Skip to content

Commit 2c04f52

Browse files
Sync EUVD catalog: Sun Jul 19 00:39:09 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent b7580d6 commit 2c04f52

168 files changed

Lines changed: 5912 additions & 320 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2024/05/EUVD-2024-1367.json

Lines changed: 627 additions & 4 deletions
Large diffs are not rendered by default.

advisories/2024/05/EUVD-2024-1469.json

Lines changed: 302 additions & 77 deletions
Large diffs are not rendered by default.

advisories/2025/02/EUVD-2025-5983.json

Lines changed: 52 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,60 +2,101 @@
22
"id": "EUVD-2025-5983",
33
"enisaUuid": "3affd854-00f1-3f89-bf3b-d0506e1fb812",
44
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: mark GFP_NOIO around sysfs ->store()\n\nsysfs ->store is called with queue freezed, meantime we have several\n->store() callbacks(update_nr_requests, wbt, scheduler) to allocate\nmemory with GFP_KERNEL which may run into direct reclaim code path,\nthen potential deadlock can be caused.\n\nFix the issue by marking NOIO around sysfs ->store()",
5-
"datePublished": "Feb 27, 2025, 9:32:17 PM",
6-
"dateUpdated": "Oct 28, 2025, 3:30:13 AM",
5+
"datePublished": "Feb 27, 2025, 8:04:15 PM",
6+
"dateUpdated": "Jul 18, 2026, 3:00:43 PM",
77
"baseScore": 0.0,
8-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-21817\nhttps://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31\nhttps://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c\n",
8+
"references": "https://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31\nhttps://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c\n",
99
"aliases": "GHSA-3f4p-8qj7-5fxp\nCVE-2025-21817\n",
1010
"assigner": "Linux",
11-
"epss": 0.03,
11+
"epss": 0.12,
1212
"enisaIdProduct": [
1313
{
1414
"id": "11cd9acc-1500-3688-921b-0eba4fd93f50",
1515
"product": {
16-
"name": "Linux"
16+
"name": "Linux",
17+
"vendor": {
18+
"name": "Linux"
19+
}
1720
},
1821
"product_version": "8985da5481562e96b95e94ed8e5cc9b6565eb82b <2566ce907e5d5db8a039647208e029ce559baa31"
1922
},
2023
{
2124
"id": "1fab57b5-eaf7-3990-8fc4-30d05458d3cd",
2225
"product": {
23-
"name": "Linux"
26+
"name": "Linux",
27+
"vendor": {
28+
"name": "Linux"
29+
}
2430
},
2531
"product_version": "patch: 6.13.3"
2632
},
2733
{
2834
"id": "53e91d64-143f-33dd-9d49-eaaa10fec74b",
2935
"product": {
30-
"name": "Linux"
36+
"name": "Linux",
37+
"vendor": {
38+
"name": "Linux"
39+
}
3140
},
3241
"product_version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2566ce907e5d5db8a039647208e029ce559baa31"
3342
},
3443
{
3544
"id": "67043ce5-82ec-37a2-8645-41ba13cf0163",
3645
"product": {
37-
"name": "Linux"
46+
"name": "Linux",
47+
"vendor": {
48+
"name": "Linux"
49+
}
3850
},
3951
"product_version": "6.13.2 <6.13.3"
4052
},
53+
{
54+
"id": "7524508f-380f-38a0-b8a6-45963cad45c5",
55+
"product": {
56+
"name": "Linux",
57+
"vendor": {
58+
"name": "Linux"
59+
}
60+
},
61+
"product_version": "1645cd7fd42c236c952e9228badcac4fea1829ea"
62+
},
4163
{
4264
"id": "7d113517-6159-32a5-b01a-c1a4d95b38d4",
4365
"product": {
44-
"name": "Linux"
66+
"name": "Linux",
67+
"vendor": {
68+
"name": "Linux"
69+
}
4570
},
4671
"product_version": "patch: 6.14"
4772
},
4873
{
4974
"id": "8167b0c6-dd8f-33a2-a9db-020126a03725",
5075
"product": {
51-
"name": "Linux"
76+
"name": "Linux",
77+
"vendor": {
78+
"name": "Linux"
79+
}
5280
},
5381
"product_version": "c99f66e4084a62a2cc401c4704a84328aeddc9ec <7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c"
5482
},
83+
{
84+
"id": "9e8ab3dc-84ab-3af7-866f-ad7ef80eae4d",
85+
"product": {
86+
"name": "Linux",
87+
"vendor": {
88+
"name": "Linux"
89+
}
90+
},
91+
"product_version": "6.12.96 <6.13"
92+
},
5593
{
5694
"id": "a8e35c63-ac42-3d6b-a30d-ebe4012e85b5",
5795
"product": {
58-
"name": "Linux"
96+
"name": "Linux",
97+
"vendor": {
98+
"name": "Linux"
99+
}
59100
},
60101
"product_version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c"
61102
}

