Skip to content

Commit df824b4

Browse files
Advisory Database Sync
1 parent f994a1d commit df824b4

82 files changed

Lines changed: 3562 additions & 0 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-22cc-9j92-vx92",
4+
"modified": "2026-09-16T09:30:23Z",
5+
"published": "2026-09-16T09:30:23Z",
6+
"aliases": [
7+
"CVE-2025-14871"
8+
],
9+
"details": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14871"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://hackerone.com/reports/3462311"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/584492"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-770"
38+
],
39+
"severity": "HIGH",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2026-09-16T07:16:32Z"
43+
}
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-23xw-rw6g-gx4m",
4+
"modified": "2026-09-16T09:30:26Z",
5+
"published": "2026-09-16T09:30:25Z",
6+
"aliases": [
7+
"CVE-2026-27558"
8+
],
9+
"details": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27558"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://www.certvde.com/en/advisories/VDE-2026-014"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://www.certvde.com/en/advisories/VDE-2026-027"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://www.certvde.com/en/advisories/VDE-2026-028"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-78"
38+
],
39+
"severity": "HIGH",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2026-09-16T08:16:38Z"
43+
}
44+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-26hj-3mvp-2g64",
4+
"modified": "2026-09-16T09:30:26Z",
5+
"published": "2026-09-16T09:30:26Z",
6+
"aliases": [
7+
"CVE-2026-89207"
8+
],
9+
"details": "A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services.\nThis could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89207"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://cert-portal.siemens.com/productcert/html/ssa-823812.html"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-1287"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-09-16T08:16:40Z"
39+
}
40+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-29wc-2986-775f",
4+
"modified": "2026-09-16T09:30:30Z",
5+
"published": "2026-09-16T09:30:30Z",
6+
"aliases": [
7+
"CVE-2026-89788"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix tree connection use-after-free in smb2_tree_connect()\n\nksmbd_tree_conn_connect() publishes a new tree connection in\nsess->tree_conns with a single reference and returns its pointer to\nsmb2_tree_connect(). The handler continues to initialize the object and\nbuild the response after publication. A concurrent session logoff can\nerase the connection and drop that reference, freeing the object while\nthe handler still uses it.\n\nBUG: KASAN: slab-use-after-free in smb2_tree_connect+0xe3d/0xf90\n smb2_tree_connect (fs/smb/server/smb2pdu.c:2872)\n handle_ksmbd_work\n process_one_work\n worker_thread\n kthread\n\nAfter xa_store() succeeds, take a second reference before releasing\ntree_conns_lock. The original reference belongs to the xarray entry and\nthe second belongs to the creating smb2_tree_connect() handler.\n\nKeep the references balanced in every path:\n\n- On normal exit or an error after publication, smb2_tree_connect()\n drops its creator reference. Error cleanup also calls\n ksmbd_tree_conn_disconnect(), which drops the xarray reference only if\n it removes the exact entry.\n- SMB2 TREE_DISCONNECT uses the same helper to remove the entry and drop\n its xarray reference. The request's existing lookup reference remains\n owned by the request and is released by the existing cleanup.\n- Session LOGOFF removes each entry and drops its xarray reference. If\n it wins the race, later cleanup sees that the entry is gone and does\n not drop that reference again.\n\nTo enforce this ownership, claim the disconnected state and erase the\nexact entry atomically under tree_conns_lock. This guarantees one drop\nfor the xarray reference and one drop by each in-flight user, regardless\nof which teardown path wins. If logoff removes the entry before\ninitialization completes, fail the connect instead of marking the\ndetached object TREE_CONNECTED.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89788"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/4e30fbd26e84efa2e5cbec4eb11e126ac0c79313"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/b5ec6c462aab1062cf5d1e667ba7c6442f737055"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-09-16T09:17:09Z"
32+
}
33+
}
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2f6m-7f8f-p7hp",
4+
"modified": "2026-09-16T09:30:30Z",
5+
"published": "2026-09-16T09:30:30Z",
6+
"aliases": [
7+
"CVE-2026-89780"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qualcomm: rmnet: restore skb->dev on deaggregated frames\n\nrmnet_map_deaggregate() allocates each sub-frame with alloc_skb() and\nleaves skb->dev NULL. __rmnet_map_ingress_handler() assigns\nskb->dev = ep->egress_dev only on the data path, but a MAP command frame\nis dispatched to rmnet_map_command() before that, so rmnet_map_send_ack()\nruns netif_tx_lock(skb->dev) on a NULL device. An unprivileged user\nreaches this by unsharing a user+net namespace, creating an rmnet link\nover a tap device with INGRESS_DEAGGREGATION and INGRESS_MAP_COMMANDS,\nand writing an aggregated frame carrying a flow-control command to the\ntap fd.\n\nRestore the assignment dropped by 378e25357ac7, so every skb leaving\nrmnet_map_deaggregate() has a valid device.