purgatory, since the trap handler is then set to the\nkexec one. Without the alignment, hitting the exception would\nultimately crash. On other occasions, the kernel's handler would take\ncare of exceptions.\nThis has been tested on a JH7110 SoC with oreboot and its SBI delegating\nunaligned access exceptions and the kernel configured to handle them.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43868', 'https://git.kernel.org/linus/fb197c5d2fd24b9af3d4697d0cf778645846d6d5 (6.11-rc2)', 'https://git.kernel.org/stable/c/5d4aaf16a8255f7c71790e211724ba029609c5ff', 'https://git.kernel.org/stable/c/fb197c5d2fd24b9af3d4697d0cf778645846d6d5', 'https://lore.kernel.org/linux-cve-announce/2024082157-CVE-2024-43868-9a44@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43868', 'https://www.cve.org/CVERecord?id=CVE-2024-43868'], 'PublishedDate': '2024-08-21T00:15:05.15Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43869', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43869', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf: Fix event leak upon exec and file release', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix event leak upon exec and file release\n\nThe perf pending task work is never waited upon the matching event\nrelease. In the case of a child event, released via free_event()\ndirectly, this can potentially result in a leaked event, such as in the\nfollowing scenario that doesn't even require a weak IRQ work\nimplementation to trigger:\n\nschedule()\n prepare_task_switch()\n=======> \n perf_event_overflow()\n event->pending_sigtrap = ...\n irq_work_queue(&event->pending_irq)\n<======= \n perf_event_task_sched_out()\n event_sched_out()\n event->pending_sigtrap = 0;\n atomic_long_inc_not_zero(&event->refcount)\n task_work_add(&event->pending_task)\n finish_lock_switch()\n=======> \n perf_pending_irq()\n //do nothing, rely on pending task work\n<======= \n\nbegin_new_exec()\n perf_event_exit_task()\n perf_event_exit_event()\n // If is child event\n free_event()\n WARN(atomic_long_cmpxchg(&event->refcount, 1, 0) != 1)\n // event is leaked\n\nSimilar scenarios can also happen with perf_event_remove_on_exec() or\nsimply against concurrent perf_event_release().\n\nFix this with synchonizing against the possibly remaining pending task\nwork while freeing the event, just like is done with remaining pending\nIRQ work. This means that the pending task callback neither need nor\nshould hold a reference to the event, preventing it from ever beeing\nfreed.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43869', 'https://git.kernel.org/linus/3a5465418f5fd970e86a86c7f4075be262682840 (6.11-rc1)', 'https://git.kernel.org/stable/c/104e258a004037bc7dba9f6085c71dad6af57ad4', 'https://git.kernel.org/stable/c/3a5465418f5fd970e86a86c7f4075be262682840', 'https://git.kernel.org/stable/c/9ad46f1fef421d43cdab3a7d1744b2f43b54dae0', 'https://git.kernel.org/stable/c/ed2c202dac55423a52d7e2290f2888bf08b8ee99', 'https://git.kernel.org/stable/c/f34d8307a73a18de5320fcc6f40403146d061891', 'https://lore.kernel.org/linux-cve-announce/2024082133-CVE-2024-43869-26aa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43869', 'https://www.cve.org/CVERecord?id=CVE-2024-43869'], 'PublishedDate': '2024-08-21T01:15:11.55Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43870', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43870', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: perf: Fix event leak upon exit', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix event leak upon exit\n\nWhen a task is scheduled out, pending sigtrap deliveries are deferred\nto the target task upon resume to userspace via task_work.\n\nHowever failures while adding an event's callback to the task_work\nengine are ignored. And since the last call for events exit happen\nafter task work is eventually closed, there is a small window during\nwhich pending sigtrap can be queued though ignored, leaking the event\nrefcount addition such as in the following scenario:\n\n TASK A\n -----\n\n do_exit()\n exit_task_work(tsk);\n\n \n perf_event_overflow()\n event->pending_sigtrap = pending_id;\n irq_work_queue(&event->pending_irq);\n \n =========> PREEMPTION: TASK A -> TASK B\n event_sched_out()\n event->pending_sigtrap = 0;\n atomic_long_inc_not_zero(&event->refcount)\n // FAILS: task work has exited\n task_work_add(&event->pending_task)\n [...]\n \n perf_pending_irq()\n // early return: event->oncpu = -1\n \n [...]\n =========> TASK B -> TASK A\n perf_event_exit_task(tsk)\n perf_event_exit_event()\n free_event()\n WARN(atomic_long_cmpxchg(&event->refcount, 1, 0) != 1)\n // leak event due to unexpected refcount == 2\n\nAs a result the event is never released while the task exits.\n\nFix this with appropriate task_work_add()'s error handling.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43870', 'https://git.kernel.org/linus/2fd5ad3f310de22836cdacae919dd99d758a1f1b (6.11-rc1)', 'https://git.kernel.org/stable/c/05d3fd599594abf79aad4484bccb2b26e1cb0b51', 'https://git.kernel.org/stable/c/2fd5ad3f310de22836cdacae919dd99d758a1f1b', 'https://git.kernel.org/stable/c/3d7a63352a93bdb8a1cdf29606bf617d3ac1c22a', 'https://git.kernel.org/stable/c/67fad724f1b568b356c1065d50df46e6b30eb2f7', 'https://git.kernel.org/stable/c/70882d7fa74f0731492a0d493e8515a4f7131831', 'https://lore.kernel.org/linux-cve-announce/2024082135-CVE-2024-43870-2b6f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43870', 'https://www.cve.org/CVERecord?id=CVE-2024-43870'], 'PublishedDate': '2024-08-21T01:15:11.62Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43871', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43871', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: devres: Fix memory leakage caused by driver API devm_free_percpu()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndevres: Fix memory leakage caused by driver API devm_free_percpu()\n\nIt will cause memory leakage when use driver API devm_free_percpu()\nto free memory allocated by devm_alloc_percpu(), fixed by using\ndevres_release() instead of devres_destroy() within devm_free_percpu().', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/errata/RHSA-2024:7001', 'https://access.redhat.com/security/cve/CVE-2024-43871', 'https://bugzilla.redhat.com/2258012', 'https://bugzilla.redhat.com/2258013', 'https://bugzilla.redhat.com/2260038', 'https://bugzilla.redhat.com/2265799', 'https://bugzilla.redhat.com/2266358', 'https://bugzilla.redhat.com/2266750', 'https://bugzilla.redhat.com/2267036', 'https://bugzilla.redhat.com/2267041', 'https://bugzilla.redhat.com/2267795', 'https://bugzilla.redhat.com/2267916', 'https://bugzilla.redhat.com/2267925', 'https://bugzilla.redhat.com/2268295', 'https://bugzilla.redhat.com/2271648', 'https://bugzilla.redhat.com/2271796', 'https://bugzilla.redhat.com/2272793', 'https://bugzilla.redhat.com/2273141', 'https://bugzilla.redhat.com/2273148', 'https://bugzilla.redhat.com/2273180', 'https://bugzilla.redhat.com/2275661', 'https://bugzilla.redhat.com/2275690', 'https://bugzilla.redhat.com/2275742', 'https://bugzilla.redhat.com/2277171', 'https://bugzilla.redhat.com/2278220', 'https://bugzilla.redhat.com/2278270', 'https://bugzilla.redhat.com/2278447', 'https://bugzilla.redhat.com/2281217', 'https://bugzilla.redhat.com/2281317', 'https://bugzilla.redhat.com/2281704', 'https://bugzilla.redhat.com/2281720', 'https://bugzilla.redhat.com/2281807', 'https://bugzilla.redhat.com/2281847', 'https://bugzilla.redhat.com/2282324', 'https://bugzilla.redhat.com/2282345', 'https://bugzilla.redhat.com/2282354', 'https://bugzilla.redhat.com/2282355', 'https://bugzilla.redhat.com/2282356', 'https://bugzilla.redhat.com/2282357', 'https://bugzilla.redhat.com/2282366', 'https://bugzilla.redhat.com/2282401', 'https://bugzilla.redhat.com/2282422', 'https://bugzilla.redhat.com/2282440', 'https://bugzilla.redhat.com/2282508', 'https://bugzilla.redhat.com/2282511', 'https://bugzilla.redhat.com/2282676', 'https://bugzilla.redhat.com/2282757', 'https://bugzilla.redhat.com/2282851', 'https://bugzilla.redhat.com/2282890', 'https://bugzilla.redhat.com/2282903', 'https://bugzilla.redhat.com/2282918', 'https://bugzilla.redhat.com/2283389', 'https://bugzilla.redhat.com/2283424', 'https://bugzilla.redhat.com/2284271', 'https://bugzilla.redhat.com/2284515', 'https://bugzilla.redhat.com/2284545', 'https://bugzilla.redhat.com/2284596', 'https://bugzilla.redhat.com/2284628', 'https://bugzilla.redhat.com/2284634', 'https://bugzilla.redhat.com/2293247', 'https://bugzilla.redhat.com/2293270', 'https://bugzilla.redhat.com/2293273', 'https://bugzilla.redhat.com/2293304', 'https://bugzilla.redhat.com/2293377', 'https://bugzilla.redhat.com/2293408', 'https://bugzilla.redhat.com/2293423', 'https://bugzilla.redhat.com/2293440', 'https://bugzilla.redhat.com/2293441', 'https://bugzilla.redhat.com/2293658', 'https://bugzilla.redhat.com/2294313', 'https://bugzilla.redhat.com/2297471', 'https://bugzilla.redhat.com/2297473', 'https://bugzilla.redhat.com/2297478', 'https://bugzilla.redhat.com/2297488', 'https://bugzilla.redhat.com/2297495', 'https://bugzilla.redhat.com/2297496', 'https://bugzilla.redhat.com/2297513', 'https://bugzilla.redhat.com/2297515', 'https://bugzilla.redhat.com/2297525', 'https://bugzilla.redhat.com/2297538', 'https://bugzilla.redhat.com/2297542', 'https://bugzilla.redhat.com/2297543', 'https://bugzilla.redhat.com/2297544', 'https://bugzilla.redhat.com/2297556', 'https://bugzilla.redhat.com/2297561', 'https://bugzilla.redhat.com/2297562', 'https://bugzilla.redhat.com/2297572', 'https://bugzilla.redhat.com/2297573', 'https://bugzilla.redhat.com/2297579', 'https://bugzilla.redhat.com/2297581', 'https://bugzilla.redhat.com/2297582', 'https://bugzilla.redhat.com/2297589', 'https://bugzilla.redhat.com/2297706', 'https://bugzilla.redhat.com/2297909', 'https://bugzilla.redhat.com/2298079', 'https://bugzilla.redhat.com/2298140', 'https://bugzilla.redhat.com/2298177', 'https://bugzilla.redhat.com/2298640', 'https://bugzilla.redhat.com/2299240', 'https://bugzilla.redhat.com/2299336', 'https://bugzilla.redhat.com/2299452', 'https://bugzilla.redhat.com/2300296', 'https://bugzilla.redhat.com/2300297', 'https://bugzilla.redhat.com/2300402', 'https://bugzilla.redhat.com/2300407', 'https://bugzilla.redhat.com/2300408', 'https://bugzilla.redhat.com/2300409', 'https://bugzilla.redhat.com/2300410', 'https://bugzilla.redhat.com/2300414', 'https://bugzilla.redhat.com/2300429', 'https://bugzilla.redhat.com/2300430', 'https://bugzilla.redhat.com/2300434', 'https://bugzilla.redhat.com/2300448', 'https://bugzilla.redhat.com/2300453', 'https://bugzilla.redhat.com/2300492', 'https://bugzilla.redhat.com/2300533', 'https://bugzilla.redhat.com/2300552', 'https://bugzilla.redhat.com/2300713', 'https://bugzilla.redhat.com/2301477', 'https://bugzilla.redhat.com/2301489', 'https://bugzilla.redhat.com/2301496', 'https://bugzilla.redhat.com/2301519', 'https://bugzilla.redhat.com/2301522', 'https://bugzilla.redhat.com/2301544', 'https://bugzilla.redhat.com/2303077', 'https://bugzilla.redhat.com/2303505', 'https://bugzilla.redhat.com/2303506', 'https://bugzilla.redhat.com/2303508', 'https://bugzilla.redhat.com/2303514', 'https://bugzilla.redhat.com/2305467', 'https://bugzilla.redhat.com/2306365', 'https://errata.almalinux.org/8/ALSA-2024-7001.html', 'https://git.kernel.org/linus/bd50a974097bb82d52a458bd3ee39fb723129a0c (6.11-rc1)', 'https://git.kernel.org/stable/c/3047f99caec240a88ccd06197af2868da1af6a96', 'https://git.kernel.org/stable/c/3dcd0673e47664bc6c719ad47dadac6d55d5950d', 'https://git.kernel.org/stable/c/700e8abd65b10792b2f179ce4e858f2ca2880f85', 'https://git.kernel.org/stable/c/95065edb8ebb27771d5f1e898eef6ab43dc6c87c', 'https://git.kernel.org/stable/c/b044588a16a978cd891cb3d665dd7ae06850d5bf', 'https://git.kernel.org/stable/c/b67552d7c61f52f1271031adfa7834545ae99701', 'https://git.kernel.org/stable/c/bd50a974097bb82d52a458bd3ee39fb723129a0c', 'https://git.kernel.org/stable/c/ef56dcdca8f2a53abc3a83d388b8336447533d85', 'https://linux.oracle.com/cve/CVE-2024-43871.html', 'https://linux.oracle.com/errata/ELSA-2024-7000.html', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43871-c2cd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43871', 'https://www.cve.org/CVERecord?id=CVE-2024-43871'], 'PublishedDate': '2024-08-21T01:15:11.68Z', 'LastModifiedDate': '2024-09-03T13:39:19.553Z'}, {'VulnerabilityID': 'CVE-2024-43872', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43872', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: RDMA/hns: Fix soft lockup under heavy CEQE load', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix soft lockup under heavy CEQE load\n\nCEQEs are handled in interrupt handler currently. This may cause the\nCPU core staying in interrupt context too long and lead to soft lockup\nunder heavy load.\n\nHandle CEQEs in BH workqueue and set an upper limit for the number of\nCEQE handled by a single call of work handler.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43872', 'https://git.kernel.org/linus/2fdf34038369c0a27811e7b4680662a14ada1d6b (6.11-rc1)', 'https://git.kernel.org/stable/c/06580b33c183c9f98e2a2ca96a86137179032c08', 'https://git.kernel.org/stable/c/2fdf34038369c0a27811e7b4680662a14ada1d6b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43872-c87e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43872', 'https://www.cve.org/CVERecord?id=CVE-2024-43872'], 'PublishedDate': '2024-08-21T01:15:11.74Z', 'LastModifiedDate': '2024-09-03T13:38:34.867Z'}, {'VulnerabilityID': 'CVE-2024-43873', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43873', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: vhost/vsock: always initialize seqpacket_allow', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/vsock: always initialize seqpacket_allow\n\nThere are two issues around seqpacket_allow:\n1. seqpacket_allow is not initialized when socket is\n created. Thus if features are never set, it will be\n read uninitialized.\n2. if VIRTIO_VSOCK_F_SEQPACKET is set and then cleared,\n then seqpacket_allow will not be cleared appropriately\n (existing apps I know about don't usually do this but\n it's legal and there's no way to be sure no one relies\n on this).\n\nTo fix:\n\t- initialize seqpacket_allow after allocation\n\t- set it unconditionally in set_features", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-909'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43873', 'https://git.kernel.org/linus/1e1fdcbdde3b7663e5d8faeb2245b9b151417d22 (6.11-rc1)', 'https://git.kernel.org/stable/c/1e1fdcbdde3b7663e5d8faeb2245b9b151417d22', 'https://git.kernel.org/stable/c/3062cb100787a9ddf45de30004b962035cd497fb', 'https://git.kernel.org/stable/c/30bd4593669443ac58515e23557dc8cef70d8582', 'https://git.kernel.org/stable/c/ea558f10fb05a6503c6e655a1b7d81fdf8e5924c', 'https://git.kernel.org/stable/c/eab96e8716cbfc2834b54f71cc9501ad4eec963b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43873-c547@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43873', 'https://www.cve.org/CVERecord?id=CVE-2024-43873'], 'PublishedDate': '2024-08-21T01:15:11.79Z', 'LastModifiedDate': '2024-09-03T13:35:44.897Z'}, {'VulnerabilityID': 'CVE-2024-43875', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43875', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: endpoint: Clean up error handling in vpci_scan_bus()', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: Clean up error handling in vpci_scan_bus()\n\nSmatch complains about inconsistent NULL checking in vpci_scan_bus():\n\n drivers/pci/endpoint/functions/pci-epf-vntb.c:1024 vpci_scan_bus() error: we previously assumed 'vpci_bus' could be null (see line 1021)\n\nInstead of printing an error message and then crashing we should return\nan error code and clean up.\n\nAlso the NULL check is reversed so it prints an error for success\ninstead of failure.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43875', 'https://git.kernel.org/linus/8e0f5a96c534f781e8c57ca30459448b3bfe5429 (6.11-rc1)', 'https://git.kernel.org/stable/c/0e27e2e8697b8ce96cdef43f135426525d9d1f8f', 'https://git.kernel.org/stable/c/24414c842a24d0fd498f9db6d2a762a8dddf1832', 'https://git.kernel.org/stable/c/7d368de78b60088ec9031c60c88976c0063ea4c0', 'https://git.kernel.org/stable/c/8e0f5a96c534f781e8c57ca30459448b3bfe5429', 'https://git.kernel.org/stable/c/b9e8695246bcfc028341470cbf92630cdc1ba36b', 'https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43875-1257@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43875', 'https://www.cve.org/CVERecord?id=CVE-2024-43875'], 'PublishedDate': '2024-08-21T01:15:11.91Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43876', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43876', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: PCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()\n\nAvoid large backtrace, it is sufficient to warn the user that there has\nbeen a link problem. Either the link has failed and the system is in need\nof maintenance, or the link continues to work and user has been informed.\nThe message from the warning can be looked up in the sources.\n\nThis makes an actual link issue less verbose.\n\nFirst of all, this controller has a limitation in that the controller\ndriver has to assist the hardware with transition to L1 link state by\nwriting L1IATN to PMCTRL register, the L1 and L0 link state switching\nis not fully automatic on this controller.\n\nIn case of an ASMedia ASM1062 PCIe SATA controller which does not support\nASPM, on entry to suspend or during platform pm_test, the SATA controller\nenters D3hot state and the link enters L1 state. If the SATA controller\nwakes up before rcar_pcie_wakeup() was called and returns to D0, the link\nreturns to L0 before the controller driver even started its transition to\nL1 link state. At this point, the SATA controller did send an PM_ENTER_L1\nDLLP to the PCIe controller and the PCIe controller received it, and the\nPCIe controller did set PMSR PMEL1RX bit.