advisories/2025/02/EUVD-2025-5993.json

Lines changed: 48 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,53 +2,91 @@
22
"id": "EUVD-2025-5993",
33
"enisaUuid": "4250e222-551d-35f7-8dfe-e3497c0b9941",
44
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix queue freeze vs limits lock order in sysfs store methods\n\nqueue_attr_store() always freezes a device queue before calling the\nattribute store operation. For attributes that control queue limits, the\nstore operation will also lock the queue limits with a call to\nqueue_limits_start_update(). However, some drivers (e.g. SCSI sd) may\nneed to issue commands to a device to obtain limit values from the\nhardware with the queue limits locked. This creates a potential ABBA\ndeadlock situation if a user attempts to modify a limit (thus freezing\nthe device queue) while the device driver starts a revalidation of the\ndevice queue limits.\n\nAvoid such deadlock by not freezing the queue before calling the\n->store_limit() method in struct queue_sysfs_entry and instead use the\nqueue_limits_commit_update_frozen helper to freeze the queue after taking\nthe limits lock.\n\nThis also removes taking the sysfs lock for the store_limit method as\nit doesn't protect anything here, but creates even more nesting.\nHopefully it will go away from the actual sysfs methods entirely soon.\n\n(commit log adapted from a similar patch from Damien Le Moal)",
5-
"datePublished": "Feb 27, 2025, 9:32:16 PM",
6-
"dateUpdated": "Oct 28, 2025, 3:30:13 AM",
5+
"datePublished": "Feb 27, 2025, 8:00:59 PM",
6+
"dateUpdated": "Jul 18, 2026, 3:00:42 PM",
77
"baseScore": 0.0,
8-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-21807\nhttps://git.kernel.org/stable/c/8985da5481562e96b95e94ed8e5cc9b6565eb82b\nhttps://git.kernel.org/stable/c/c99f66e4084a62a2cc401c4704a84328aeddc9ec\n",
8+
"references": "https://git.kernel.org/stable/c/1645cd7fd42c236c952e9228badcac4fea1829ea\nhttps://git.kernel.org/stable/c/8985da5481562e96b95e94ed8e5cc9b6565eb82b\nhttps://git.kernel.org/stable/c/c99f66e4084a62a2cc401c4704a84328aeddc9ec\n",
99
"aliases": "CVE-2025-21807\nGHSA-cp43-x3rr-gwcc\n",
1010
"assigner": "Linux",
11-
"epss": 0.04,
11+
"epss": 0.12,
1212
"enisaIdProduct": [
13+
{
14+
"id": "25932073-0b74-3fd2-bce7-23ee8bafe519",
15+
"product": {
16+
"name": "Linux",
17+
"vendor": {
18+
"name": "Linux"
19+
}
20+
},
21+
"product_version": "0327ca9d53bfbb0918867313049bba7046900f73 <1645cd7fd42c236c952e9228badcac4fea1829ea"
22+
},
1323
{
1424
"id": "25d9186a-4776-3f01-aea7-9b8731886725",
1525
"product": {
16-
"name": "Linux"
26+
"name": "Linux",
27+
"vendor": {
28+
"name": "Linux"
29+
}
1730
},
1831
"product_version": "patch: 6.14"
1932
},
2033
{
2134
"id": "31bc80fe-5a69-3eb4-97a9-7e0d08c5b5fc",
2235
"product": {
23-
"name": "Linux"
36+
"name": "Linux",
37+
"vendor": {
38+
"name": "Linux"
39+
}
2440
},
2541
"product_version": "patch: 0"
2642
},
2743
{
2844
"id": "417c2f18-2a38-3fdc-9a1f-b96f0de8fbb2",
2945
"product": {
30-
"name": "Linux"
46+
"name": "Linux",
47+
"vendor": {
48+
"name": "Linux"
49+
}
3150
},
3251
"product_version": "6.9"
3352
},
3453
{
3554
"id": "5475a6e2-9b8a-3b4e-843d-ba222ac74ce3",
3655
"product": {
37-
"name": "Linux"
56+
"name": "Linux",
57+
"vendor": {
58+
"name": "Linux"
59+
}
3860
},
3961
"product_version": "patch: 6.13.2"
4062
},
63+
{
64+
"id": "9ff818a5-8733-3c7d-b832-61bb3cb60819",
65+
"product": {
66+
"name": "Linux",
67+
"vendor": {
68+
"name": "Linux"
69+
}
70+
},
71+
"product_version": "patch: 6.12.96"
72+
},
4173
{
4274
"id": "cccdf0da-9b75-3580-a3ee-fc23a264fdde",
4375
"product": {
44-
"name": "Linux"
76+
"name": "Linux",
77+
"vendor": {
78+
"name": "Linux"
79+
}
4580
},
4681
"product_version": "0327ca9d53bfbb0918867313049bba7046900f73 <c99f66e4084a62a2cc401c4704a84328aeddc9ec"
4782
},
4883
{
4984
"id": "f1c4cd2b-eba7-350d-864f-6aeef9b54dfd",
5085
"product": {
51-
"name": "Linux"
86+
"name": "Linux",
87+
"vendor": {
88+
"name": "Linux"
89+
}
5290
},
5391
"product_version": "0327ca9d53bfbb0918867313049bba7046900f73 <8985da5481562e96b95e94ed8e5cc9b6565eb82b"
5492
}

