Skip to content

Commit f02c40b

Browse files
Sync EUVD catalog: Tue Sep 8 00:34:33 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c4d5d38 commit f02c40b

571 files changed

Lines changed: 18773 additions & 1803 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2025/01/EUVD-2025-0041.json

Lines changed: 35 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,68 +3,92 @@
33
"enisaUuid": "275fe682-ab6c-3608-8ce0-fd076c4486ca",
44
"description": "A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.",
55
"datePublished": "Jan 2, 2025, 8:19:29 PM",
6-
"dateUpdated": "Nov 11, 2025, 12:43:36 AM",
6+
"dateUpdated": "Sep 7, 2026, 2:22:43 PM",
77
"baseScore": 5.9,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2024-8447\nhttps://github.com/jbosstm/narayana/pull/2293\nhttps://github.com/jbosstm/narayana/commit/eb778412de230afc4687a2df43641280494156c5\nhttps://access.redhat.com/security/cve/CVE-2024-8447\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2335206\nhttps://github.com/jbosstm/narayana\nhttps://access.redhat.com/errata/RHSA-2025:3357\nhttps://access.redhat.com/errata/RHSA-2025:3358\nhttps://access.redhat.com/errata/RHSA-2025:7620\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2025:3357\nhttps://access.redhat.com/errata/RHSA-2025:3358\nhttps://access.redhat.com/errata/RHSA-2025:7620\nhttps://access.redhat.com/security/cve/CVE-2024-8447\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2335206\nhttps://github.com/jbosstm/narayana/pull/2293\n",
1111
"aliases": "CVE-2024-8447\nGHSA-qq9f-q439-2574\n",
1212
"assigner": "redhat",
13-
"epss": 0.17,
13+
"epss": 0.62,
1414
"enisaIdProduct": [
1515
{
1616
"id": "61c0c484-3cf3-3944-9faf-46ae735ac1b0",
1717
"product": {
18-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8"
18+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
1922
},
2023
"product_version": "patch: 0:2.0.16-2.redhat_00003.1.el8eap"
2124
},
2225
{
2326
"id": "7c5f1859-df32-3d6c-a774-152d46169076",
2427
"product": {
25-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8"
28+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
2632
},
2733
"product_version": "patch: 0:800.6.1-1.GA_redhat_00001.1.el8eap"
2834
},
2935
{
3036
"id": "8c214597-9698-36f5-8823-d9de79c64285",
3137
"product": {
32-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9"
38+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
3342
},
3443
"product_version": "patch: 0:800.6.1-1.GA_redhat_00001.1.el9eap"
3544
},
3645
{
3746
"id": "c4c9a8fb-bcaa-3a45-bce6-a581928a72fe",
3847
"product": {
39-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9"
48+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
4052
},
4153
"product_version": "patch: 0:2.0.16-2.redhat_00003.1.el9eap"
4254
},
4355
{
4456
"id": "ca9611ad-2d8d-33d1-9138-525afd5fc96d",
4557
"product": {
46-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9"
58+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
4762
},
4863
"product_version": "patch: 0:4.1.119-1.Final_redhat_00002.1.el9eap"
4964
},
5065
{
5166
"id": "d6f157dd-cb1c-3340-94c8-e2f9b751472b",
5267
"product": {
53-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8"
68+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
69+
"vendor": {
70+
"name": "Red Hat"
71+
}
5472
},
5573
"product_version": "patch: 0:4.1.119-1.Final_redhat_00002.1.el8eap"
5674
},
5775
{
5876
"id": "de1f8d17-aaf0-3dcd-acdc-dcab14868e7a",
5977
"product": {
60-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8"
78+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
79+
"vendor": {
80+
"name": "Red Hat"
81+
}
6182
},
6283
"product_version": "patch: 0:8.0.6-15.GA_redhat_00009.1.el8eap"
6384
},
6485
{
6586
"id": "f3bdbfea-4e1b-34e4-b344-d96d37cde7f1",
6687
"product": {
67-
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9"
88+
"name": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
89+
"vendor": {
90+
"name": "Red Hat"
91+
}
6892
},
6993
"product_version": "patch: 0:8.0.6-15.GA_redhat_00009.1.el9eap"
7094
}