\n\nOnce rcar_pcie_wakeup() is called, if the link is already back in L0 state\nand PMEL1RX bit is set, the controller driver has no way to determine if\nit should perform the link transition to L1 state, or treat the link as if\nit is in L0 state. Currently the driver attempts to perform the transition\nto L1 link state unconditionally, which in this specific case fails with a\nPMSR L1FAEG poll timeout, however the link still works as it is already\nback in L0 state.\n\nReduce this warning verbosity. In case the link is really broken, the\nrcar_pcie_config_access() would fail, otherwise it will succeed and any\nsystem with this controller and ASM1062 can suspend without generating\na backtrace.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'V3Score': 2.3}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43876', 'https://git.kernel.org/linus/c93637e6a4c4e1d0e85ef7efac78d066bbb24d96 (6.11-rc1)', 'https://git.kernel.org/stable/c/2ae4769332dfdb97f4b6f5dc9ac8f46d02aaa3df', 'https://git.kernel.org/stable/c/3ff3bdde950f1840df4030726cef156758a244d7', 'https://git.kernel.org/stable/c/526a877c6273d4cd0d0aede84c1d620479764b1c', 'https://git.kernel.org/stable/c/c93637e6a4c4e1d0e85ef7efac78d066bbb24d96', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43876-793b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43876', 'https://www.cve.org/CVERecord?id=CVE-2024-43876'], 'PublishedDate': '2024-08-21T01:15:11.973Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43877', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43877', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: pci: ivtv: Add check for DMA map result', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: ivtv: Add check for DMA map result\n\nIn case DMA fails, 'dma->SG_length' is 0. This value is later used to\naccess 'dma->SGarray[dma->SG_length - 1]', which will cause out of\nbounds access.\n\nAdd check to return early on invalid value. Adjust warnings accordingly.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43877', 'https://git.kernel.org/linus/629913d6d79508b166c66e07e4857e20233d85a9 (6.11-rc1)', 'https://git.kernel.org/stable/c/24062aa7407091dee3e45a8e8037df437e848718', 'https://git.kernel.org/stable/c/3d8fd92939e21ff0d45100ab208f8124af79402a', 'https://git.kernel.org/stable/c/629913d6d79508b166c66e07e4857e20233d85a9', 'https://git.kernel.org/stable/c/c766065e8272085ea9c436414b7ddf1f12e7787b', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43877-e8e4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43877', 'https://www.cve.org/CVERecord?id=CVE-2024-43877'], 'PublishedDate': '2024-08-21T01:15:12.033Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43879', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43879', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()\n\nCurrently NL80211_RATE_INFO_HE_RU_ALLOC_2x996 is not handled in\ncfg80211_calculate_bitrate_he(), leading to below warning:\n\nkernel: invalid HE MCS: bw:6, ru:6\nkernel: WARNING: CPU: 0 PID: 2312 at net/wireless/util.c:1501 cfg80211_calculate_bitrate_he+0x22b/0x270 [cfg80211]\n\nFix it by handling 2x996 RU allocation in the same way as 160 MHz bandwidth.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43879', 'https://git.kernel.org/linus/bcbd771cd5d68c0c52567556097d75f9fc4e7cd6 (6.11-rc1)', 'https://git.kernel.org/stable/c/16ad67e73309db0c20cc2a651992bd01c05e6b27', 'https://git.kernel.org/stable/c/19eaf4f2f5a981f55a265242ada2bf92b0c742dd', 'https://git.kernel.org/stable/c/2e201b3d162c6c49417c438ffb30b58c9f85769f', 'https://git.kernel.org/stable/c/45d20a1c54be4f3173862c7b950d4468447814c9', 'https://git.kernel.org/stable/c/576c64622649f3ec07e97bac8fec8b8a2ef4d086', 'https://git.kernel.org/stable/c/67b5f1054197e4f5553047759c15c1d67d4c8142', 'https://git.kernel.org/stable/c/b289ebb0516526cb4abae081b7ec29fd4fa1209d', 'https://git.kernel.org/stable/c/bcbd771cd5d68c0c52567556097d75f9fc4e7cd6', 'https://linux.oracle.com/cve/CVE-2024-43879.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43879-95cb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43879', 'https://www.cve.org/CVERecord?id=CVE-2024-43879'], 'PublishedDate': '2024-08-21T01:15:12.153Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43880', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43880', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mlxsw: spectrum_acl_erp: Fix object nesting warning', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_erp: Fix object nesting warning\n\nACLs in Spectrum-2 and newer ASICs can reside in the algorithmic TCAM\n(A-TCAM) or in the ordinary circuit TCAM (C-TCAM). The former can\ncontain more ACLs (i.e., tc filters), but the number of masks in each\nregion (i.e., tc chain) is limited.\n\nIn order to mitigate the effects of the above limitation, the device\nallows filters to share a single mask if their masks only differ in up\nto 8 consecutive bits. For example, dst_ip/25 can be represented using\ndst_ip/24 with a delta of 1 bit. The C-TCAM does not have a limit on the\nnumber of masks being used (and therefore does not support mask\naggregation), but can contain a limited number of filters.\n\nThe driver uses the "objagg" library to perform the mask aggregation by\npassing it objects that consist of the filter\'s mask and whether the\nfilter is to be inserted into the A-TCAM or the C-TCAM since filters in\ndifferent TCAMs cannot share a mask.\n\nThe set of created objects is dependent on the insertion order of the\nfilters and is not necessarily optimal. Therefore, the driver will\nperiodically ask the library to compute a more optimal set ("hints") by\nlooking at all the existing objects.\n\nWhen the library asks the driver whether two objects can be aggregated\nthe driver only compares the provided masks and ignores the A-TCAM /\nC-TCAM indication. This is the right thing to do since the goal is to\nmove as many filters as possible to the A-TCAM. The driver also forbids\ntwo identical masks from being aggregated since this can only happen if\none was intentionally put in the C-TCAM to avoid a conflict in the\nA-TCAM.\n\nThe above can result in the following set of hints:\n\nH1: {mask X, A-TCAM} -> H2: {mask Y, A-TCAM} // X is Y + delta\nH3: {mask Y, C-TCAM} -> H4: {mask Z, A-TCAM} // Y is Z + delta\n\nAfter getting the hints from the library the driver will start migrating\nfilters from one region to another while consulting the computed hints\nand instructing the device to perform a lookup in both regions during\nthe transition.\n\nAssuming a filter with mask X is being migrated into the A-TCAM in the\nnew region, the hints lookup will return H1. Since H2 is the parent of\nH1, the library will try to find the object associated with it and\ncreate it if necessary in which case another hints lookup (recursive)\nwill be performed. This hints lookup for {mask Y, A-TCAM} will either\nreturn H2 or H3 since the driver passes the library an object comparison\nfunction that ignores the A-TCAM / C-TCAM indication.\n\nThis can eventually lead to nested objects which are not supported by\nthe library [1].\n\nFix by removing the object comparison function from both the driver and\nthe library as the driver was the only user. That way the lookup will\nonly return exact matches.\n\nI do not have a reliable reproducer that can reproduce the issue in a\ntimely manner, but before the fix the issue would reproduce in several\nminutes and with the fix it does not reproduce in over an hour.\n\nNote that the current usefulness of the hints is limited because they\ninclude the C-TCAM indication and represent aggregation that cannot\nactually happen. This will be addressed in net-next.\n\n[1]\nWARNING: CPU: 0 PID: 153 at lib/objagg.c:170 objagg_obj_parent_assign+0xb5/0xd0\nModules linked in:\nCPU: 0 PID: 153 Comm: kworker/0:18 Not tainted 6.9.0-rc6-custom-g70fbc2c1c38b #42\nHardware name: Mellanox Technologies Ltd. MSN3700C/VMOD0008, BIOS 5.11 10/10/2018\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:objagg_obj_parent_assign+0xb5/0xd0\n[...]\nCall Trace:\n \n __objagg_obj_get+0x2bb/0x580\n objagg_obj_get+0xe/0x80\n mlxsw_sp_acl_erp_mask_get+0xb5/0xf0\n mlxsw_sp_acl_atcam_entry_add+0xe8/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43880', 'https://git.kernel.org/linus/97d833ceb27dc19f8777d63f90be4a27b5daeedf (6.11-rc1)', 'https://git.kernel.org/stable/c/0e59c2d22853266704e127915653598f7f104037', 'https://git.kernel.org/stable/c/25c6fd9648ad05da493a5d30881896a78a08b624', 'https://git.kernel.org/stable/c/36a9996e020dd5aa325e0ecc55eb2328288ea6bb', 'https://git.kernel.org/stable/c/4dc09f6f260db3c4565a4ec52ba369393598f2fb', 'https://git.kernel.org/stable/c/97d833ceb27dc19f8777d63f90be4a27b5daeedf', 'https://git.kernel.org/stable/c/9a5261a984bba4f583d966c550fa72c33ff3714e', 'https://git.kernel.org/stable/c/fb5d4fc578e655d113f09565f6f047e15f7ab578', 'https://linux.oracle.com/cve/CVE-2024-43880.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082137-CVE-2024-43880-78ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43880', 'https://www.cve.org/CVERecord?id=CVE-2024-43880'], 'PublishedDate': '2024-08-21T01:15:12.213Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43881', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43881', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: ath12k: change DMA direction while mapping reinjected packets', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: change DMA direction while mapping reinjected packets\n\nFor fragmented packets, ath12k reassembles each fragment as a normal\npacket and then reinjects it into HW ring. In this case, the DMA\ndirection should be DMA_TO_DEVICE, not DMA_FROM_DEVICE. Otherwise,\nan invalid payload may be reinjected into the HW and\nsubsequently delivered to the host.\n\nGiven that arbitrary memory can be allocated to the skb buffer,\nknowledge about the data contained in the reinjected buffer is lacking.\nConsequently, there’s a risk of private information being leaked.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'V3Score': 6.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43881', 'https://git.kernel.org/linus/33322e3ef07409278a18c6919c448e369d66a18e (6.11-rc1)', 'https://git.kernel.org/stable/c/33322e3ef07409278a18c6919c448e369d66a18e', 'https://git.kernel.org/stable/c/6925320fcd40d8042d32bf4ede8248e7a5315c3b', 'https://git.kernel.org/stable/c/e99d9b16ff153de9540073239d24adc3b0a3a997', 'https://lore.kernel.org/linux-cve-announce/2024082138-CVE-2024-43881-ead4@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43881', 'https://www.cve.org/CVERecord?id=CVE-2024-43881'], 'PublishedDate': '2024-08-21T01:15:12.28Z', 'LastModifiedDate': '2024-08-21T12:30:33.697Z'}, {'VulnerabilityID': 'CVE-2024-43883', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43883', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: usb: vhci-hcd: Do not drop references before new references are gained', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: vhci-hcd: Do not drop references before new references are gained\n\nAt a few places the driver carries stale pointers\nto references that can still be used. Make sure that does not happen.\nThis strictly speaking closes ZDI-CAN-22273, though there may be\nsimilar races in the driver.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43883', 'https://git.kernel.org/stable/c/128e82e41cf7d74a562726c1587d9d2ede1a0a37', 'https://git.kernel.org/stable/c/4dacdb9720aaab10b6be121eae55820174d97174', 'https://git.kernel.org/stable/c/585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14', 'https://git.kernel.org/stable/c/5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89', 'https://git.kernel.org/stable/c/9c3746ce8d8fcb3a2405644fc0eec7fc5312de80', 'https://git.kernel.org/stable/c/afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a', 'https://git.kernel.org/stable/c/c3d0857b7fc2c49f68f89128a5440176089a8f54', 'https://git.kernel.org/stable/c/e8c1e606dab8c56cf074b43b98d0805de7322ba2', 'https://linux.oracle.com/cve/CVE-2024-43883.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082313-CVE-2024-43883-a594@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43883', 'https://www.cve.org/CVERecord?id=CVE-2024-43883'], 'PublishedDate': '2024-08-23T13:15:03.873Z', 'LastModifiedDate': '2024-08-23T16:18:28.547Z'}, {'VulnerabilityID': 'CVE-2024-43884', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43884', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: Bluetooth: MGMT: Add error handling to pair_device()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Add error handling to pair_device()\n\nhci_conn_params_add() never checks for a NULL value and could lead to a NULL\npointer dereference causing a crash.\n\nFixed by adding error handling in the function.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43884', 'https://git.kernel.org/linus/538fd3921afac97158d4177139a0ad39f056dbb2 (6.11-rc5)', 'https://git.kernel.org/stable/c/064dd929c76532359d2905d90a7c12348043cfd4', 'https://git.kernel.org/stable/c/11b4b0e63f2621b33b2e107407a7d67a65994ca1', 'https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2', 'https://git.kernel.org/stable/c/5da2884292329bc9be32a7778e0e119f06abe503', 'https://git.kernel.org/stable/c/90e1ff1c15e5a8f3023ca8266e3a85869ed03ee9', 'https://git.kernel.org/stable/c/951d6cb5eaac5130d076c728f2a6db420621afdb', 'https://git.kernel.org/stable/c/9df9783bd85610d3d6e126a1aca221531f6f6dcb', 'https://git.kernel.org/stable/c/ee0799103b1ae4bcfd80dc11a15df085f6ee1b61', 'https://lore.kernel.org/linux-cve-announce/2024082621-CVE-2024-43884-43fa@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43884', 'https://www.cve.org/CVERecord?id=CVE-2024-43884'], 'PublishedDate': '2024-08-26T08:15:03.827Z', 'LastModifiedDate': '2024-09-04T12:15:04.927Z'}, {'VulnerabilityID': 'CVE-2024-43886', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43886', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null check in resource_log_pipe_topology_update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check in resource_log_pipe_topology_update\n\n[WHY]\nWhen switching from "Extend" to "Second Display Only" we sometimes\ncall resource_get_otg_master_for_stream on a stream for the eDP,\nwhich is disconnected. This leads to a null pointer dereference.\n\n[HOW]\nAdded a null check in dc_resource.c/resource_log_pipe_topology_update.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43886', 'https://git.kernel.org/linus/899d92fd26fe780aad711322aa671f68058207a6 (6.11-rc1)', 'https://git.kernel.org/stable/c/899d92fd26fe780aad711322aa671f68058207a6', 'https://git.kernel.org/stable/c/c36e922a36bdf69765c340a0857ca74092003bee', 'https://lore.kernel.org/linux-cve-announce/2024082657-CVE-2024-43886-0726@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43886', 'https://www.cve.org/CVERecord?id=CVE-2024-43886'], 'PublishedDate': '2024-08-26T11:15:03.83Z', 'LastModifiedDate': '2024-08-27T14:37:45.377Z'}, {'VulnerabilityID': 'CVE-2024-43887', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43887', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net/tcp: Disable TCP-AO static key after RCU grace period', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp: Disable TCP-AO static key after RCU grace period\n\nThe lifetime of TCP-AO static_key is the same as the last\ntcp_ao_info. On the socket destruction tcp_ao_info ceases to be\nwith RCU grace period, while tcp-ao static branch is currently deferred\ndestructed. The static key definition is\n: DEFINE_STATIC_KEY_DEFERRED_FALSE(tcp_ao_needed, HZ);\n\nwhich means that if RCU grace period is delayed by more than a second\nand tcp_ao_needed is in the process of disablement, other CPUs may\nyet see tcp_ao_info which atent dead, but soon-to-be.\nAnd that breaks the assumption of static_key_fast_inc_not_disabled().\n\nSee the comment near the definition:\n> * The caller must make sure that the static key can\'t get disabled while\n> * in this function. It doesn\'t patch jump labels, only adds a user to\n> * an already enabled static key.\n\nOriginally it was introduced in commit eb8c507296f6 ("jump_label:\nPrevent key->enabled int overflow"), which is needed for the atomic\ncontexts, one of which would be the creation of a full socket from a\nrequest socket. In that atomic context, it\'s known by the presence\nof the key (md5/ao) that the static branch is already enabled.\nSo, the ref counter for that static branch is just incremented\ninstead of holding the proper mutex.\nstatic_key_fast_inc_not_disabled() is just a helper for such usage\ncase. But it must not be used if the static branch could get disabled\nin parallel as it\'s not protected by jump_label_mutex and as a result,\nraces with jump_label_update() implementation details.\n\nHappened on netdev test-bot[1], so not a theoretical issue:\n\n[] jump_label: Fatal kernel bug, unexpected op at tcp_inbound_hash+0x1a7/0x870 [ffffffffa8c4e9b7] (eb 50 0f 1f 44 != 66 90 0f 1f 00)) size:2 type:1\n[] ------------[ cut here ]------------\n[] kernel BUG at arch/x86/kernel/jump_label.c:73!\n[] Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[] CPU: 3 PID: 243 Comm: kworker/3:3 Not tainted 6.10.0-virtme #1\n[] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[] Workqueue: events jump_label_update_timeout\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n...\n[] Call Trace:\n[] \n[] arch_jump_label_transform_queue+0x6c/0x110\n[] __jump_label_update+0xef/0x350\n[] __static_key_slow_dec_cpuslocked.part.0+0x3c/0x60\n[] jump_label_update_timeout+0x2c/0x40\n[] process_one_work+0xe3b/0x1670\n[] worker_thread+0x587/0xce0\n[] kthread+0x28a/0x350\n[] ret_from_fork+0x31/0x70\n[] ret_from_fork_asm+0x1a/0x30\n[] \n[] Modules linked in: veth\n[] ---[ end trace 0000000000000000 ]---\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n\n[1]: https://netdev-3.bots.linux.dev/vmksft-tcp-ao-dbg/results/696681/5-connect-deny-ipv6/stderr', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43887', 'https://git.kernel.org/linus/14ab4792ee120c022f276a7e4768f4dcb08f0cdd (6.11-rc3)', 'https://git.kernel.org/stable/c/14ab4792ee120c022f276a7e4768f4dcb08f0cdd', 'https://git.kernel.org/stable/c/954d55a59b2501f4a9bd693b40ce45a1c46cb2b3', 'https://lore.kernel.org/linux-cve-announce/2024082658-CVE-2024-43887-93bf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43887', 'https://www.cve.org/CVERecord?id=CVE-2024-43887'], 'PublishedDate': '2024-08-26T11:15:03.877Z', 'LastModifiedDate': '2024-09-05T19:43:44.197Z'}, {'VulnerabilityID': 'CVE-2024-43888', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43888', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: mm: list_lru: fix UAF for memory cgroup', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: list_lru: fix UAF for memory cgroup\n\nThe mem_cgroup_from_slab_obj() is supposed to be called under rcu lock or\ncgroup_mutex or others which could prevent returned memcg from being\nfreed. Fix it by adding missing rcu read lock.