advisories/2025/04/EUVD-2025-9701.json

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,19 +3,22 @@
33
"enisaUuid": "0d789117-635f-37ad-9fc9-5567bd6e6d7c",
44
"description": "Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.",
55
"datePublished": "Apr 4, 2025, 5:00:05 AM",
6-
"dateUpdated": "Apr 4, 2025, 5:00:05 AM",
6+
"dateUpdated": "Jul 18, 2026, 3:25:27 PM",
77
"baseScore": 8.7,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-3194\nhttps://github.com/no2chem/bigint-buffer/blob/master/src/index.ts%23L25\nhttps://security.snyk.io/vuln/SNYK-JS-BIGINTBUFFER-3364597\nhttps://www.usenix.org/system/files/sec23fall-prepub-262_staicu.pdf\n",
10+
"references": "https://security.snyk.io/vuln/SNYK-JS-BIGINTBUFFER-3364597\nhttps://github.com/no2chem/bigint-buffer/blob/master/src/index.ts%23L25\nhttps://www.usenix.org/system/files/sec23fall-prepub-262_staicu.pdf\n",
1111
"aliases": "GHSA-3gc7-fjrx-p6mg\nCVE-2025-3194\n",
1212
"assigner": "snyk",
13-
"epss": 0.38,
13+
"epss": 0.57,
1414
"enisaIdProduct": [
1515
{
1616
"id": "6c67af93-b3b1-3adf-ad1f-06c677999844",
1717
"product": {
18-
"name": "bigint-buffer"
18+
"name": "bigint-buffer",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1922
},
2023
"product_version": "0.0.0 <*"
2124
}