\n\n BUG: KASAN: null-ptr-deref in _raw_spin_lock (kernel/locking/spinlock.c:158)\n Write of size 4 at addr 00000000000004b4 by task exploit/144\n Call Trace:\n _raw_spin_lock (kernel/locking/spinlock.c:158)\n netif_tx_lock (net/sched/sch_generic.c:497)\n rmnet_map_command (drivers/net/ethernet/qualcomm/rmnet/rmnet_map_command.c:67)\n rmnet_rx_handler (drivers/net/ethernet/qualcomm/rmnet/rmnet_handlers.c:125)\n __netif_receive_skb_core.constprop.0 (net/core/dev.c:6103)\n ...\n __netif_receive_skb_one_core (net/core/dev.c:6214)\n netif_receive_skb (net/core/dev.c:6474)\n tun_get_user (drivers/net/tun.c:1966)\n tun_chr_write_iter (drivers/net/tun.c:2012)\n vfs_write (fs/read_write.c:687)\n ksys_write (fs/read_write.c:739)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n Kernel panic - not syncing: Fatal exception in interrupt",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89780"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/200460a0793dc6af97d3b36d92ac245350ac26fc"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/4bcef54e4a3355a62d9ad90729fe563435ec76c3"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/5aaa7409c1b4ca4c60d66e2afa99703bf4eb7ddd"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://git.kernel.org/stable/c/7abe769e72c792e5f9eb273813eb3ecd8389854c"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://git.kernel.org/stable/c/9b78ab84ddf97c06a8567edb62b6c0fd582f9a62"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://git.kernel.org/stable/c/9d18c6c6cd1666b2cb7915cad052e22abf520997"
40+
},
41+
{
42+
"type": "WEB",
43+
"url": "https://git.kernel.org/stable/c/a66734a1c5e36525ea07e9f4547fddc51e916de3"
44+
},
45+
{
46+
"type": "WEB",
47+
"url": "https://git.kernel.org/stable/c/b14c22c31d9e30f38ea1693ac06d318f32258f5d"
48+
}
49+
],
50+
"database_specific": {
51+
"cwe_ids": [],
52+
"severity": null,
53+
"github_reviewed": false,
54+
"github_reviewed_at": null,
55+
"nvd_published_at": "2026-09-16T09:17:08Z"
56+
}
57+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2wvv-pq2h-2gcr",
4+
"modified": "2026-09-16T09:30:26Z",
5+
"published": "2026-09-16T09:30:26Z",
6+
"aliases": [
7+
"CVE-2026-27562"
8+
],
9+
"details": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27562"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://www.certvde.com/en/advisories/VDE-2026-014"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://www.certvde.com/en/advisories/VDE-2026-027"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://www.certvde.com/en/advisories/VDE-2026-028"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-78"
38+
],
39+
"severity": "HIGH",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2026-09-16T08:16:39Z"
43+
}
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3237-x8jg-4g4c",
4+
"modified": "2026-09-16T09:30:25Z",
5+
"published": "2026-09-16T09:30:25Z",
6+
"aliases": [
7+
"CVE-2026-27547"
8+
],
9+
"details": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27547"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://www.certvde.com/en/advisories/VDE-2026-014"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://www.certvde.com/en/advisories/VDE-2026-027"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://www.certvde.com/en/advisories/VDE-2026-028"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-78"
38+
],
39+
"severity": "HIGH",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2026-09-16T08:16:37Z"
43+
}
44+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3xg9-4g5f-3mp3",
4+
"modified": "2026-09-16T09:30:30Z",
5+
"published": "2026-09-16T09:30:30Z",
6+
"aliases": [
7+
"CVE-2026-89791"
8+
],
9+
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix use-after-free when perf mmap() revival races with the last munmap()\n\nperf_mmap_close() drops rb->mmap_count *without* holding\nevent->mmap_mutex (the refcount_dec_and_test() right before the\nrefcount_dec_and_mutex_lock() of event->mmap_count). A concurrent\nperf_mmap_rb() can slot its entire \"revival\" path into that window\n(perf_mmap holds event->mmap_mutex for its whole duration, including\nrb_alloc):\n\n munmap side (perf_mmap_close) mmap side (perf_mmap_rb)\n ----------------------------------- --------------------------------\n rb->mmap_count 1 -> 0 (no lock) (holds event->mmap_mutex)\n inc_not_zero(rb->mmap_count) fails\n ring_buffer_attach(event, NULL)\n rb_alloc() + attach new rb\n refcount_set(&event->mmap_count, 1)\n lock; event->mmap_count 1 -> 0\n ring_buffer_attach(event, NULL)\n ring_buffer_put() -> frees the *new* rb\n\nThe revival's refcount_set(&event->mmap_count, 1) is an invisible\n1 -> 1 write: the close frees the just-revived buffer although the\nother process still has it mapped -- a page-level use-after-free\nallowing local privilege escalation to root by any unprivileged user\n(default kernel.perf_event_paranoid=2).\n\nSwap the order of the two counter updates: event->mmap_count is\ndropped first via refcount_dec_and_mutex_lock(), so its 1 -> 0\ntransition and the ring_buffer_attach() stay serialized with\nperf_mmap(). rb->mmap_count == 0 then implies every event using the\nbuffer is detached already, so the result of the rb->mmap_count drop\ncan gate the remaining teardown directly and detach_rest is no longer\nneeded.\n\nAn earlier fix for this race from Kyle Zeng and David Lee takes\nevent->mmap_mutex around both counter updates [0]; here the not-last\nclose stays lockless.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89791"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://git.kernel.org/stable/c/0c739f54f1c77f3a4643160cd2e031b6c2f2aab6"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/58a8108bc73de0740d5b88150465d6690ea5f85f"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://git.kernel.org/stable/c/929cb3b9dc818dd9fa89d510d4ff2b255e42badd"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-09-16T09:17:09Z"
36+
}
37+
}

0 commit comments

Comments
 (0)