\n\nFound by code inspection.\n\n[songmuchun@bytedance.com: only grab rcu lock when necessary, per Vlastimil]\n Link: https://lkml.kernel.org/r/20240801024603.1865-1-songmuchun@bytedance.com', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43888', 'https://git.kernel.org/linus/5161b48712dcd08ec427c450399d4d1483e21dea (6.11-rc3)', 'https://git.kernel.org/stable/c/4589f77c18dd98b65f45617b6d1e95313cf6fcab', 'https://git.kernel.org/stable/c/5161b48712dcd08ec427c450399d4d1483e21dea', 'https://lore.kernel.org/linux-cve-announce/2024082659-CVE-2024-43888-5beb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43888', 'https://www.cve.org/CVERecord?id=CVE-2024-43888'], 'PublishedDate': '2024-08-26T11:15:03.93Z', 'LastModifiedDate': '2024-08-27T14:37:52.61Z'}, {'VulnerabilityID': 'CVE-2024-43889', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43889', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\npadata: Fix possible divide-by-0 panic in padata_mt_helper()\n\nWe are hit with a not easily reproducible divide-by-0 panic in padata.c at\nbootup time.\n\n [ 10.017908] Oops: divide error: 0000 1 PREEMPT SMP NOPTI\n [ 10.017908] CPU: 26 PID: 2627 Comm: kworker/u1666:1 Not tainted 6.10.0-15.el10.x86_64 #1\n [ 10.017908] Hardware name: Lenovo ThinkSystem SR950 [7X12CTO1WW]/[7X12CTO1WW], BIOS [PSE140J-2.30] 07/20/2021\n [ 10.017908] Workqueue: events_unbound padata_mt_helper\n [ 10.017908] RIP: 0010:padata_mt_helper+0x39/0xb0\n :\n [ 10.017963] Call Trace:\n [ 10.017968] \n [ 10.018004] ? padata_mt_helper+0x39/0xb0\n [ 10.018084] process_one_work+0x174/0x330\n [ 10.018093] worker_thread+0x266/0x3a0\n [ 10.018111] kthread+0xcf/0x100\n [ 10.018124] ret_from_fork+0x31/0x50\n [ 10.018138] ret_from_fork_asm+0x1a/0x30\n [ 10.018147] \n\nLooking at the padata_mt_helper() function, the only way a divide-by-0\npanic can happen is when ps->chunk_size is 0. The way that chunk_size is\ninitialized in padata_do_multithreaded(), chunk_size can be 0 when the\nmin_chunk in the passed-in padata_mt_job structure is 0.\n\nFix this divide-by-0 panic by making sure that chunk_size will be at least\n1 no matter what the input parameters are.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43889', 'https://git.kernel.org/linus/6d45e1c948a8b7ed6ceddb14319af69424db730c (6.11-rc3)', 'https://git.kernel.org/stable/c/6d45e1c948a8b7ed6ceddb14319af69424db730c', 'https://git.kernel.org/stable/c/8f5ffd2af7274853ff91d6cd62541191d9fbd10d', 'https://git.kernel.org/stable/c/924f788c906dccaca30acab86c7124371e1d6f2c', 'https://git.kernel.org/stable/c/a29cfcb848c31f22b4de6a531c3e1d68c9bfe09f', 'https://git.kernel.org/stable/c/ab8b397d5997d8c37610252528edc54bebf9f6d3', 'https://git.kernel.org/stable/c/da0ffe84fcc1627a7dff82c80b823b94236af905', 'https://lore.kernel.org/linux-cve-announce/2024082600-CVE-2024-43889-4d0b@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43889', 'https://www.cve.org/CVERecord?id=CVE-2024-43889'], 'PublishedDate': '2024-08-26T11:15:03.98Z', 'LastModifiedDate': '2024-08-27T14:38:09.34Z'}, {'VulnerabilityID': 'CVE-2024-43890', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43890', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Fix overflow in get_free_elt()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix overflow in get_free_elt()\n\n"tracing_map->next_elt" in get_free_elt() is at risk of overflowing.\n\nOnce it overflows, new elements can still be inserted into the tracing_map\neven though the maximum number of elements (`max_elts`) has been reached.\nContinuing to insert elements after the overflow could result in the\ntracing_map containing "tracing_map->max_size" elements, leaving no empty\nentries.\nIf any attempt is made to insert an element into a full tracing_map using\n`__tracing_map_insert()`, it will cause an infinite loop with preemption\ndisabled, leading to a CPU hang problem.\n\nFix this by preventing any further increments to "tracing_map->next_elt"\nonce it reaches "tracing_map->max_elt".', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-190'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43890', 'https://git.kernel.org/linus/bcf86c01ca4676316557dd482c8416ece8c2e143 (6.11-rc3)', 'https://git.kernel.org/stable/c/236bb4690773ab6869b40bedc7bc8d889e36f9d6', 'https://git.kernel.org/stable/c/302ceb625d7b990db205a15e371f9a71238de91c', 'https://git.kernel.org/stable/c/788ea62499b3c18541fd6d621964d8fafbc4aec5', 'https://git.kernel.org/stable/c/a172c7b22bc2feaf489cfc6d6865f7237134fdf8', 'https://git.kernel.org/stable/c/bcf86c01ca4676316557dd482c8416ece8c2e143', 'https://git.kernel.org/stable/c/cd10d186a5409a1fe6e976df82858e9773a698da', 'https://git.kernel.org/stable/c/d3e4dbc2858fe85d1dbd2e72a9fc5dea988b5c18', 'https://git.kernel.org/stable/c/eb223bf01e688dfe37e813c8988ee11c8c9f8d0a', 'https://linux.oracle.com/cve/CVE-2024-43890.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082601-CVE-2024-43890-1c3a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43890', 'https://www.cve.org/CVERecord?id=CVE-2024-43890'], 'PublishedDate': '2024-08-26T11:15:04.04Z', 'LastModifiedDate': '2024-09-05T18:48:30.32Z'}, {'VulnerabilityID': 'CVE-2024-43891', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43891', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracing: Have format file honor EVENT_FILE_FL_FREED', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have format file honor EVENT_FILE_FL_FREED\n\nWhen eventfs was introduced, special care had to be done to coordinate the\nfreeing of the file meta data with the files that are exposed to user\nspace. The file meta data would have a ref count that is set when the file\nis created and would be decremented and freed after the last user that\nopened the file closed it. When the file meta data was to be freed, it\nwould set a flag (EVENT_FILE_FL_FREED) to denote that the file is freed,\nand any new references made (like new opens or reads) would fail as it is\nmarked freed. This allowed other meta data to be freed after this flag was\nset (under the event_mutex).\n\nAll the files that were dynamically created in the events directory had a\npointer to the file meta data and would call event_release() when the last\nreference to the user space file was closed. This would be the time that it\nis safe to free the file meta data.\n\nA shortcut was made for the "format" file. It\'s i_private would point to\nthe "call" entry directly and not point to the file\'s meta data. This is\nbecause all format files are the same for the same "call", so it was\nthought there was no reason to differentiate them. The other files\nmaintain state (like the "enable", "trigger", etc). But this meant if the\nfile were to disappear, the "format" file would be unaware of it.\n\nThis caused a race that could be trigger via the user_events test (that\nwould create dynamic events and free them), and running a loop that would\nread the user_events format files:\n\nIn one console run:\n\n # cd tools/testing/selftests/user_events\n # while true; do ./ftrace_test; done\n\nAnd in another console run:\n\n # cd /sys/kernel/tracing/\n # while true; do cat events/user_events/__test_event/format; done 2>/dev/null\n\nWith KASAN memory checking, it would trigger a use-after-free bug report\n(which was a real bug). This was because the format file was not checking\nthe file\'s meta data flag "EVENT_FILE_FL_FREED", so it would access the\nevent that the file meta data pointed to after the event was freed.\n\nAfter inspection, there are other locations that were found to not check\nthe EVENT_FILE_FL_FREED flag when accessing the trace_event_file. Add a\nnew helper function: event_file_file() that will make sure that the\nevent_mutex is held, and will return NULL if the trace_event_file has the\nEVENT_FILE_FL_FREED flag set. Have the first reference of the struct file\npointer use event_file_file() and check for NULL. Later uses can still use\nthe event_file_data() helper function if the event_mutex is still held and\nwas not released since the event_file_file() call.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43891', 'https://git.kernel.org/linus/b1560408692cd0ab0370cfbe9deb03ce97ab3f6d (6.11-rc3)', 'https://git.kernel.org/stable/c/4ed03758ddf0b19d69eed69386d65a92d0091e0c', 'https://git.kernel.org/stable/c/531dc6780d94245af037c25c2371c8caf652f0f9', 'https://git.kernel.org/stable/c/b1560408692cd0ab0370cfbe9deb03ce97ab3f6d', 'https://lore.kernel.org/linux-cve-announce/2024082603-CVE-2024-43891-a69d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43891', 'https://www.cve.org/CVERecord?id=CVE-2024-43891'], 'PublishedDate': '2024-08-26T11:15:04.103Z', 'LastModifiedDate': '2024-09-05T18:46:18.44Z'}, {'VulnerabilityID': 'CVE-2024-43892', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43892', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: memcg: protect concurrent access to mem_cgroup_idr', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: protect concurrent access to mem_cgroup_idr\n\nCommit 73f576c04b94 ("mm: memcontrol: fix cgroup creation failure after\nmany small jobs") decoupled the memcg IDs from the CSS ID space to fix the\ncgroup creation failures. It introduced IDR to maintain the memcg ID\nspace. The IDR depends on external synchronization mechanisms for\nmodifications. For the mem_cgroup_idr, the idr_alloc() and idr_replace()\nhappen within css callback and thus are protected through cgroup_mutex\nfrom concurrent modifications. However idr_remove() for mem_cgroup_idr\nwas not protected against concurrency and can be run concurrently for\ndifferent memcgs when they hit their refcnt to zero. Fix that.\n\nWe have been seeing list_lru based kernel crashes at a low frequency in\nour fleet for a long time. These crashes were in different part of\nlist_lru code including list_lru_add(), list_lru_del() and reparenting\ncode. Upon further inspection, it looked like for a given object (dentry\nand inode), the super_block\'s list_lru didn\'t have list_lru_one for the\nmemcg of that object. The initial suspicions were either the object is\nnot allocated through kmem_cache_alloc_lru() or somehow\nmemcg_list_lru_alloc() failed to allocate list_lru_one() for a memcg but\nreturned success. No evidence were found for these cases.\n\nLooking more deeply, we started seeing situations where valid memcg\'s id\nis not present in mem_cgroup_idr and in some cases multiple valid memcgs\nhave same id and mem_cgroup_idr is pointing to one of them. So, the most\nreasonable explanation is that these situations can happen due to race\nbetween multiple idr_remove() calls or race between\nidr_alloc()/idr_replace() and idr_remove(). These races are causing\nmultiple memcgs to acquire the same ID and then offlining of one of them\nwould cleanup list_lrus on the system for all of them. Later access from\nother memcgs to the list_lru cause crashes due to missing list_lru_one.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43892', 'https://git.kernel.org/linus/9972605a238339b85bd16b084eed5f18414d22db (6.11-rc3)', 'https://git.kernel.org/stable/c/37a060b64ae83b76600d187d76591ce488ab836b', 'https://git.kernel.org/stable/c/51c0b1bb7541f8893ec1accba59eb04361a70946', 'https://git.kernel.org/stable/c/56fd70f4aa8b82199dbe7e99366b1fd7a04d86fb', 'https://git.kernel.org/stable/c/912736a0435ef40e6a4ae78197ccb5553cb80b05', 'https://git.kernel.org/stable/c/9972605a238339b85bd16b084eed5f18414d22db', 'https://git.kernel.org/stable/c/e6cc9ff2ac0b5df9f25eb790934c3104f6710278', 'https://lore.kernel.org/linux-cve-announce/2024082604-CVE-2024-43892-584a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43892', 'https://www.cve.org/CVERecord?id=CVE-2024-43892'], 'PublishedDate': '2024-08-26T11:15:04.157Z', 'LastModifiedDate': '2024-09-12T12:15:49.593Z'}, {'VulnerabilityID': 'CVE-2024-43893', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43893', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: core: check uartclk for zero to avoid divide by zero', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: check uartclk for zero to avoid divide by zero\n\nCalling ioctl TIOCSSERIAL with an invalid baud_base can\nresult in uartclk being zero, which will result in a\ndivide by zero error in uart_get_divisor(). The check for\nuartclk being zero in uart_set_info() needs to be done\nbefore other settings are made as subsequent calls to\nioctl TIOCSSERIAL for the same port would be impacted if\nthe uartclk check was done where uartclk gets set.\n\nOops: divide error: 0000 PREEMPT SMP KASAN PTI\nRIP: 0010:uart_get_divisor (drivers/tty/serial/serial_core.c:580)\nCall Trace:\n \nserial8250_get_divisor (drivers/tty/serial/8250/8250_port.c:2576\n drivers/tty/serial/8250/8250_port.c:2589)\nserial8250_do_set_termios (drivers/tty/serial/8250/8250_port.c:502\n drivers/tty/serial/8250/8250_port.c:2741)\nserial8250_set_termios (drivers/tty/serial/8250/8250_port.c:2862)\nuart_change_line_settings (./include/linux/spinlock.h:376\n ./include/linux/serial_core.h:608 drivers/tty/serial/serial_core.c:222)\nuart_port_startup (drivers/tty/serial/serial_core.c:342)\nuart_startup (drivers/tty/serial/serial_core.c:368)\nuart_set_info (drivers/tty/serial/serial_core.c:1034)\nuart_set_info_user (drivers/tty/serial/serial_core.c:1059)\ntty_set_serial (drivers/tty/tty_io.c:2637)\ntty_ioctl (drivers/tty/tty_io.c:2647 drivers/tty/tty_io.c:2791)\n__x64_sys_ioctl (fs/ioctl.c:52 fs/ioctl.c:907\n fs/ioctl.c:893 fs/ioctl.c:893)\ndo_syscall_64 (arch/x86/entry/common.c:52\n (discriminator 1) arch/x86/entry/common.c:83 (discriminator 1))\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nRule: add', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-369'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43893', 'https://git.kernel.org/linus/6eabce6608d6f3440f4c03aa3d3ef50a47a3d193 (6.11-rc3)', 'https://git.kernel.org/stable/c/3bbd90fca824e6fd61fb20f6dd2b0fa5f8b14bba', 'https://git.kernel.org/stable/c/52b138f1021113e593ee6ad258ce08fe90693a9e', 'https://git.kernel.org/stable/c/55b2a5d331a6ceb1c4372945fdb77181265ba24f', 'https://git.kernel.org/stable/c/68dc02f319b9ee54dc23caba742a5c754d1cccc8', 'https://git.kernel.org/stable/c/6eabce6608d6f3440f4c03aa3d3ef50a47a3d193', 'https://git.kernel.org/stable/c/9196e42a3b8eeff1707e6ef769112b4b6096be49', 'https://git.kernel.org/stable/c/e13ba3fe5ee070f8a9dab60029d52b1f61da5051', 'https://git.kernel.org/stable/c/e3ad503876283ac3fcca922a1bf243ef9eb0b0e2', 'https://linux.oracle.com/cve/CVE-2024-43893.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082605-CVE-2024-43893-25dd@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43893', 'https://www.cve.org/CVERecord?id=CVE-2024-43893'], 'PublishedDate': '2024-08-26T11:15:04.213Z', 'LastModifiedDate': '2024-09-10T18:13:21.92Z'}, {'VulnerabilityID': 'CVE-2024-43894', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43894', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/client: fix null pointer dereference in drm_client_modeset_probe', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/client: fix null pointer dereference in drm_client_modeset_probe\n\nIn drm_client_modeset_probe(), the return value of drm_mode_duplicate() is\nassigned to modeset->mode, which will lead to a possible NULL pointer\ndereference on failure of drm_mode_duplicate(). Add a check to avoid npd.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43894', 'https://git.kernel.org/linus/113fd6372a5bb3689aba8ef5b8a265ed1529a78f (6.11-rc3)', 'https://git.kernel.org/stable/c/113fd6372a5bb3689aba8ef5b8a265ed1529a78f', 'https://git.kernel.org/stable/c/24ddda932c43ffe156c7f3c568bed85131c63ae6', 'https://git.kernel.org/stable/c/5291d4f73452c91e8a11f71207617e3e234d418e', 'https://git.kernel.org/stable/c/612cae53e99ce32a58cb821b3b67199eb6e92dff', 'https://git.kernel.org/stable/c/c763dfe09425152b6bb0e348900a637c62c2ce52', 'https://git.kernel.org/stable/c/d64847c383100423aecb6ac5f18be5f4316d9d62', 'https://git.kernel.org/stable/c/d64fc94f7bb24fc2be0d6bd5df8df926da461a6d', 'https://linux.oracle.com/cve/CVE-2024-43894.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082607-CVE-2024-43894-aeee@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43894', 'https://www.cve.org/CVERecord?id=CVE-2024-43894'], 'PublishedDate': '2024-08-26T11:15:04.28Z', 'LastModifiedDate': '2024-09-10T18:09:41.23Z'}, {'VulnerabilityID': 'CVE-2024-43895', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43895', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Skip Recompute DSC Params if no Stream on Link', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip Recompute DSC Params if no Stream on Link\n\n[why]\nEncounter NULL pointer dereference uner mst + dsc setup.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 4 PID: 917 Comm: sway Not tainted 6.3.9-arch1-1 #1 124dc55df4f5272ccb409f39ef4872fc2b3376a2\n Hardware name: LENOVO 20NKS01Y00/20NKS01Y00, BIOS R12ET61W(1.31 ) 07/28/2022\n RIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\n Code: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\n RSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\n RAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\n RDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\n RBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\n R10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\n R13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\n FS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000010ddc6000 CR4: 00000000003506e0\n Call Trace:\n\n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? plist_add+0xbe/0x100\n ? exc_page_fault+0x7c/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n ? drm_dp_atomic_find_time_slots+0x28/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n compute_mst_dsc_configs_for_link+0x2ff/0xa40 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n ? fill_plane_buffer_attributes+0x419/0x510 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n compute_mst_dsc_configs_for_state+0x1e1/0x250 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n amdgpu_dm_atomic_check+0xecd/0x1190 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n drm_atomic_check_only+0x5c5/0xa40\n drm_mode_atomic_ioctl+0x76e/0xbc0\n\n[how]\ndsc recompute should be skipped if no mode change detected on the new\nrequest. If detected, keep checking whether the stream is already on\ncurrent state or not.