advisories/2025/11/EUVD-2025-131920.json

Lines changed: 25 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,33 +3,52 @@
33
"enisaUuid": "4cc0b2ef-635d-369d-8a70-a44e50631571",
44
"description": "A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues.",
55
"datePublished": "Nov 12, 2025, 4:36:04 PM",
6-
"dateUpdated": "Dec 19, 2025, 6:30:24 PM",
6+
"dateUpdated": "Jul 18, 2026, 7:04:46 PM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://access.redhat.com/errata/RHSA-2025:21146\nhttps://access.redhat.com/security/cve/CVE-2025-2843\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2355222\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2843\nhttps://github.com/rhobs/observability-operator/commit/98b927fab755decd6e030ac6af5c005879bab020\nhttps://github.com/rhobs/observability-operator/releases/tag/v1.3.0\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2025:21146\nhttps://access.redhat.com/security/cve/CVE-2025-2843\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2355222\n",
1111
"aliases": "CVE-2025-2843\nGHSA-mj6p-p843-x5wc\n",
1212
"assigner": "redhat",
13-
"epss": 0.05,
13+
"epss": 0.32,
1414
"enisaIdProduct": [
1515
{
1616
"id": "12960f58-f122-3838-add1-9153d87c5b15",
1717
"product": {
18-
"name": "Cluster Observability Operator 1.3.0"
18+
"name": "Cluster Observability Operator 1.3.0",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
1922
},
2023
"product_version": "patch: sha256:efff0f5b6835286172ae99dd368dcc48aca98398c382cb4c38d02533afee8670"
2124
},
25+
{
26+
"id": "3a66d18d-59bf-3178-94b4-f10a751ce624",
27+
"product": {
28+
"name": "Cluster Observability Operator 1.3.0",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
},
33+
"product_version": "patch: 1.3.0-1762825457"
34+
},
2235
{
2336
"id": "43b425cf-71c4-3e68-b706-806c135d3a79",
2437
"product": {
25-
"name": "observability-operator"
38+
"name": "observability-operator",
39+
"vendor": {
40+
"name": "rhobs"
41+
}
2642
},
2743
"product_version": "0 <1.3.0"
2844
},
2945
{
3046
"id": "bb7c829e-e95b-3b1a-8400-e447a97cec8f",
3147
"product": {
32-
"name": "Cluster Observability Operator 1.3.1"
48+
"name": "Cluster Observability Operator 1.3.1",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
3352
},
3453
"product_version": "patch: sha256:84a281b3cd370cd42b89489c770f8b31d13e9aa570dc1b6cda6042bfba4824f8"
3554
}

advisories/2025/12/EUVD-2025-203395.json

Lines changed: 28 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,42 +3,64 @@
33
"enisaUuid": "0077b477-ed40-3f6a-a098-5b9a6118b558",
44
"description": "A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle.\n\nThis allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform.",
55
"datePublished": "Dec 15, 2025, 5:03:44 PM",
6-
"dateUpdated": "May 15, 2026, 8:07:37 PM",
6+
"dateUpdated": "Jul 18, 2026, 7:02:38 PM",
77
"baseScore": 8.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
1010
"references": "https://access.redhat.com/errata/RHSA-2025:23236\nhttps://access.redhat.com/security/cve/CVE-2025-11393\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2402032\n",
1111
"aliases": "GHSA-cc8c-28gj-px38\nCVE-2025-11393\n",
1212
"assigner": "redhat",
13-
"epss": 0.01,
13+
"epss": 0.23,
1414
"enisaIdProduct": [
1515
{
1616
"id": "0e90daaa-4317-3fa2-95e3-e5457d57c8cc",
1717
"product": {
18-
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0"
18+
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
1922
},
2023
"product_version": "patch: sha256:08f473dec97e110a73e1c9886ee31512bb6937f87bdb95fbe77cb2d85695b936"
2124
},
2225
{
2326
"id": "83e46c87-f557-322c-8be4-73919c286542",
2427
"product": {
25-
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0"
28+
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
2632
},
2733
"product_version": "patch: sha256:33ddc7c7c65374ab7b2b2c02f6319e52fe33904a9d951791cefcd72a39b66453"
2834
},
2935
{
3036
"id": "9d448751-4906-3e49-8742-e441da918a91",
3137
"product": {
32-
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0"
38+
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
3342
},
3443
"product_version": "patch: 1.0.0-1765483112"
3544
},
3645
{
3746
"id": "f06c8640-8d10-3ced-b452-22a83c842a0d",
3847
"product": {
39-
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1"
48+
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
4052
},
4153
"product_version": "patch: sha256:08f473dec97e110a73e1c9886ee31512bb6937f87bdb95fbe77cb2d85695b936"
54+
},
55+
{
56+
"id": "f27e3206-a0b6-30fd-9f14-2b9014ec9579",
57+
"product": {
58+
"name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
62+
},
63+
"product_version": "patch: 1.0.0-1765483112"
4264
}
4365
],
4466
"enisaIdVendor": [

0 commit comments

Comments
 (0)