\n\n(cherry picked from commit 8151a6c13111b465dbabe07c19f572f7cbd16fef)', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43895', 'https://git.kernel.org/linus/50e376f1fe3bf571d0645ddf48ad37eb58323919 (6.11-rc3)', 'https://git.kernel.org/stable/c/282f0a482ee61d5e863512f3c4fcec90216c20d9', 'https://git.kernel.org/stable/c/50e376f1fe3bf571d0645ddf48ad37eb58323919', 'https://git.kernel.org/stable/c/5357141b4c2e2b332b6f11607ba8c5fbc2669a10', 'https://git.kernel.org/stable/c/70275bb960c71d313254473d38c14e7101cee5ad', 'https://git.kernel.org/stable/c/718d83f66fb07b2cab89a1fc984613a00e3db18f', 'https://lore.kernel.org/linux-cve-announce/2024082608-CVE-2024-43895-d3c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43895', 'https://www.cve.org/CVERecord?id=CVE-2024-43895'], 'PublishedDate': '2024-08-26T11:15:04.333Z', 'LastModifiedDate': '2024-10-10T12:15:04.35Z'}, {'VulnerabilityID': 'CVE-2024-43898', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43898', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ext4: sanity check for NULL pointer after ext4_force_shutdown', 'Description': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43898', 'https://git.kernel.org/linus/83f4414b8f84249d538905825b088ff3ae555652 (6.11-rc1)', 'https://git.kernel.org/stable/c/3f6bbe6e07e5239294ecc3d2efa70d1f98aed52e', 'https://git.kernel.org/stable/c/83f4414b8f84249d538905825b088ff3ae555652', 'https://git.kernel.org/stable/c/f619876ccbfd329ae785fe5d3289b9dcd6eb5901', 'https://lore.kernel.org/linux-cve-announce/2024082613-CVE-2024-43898-52c2@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43898', 'https://www.cve.org/CVERecord?id=CVE-2024-43898'], 'PublishedDate': '2024-08-26T11:15:04.493Z', 'LastModifiedDate': '2024-09-10T08:15:02.96Z'}, {'VulnerabilityID': 'CVE-2024-43899', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43899', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Fix null pointer deref in dcn20_resource.c', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null pointer deref in dcn20_resource.c\n\nFixes a hang thats triggered when MPV is run on a DCN401 dGPU:\n\nmpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all\n\nand then enabling fullscreen playback (double click on the video)\n\nThe following calltrace will be seen:\n\n[ 181.843989] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 181.843997] #PF: supervisor instruction fetch in kernel mode\n[ 181.844003] #PF: error_code(0x0010) - not-present page\n[ 181.844009] PGD 0 P4D 0\n[ 181.844020] Oops: 0010 [#1] PREEMPT SMP NOPTI\n[ 181.844028] CPU: 6 PID: 1892 Comm: gnome-shell Tainted: G W OE 6.5.0-41-generic #41~22.04.2-Ubuntu\n[ 181.844038] Hardware name: System manufacturer System Product Name/CROSSHAIR VI HERO, BIOS 6302 10/23/2018\n[ 181.844044] RIP: 0010:0x0\n[ 181.844079] Code: Unable to access opcode bytes at 0xffffffffffffffd6.\n[ 181.844084] RSP: 0018:ffffb593c2b8f7b0 EFLAGS: 00010246\n[ 181.844093] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004\n[ 181.844099] RDX: ffffb593c2b8f804 RSI: ffffb593c2b8f7e0 RDI: ffff9e3c8e758400\n[ 181.844105] RBP: ffffb593c2b8f7b8 R08: ffffb593c2b8f9c8 R09: ffffb593c2b8f96c\n[ 181.844110] R10: 0000000000000000 R11: 0000000000000000 R12: ffffb593c2b8f9c8\n[ 181.844115] R13: 0000000000000001 R14: ffff9e3c88000000 R15: 0000000000000005\n[ 181.844121] FS: 00007c6e323bb5c0(0000) GS:ffff9e3f85f80000(0000) knlGS:0000000000000000\n[ 181.844128] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 181.844134] CR2: ffffffffffffffd6 CR3: 0000000140fbe000 CR4: 00000000003506e0\n[ 181.844141] Call Trace:\n[ 181.844146] \n[ 181.844153] ? show_regs+0x6d/0x80\n[ 181.844167] ? __die+0x24/0x80\n[ 181.844179] ? page_fault_oops+0x99/0x1b0\n[ 181.844192] ? do_user_addr_fault+0x31d/0x6b0\n[ 181.844204] ? exc_page_fault+0x83/0x1b0\n[ 181.844216] ? asm_exc_page_fault+0x27/0x30\n[ 181.844237] dcn20_get_dcc_compression_cap+0x23/0x30 [amdgpu]\n[ 181.845115] amdgpu_dm_plane_validate_dcc.constprop.0+0xe5/0x180 [amdgpu]\n[ 181.845985] amdgpu_dm_plane_fill_plane_buffer_attributes+0x300/0x580 [amdgpu]\n[ 181.846848] fill_dc_plane_info_and_addr+0x258/0x350 [amdgpu]\n[ 181.847734] fill_dc_plane_attributes+0x162/0x350 [amdgpu]\n[ 181.848748] dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[ 181.849791] ? dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[ 181.850840] amdgpu_dm_atomic_check+0xdfe/0x1760 [amdgpu]', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43899', 'https://git.kernel.org/linus/ecbf60782662f0a388493685b85a645a0ba1613c (6.11-rc1)', 'https://git.kernel.org/stable/c/974fccd61758599a9716c4b909d9226749efe37e', 'https://git.kernel.org/stable/c/ecbf60782662f0a388493685b85a645a0ba1613c', 'https://lore.kernel.org/linux-cve-announce/2024082614-CVE-2024-43899-2339@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43899', 'https://www.cve.org/CVERecord?id=CVE-2024-43899'], 'PublishedDate': '2024-08-26T11:15:04.557Z', 'LastModifiedDate': '2024-08-27T14:38:19.74Z'}, {'VulnerabilityID': 'CVE-2024-43900', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43900', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: media: xc2028: avoid use-after-free in load_firmware_cb()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: xc2028: avoid use-after-free in load_firmware_cb()\n\nsyzkaller reported use-after-free in load_firmware_cb() [1].\nThe reason is because the module allocated a struct tuner in tuner_probe(),\nand then the module initialization failed, the struct tuner was released.\nA worker which created during module initialization accesses this struct\ntuner later, it caused use-after-free.\n\nThe process is as follows:\n\ntask-6504 worker_thread\ntuner_probe <= alloc dvb_frontend [2]\n...\nrequest_firmware_nowait <= create a worker\n...\ntuner_remove <= free dvb_frontend\n...\n request_firmware_work_func <= the firmware is ready\n load_firmware_cb <= but now the dvb_frontend has been freed\n\nTo fix the issue, check the dvd_frontend in load_firmware_cb(), if it is\nnull, report a warning and just return.\n\n[1]:\n ==================================================================\n BUG: KASAN: use-after-free in load_firmware_cb+0x1310/0x17a0\n Read of size 8 at addr ffff8000d7ca2308 by task kworker/2:3/6504\n\n Call trace:\n load_firmware_cb+0x1310/0x17a0\n request_firmware_work_func+0x128/0x220\n process_one_work+0x770/0x1824\n worker_thread+0x488/0xea0\n kthread+0x300/0x430\n ret_from_fork+0x10/0x20\n\n Allocated by task 6504:\n kzalloc\n tuner_probe+0xb0/0x1430\n i2c_device_probe+0x92c/0xaf0\n really_probe+0x678/0xcd0\n driver_probe_device+0x280/0x370\n __device_attach_driver+0x220/0x330\n bus_for_each_drv+0x134/0x1c0\n __device_attach+0x1f4/0x410\n device_initial_probe+0x20/0x30\n bus_probe_device+0x184/0x200\n device_add+0x924/0x12c0\n device_register+0x24/0x30\n i2c_new_device+0x4e0/0xc44\n v4l2_i2c_new_subdev_board+0xbc/0x290\n v4l2_i2c_new_subdev+0xc8/0x104\n em28xx_v4l2_init+0x1dd0/0x3770\n\n Freed by task 6504:\n kfree+0x238/0x4e4\n tuner_remove+0x144/0x1c0\n i2c_device_remove+0xc8/0x290\n __device_release_driver+0x314/0x5fc\n device_release_driver+0x30/0x44\n bus_remove_device+0x244/0x490\n device_del+0x350/0x900\n device_unregister+0x28/0xd0\n i2c_unregister_device+0x174/0x1d0\n v4l2_device_unregister+0x224/0x380\n em28xx_v4l2_init+0x1d90/0x3770\n\n The buggy address belongs to the object at ffff8000d7ca2000\n which belongs to the cache kmalloc-2k of size 2048\n The buggy address is located 776 bytes inside of\n 2048-byte region [ffff8000d7ca2000, ffff8000d7ca2800)\n The buggy address belongs to the page:\n page:ffff7fe00035f280 count:1 mapcount:0 mapping:ffff8000c001f000 index:0x0\n flags: 0x7ff800000000100(slab)\n raw: 07ff800000000100 ffff7fe00049d880 0000000300000003 ffff8000c001f000\n raw: 0000000000000000 0000000080100010 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8000d7ca2200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8000d7ca2280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n >ffff8000d7ca2300: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8000d7ca2380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8000d7ca2400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ==================================================================\n\n[2]\n Actually, it is allocated for struct tuner, and dvb_frontend is inside.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 6.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43900', 'https://git.kernel.org/linus/68594cec291ff9523b9feb3f43fd853dcddd1f60 (6.11-rc1)', 'https://git.kernel.org/stable/c/208deb6d8c3cb8c3acb1f41eb31cf68ea08726d5', 'https://git.kernel.org/stable/c/68594cec291ff9523b9feb3f43fd853dcddd1f60', 'https://git.kernel.org/stable/c/850304152d367f104d21c77cfbcc05806504218b', 'https://git.kernel.org/stable/c/ef517bdfc01818419f7bd426969a0c86b14f3e0e', 'https://lore.kernel.org/linux-cve-announce/2024082616-CVE-2024-43900-029c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43900', 'https://www.cve.org/CVERecord?id=CVE-2024-43900'], 'PublishedDate': '2024-08-26T11:15:04.613Z', 'LastModifiedDate': '2024-08-27T14:38:32.967Z'}, {'VulnerabilityID': 'CVE-2024-43902', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43902', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/display: Add null checker before passing variables', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null checker before passing variables\n\nChecks null pointer before passing variables to functions.\n\nThis fixes 3 NULL_RETURNS issues reported by Coverity.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43902', 'https://git.kernel.org/linus/8092aa3ab8f7b737a34b71f91492c676a843043a (6.11-rc1)', 'https://git.kernel.org/stable/c/1686675405d07f35eae7ff3d13a530034b899df2', 'https://git.kernel.org/stable/c/4cc2a94d96caeb3c975acdae7351c2f997c32175', 'https://git.kernel.org/stable/c/8092aa3ab8f7b737a34b71f91492c676a843043a', 'https://git.kernel.org/stable/c/83c7f509ef087041604e9572938f82e18b724c9d', 'https://git.kernel.org/stable/c/d0b8b23b9c2ebec693a36fea518d8f13493ad655', 'https://lore.kernel.org/linux-cve-announce/2024082618-CVE-2024-43902-eb6d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43902', 'https://www.cve.org/CVERecord?id=CVE-2024-43902'], 'PublishedDate': '2024-08-26T11:15:04.733Z', 'LastModifiedDate': '2024-08-27T14:38:51.73Z'}, {'VulnerabilityID': 'CVE-2024-43903', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43903', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update\n\nThis commit adds a null check for the 'afb' variable in the\namdgpu_dm_plane_handle_cursor_update function. Previously, 'afb' was\nassumed to be null, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed 'afb' could be null (see line 1252)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43903', 'https://git.kernel.org/linus/38e6f715b02b572f74677eb2f29d3b4bc6f1ddff (6.11-rc1)', 'https://git.kernel.org/stable/c/31a679a880102dee6e10985a7b1789af8dc328cc', 'https://git.kernel.org/stable/c/38e6f715b02b572f74677eb2f29d3b4bc6f1ddff', 'https://git.kernel.org/stable/c/94220b35aeba2b68da81deeefbb784d94eeb5c04', 'https://git.kernel.org/stable/c/ce5d090af683137cb779ed7e3683839f9c778b35', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-43903-3644@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43903', 'https://www.cve.org/CVERecord?id=CVE-2024-43903'], 'PublishedDate': '2024-08-26T11:15:04.793Z', 'LastModifiedDate': '2024-08-27T13:39:48.683Z'}, {'VulnerabilityID': 'CVE-2024-43904', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43904', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing\n\nThis commit adds null checks for the 'stream' and 'plane' variables in\nthe dcn30_apply_idle_power_optimizations function. These variables were\npreviously assumed to be null at line 922, but they were used later in\nthe code without checking if they were null. This could potentially lead\nto a null pointer dereference, which would cause a crash.\n\nThe null checks ensure that 'stream' and 'plane' are not null before\nthey are used, preventing potential crashes.\n\nFixes the below static smatch checker:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:938 dcn30_apply_idle_power_optimizations() error: we previously assumed 'stream' could be null (see line 922)\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:940 dcn30_apply_idle_power_optimizations() error: we previously assumed 'plane' could be null (see line 922)", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43904', 'https://git.kernel.org/linus/15c2990e0f0108b9c3752d7072a97d45d4283aea (6.11-rc1)', 'https://git.kernel.org/stable/c/15c2990e0f0108b9c3752d7072a97d45d4283aea', 'https://git.kernel.org/stable/c/16a8a2a839d19c4cf7253642b493ffb8eee1d857', 'https://lore.kernel.org/linux-cve-announce/2024082621-CVE-2024-43904-63a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43904', 'https://www.cve.org/CVERecord?id=CVE-2024-43904'], 'PublishedDate': '2024-08-26T11:15:04.847Z', 'LastModifiedDate': '2024-08-27T13:40:50.577Z'}, {'VulnerabilityID': 'CVE-2024-43905', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43905', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amd/pm: Fix the null pointer dereference for vega10_hwmgr', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Fix the null pointer dereference for vega10_hwmgr\n\nCheck return value and conduct null pointer handling to avoid null pointer dereference.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43905', 'https://git.kernel.org/linus/50151b7f1c79a09117837eb95b76c2de76841dab (6.11-rc1)', 'https://git.kernel.org/stable/c/0fa11f9df96217c2785b040629ff1a16900fb51c', 'https://git.kernel.org/stable/c/2ac9deb7e087f0b461c3559d9eaa6b9cf19d3fa8', 'https://git.kernel.org/stable/c/2e538944996d0dd497faf8ee81f8bfcd3aca7d80', 'https://git.kernel.org/stable/c/50151b7f1c79a09117837eb95b76c2de76841dab', 'https://git.kernel.org/stable/c/69a441473fec2fc2aa2cf56122d6c42c4266a239', 'https://git.kernel.org/stable/c/c2629daf218a325f4d69754452cd42fe8451c15b', 'https://lore.kernel.org/linux-cve-announce/2024082623-CVE-2024-43905-008f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43905', 'https://www.cve.org/CVERecord?id=CVE-2024-43905'], 'PublishedDate': '2024-08-26T11:15:04.897Z', 'LastModifiedDate': '2024-09-12T12:15:51.26Z'}, {'VulnerabilityID': 'CVE-2024-43906', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43906', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/admgpu: fix dereferencing null pointer context', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/admgpu: fix dereferencing null pointer context\n\nWhen user space sets an invalid ta type, the pointer context will be empty.\nSo it need to check the pointer context before using it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43906', 'https://git.kernel.org/linus/030ffd4d43b433bc6671d9ec34fc12c59220b95d (6.11-rc1)', 'https://git.kernel.org/stable/c/030ffd4d43b433bc6671d9ec34fc12c59220b95d', 'https://git.kernel.org/stable/c/4fd52f7c2c11d330571c6bde06e5ea508ec25c9d', 'https://git.kernel.org/stable/c/641dac64178ccdb9e45c92b67120316896294d05', 'https://lore.kernel.org/linux-cve-announce/2024082624-CVE-2024-43906-27ab@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43906', 'https://www.cve.org/CVERecord?id=CVE-2024-43906'], 'PublishedDate': '2024-08-26T11:15:04.947Z', 'LastModifiedDate': '2024-08-27T13:41:30.093Z'}, {'VulnerabilityID': 'CVE-2024-43907', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43907', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/pm: Fix the null pointer dereference in apply_state_adjust_rules', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm: Fix the null pointer dereference in apply_state_adjust_rules\n\nCheck the pointer value to fix potential null pointer\ndereference', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43907', 'https://git.kernel.org/linus/d19fb10085a49b77578314f69fff21562f7cd054 (6.11-rc1)', 'https://git.kernel.org/stable/c/0c065e50445aea2e0a1815f12e97ee49e02cbaac', 'https://git.kernel.org/stable/c/13937a40aae4efe64592ba48c057ac3c72f7fe82', 'https://git.kernel.org/stable/c/3a01bf2ca9f860fdc88c358567b8fa3033efcf30', 'https://git.kernel.org/stable/c/c1749313f35b98e2e655479f037db37f19756622', 'https://git.kernel.org/stable/c/d19fb10085a49b77578314f69fff21562f7cd054', 'https://git.kernel.org/stable/c/e04d18c29954441aa1054af649f957ffad90a201', 'https://lore.kernel.org/linux-cve-announce/2024082626-CVE-2024-43907-91a1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43907', 'https://www.cve.org/CVERecord?id=CVE-2024-43907'], 'PublishedDate': '2024-08-26T11:15:05Z', 'LastModifiedDate': '2024-08-27T13:41:40.497Z'}, {'VulnerabilityID': 'CVE-2024-43908', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43908', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu: Fix the null pointer dereference to ras_manager', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the null pointer dereference to ras_manager\n\nCheck ras_manager before using it', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43908', 'https://git.kernel.org/linus/4c11d30c95576937c6c35e6f29884761f2dddb43 (6.11-rc1)', 'https://git.kernel.org/stable/c/033187a70ba9743c73a810a006816e5553d1e7d4', 'https://git.kernel.org/stable/c/48cada0ac79e4775236d642e9ec5998a7c7fb7a4', 'https://git.kernel.org/stable/c/4c11d30c95576937c6c35e6f29884761f2dddb43', 'https://git.kernel.org/stable/c/56e848034ccabe44e8f22ffcf49db771c17b0d0a', 'https://git.kernel.org/stable/c/b89616333979114bb0da5fa40fb6e4a2f5294ca2', 'https://git.kernel.org/stable/c/d81c1eeb333d84b3012a91c0500189dc1d71e46c', 'https://git.kernel.org/stable/c/ff5c4eb71ee8951c789b079f6e948f86708b04ed', 'https://linux.oracle.com/cve/CVE-2024-43908.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082627-CVE-2024-43908-4406@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43908', 'https://www.cve.org/CVERecord?id=CVE-2024-43908'], 'PublishedDate': '2024-08-26T11:15:05.057Z', 'LastModifiedDate': '2024-08-27T13:41:55.26Z'}, {'VulnerabilityID': 'CVE-2024-43909', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43909', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/amdgpu/pm: Fix the null pointer dereference for smu7', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm: Fix the null pointer dereference for smu7\n\noptimize the code to avoid pass a null pointer (hwmgr->backend)\nto function smu7_update_edc_leakage_table.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43909', 'https://git.kernel.org/linus/c02c1960c93eede587576625a1221205a68a904f (6.11-rc1)', 'https://git.kernel.org/stable/c/09544cd95c688d3041328a4253bd7514972399bb', 'https://git.kernel.org/stable/c/1b8aa82b80bd947b68a8ab051d960a0c7935e22d', 'https://git.kernel.org/stable/c/37b9df457cbcf095963d18f17d6cb7dfa0a03fce', 'https://git.kernel.org/stable/c/7f56f050f02c27ed89cce1ea0c04b34abce32751', 'https://git.kernel.org/stable/c/c02c1960c93eede587576625a1221205a68a904f', 'https://lore.kernel.org/linux-cve-announce/2024082628-CVE-2024-43909-acb8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43909', 'https://www.cve.org/CVERecord?id=CVE-2024-43909'], 'PublishedDate': '2024-08-26T11:15:05.117Z', 'LastModifiedDate': '2024-08-27T13:41:48.467Z'}, {'VulnerabilityID': 'CVE-2024-43910', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43910', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses\n\nCurrently, it's possible to pass in a modified CONST_PTR_TO_DYNPTR to\na global function as an argument. The adverse effects of this is that\nBPF helpers can continue to make use of this modified\nCONST_PTR_TO_DYNPTR from within the context of the global function,\nwhich can unintentionally result in out-of-bounds memory accesses and\ntherefore compromise overall system stability i.e.\n\n[ 244.157771] BUG: KASAN: slab-out-of-bounds in bpf_dynptr_data+0x137/0x140\n[ 244.161345] Read of size 8 at addr ffff88810914be68 by task test_progs/302\n[ 244.167151] CPU: 0 PID: 302 Comm: test_progs Tainted: G O E 6.10.0-rc3-00131-g66b586715063 #533\n[ 244.174318] Call Trace:\n[ 244.175787] \n[ 244.177356] dump_stack_lvl+0x66/0xa0\n[ 244.179531] print_report+0xce/0x670\n[ 244.182314] ? __virt_addr_valid+0x200/0x3e0\n[ 244.184908] kasan_report+0xd7/0x110\n[ 244.187408] ? bpf_dynptr_data+0x137/0x140\n[ 244.189714] ? bpf_dynptr_data+0x137/0x140\n[ 244.192020] bpf_dynptr_data+0x137/0x140\n[ 244.194264] bpf_prog_b02a02fdd2bdc5fa_global_call_bpf_dynptr_data+0x22/0x26\n[ 244.198044] bpf_prog_b0fe7b9d7dc3abde_callback_adjust_bpf_dynptr_reg_off+0x1f/0x23\n[ 244.202136] bpf_user_ringbuf_drain+0x2c7/0x570\n[ 244.204744] ? 0xffffffffc0009e58\n[ 244.206593] ? __pfx_bpf_user_ringbuf_drain+0x10/0x10\n[ 244.209795] bpf_prog_33ab33f6a804ba2d_user_ringbuf_callback_const_ptr_to_dynptr_reg_off+0x47/0x4b\n[ 244.215922] bpf_trampoline_6442502480+0x43/0xe3\n[ 244.218691] __x64_sys_prlimit64+0x9/0xf0\n[ 244.220912] do_syscall_64+0xc1/0x1d0\n[ 244.223043] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 244.226458] RIP: 0033:0x7ffa3eb8f059\n[ 244.228582] Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8f 1d 0d 00 f7 d8 64 89 01 48\n[ 244.241307] RSP: 002b:00007ffa3e9c6eb8 EFLAGS: 00000206 ORIG_RAX: 000000000000012e\n[ 244.246474] RAX: ffffffffffffffda RBX: 00007ffa3e9c7cdc RCX: 00007ffa3eb8f059\n[ 244.250478] RDX: 00007ffa3eb162b4 RSI: 0000000000000000 RDI: 00007ffa3e9c7fb0\n[ 244.255396] RBP: 00007ffa3e9c6ed0 R08: 00007ffa3e9c76c0 R09: 0000000000000000\n[ 244.260195] R10: 0000000000000000 R11: 0000000000000206 R12: ffffffffffffff80\n[ 244.264201] R13: 000000000000001c R14: 00007ffc5d6b4260 R15: 00007ffa3e1c7000\n[ 244.268303] \n\nAdd a check_func_arg_reg_off() to the path in which the BPF verifier\nverifies the arguments of global function arguments, specifically\nthose which take an argument of type ARG_PTR_TO_DYNPTR |\nMEM_RDONLY. Also, process_dynptr_func() doesn't appear to perform any\nexplicit and strict type matching on the supplied register type, so\nlet's also enforce that a register either type PTR_TO_STACK or\nCONST_PTR_TO_DYNPTR is by the caller.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43910', 'https://git.kernel.org/linus/ec2b9a5e11e51fea1bb04c1e7e471952e887e874 (6.11-rc1)', 'https://git.kernel.org/stable/c/13663a7c644bf1dedaf461d07252db5d76c8759a', 'https://git.kernel.org/stable/c/ec2b9a5e11e51fea1bb04c1e7e471952e887e874', 'https://lore.kernel.org/linux-cve-announce/2024082630-CVE-2024-43910-c6ec@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43910', 'https://www.cve.org/CVERecord?id=CVE-2024-43910'], 'PublishedDate': '2024-08-26T11:15:05.177Z', 'LastModifiedDate': '2024-09-05T18:30:23.437Z'}, {'VulnerabilityID': 'CVE-2024-43911', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43911', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: mac80211: fix NULL dereference at band check in starting tx ba session', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix NULL dereference at band check in starting tx ba session\n\nIn MLD connection, link_data/link_conf are dynamically allocated. They\ndon't point to vif->bss_conf. So, there will be no chanreq assigned to\nvif->bss_conf and then the chan will be NULL. Tweak the code to check\nht_supported/vht_supported/has_he/has_eht on sta deflink.\n\nCrash log (with rtw89 version under MLO development):\n[ 9890.526087] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 9890.526102] #PF: supervisor read access in kernel mode\n[ 9890.526105] #PF: error_code(0x0000) - not-present page\n[ 9890.526109] PGD 0 P4D 0\n[ 9890.526114] Oops: 0000 [#1] PREEMPT SMP PTI\n[ 9890.526119] CPU: 2 PID: 6367 Comm: kworker/u16:2 Kdump: loaded Tainted: G OE 6.9.0 #1\n[ 9890.526123] Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB3WW (2.73 ) 11/28/2018\n[ 9890.526126] Workqueue: phy2 rtw89_core_ba_work [rtw89_core]\n[ 9890.526203] RIP: 0010:ieee80211_start_tx_ba_session (net/mac80211/agg-tx.c:618 (discriminator 1)) mac80211\n[ 9890.526279] Code: f7 e8 d5 93 3e ea 48 83 c4 28 89 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 49 8b 84 24 e0 f1 ff ff 48 8b 80 90 1b 00 00 <83> 38 03 0f 84 37 fe ff ff bb ea ff ff ff eb cc 49 8b 84 24 10 f3\nAll code\n========\n 0:\tf7 e8 \timul %eax\n 2:\td5 \t(bad)\n 3:\t93 \txchg %eax,%ebx\n 4:\t3e ea \tds (bad)\n 6:\t48 83 c4 28 \tadd $0x28,%rsp\n a:\t89 d8 \tmov %ebx,%eax\n c:\t5b \tpop %rbx\n d:\t41 5c \tpop %r12\n f:\t41 5d \tpop %r13\n 11:\t41 5e \tpop %r14\n 13:\t41 5f \tpop %r15\n 15:\t5d \tpop %rbp\n 16:\tc3 \tretq\n 17:\tcc \tint3\n 18:\tcc \tint3\n 19:\tcc \tint3\n 1a:\tcc \tint3\n 1b:\t49 8b 84 24 e0 f1 ff \tmov -0xe20(%r12),%rax\n 22:\tff\n 23:\t48 8b 80 90 1b 00 00 \tmov 0x1b90(%rax),%rax\n 2a:*\t83 38 03 \tcmpl $0x3,(%rax)\t\t<-- trapping instruction\n 2d:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe6a\n 33:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n 38:\teb cc \tjmp 0x6\n 3a:\t49 \trex.WB\n 3b:\t8b \t.byte 0x8b\n 3c:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 3f:\tf3 \trepz\n\nCode starting with the faulting instruction\n===========================================\n 0:\t83 38 03 \tcmpl $0x3,(%rax)\n 3:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe40\n 9:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n e:\teb cc \tjmp 0xffffffffffffffdc\n 10:\t49 \trex.WB\n 11:\t8b \t.byte 0x8b\n 12:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 15:\tf3 \trepz\n[ 9890.526285] RSP: 0018:ffffb8db09013d68 EFLAGS: 00010246\n[ 9890.526291] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff9308e0d656c8\n[ 9890.526295] RDX: 0000000000000000 RSI: ffffffffab99460b RDI: ffffffffab9a7685\n[ 9890.526300] RBP: ffffb8db09013db8 R08: 0000000000000000 R09: 0000000000000873\n[ 9890.526304] R10: ffff9308e0d64800 R11: 0000000000000002 R12: ffff9308e5ff6e70\n[ 9890.526308] R13: ffff930952500e20 R14: ffff9309192a8c00 R15: 0000000000000000\n[ 9890.526313] FS: 0000000000000000(0000) GS:ffff930b4e700000(0000) knlGS:0000000000000000\n[ 9890.526316] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9890.526318] CR2: 0000000000000000 CR3: 0000000391c58005 CR4: 00000000001706f0\n[ 9890.526321] Call Trace:\n[ 9890.526324] \n[ 9890.526327] ? show_regs (arch/x86/kernel/dumpstack.c:479)\n[ 9890.526335] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n[ 9890.526340] ? page_fault_oops (arch/x86/mm/fault.c:713)\n[ 9890.526347] ? search_module_extables (kernel/module/main.c:3256 (discriminator\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.7}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43911', 'https://git.kernel.org/linus/021d53a3d87eeb9dbba524ac515651242a2a7e3b (6.11-rc1)', 'https://git.kernel.org/stable/c/021d53a3d87eeb9dbba524ac515651242a2a7e3b', 'https://git.kernel.org/stable/c/a5594c1e03b0df3908b1e1202a1ba34422eed0f6', 'https://lore.kernel.org/linux-cve-announce/2024082631-CVE-2024-43911-96bb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43911', 'https://www.cve.org/CVERecord?id=CVE-2024-43911'], 'PublishedDate': '2024-08-26T11:15:05.227Z', 'LastModifiedDate': '2024-08-27T16:08:52.493Z'}, {'VulnerabilityID': 'CVE-2024-43912', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43912', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: wifi: nl80211: disallow setting special AP channel widths', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: disallow setting special AP channel widths\n\nSetting the AP channel width is meant for use with the normal\n20/40/... MHz channel width progression, and switching around\nin S1G or narrow channels isn't supported. Disallow that.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'V3Score': 4.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43912', 'https://git.kernel.org/linus/23daf1b4c91db9b26f8425cc7039cf96d22ccbfe (6.11-rc1)', 'https://git.kernel.org/stable/c/23daf1b4c91db9b26f8425cc7039cf96d22ccbfe', 'https://git.kernel.org/stable/c/3d42f2125f6c89e1e71c87b9f23412afddbba45e', 'https://git.kernel.org/stable/c/ac3bf6e47fd8da9bfe8027e1acfe0282a91584fc', 'https://git.kernel.org/stable/c/c6ea738e3feb407a3283197d9a25d0788f4f3cee', 'https://lore.kernel.org/linux-cve-announce/2024082632-CVE-2024-43912-801f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43912', 'https://www.cve.org/CVERecord?id=CVE-2024-43912'], 'PublishedDate': '2024-08-26T11:15:05.28Z', 'LastModifiedDate': '2024-09-05T18:19:17.067Z'}, {'VulnerabilityID': 'CVE-2024-43913', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43913', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: nvme: apple: fix device reference counting', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: apple: fix device reference counting\n\nDrivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.\nSplit the allocation side out to make the error handling boundary easier\nto navigate. The apple driver had been doing this wrong, leaking the\ncontroller device memory on a tagset failure.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43913', 'https://git.kernel.org/linus/b9ecbfa45516182cd062fecd286db7907ba84210 (6.11-rc1)', 'https://git.kernel.org/stable/c/b9ecbfa45516182cd062fecd286db7907ba84210', 'https://git.kernel.org/stable/c/d59c4d0eb6adc24c2201f153ccb7fd0a335b0d3d', 'https://lore.kernel.org/linux-cve-announce/2024082633-CVE-2024-43913-6ec7@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43913', 'https://www.cve.org/CVERecord?id=CVE-2024-43913'], 'PublishedDate': '2024-08-26T11:15:05.33Z', 'LastModifiedDate': '2024-09-05T18:12:55.68Z'}, {'VulnerabilityID': 'CVE-2024-43914', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-43914', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: md/raid5: avoid BUG_ON() while continue reshape after reassembling', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid BUG_ON() while continue reshape after reassembling\n\nCurrently, mdadm support --revert-reshape to abort the reshape while\nreassembling, as the test 07revert-grow. However, following BUG_ON()\ncan be triggerred by the test:\n\nkernel BUG at drivers/md/raid5.c:6278!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nirq event stamp: 158985\nCPU: 6 PID: 891 Comm: md0_reshape Not tainted 6.9.0-03335-g7592a0b0049a #94\nRIP: 0010:reshape_request+0x3f1/0xe60\nCall Trace:\n \n raid5_sync_request+0x43d/0x550\n md_do_sync+0xb7a/0x2110\n md_thread+0x294/0x2b0\n kthread+0x147/0x1c0\n ret_from_fork+0x59/0x70\n ret_from_fork_asm+0x1a/0x30\n \n\nRoot cause is that --revert-reshape update the raid_disks from 5 to 4,\nwhile reshape position is still set, and after reassembling the array,\nreshape position will be read from super block, then during reshape the\nchecking of 'writepos' that is caculated by old reshape position will\nfail.\n\nFix this panic the easy way first, by converting the BUG_ON() to\nWARN_ON(), and stop the reshape if checkings fail.\n\nNoted that mdadm must fix --revert-shape as well, and probably md/raid\nshould enhance metadata validation as well, however this means\nreassemble will fail and there must be user tools to fix the wrong\nmetadata.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-43914', 'https://git.kernel.org/linus/305a5170dc5cf3d395bb4c4e9239bca6d0b54b49 (6.11-rc1)', 'https://git.kernel.org/stable/c/2c92f8c1c456d556f15cbf51667b385026b2e6a0', 'https://git.kernel.org/stable/c/305a5170dc5cf3d395bb4c4e9239bca6d0b54b49', 'https://git.kernel.org/stable/c/3b33740c1750a39e046339ff9240e954f0156707', 'https://git.kernel.org/stable/c/4811d6e5d9f4090c3e0ff9890eb24077108046ab', 'https://git.kernel.org/stable/c/6b33c468d543f6a83de2d61f09fec74b27e19fd2', 'https://git.kernel.org/stable/c/775a9ba16c9ffe98fe54ebf14e55d5660f2bf600', 'https://git.kernel.org/stable/c/bf0ff69a42a3d2d46876d0514ecf13dffc516666', 'https://git.kernel.org/stable/c/c384dd4f1fb3b14a2fd199360701cc163ea88705', 'https://linux.oracle.com/cve/CVE-2024-43914.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082635-CVE-2024-43914-a664@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-43914', 'https://www.cve.org/CVERecord?id=CVE-2024-43914'], 'PublishedDate': '2024-08-26T11:15:05.38Z', 'LastModifiedDate': '2024-09-05T18:03:49.997Z'}, {'VulnerabilityID': 'CVE-2024-44931', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44931', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: gpio: prevent potential speculation leaks in gpio_device_get_desc()', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: prevent potential speculation leaks in gpio_device_get_desc()\n\nUserspace may trigger a speculative read of an address outside the gpio\ndescriptor array.\nUsers can do that by calling gpio_ioctl() with an offset out of range.\nOffset is copied from user and then used as an array index to get\nthe gpio descriptor without sanitization in gpio_device_get_desc().\n\nThis change ensures that the offset is sanitized by using\narray_index_nospec() to mitigate any possibility of speculative\ninformation leaks.\n\nThis bug was discovered and resolved using Coverity Static Analysis\nSecurity Testing (SAST) by Synopsys, Inc.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44931', 'https://git.kernel.org/linus/d795848ecce24a75dfd46481aee066ae6fe39775 (6.11-rc1)', 'https://git.kernel.org/stable/c/1b955f786a4bcde8c0ccb2b7d519def2acb6f3cc', 'https://git.kernel.org/stable/c/672c19165fc96dfad531a5458e0b3cdab414aae4', 'https://git.kernel.org/stable/c/9d682e89c44bd5819b01f3fbb45a8e3681a4b6d0', 'https://git.kernel.org/stable/c/c65ab97efcd438cb4e9f299400f2ea55251f3a67', 'https://git.kernel.org/stable/c/d776c0486b03a5c4afca65b8ff44573592bf93bb', 'https://git.kernel.org/stable/c/d795848ecce24a75dfd46481aee066ae6fe39775', 'https://lore.kernel.org/linux-cve-announce/2024082636-CVE-2024-44931-8212@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44931', 'https://www.cve.org/CVERecord?id=CVE-2024-44931'], 'PublishedDate': '2024-08-26T11:15:05.447Z', 'LastModifiedDate': '2024-10-17T14:15:07.39Z'}, {'VulnerabilityID': 'CVE-2024-44932', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44932', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: idpf: fix UAFs when destroying the queues', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix UAFs when destroying the queues\n\nThe second tagged commit started sometimes (very rarely, but possible)\nthrowing WARNs from\nnet/core/page_pool.c:page_pool_disable_direct_recycling().\nTurned out idpf frees interrupt vectors with embedded NAPIs *before*\nfreeing the queues making page_pools' NAPI pointers lead to freed\nmemory before these pools are destroyed by libeth.\nIt's not clear whether there are other accesses to the freed vectors\nwhen destroying the queues, but anyway, we usually free queue/interrupt\nvectors only when the queues are destroyed and the NAPIs are guaranteed\nto not be referenced anywhere.\n\nInvert the allocation and freeing logic making queue/interrupt vectors\nbe allocated first and freed last. Vectors don't require queues to be\npresent, so this is safe. Additionally, this change allows to remove\nthat useless queue->q_vector pointer cleanup, as vectors are still\nvalid when freeing the queues (+ both are freed within one function,\nso it's not clear why nullify the pointers at all).", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44932', 'https://git.kernel.org/linus/290f1c033281c1a502a3cd1c53c3a549259c491f (6.11-rc3)', 'https://git.kernel.org/stable/c/290f1c033281c1a502a3cd1c53c3a549259c491f', 'https://git.kernel.org/stable/c/3cde714b0e77206ed1b5cf31f28c18ba9ae946fd', 'https://lore.kernel.org/linux-cve-announce/2024082638-CVE-2024-44932-2659@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44932', 'https://www.cve.org/CVERecord?id=CVE-2024-44932'], 'PublishedDate': '2024-08-26T11:15:05.5Z', 'LastModifiedDate': '2024-08-27T16:08:45.02Z'}, {'VulnerabilityID': 'CVE-2024-44934', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44934', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: net: bridge: mcast: wait for previous gc cycles when removing port', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: wait for previous gc cycles when removing port\n\nsyzbot hit a use-after-free[1] which is caused because the bridge doesn't\nmake sure that all previous garbage has been collected when removing a\nport. What happens is:\n CPU 1 CPU 2\n start gc cycle remove port\n acquire gc lock first\n wait for lock\n call br_multicasg_gc() directly\n acquire lock now but free port\n the port can be freed\n while grp timers still\n running\n\nMake sure all previous gc cycles have finished by using flush_work before\nfreeing the port.\n\n[1]\n BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699\n\n CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024\n Call Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n call_timer_fn+0x1a3/0x610 kernel/time/timer.c:1792\n expire_timers kernel/time/timer.c:1843 [inline]\n __run_timers+0x74b/0xaf0 kernel/time/timer.c:2417\n __run_timer_base kernel/time/timer.c:2428 [inline]\n __run_timer_base kernel/time/timer.c:2421 [inline]\n run_timer_base+0x111/0x190 kernel/time/timer.c:2437", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44934', 'https://git.kernel.org/linus/92c4ee25208d0f35dafc3213cdf355fbe449e078 (6.11-rc3)', 'https://git.kernel.org/stable/c/0d8b26e10e680c01522d7cc14abe04c3265a928f', 'https://git.kernel.org/stable/c/1e16828020c674b3be85f52685e8b80f9008f50f', 'https://git.kernel.org/stable/c/92c4ee25208d0f35dafc3213cdf355fbe449e078', 'https://git.kernel.org/stable/c/b2f794b168cf560682ff976b255aa6d29d14a658', 'https://git.kernel.org/stable/c/e3145ca904fa8dbfd1a5bf0187905bc117b0efce', 'https://lore.kernel.org/linux-cve-announce/2024082641-CVE-2024-44934-a7fe@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44934', 'https://www.cve.org/CVERecord?id=CVE-2024-44934'], 'PublishedDate': '2024-08-26T11:15:05.593Z', 'LastModifiedDate': '2024-08-27T16:07:58.727Z'}, {'VulnerabilityID': 'CVE-2024-44935', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44935', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sctp: Fix null-ptr-deref in reuseport_add_sock().', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Fix null-ptr-deref in reuseport_add_sock().\n\nsyzbot reported a null-ptr-deref while accessing sk2->sk_reuseport_cb in\nreuseport_add_sock(). [0]\n\nThe repro first creates a listener with SO_REUSEPORT. Then, it creates\nanother listener on the same port and concurrently closes the first\nlistener.\n\nThe second listen() calls reuseport_add_sock() with the first listener as\nsk2, where sk2->sk_reuseport_cb is not expected to be cleared concurrently,\nbut the close() does clear it by reuseport_detach_sock().\n\nThe problem is SCTP does not properly synchronise reuseport_alloc(),\nreuseport_add_sock(), and reuseport_detach_sock().\n\nThe caller of reuseport_alloc() and reuseport_{add,detach}_sock() must\nprovide synchronisation for sockets that are classified into the same\nreuseport group.\n\nOtherwise, such sockets form multiple identical reuseport groups, and\nall groups except one would be silently dead.\n\n 1. Two sockets call listen() concurrently\n 2. No socket in the same group found in sctp_ep_hashtable[]\n 3. Two sockets call reuseport_alloc() and form two reuseport groups\n 4. Only one group hit first in __sctp_rcv_lookup_endpoint() receives\n incoming packets\n\nAlso, the reported null-ptr-deref could occur.\n\nTCP/UDP guarantees that would not happen by holding the hash bucket lock.\n\nLet's apply the locking strategy to __sctp_hash_endpoint() and\n__sctp_unhash_endpoint().\n\n[0]:\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nCPU: 1 UID: 0 PID: 10230 Comm: syz-executor119 Not tainted 6.10.0-syzkaller-12585-g301927d2d2eb #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024\nRIP: 0010:reuseport_add_sock+0x27e/0x5e0 net/core/sock_reuseport.c:350\nCode: 00 0f b7 5d 00 bf 01 00 00 00 89 de e8 1b a4 ff f7 83 fb 01 0f 85 a3 01 00 00 e8 6d a0 ff f7 49 8d 7e 12 48 89 f8 48 c1 e8 03 <42> 0f b6 04 28 84 c0 0f 85 4b 02 00 00 41 0f b7 5e 12 49 8d 7e 14\nRSP: 0018:ffffc9000b947c98 EFLAGS: 00010202\nRAX: 0000000000000002 RBX: ffff8880252ddf98 RCX: ffff888079478000\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000012\nRBP: 0000000000000001 R08: ffffffff8993e18d R09: 1ffffffff1fef385\nR10: dffffc0000000000 R11: fffffbfff1fef386 R12: ffff8880252ddac0\nR13: dffffc0000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f24e45b96c0(0000) GS:ffff8880b9300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffcced5f7b8 CR3: 00000000241be000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __sctp_hash_endpoint net/sctp/input.c:762 [inline]\n sctp_hash_endpoint+0x52a/0x600 net/sctp/input.c:790\n sctp_listen_start net/sctp/socket.c:8570 [inline]\n sctp_inet_listen+0x767/0xa20 net/sctp/socket.c:8625\n __sys_listen_socket net/socket.c:1883 [inline]\n __sys_listen+0x1b7/0x230 net/socket.c:1894\n __do_sys_listen net/socket.c:1902 [inline]\n __se_sys_listen net/socket.c:1900 [inline]\n __x64_sys_listen+0x5a/0x70 net/socket.c:1900\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f24e46039b9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 91 1a 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f24e45b9228 EFLAGS: 00000246 ORIG_RAX: 0000000000000032\nRAX: ffffffffffffffda RBX: 00007f24e468e428 RCX: 00007f24e46039b9\nRDX: 00007f24e46039b9 RSI: 0000000000000003 RDI: 0000000000000004\nRBP: 00007f24e468e420 R08: 00007f24e45b96c0 R09: 00007f24e45b96c0\nR10: 00007f24e45b96c0 R11: 0000000000000246 R12: 00007f24e468e42c\nR13:\n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44935', 'https://git.kernel.org/linus/9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18 (6.11-rc3)', 'https://git.kernel.org/stable/c/05e4a0fa248240efd99a539853e844f0f0a9e6a5', 'https://git.kernel.org/stable/c/1407be30fc17eff918a98e0a990c0e988f11dc84', 'https://git.kernel.org/stable/c/52319d9d2f522ed939af31af70f8c3a0f0f67e6c', 'https://git.kernel.org/stable/c/54b303d8f9702b8ab618c5032fae886b16356928', 'https://git.kernel.org/stable/c/9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18', 'https://git.kernel.org/stable/c/c9b3fc4f157867e858734e31022ebee8a24f0de7', 'https://git.kernel.org/stable/c/e809a84c802377ef61525a298a1ec1728759b913', 'https://linux.oracle.com/cve/CVE-2024-44935.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024082642-CVE-2024-44935-3452@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44935', 'https://www.cve.org/CVERecord?id=CVE-2024-44935'], 'PublishedDate': '2024-08-26T11:15:05.643Z', 'LastModifiedDate': '2024-08-27T16:09:01.633Z'}, {'VulnerabilityID': 'CVE-2024-44937', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44937', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: platform/x86: intel-vbtn: Protect ACPI notify handler against recursion', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: intel-vbtn: Protect ACPI notify handler against recursion\n\nSince commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on\nall CPUs") ACPI notify handlers like the intel-vbtn notify_handler() may\nrun on multiple CPU cores racing with themselves.\n\nThis race gets hit on Dell Venue 7140 tablets when undocking from\nthe keyboard, causing the handler to try and register priv->switches_dev\ntwice, as can be seen from the dev_info() message getting logged twice:\n\n[ 83.861800] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n[ 83.861858] input: Intel Virtual Switches as /devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\n[ 83.861865] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n\nAfter which things go seriously wrong:\n[ 83.861872] sysfs: cannot create duplicate filename \'/devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\'\n...\n[ 83.861967] kobject: kobject_add_internal failed for input17 with -EEXIST, don\'t try to register things with the same name in the same directory.\n[ 83.877338] BUG: kernel NULL pointer dereference, address: 0000000000000018\n...\n\nProtect intel-vbtn notify_handler() from racing with itself with a mutex\nto fix this.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44937', 'https://git.kernel.org/linus/e075c3b13a0a142dcd3151b25d29a24f31b7b640 (6.11-rc3)', 'https://git.kernel.org/stable/c/5c9618a3b6ea94cf7bdff7702aca8bf2d777d97b', 'https://git.kernel.org/stable/c/e075c3b13a0a142dcd3151b25d29a24f31b7b640', 'https://lore.kernel.org/linux-cve-announce/2024082645-CVE-2024-44937-5c1d@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44937', 'https://www.cve.org/CVERecord?id=CVE-2024-44937'], 'PublishedDate': '2024-08-26T11:15:05.753Z', 'LastModifiedDate': '2024-08-27T16:10:11.423Z'}, {'VulnerabilityID': 'CVE-2024-44938', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44938', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: jfs: Fix shift-out-of-bounds in dbDiscardAG', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix shift-out-of-bounds in dbDiscardAG\n\nWhen searching for the next smaller log2 block, BLKSTOL2() returned 0,\ncausing shift exponent -1 to be negative.\n\nThis patch fixes the issue by exiting the loop directly when negative\nshift is found.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-787'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44938', 'https://git.kernel.org/linus/7063b80268e2593e58bee8a8d709c2f3ff93e2f2 (6.11-rc1)', 'https://git.kernel.org/stable/c/234e6ea0855cdb5673d54ecaf7dc5c78f3e84630', 'https://git.kernel.org/stable/c/7063b80268e2593e58bee8a8d709c2f3ff93e2f2', 'https://git.kernel.org/stable/c/bd04a149e3a29e7f71b7956ed41dba34e42d539e', 'https://git.kernel.org/stable/c/f650148b43949ca9e37e820804bb6026fff404f3', 'https://lore.kernel.org/linux-cve-announce/2024082616-CVE-2024-44938-fc08@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44938', 'https://www.cve.org/CVERecord?id=CVE-2024-44938'], 'PublishedDate': '2024-08-26T12:15:05.96Z', 'LastModifiedDate': '2024-09-12T14:05:44.31Z'}, {'VulnerabilityID': 'CVE-2024-44939', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44939', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: jfs: fix null ptr deref in dtInsertEntry', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix null ptr deref in dtInsertEntry\n\n[syzbot reported]\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nRIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713\n...\n[Analyze]\nIn dtInsertEntry(), when the pointer h has the same value as p, after writing\nname in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the\npreviously true judgment "p->header.flag & BT-LEAF" to change to no after writing\nthe name operation, this leads to entering an incorrect branch and accessing the\nuninitialized object ih when judging this condition for the second time.\n\n[Fix]\nAfter got the page, check freelist first, if freelist == 0 then exit dtInsert()\nand return -EINVAL.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44939', 'https://git.kernel.org/linus/ce6dede912f064a855acf6f04a04cbb2c25b8c8c (6.11-rc1)', 'https://git.kernel.org/stable/c/53023ab11836ac56fd75f7a71ec1356e50920fa9', 'https://git.kernel.org/stable/c/6ea10dbb1e6c58384136e9adfd75f81951e423f6', 'https://git.kernel.org/stable/c/9c2ac38530d1a3ee558834dfa16c85a40fd0e702', 'https://git.kernel.org/stable/c/ce6dede912f064a855acf6f04a04cbb2c25b8c8c', 'https://lore.kernel.org/linux-cve-announce/2024082619-CVE-2024-44939-cf96@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44939', 'https://www.cve.org/CVERecord?id=CVE-2024-44939'], 'PublishedDate': '2024-08-26T12:15:06.007Z', 'LastModifiedDate': '2024-09-12T20:58:03.783Z'}, {'VulnerabilityID': 'CVE-2024-44940', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44940', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fou: remove warn in gue_gro_receive on unsupported protocol', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfou: remove warn in gue_gro_receive on unsupported protocol\n\nDrop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is\nnot known or does not have a GRO handler.\n\nSuch a packet is easily constructed. Syzbot generates them and sets\noff this warning.\n\nRemove the warning as it is expected and not actionable.\n\nThe warning was previously reduced from WARN_ON to WARN_ON_ONCE in\ncommit 270136613bf7 ("fou: Do WARN_ON_ONCE in gue_gro_receive for bad\nproto callbacks").', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44940', 'https://git.kernel.org/linus/dd89a81d850fa9a65f67b4527c0e420d15bf836c (6.11-rc1)', 'https://git.kernel.org/stable/c/3db4395332e7050ef9ddeb3052e6b5019f2a2a59', 'https://git.kernel.org/stable/c/440ab7f97261bc28501636a13998e1b1946d2e79', 'https://git.kernel.org/stable/c/5a2e37bc648a2503bf6d687aed27b9f4455d82eb', 'https://git.kernel.org/stable/c/dd89a81d850fa9a65f67b4527c0e420d15bf836c', 'https://lore.kernel.org/linux-cve-announce/2024082619-CVE-2024-44940-249f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44940', 'https://ubuntu.com/security/notices/USN-7069-1', 'https://ubuntu.com/security/notices/USN-7069-2', 'https://www.cve.org/CVERecord?id=CVE-2024-44940'], 'PublishedDate': '2024-08-26T12:15:06.053Z', 'LastModifiedDate': '2024-09-12T14:10:00.857Z'}, {'VulnerabilityID': 'CVE-2024-44941', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44941', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to cover read extent cache access with lock', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to cover read extent cache access with lock\n\nsyzbot reports a f2fs bug as below:\n\nBUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\nRead of size 4 at addr ffff8880739ab220 by task syz-executor200/5097\n\nCPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\n do_read_inode fs/f2fs/inode.c:509 [inline]\n f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560\n f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237\n generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413\n exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444\n exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584\n do_handle_to_path fs/fhandle.c:155 [inline]\n handle_to_path fs/fhandle.c:210 [inline]\n do_handle_open+0x495/0x650 fs/fhandle.c:226\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWe missed to cover sanity_check_extent_cache() w/ extent cache lock,\nso, below race case may happen, result in use after free issue.\n\n- f2fs_iget\n - do_read_inode\n - f2fs_init_read_extent_tree\n : add largest extent entry in to cache\n\t\t\t\t\t- shrink\n\t\t\t\t\t - f2fs_shrink_read_extent_tree\n\t\t\t\t\t - __shrink_extent_tree\n\t\t\t\t\t - __detach_extent_node\n\t\t\t\t\t : drop largest extent entry\n - sanity_check_extent_cache\n : access et->largest w/o lock\n\nlet's refactor sanity_check_extent_cache() to avoid extent cache access\nand call it before f2fs_init_read_extent_tree() to fix this issue.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44941', 'https://git.kernel.org/linus/d7409b05a64f212735f0d33f5f1602051a886eab (6.11-rc1)', 'https://git.kernel.org/stable/c/263df78166d3a9609b97d28c34029bd01874cbb8', 'https://git.kernel.org/stable/c/323ef20b5558b9d9fd10c1224327af6f11a8177d', 'https://git.kernel.org/stable/c/d7409b05a64f212735f0d33f5f1602051a886eab', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-44941-143e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44941', 'https://www.cve.org/CVERecord?id=CVE-2024-44941'], 'PublishedDate': '2024-08-26T12:15:06.107Z', 'LastModifiedDate': '2024-09-12T20:57:26.143Z'}, {'VulnerabilityID': 'CVE-2024-44942', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44942', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/inline.c:258!\nCPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0\nRIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258\nCall Trace:\n f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834\n f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315\n do_writepages+0x35b/0x870 mm/page-writeback.c:2612\n __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650\n writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941\n wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117\n wb_do_writeback fs/fs-writeback.c:2264 [inline]\n wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335\n worker_thread+0x86d/0xd70 kernel/workqueue.c:3416\n kthread+0x2f2/0x390 kernel/kthread.c:388\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nThe root cause is: inline_data inode can be fuzzed, so that there may\nbe valid blkaddr in its direct node, once f2fs triggers background GC\nto migrate the block, it will hit f2fs_bug_on() during dirty page\nwriteback.\n\nLet's add sanity check on F2FS_INLINE_DATA flag in inode during GC,\nso that, it can forbid migrating inline_data inode's data block for\nfixing.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44942', 'https://git.kernel.org/linus/fc01008c92f40015aeeced94750855a7111b6929 (6.11-rc1)', 'https://git.kernel.org/stable/c/26c07775fb5dc74351d1c3a2bc3cdf609b03e49f', 'https://git.kernel.org/stable/c/ae00e6536a2dd54b64b39e9a39548870cf835745', 'https://git.kernel.org/stable/c/fc01008c92f40015aeeced94750855a7111b6929', 'https://lore.kernel.org/linux-cve-announce/2024082620-CVE-2024-44942-651a@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44942', 'https://www.cve.org/CVERecord?id=CVE-2024-44942'], 'PublishedDate': '2024-08-26T12:15:06.157Z', 'LastModifiedDate': '2024-08-27T16:09:10.01Z'}, {'VulnerabilityID': 'CVE-2024-44943', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44943', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'In the Linux kernel, the following vulnerability has been resolved: m ...', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: gup: stop abusing try_grab_folio\n\nA kernel warning was reported when pinning folio in CMA memory when\nlaunching SEV virtual machine. The splat looks like:\n\n[ 464.325306] WARNING: CPU: 13 PID: 6734 at mm/gup.c:1313 __get_user_pages+0x423/0x520\n[ 464.325464] CPU: 13 PID: 6734 Comm: qemu-kvm Kdump: loaded Not tainted 6.6.33+ #6\n[ 464.325477] RIP: 0010:__get_user_pages+0x423/0x520\n[ 464.325515] Call Trace:\n[ 464.325520] \n[ 464.325523] ? __get_user_pages+0x423/0x520\n[ 464.325528] ? __warn+0x81/0x130\n[ 464.325536] ? __get_user_pages+0x423/0x520\n[ 464.325541] ? report_bug+0x171/0x1a0\n[ 464.325549] ? handle_bug+0x3c/0x70\n[ 464.325554] ? exc_invalid_op+0x17/0x70\n[ 464.325558] ? asm_exc_invalid_op+0x1a/0x20\n[ 464.325567] ? __get_user_pages+0x423/0x520\n[ 464.325575] __gup_longterm_locked+0x212/0x7a0\n[ 464.325583] internal_get_user_pages_fast+0xfb/0x190\n[ 464.325590] pin_user_pages_fast+0x47/0x60\n[ 464.325598] sev_pin_memory+0xca/0x170 [kvm_amd]\n[ 464.325616] sev_mem_enc_register_region+0x81/0x130 [kvm_amd]\n\nPer the analysis done by yangge, when starting the SEV virtual machine, it\nwill call pin_user_pages_fast(..., FOLL_LONGTERM, ...) to pin the memory. \nBut the page is in CMA area, so fast GUP will fail then fallback to the\nslow path due to the longterm pinnalbe check in try_grab_folio().\n\nThe slow path will try to pin the pages then migrate them out of CMA area.\nBut the slow path also uses try_grab_folio() to pin the page, it will\nalso fail due to the same check then the above warning is triggered.\n\nIn addition, the try_grab_folio() is supposed to be used in fast path and\nit elevates folio refcount by using add ref unless zero. We are guaranteed\nto have at least one stable reference in slow path, so the simple atomic add\ncould be used. The performance difference should be trivial, but the\nmisuse may be confusing and misleading.\n\nRedefined try_grab_folio() to try_grab_folio_fast(), and try_grab_page()\nto try_grab_folio(), and use them in the proper paths. This solves both\nthe abuse and the kernel warning.\n\nThe proper naming makes their usecase more clear and should prevent from\nabusing in the future.\n\npeterx said:\n\n: The user will see the pin fails, for gpu-slow it further triggers the WARN\n: right below that failure (as in the original report):\n: \n: folio = try_grab_folio(page, page_increm - 1,\n: foll_flags);\n: if (WARN_ON_ONCE(!folio)) { <------------------------ here\n: /*\n: * Release the 1st page ref if the\n: * folio is problematic, fail hard.\n: */\n: gup_put_folio(page_folio(page), 1,\n: foll_flags);\n: ret = -EFAULT;\n: goto out;\n: }\n\n[1] https://lore.kernel.org/linux-mm/1719478388-31917-1-git-send-email-yangge1116@126.com/\n\n[shy828301@gmail.com: fix implicit declaration of function try_grab_folio_fast]\n Link: https://lkml.kernel.org/r/CAHbLzkowMSso-4Nufc9hcMehQsK9PNz3OSu-+eniU-2Mm-xjhA@mail.gmail.com', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44943', 'https://git.kernel.org/linus/f442fa6141379a20b48ae3efabee827a3d260787 (6.10)', 'https://git.kernel.org/stable/c/26273f5f4cf68b29414e403837093408a9c98e1f', 'https://git.kernel.org/stable/c/f442fa6141379a20b48ae3efabee827a3d260787', 'https://lore.kernel.org/linux-cve-announce/2024082853-CVE-2024-44943-234f@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44943', 'https://www.cve.org/CVERecord?id=CVE-2024-44943'], 'PublishedDate': '2024-08-28T08:15:06.963Z', 'LastModifiedDate': '2024-09-10T18:12:43.38Z'}, {'VulnerabilityID': 'CVE-2024-44944', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44944', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: netfilter: ctnetlink: use helper function to calculate expect ID', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: use helper function to calculate expect ID\n\nDelete expectation path is missing a call to the nf_expect_get_id()\nhelper function to calculate the expectation ID, otherwise LSB of the\nexpectation object address is leaked to userspace.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-401'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44944', 'https://git.kernel.org/linus/782161895eb4ac45cf7cfa8db375bd4766cb8299 (6.11-rc1)', 'https://git.kernel.org/stable/c/24f407042cf90b0872de667460230d8d50c06c39', 'https://git.kernel.org/stable/c/27662b46f2adaa52c1665a82af4b21c42c4337fd', 'https://git.kernel.org/stable/c/5e2c24f7b0911b15c29aefce760bcf770542fb61', 'https://git.kernel.org/stable/c/64c0b8e64be8368617ef08dfc59a3160563a1435', 'https://git.kernel.org/stable/c/66e7650dbbb8e236e781c670b167edc81e771450', 'https://git.kernel.org/stable/c/74de442b8e12a207c07953ee068009a7701aff8f', 'https://git.kernel.org/stable/c/782161895eb4ac45cf7cfa8db375bd4766cb8299', 'https://git.kernel.org/stable/c/eb4ca1a97e08ff5b920664ba292e576257e2d184', 'https://linux.oracle.com/cve/CVE-2024-44944.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024083044-CVE-2024-44944-56c0@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44944', 'https://www.cve.org/CVERecord?id=CVE-2024-44944', 'https://www.zerodayinitiative.com/advisories/ZDI-24-1182/'], 'PublishedDate': '2024-08-30T08:15:04.58Z', 'LastModifiedDate': '2024-09-10T08:15:03.23Z'}, {'VulnerabilityID': 'CVE-2024-44946', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44946', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: kcm: Serialise kcm_sendmsg() for the same socket.', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: Serialise kcm_sendmsg() for the same socket.\n\nsyzkaller reported UAF in kcm_release(). [0]\n\nThe scenario is\n\n 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb.\n\n 2. Thread A resumes building skb from kcm->seq_skb but is blocked\n by sk_stream_wait_memory()\n\n 3. Thread B calls sendmsg() concurrently, finishes building kcm->seq_skb\n and puts the skb to the write queue\n\n 4. Thread A faces an error and finally frees skb that is already in the\n write queue\n\n 5. kcm_release() does double-free the skb in the write queue\n\nWhen a thread is building a MSG_MORE skb, another thread must not touch it.\n\nLet's add a per-sk mutex and serialise kcm_sendmsg().\n\n[0]:\nBUG: KASAN: slab-use-after-free in __skb_unlink include/linux/skbuff.h:2366 [inline]\nBUG: KASAN: slab-use-after-free in __skb_dequeue include/linux/skbuff.h:2385 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\nBUG: KASAN: slab-use-after-free in __skb_queue_purge include/linux/skbuff.h:3181 [inline]\nBUG: KASAN: slab-use-after-free in kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\nRead of size 8 at addr ffff0000ced0fc80 by task syz-executor329/6167\n\nCPU: 1 PID: 6167 Comm: syz-executor329 Tainted: G B 6.8.0-rc5-syzkaller-g9abbc24128bc #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nCall trace:\n dump_backtrace+0x1b8/0x1e4 arch/arm64/kernel/stacktrace.c:291\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:298\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd0/0x124 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x178/0x518 mm/kasan/report.c:488\n kasan_report+0xd8/0x138 mm/kasan/report.c:601\n __asan_report_load8_noabort+0x20/0x2c mm/kasan/report_generic.c:381\n __skb_unlink include/linux/skbuff.h:2366 [inline]\n __skb_dequeue include/linux/skbuff.h:2385 [inline]\n __skb_queue_purge_reason include/linux/skbuff.h:3175 [inline]\n __skb_queue_purge include/linux/skbuff.h:3181 [inline]\n kcm_release+0x170/0x4c8 net/kcm/kcmsock.c:1691\n __sock_release net/socket.c:659 [inline]\n sock_close+0xa4/0x1e8 net/socket.c:1421\n __fput+0x30c/0x738 fs/file_table.c:376\n ____fput+0x20/0x30 fs/file_table.c:404\n task_work_run+0x230/0x2e0 kernel/task_work.c:180\n exit_task_work include/linux/task_work.h:38 [inline]\n do_exit+0x618/0x1f64 kernel/exit.c:871\n do_group_exit+0x194/0x22c kernel/exit.c:1020\n get_signal+0x1500/0x15ec kernel/signal.c:2893\n do_signal+0x23c/0x3b44 arch/arm64/kernel/signal.c:1249\n do_notify_resume+0x74/0x1f4 arch/arm64/kernel/entry-common.c:148\n exit_to_user_mode_prepare arch/arm64/kernel/entry-common.c:169 [inline]\n exit_to_user_mode arch/arm64/kernel/entry-common.c:178 [inline]\n el0_svc+0xac/0x168 arch/arm64/kernel/entry-common.c:713\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\n\nAllocated by task 6166:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x70/0x84 mm/kasan/generic.c:626\n unpoison_slab_object mm/kasan/common.c:314 [inline]\n __kasan_slab_alloc+0x74/0x8c mm/kasan/common.c:340\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3813 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_node+0x204/0x4c0 mm/slub.c:3903\n __alloc_skb+0x19c/0x3d8 net/core/skbuff.c:641\n alloc_skb include/linux/skbuff.h:1296 [inline]\n kcm_sendmsg+0x1d3c/0x2124 net/kcm/kcmsock.c:783\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n sock_sendmsg+0x220/0x2c0 net/socket.c:768\n splice_to_socket+0x7cc/0xd58 fs/splice.c:889\n do_splice_from fs/splice.c:941 [inline]\n direct_splice_actor+0xec/0x1d8 fs/splice.c:1164\n splice_direct_to_actor+0x438/0xa0c fs/splice.c:1108\n do_splice_direct_actor \n---truncated---", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-416'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44946', 'https://git.kernel.org/linus/807067bf014d4a3ae2cc55bd3de16f22a01eb580 (6.11-rc5)', 'https://git.kernel.org/stable/c/00425508f30baa5ab6449a1f478480ca7cffa6da', 'https://git.kernel.org/stable/c/6633b17840bf828921254d788ccd15602843fe9b', 'https://git.kernel.org/stable/c/72da240aafb142630cf16adc803ccdacb3780849', 'https://git.kernel.org/stable/c/807067bf014d4a3ae2cc55bd3de16f22a01eb580', 'https://git.kernel.org/stable/c/8c9cdbf600143bd6835c8b8351e5ac956da79aec', 'https://git.kernel.org/stable/c/9c8d544ed619f704e2b70e63e08ab75630c2ea23', 'https://git.kernel.org/stable/c/eb06c8d3022ce6738711191c89f9b3e9cfb91914', 'https://git.kernel.org/stable/c/fa6c23fe6dcac8c8bd63920ee8681292a2bd544e', 'https://lore.kernel.org/linux-cve-announce/2024083150-CVE-2024-44946-9cf1@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44946', 'https://www.cve.org/CVERecord?id=CVE-2024-44946'], 'PublishedDate': '2024-08-31T14:15:04.32Z', 'LastModifiedDate': '2024-09-04T12:15:05.15Z'}, {'VulnerabilityID': 'CVE-2024-44947', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44947', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: fuse: Initialize beyond-EOF page contents before setting uptodate', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: Initialize beyond-EOF page contents before setting uptodate\n\nfuse_notify_store(), unlike fuse_do_readpage(), does not enable page\nzeroing (because it can be used to change partial page contents).\n\nSo fuse_notify_store() must be more careful to fully initialize page\ncontents (including parts of the page that are beyond end-of-file)\nbefore marking the page uptodate.\n\nThe current code can leave beyond-EOF page contents uninitialized, which\nmakes these uninitialized page contents visible to userspace via mmap().\n\nThis is an information leak, but only affects systems which do not\nenable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the\ncorresponding kernel command line parameter).', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-665'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44947', 'https://git.kernel.org/stable/c/18a067240817bee8a9360539af5d79a4bf5398a5', 'https://git.kernel.org/stable/c/33168db352c7b56ae18aa55c2cae1a1c5905d30e', 'https://git.kernel.org/stable/c/3c0da3d163eb32f1f91891efaade027fa9b245b9', 'https://git.kernel.org/stable/c/4690e2171f651e2b415e3941ce17f2f7b813aff6', 'https://git.kernel.org/stable/c/49934861514d36d0995be8e81bb3312a499d8d9a', 'https://git.kernel.org/stable/c/831433527773e665bdb635ab5783d0b95d1246f4', 'https://git.kernel.org/stable/c/8c78303eafbf85a728dd84d1750e89240c677dd9', 'https://git.kernel.org/stable/c/ac42e0f0eb66af966015ee33fd355bc6f5d80cd6', 'https://lore.kernel.org/linux-cve-announce/2024090219-CVE-2024-44947-f49c@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44947', 'https://www.cve.org/CVERecord?id=CVE-2024-44947'], 'PublishedDate': '2024-09-02T18:15:36.577Z', 'LastModifiedDate': '2024-09-16T17:52:37.563Z'}, {'VulnerabilityID': 'CVE-2024-44948', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44948', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: x86/mtrr: Check if fixed MTRRs exist before saving them', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mtrr: Check if fixed MTRRs exist before saving them\n\nMTRRs have an obsolete fixed variant for fine grained caching control\nof the 640K-1MB region that uses separate MSRs. This fixed variant has\na separate capability bit in the MTRR capability MSR.\n\nSo far all x86 CPUs which support MTRR have this separate bit set, so it\nwent unnoticed that mtrr_save_state() does not check the capability bit\nbefore accessing the fixed MTRR MSRs.\n\nThough on a CPU that does not support the fixed MTRR capability this\nresults in a #GP. The #GP itself is harmless because the RDMSR fault is\nhandled gracefully, but results in a WARN_ON().\n\nAdd the missing capability check to prevent this.', 'Severity': 'MEDIUM', 'CVSS': {'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44948', 'https://git.kernel.org/linus/919f18f961c03d6694aa726c514184f2311a4614 (6.11-rc3)', 'https://git.kernel.org/stable/c/06c1de44d378ec5439db17bf476507d68589bfe9', 'https://git.kernel.org/stable/c/34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e', 'https://git.kernel.org/stable/c/388f1c954019f253a8383f7eb733f38d541e10b6', 'https://git.kernel.org/stable/c/450b6b22acdaac67a18eaf5ed498421ffcf10051', 'https://git.kernel.org/stable/c/8a90d3fc7c24608548d3a750671f9dac21d1a462', 'https://git.kernel.org/stable/c/8aa79dfb216b865e96ff890bc4ea71650f9bc8d7', 'https://git.kernel.org/stable/c/919f18f961c03d6694aa726c514184f2311a4614', 'https://git.kernel.org/stable/c/ca7d00c5656d1791e28369919e3e10febe9c3b16', 'https://linux.oracle.com/cve/CVE-2024-44948.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090407-CVE-2024-44948-5554@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44948', 'https://www.cve.org/CVERecord?id=CVE-2024-44948'], 'PublishedDate': '2024-09-04T19:15:29.95Z', 'LastModifiedDate': '2024-09-05T12:53:21.11Z'}, {'VulnerabilityID': 'CVE-2024-44949', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44949', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: parisc: fix a possible DMA corruption', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: fix a possible DMA corruption\n\nARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be\npossible that two unrelated 16-byte allocations share a cache line. If\none of these allocations is written using DMA and the other is written\nusing cached write, the value that was written with DMA may be\ncorrupted.\n\nThis commit changes ARCH_DMA_MINALIGN to be 128 on PA20 and 32 on PA1.1 -\nthat's the largest possible cache line size.\n\nAs different parisc microarchitectures have different cache line size, we\ndefine arch_slab_minalign(), cache_line_size() and\ndma_get_cache_alignment() so that the kernel may tune slab cache\nparameters dynamically, based on the detected cache line size.", 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'V3Score': 7.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44949', 'https://git.kernel.org/linus/7ae04ba36b381bffe2471eff3a93edced843240f (6.11-rc2)', 'https://git.kernel.org/stable/c/533de2f470baac40d3bf622fe631f15231a03c9f', 'https://git.kernel.org/stable/c/642a0b7453daff0295310774016fcb56d1f5bc7f', 'https://git.kernel.org/stable/c/7ae04ba36b381bffe2471eff3a93edced843240f', 'https://lore.kernel.org/linux-cve-announce/2024090410-CVE-2024-44949-8f05@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44949', 'https://www.cve.org/CVERecord?id=CVE-2024-44949'], 'PublishedDate': '2024-09-04T19:15:30.04Z', 'LastModifiedDate': '2024-10-09T13:53:32.513Z'}, {'VulnerabilityID': 'CVE-2024-44950', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44950', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: sc16is7xx: fix invalid FIFO access with special register set', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix invalid FIFO access with special register set\n\nWhen enabling access to the special register set, Receiver time-out and\nRHR interrupts can happen. In this case, the IRQ handler will try to read\nfrom the FIFO thru the RHR register at address 0x00, but address 0x00 is\nmapped to DLL register, resulting in erroneous FIFO reading.\n\nCall graph example:\n sc16is7xx_startup(): entry\n sc16is7xx_ms_proc(): entry\n sc16is7xx_set_termios(): entry\n sc16is7xx_set_baud(): DLH/DLL = $009C --> access special register set\n sc16is7xx_port_irq() entry --> IIR is 0x0C\n sc16is7xx_handle_rx() entry\n sc16is7xx_fifo_read(): --> unable to access FIFO (RHR) because it is\n mapped to DLL (LCR=LCR_CONF_MODE_A)\n sc16is7xx_set_baud(): exit --> Restore access to general register set\n\nFix the problem by claiming the efr_lock mutex when accessing the Special\nregister set.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H', 'V3Score': 5.6}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44950', 'https://git.kernel.org/linus/7d3b793faaab1305994ce568b59d61927235f57b (6.11-rc3)', 'https://git.kernel.org/stable/c/6a6730812220a9a5ce4003eb347da1ee5abd06b0', 'https://git.kernel.org/stable/c/7d3b793faaab1305994ce568b59d61927235f57b', 'https://lore.kernel.org/linux-cve-announce/2024090410-CVE-2024-44950-67fb@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44950', 'https://www.cve.org/CVERecord?id=CVE-2024-44950'], 'PublishedDate': '2024-09-04T19:15:30.1Z', 'LastModifiedDate': '2024-10-09T14:21:16.773Z'}, {'VulnerabilityID': 'CVE-2024-44951', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44951', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: serial: sc16is7xx: fix TX fifo corruption', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix TX fifo corruption\n\nSometimes, when a packet is received on channel A at almost the same time\nas a packet is about to be transmitted on channel B, we observe with a\nlogic analyzer that the received packet on channel A is transmitted on\nchannel B. In other words, the Tx buffer data on channel B is corrupted\nwith data from channel A.\n\nThe problem appeared since commit 4409df5866b7 ("serial: sc16is7xx: change\nEFR lock to operate on each channels"), which changed the EFR locking to\noperate on each channel instead of chip-wise.\n\nThis commit has introduced a regression, because the EFR lock is used not\nonly to protect the EFR registers access, but also, in a very obscure and\nundocumented way, to protect access to the data buffer, which is shared by\nthe Tx and Rx handlers, but also by each channel of the IC.\n\nFix this regression first by switching to kfifo_out_linear_ptr() in\nsc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer.\n\nSecondly, replace the chip-wise Rx buffer with a separate Rx buffer for\neach channel.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'V3Score': 7.8}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L', 'V3Score': 5.1}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44951', 'https://git.kernel.org/linus/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4 (6.11-rc3)', 'https://git.kernel.org/stable/c/09cfe05e9907f3276887a20e267cc40e202f4fdd', 'https://git.kernel.org/stable/c/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44951-9121@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44951', 'https://www.cve.org/CVERecord?id=CVE-2024-44951'], 'PublishedDate': '2024-09-04T19:15:30.153Z', 'LastModifiedDate': '2024-10-09T14:27:43.973Z'}, {'VulnerabilityID': 'CVE-2024-44952', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44952', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: driver core: Fix uevent_show() vs driver detach race', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: Fix uevent_show() vs driver detach race\n\nuevent_show() wants to de-reference dev->driver->name. There is no clean\nway for a device attribute to de-reference dev->driver unless that\nattribute is defined via (struct device_driver).dev_groups. Instead, the\nanti-pattern of taking the device_lock() in the attribute handler risks\ndeadlocks with code paths that remove device attributes while holding\nthe lock.\n\nThis deadlock is typically invisible to lockdep given the device_lock()\nis marked lockdep_set_novalidate_class(), but some subsystems allocate a\nlocal lockdep key for @dev->mutex to reveal reports of the form:\n\n ======================================================\n WARNING: possible circular locking dependency detected\n 6.10.0-rc7+ #275 Tainted: G OE N\n ------------------------------------------------------\n modprobe/2374 is trying to acquire lock:\n ffff8c2270070de0 (kn->active#6){++++}-{0:0}, at: __kernfs_remove+0xde/0x220\n\n but task is already holding lock:\n ffff8c22016e88f8 (&cxl_root_key){+.+.}-{3:3}, at: device_release_driver_internal+0x39/0x210\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #1 (&cxl_root_key){+.+.}-{3:3}:\n __mutex_lock+0x99/0xc30\n uevent_show+0xac/0x130\n dev_attr_show+0x18/0x40\n sysfs_kf_seq_show+0xac/0xf0\n seq_read_iter+0x110/0x450\n vfs_read+0x25b/0x340\n ksys_read+0x67/0xf0\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n -> #0 (kn->active#6){++++}-{0:0}:\n __lock_acquire+0x121a/0x1fa0\n lock_acquire+0xd6/0x2e0\n kernfs_drain+0x1e9/0x200\n __kernfs_remove+0xde/0x220\n kernfs_remove_by_name_ns+0x5e/0xa0\n device_del+0x168/0x410\n device_unregister+0x13/0x60\n devres_release_all+0xb8/0x110\n device_unbind_cleanup+0xe/0x70\n device_release_driver_internal+0x1c7/0x210\n driver_detach+0x47/0x90\n bus_remove_driver+0x6c/0xf0\n cxl_acpi_exit+0xc/0x11 [cxl_acpi]\n __do_sys_delete_module.isra.0+0x181/0x260\n do_syscall_64+0x75/0x190\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe observation though is that driver objects are typically much longer\nlived than device objects. It is reasonable to perform lockless\nde-reference of a @driver pointer even if it is racing detach from a\ndevice. Given the infrequency of driver unregistration, use\nsynchronize_rcu() in module_remove_driver() to close any potential\nraces. It is potentially overkill to suffer synchronize_rcu() just to\nhandle the rare module removal racing uevent_show() event.\n\nThanks to Tetsuo Handa for the debug analysis of the syzbot report [1].', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44952', 'https://git.kernel.org/linus/15fffc6a5624b13b428bb1c6e9088e32a55eb82c (6.11-rc3)', 'https://git.kernel.org/stable/c/15fffc6a5624b13b428bb1c6e9088e32a55eb82c', 'https://git.kernel.org/stable/c/49ea4e0d862632d51667da5e7a9c88a560e9c5a1', 'https://git.kernel.org/stable/c/4a7c2a8387524942171037e70b80e969c3b5c05b', 'https://git.kernel.org/stable/c/4d035c743c3e391728a6f81cbf0f7f9ca700cf62', 'https://git.kernel.org/stable/c/9c23fc327d6ec67629b4ad323bd64d3834c0417d', 'https://git.kernel.org/stable/c/cd490a247ddf325325fd0de8898659400c9237ef', 'https://git.kernel.org/stable/c/dd98c9630b7ee273da87e9a244f94ddf947161e2', 'https://git.kernel.org/stable/c/f098e8fc7227166206256c18d56ab622039108b1', 'https://linux.oracle.com/cve/CVE-2024-44952.html', 'https://linux.oracle.com/errata/ELSA-2024-12779.html', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44952-6290@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44952', 'https://www.cve.org/CVERecord?id=CVE-2024-44952'], 'PublishedDate': '2024-09-04T19:15:30.213Z', 'LastModifiedDate': '2024-09-06T16:37:38.37Z'}, {'VulnerabilityID': 'CVE-2024-44953', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44953', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: scsi: ufs: core: Fix deadlock during RTC update', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix deadlock during RTC update\n\nThere is a deadlock when runtime suspend waits for the flush of RTC work,\nand the RTC work calls ufshcd_rpm_get_sync() to wait for runtime resume.\n\nHere is deadlock backtrace:\n\nkworker/0:1 D 4892.876354 10 10971 4859 0x4208060 0x8 10 0 120 670730152367\nptr f0ffff80c2e40000 0 1 0x00000001 0x000000ff 0x000000ff 0x000000ff\n __switch_to+0x1a8/0x2d4\n __schedule+0x684/0xa98\n schedule+0x48/0xc8\n schedule_timeout+0x48/0x170\n do_wait_for_common+0x108/0x1b0\n wait_for_completion+0x44/0x60\n __flush_work+0x39c/0x424\n __cancel_work_sync+0xd8/0x208\n cancel_delayed_work_sync+0x14/0x28\n __ufshcd_wl_suspend+0x19c/0x480\n ufshcd_wl_runtime_suspend+0x3c/0x1d4\n scsi_runtime_suspend+0x78/0xc8\n __rpm_callback+0x94/0x3e0\n rpm_suspend+0x2d4/0x65c\n __pm_runtime_suspend+0x80/0x114\n scsi_runtime_idle+0x38/0x6c\n rpm_idle+0x264/0x338\n __pm_runtime_idle+0x80/0x110\n ufshcd_rtc_work+0x128/0x1e4\n process_one_work+0x26c/0x650\n worker_thread+0x260/0x3d8\n kthread+0x110/0x134\n ret_from_fork+0x10/0x20\n\nSkip updating RTC if RPM state is not RPM_ACTIVE.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44953', 'https://git.kernel.org/linus/3911af778f208e5f49d43ce739332b91e26bc48e (6.11-rc2)', 'https://git.kernel.org/stable/c/3911af778f208e5f49d43ce739332b91e26bc48e', 'https://git.kernel.org/stable/c/f13f1858a28c68b7fc0d72c2008d5c1f80d2e8d5', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44953-1a10@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44953', 'https://www.cve.org/CVERecord?id=CVE-2024-44953'], 'PublishedDate': '2024-09-04T19:15:30.297Z', 'LastModifiedDate': '2024-09-06T16:37:33.65Z'}, {'VulnerabilityID': 'CVE-2024-44954', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44954', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: ALSA: line6: Fix racy access to midibuf', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: line6: Fix racy access to midibuf\n\nThere can be concurrent accesses to line6 midibuf from both the URB\ncompletion callback and the rawmidi API access. This could be a cause\nof KMSAN warning triggered by syzkaller below (so put as reported-by\nhere).\n\nThis patch protects the midibuf call of the former code path with a\nspinlock for avoiding the possible races.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-362'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.7}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'V3Score': 5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44954', 'https://git.kernel.org/linus/15b7a03205b31bc5623378c190d22b7ff60026f1 (6.11-rc3)', 'https://git.kernel.org/stable/c/15b7a03205b31bc5623378c190d22b7ff60026f1', 'https://git.kernel.org/stable/c/40f3d5cb0e0cbf7fa697913a27d5d361373bdcf5', 'https://git.kernel.org/stable/c/51d87f11dd199bbc6a85982b088ff27bde53b48a', 'https://git.kernel.org/stable/c/535df7f896a568a8a1564114eaea49d002cb1747', 'https://git.kernel.org/stable/c/643293b68fbb6c03f5e907736498da17d43f0d81', 'https://git.kernel.org/stable/c/a54da4b787dcac60b598da69c9c0072812b8282d', 'https://git.kernel.org/stable/c/c80f454a805443c274394b1db0d1ebf477abd94e', 'https://git.kernel.org/stable/c/e7e7d2b180d8f297cea6db43ea72402fd33e1a29', 'https://linux.oracle.com/cve/CVE-2024-44954.html', 'https://linux.oracle.com/errata/ELSA-2024-12782.html', 'https://lore.kernel.org/linux-cve-announce/2024090411-CVE-2024-44954-6838@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44954', 'https://www.cve.org/CVERecord?id=CVE-2024-44954'], 'PublishedDate': '2024-09-04T19:15:30.353Z', 'LastModifiedDate': '2024-10-10T18:02:42.307Z'}, {'VulnerabilityID': 'CVE-2024-44955', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44955', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': "kernel: drm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute", 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute\n\n[Why]\nWhen unplug one of monitors connected after mst hub, encounter null pointer dereference.\n\nIt's due to dc_sink get released immediately in early_unregister() or detect_ctx(). When\ncommit new state which directly referring to info stored in dc_sink will cause null pointer\ndereference.\n\n[how]\nRemove redundant checking condition. Relevant condition should already be covered by checking\nif dsc_aux is null or not. Also reset dsc_aux to NULL when the connector is disconnected.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-476'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 4.4}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44955', 'https://git.kernel.org/linus/fcf6a49d79923a234844b8efe830a61f3f0584e4 (6.11-rc1)', 'https://git.kernel.org/stable/c/39b217193729aa45eded8de24d9245468a0c0263', 'https://git.kernel.org/stable/c/fcf6a49d79923a234844b8efe830a61f3f0584e4', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44955-20e8@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44955', 'https://www.cve.org/CVERecord?id=CVE-2024-44955'], 'PublishedDate': '2024-09-04T19:15:30.423Z', 'LastModifiedDate': '2024-10-10T17:57:00.267Z'}, {'VulnerabilityID': 'CVE-2024-44956', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44956', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: drm/xe/preempt_fence: enlarge the fence critical section', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/preempt_fence: enlarge the fence critical section\n\nIt is really easy to introduce subtle deadlocks in\npreempt_fence_work_func() since we operate on single global ordered-wq\nfor signalling our preempt fences behind the scenes, so even though we\nsignal a particular fence, everything in the callback should be in the\nfence critical section, since blocking in the callback will prevent\nother published fences from signalling. If we enlarge the fence critical\nsection to cover the entire callback, then lockdep should be able to\nunderstand this better, and complain if we grab a sensitive lock like\nvm->lock, which is also held when waiting on preempt fences.', 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44956', 'https://git.kernel.org/linus/3cd1585e57908b6efcd967465ef7685f40b2a294 (6.11-rc1)', 'https://git.kernel.org/stable/c/3cd1585e57908b6efcd967465ef7685f40b2a294', 'https://git.kernel.org/stable/c/458bb83119dfee5d14c677f7846dd9363817006f', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44956-8bcf@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44956', 'https://www.cve.org/CVERecord?id=CVE-2024-44956'], 'PublishedDate': '2024-09-04T19:15:30.48Z', 'LastModifiedDate': '2024-09-06T16:37:11.777Z'}, {'VulnerabilityID': 'CVE-2024-44957', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44957', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: xen: privcmd: Switch from mutex to spinlock for irqfds', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Switch from mutex to spinlock for irqfds\n\nirqfd_wakeup() gets EPOLLHUP, when it is called by\neventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which\ngets called under spin_lock_irqsave(). We can't use a mutex here as it\nwill lead to a deadlock.\n\nFix it by switching over to a spin lock.", 'Severity': 'MEDIUM', 'CweIDs': ['CWE-667'], 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44957', 'https://git.kernel.org/linus/1c682593096a487fd9aebc079a307ff7a6d054a3 (6.11-rc1)', 'https://git.kernel.org/stable/c/1c682593096a487fd9aebc079a307ff7a6d054a3', 'https://git.kernel.org/stable/c/49f2a5da6785b2dbde93e291cae037662440346e', 'https://git.kernel.org/stable/c/c2775ae4d9227729f8ca9ee2a068f62a00d5ea9c', 'https://lore.kernel.org/linux-cve-announce/2024090412-CVE-2024-44957-5c8e@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44957', 'https://www.cve.org/CVERecord?id=CVE-2024-44957'], 'PublishedDate': '2024-09-04T19:15:30.523Z', 'LastModifiedDate': '2024-09-06T16:37:00.077Z'}, {'VulnerabilityID': 'CVE-2024-44958', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44958', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: sched/smt: Fix unbalance sched_smt_present dec/inc', 'Description': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched/smt: Fix unbalance sched_smt_present dec/inc\n\nI got the following warn report while doing stress test:\n\njump label: negative count!\nWARNING: CPU: 3 PID: 38 at kernel/jump_label.c:263 static_key_slow_try_dec+0x9d/0xb0\nCall Trace:\n \n __static_key_slow_dec_cpuslocked+0x16/0x70\n sched_cpu_deactivate+0x26e/0x2a0\n cpuhp_invoke_callback+0x3ad/0x10d0\n cpuhp_thread_fun+0x3f5/0x680\n smpboot_thread_fn+0x56d/0x8d0\n kthread+0x309/0x400\n ret_from_fork+0x41/0x70\n ret_from_fork_asm+0x1b/0x30\n \n\nBecause when cpuset_cpu_inactive() fails in sched_cpu_deactivate(),\nthe cpu offline failed, but sched_smt_present is decremented before\ncalling sched_cpu_deactivate(), it leads to unbalanced dec/inc, so\nfix it by incrementing sched_smt_present in the error path.', 'Severity': 'MEDIUM', 'CVSS': {'nvd': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}, 'redhat': {'V3Vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'V3Score': 5.5}}, 'References': ['https://access.redhat.com/security/cve/CVE-2024-44958', 'https://git.kernel.org/linus/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117 (6.11-rc2)', 'https://git.kernel.org/stable/c/2a3548c7ef2e135aee40e7e5e44e7d11b893e7c4', 'https://git.kernel.org/stable/c/2cf7665efe451e48d27953e6b5bc627d518c902b', 'https://git.kernel.org/stable/c/65727331b60197b742089855ac09464c22b96f66', 'https://git.kernel.org/stable/c/d0c87a3c6be10a57aa3463c32c3fc6b2a47c3dab', 'https://git.kernel.org/stable/c/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117', 'https://lore.kernel.org/linux-cve-announce/2024090413-CVE-2024-44958-80e9@gregkh/T', 'https://nvd.nist.gov/vuln/detail/CVE-2024-44958', 'https://www.cve.org/CVERecord?id=CVE-2024-44958'], 'PublishedDate': '2024-09-04T19:15:30.58Z', 'LastModifiedDate': '2024-10-10T17:56:24.467Z'}, {'VulnerabilityID': 'CVE-2024-44959', 'PkgID': 'linux-headers-6.8.0-1015-aws@6.8.0-1015.16~22.04.1', 'PkgName': 'linux-headers-6.8.0-1015-aws', 'InstalledVersion': '6.8.0-1015.16~22.04.1', 'Layer': {}, 'SeveritySource': 'ubuntu', 'PrimaryURL': 'https://avd.aquasec.com/nvd/cve-2024-44959', 'DataSource': {'ID': 'ubuntu', 'Name': 'Ubuntu CVE Tracker', 'URL': 'https://git.launchpad.net/ubuntu-cve-tracker'}, 'Title': 'kernel: tracefs: Use generic inode RCU for synchronizing freeing', 'Description': "In the Linux kernel, the following vulnerability has been resolved:\n\ntracefs: Use generic inode RCU for synchronizing freeing\n\nWith structure layout randomization enabled for 'struct inode' we need to\navoid overlapping any of the RCU-used / initialized-only-once members,\ne.g. i_lru or i_sb_list to not corrupt related list traversals when making\nuse of the rcu_head.\n\nFor an unlucky structure layout of 'struct inode' we may end up with the\nfollowing splat when running the ftrace selftests:\n\n[<...>] list_del corruption, ffff888103ee2cb0->next (tracefs_inode_cache+0x0/0x4e0 [slab object]) is NULL (prev is tracefs_inode_cache+0x78/0x4e0 [slab object])\n[<...>] ------------[ cut here ]------------\n[<...>] kernel BUG at lib/list_debug.c:54!\n[<...>] invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[<...>] CPU: 3 PID: 2550 Comm: mount Tainted: G N 6.8.12-grsec+ #122 ed2f536ca62f28b087b90e3cc906a8d25b3ddc65\n[<...>] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\n[<...>] RIP: 0010:[] __list_del_entry_valid_or_report+0x138/0x3e0\n[<...>] Code: 48 b8 99 fb 65 f2 ff ff ff ff e9 03 5c d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff e9 33 5a d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff <0f> 0b 4c 89 e9 48 89 ea 48 89 ee 48 c7 c7 60 8f dd 89 31 c0 e8 2f\n[<...>] RSP: 0018:fffffe80416afaf0 EFLAGS: 00010283\n[<...>] RAX: 0000000000000098 RBX: ffff888103ee2cb0 RCX: 0000000000000000\n[<...>] RDX: ffffffff84655fe8 RSI: ffffffff89dd8b60 RDI: 0000000000000001\n[<...>] RBP: ffff888103ee2cb0 R08: 0000000000000001 R09: fffffbd0082d5f25\n[<...>] R10: fffffe80416af92f R11: 0000000000000001 R12: fdf99c16731d9b6d\n[<...>] R13: 0000000000000000 R14: ffff88819ad4b8b8 R15: 0000000000000000\n[<...>] RBX: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RDX: __list_del_entry_valid_or_report+0x108/0x3e0\n[<...>] RSI: __func__.47+0x4340/0x4400\n[<...>] RBP: tracefs_inode_cache+0x0/0x4e0 [slab object]\n[<...>] RSP: process kstack fffffe80416afaf0+0x7af0/0x8000 [mount 2550 2550]\n[<...>] R09: kasan shadow of process kstack fffffe80416af928+0x7928/0x8000 [mount 2550 2550]\n[<...>] R10: process kstack fffffe80416af92f+0x792f/0x8000 [mount 2550 2550]\n[<...>] R14: tracefs_inode_cache+0x78/0x4e0 [slab object]\n[<...>] FS: 00006dcb380c1840(0000) GS:ffff8881e0600000(0000) knlGS:0000000000000000\n[<...>] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[<...>] CR2: 000076ab72b30e84 CR3: 000000000b088004 CR4: 0000000000360ef0 shadow CR4: 0000000000360ef0\n[<...>] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[<...>] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[<...>] ASID: 0003\n[<...>] Stack:\n[<...>] ffffffff818a2315 00000000f5c856ee ffffffff896f1840 ffff888103ee2cb0\n[<...>] ffff88812b6b9750 0000000079d714b6 fffffbfff1e9280b ffffffff8f49405f\n[<...>] 0000000000000001 0000000000000000 ffff888104457280 ffffffff8248b392\n[<...>] Call Trace:\n[<...>] \n[<...>] [] ? lock_release+0x175/0x380 fffffe80416afaf0\n[<...>] [] list_lru_del+0x152/0x740 fffffe80416afb48\n[<...>] [