advisories/2025/02/EUVD-2025-5983.json

Lines changed: 6 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -3,9 +3,9 @@
33
"enisaUuid": "3affd854-00f1-3f89-bf3b-d0506e1fb812",
44
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: mark GFP_NOIO around sysfs ->store()\n\nsysfs ->store is called with queue freezed, meantime we have several\n->store() callbacks(update_nr_requests, wbt, scheduler) to allocate\nmemory with GFP_KERNEL which may run into direct reclaim code path,\nthen potential deadlock can be caused.\n\nFix the issue by marking NOIO around sysfs ->store()",
55
"datePublished": "Feb 27, 2025, 8:04:15 PM",
6-
"dateUpdated": "Jul 18, 2026, 3:00:43 PM",
6+
"dateUpdated": "Sep 7, 2026, 3:44:41 PM",
77
"baseScore": 0.0,
8-
"references": "https://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31\nhttps://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c\n",
8+
"references": "https://git.kernel.org/stable/c/a09280c39ea54080daf19cfaf4a3121a8d17d5cd\nhttps://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31\nhttps://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c\n",
99
"aliases": "GHSA-3f4p-8qj7-5fxp\nCVE-2025-21817\n",
1010
"assigner": "Linux",
1111
"epss": 0.12,
@@ -21,24 +21,14 @@
2121
"product_version": "8985da5481562e96b95e94ed8e5cc9b6565eb82b <2566ce907e5d5db8a039647208e029ce559baa31"
2222
},
2323
{
24-
"id": "1fab57b5-eaf7-3990-8fc4-30d05458d3cd",
24+
"id": "54d2e8f3-bec8-3228-9f35-b16aafb4ced2",
2525
"product": {
2626
"name": "Linux",
2727
"vendor": {
2828
"name": "Linux"
2929
}
3030
},
31-
"product_version": "patch: 6.13.3"
32-
},
33-
{
34-
"id": "53e91d64-143f-33dd-9d49-eaaa10fec74b",
35-
"product": {
36-
"name": "Linux",
37-
"vendor": {
38-
"name": "Linux"
39-
}
40-
},
41-
"product_version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2566ce907e5d5db8a039647208e029ce559baa31"
31+
"product_version": "6.12.96 <6.12.109"
4232
},
4333
{
4434
"id": "67043ce5-82ec-37a2-8645-41ba13cf0163",
@@ -50,26 +40,6 @@
5040
},
5141
"product_version": "6.13.2 <6.13.3"
5242
},
53-
{
54-
"id": "7524508f-380f-38a0-b8a6-45963cad45c5",
55-
"product": {
56-
"name": "Linux",
57-
"vendor": {
58-
"name": "Linux"
59-
}
60-
},
61-
"product_version": "1645cd7fd42c236c952e9228badcac4fea1829ea"
62-
},
63-
{
64-
"id": "7d113517-6159-32a5-b01a-c1a4d95b38d4",
65-
"product": {
66-
"name": "Linux",
67-
"vendor": {
68-
"name": "Linux"
69-
}
70-
},
71-
"product_version": "patch: 6.14"
72-
},
7343
{
7444
"id": "8167b0c6-dd8f-33a2-a9db-020126a03725",
7545
"product": {
@@ -81,24 +51,14 @@
8151
"product_version": "c99f66e4084a62a2cc401c4704a84328aeddc9ec <7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c"
8252
},
8353
{
84-
"id": "9e8ab3dc-84ab-3af7-866f-ad7ef80eae4d",
85-
"product": {
86-
"name": "Linux",
87-
"vendor": {
88-
"name": "Linux"
89-
}
90-
},
91-
"product_version": "6.12.96 <6.13"
92-
},
93-
{
94-
"id": "a8e35c63-ac42-3d6b-a30d-ebe4012e85b5",
54+
"id": "d88d64e1-442b-317a-82cd-9a5d9e16da5b",
9555
"product": {
9656
"name": "Linux",
9757
"vendor": {
9858
"name": "Linux"
9959
}
10060
},
101-
"product_version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c"
61+
"product_version": "1645cd7fd42c236c952e9228badcac4fea1829ea <a09280c39ea54080daf19cfaf4a3121a8d17d5cd"
10262
}
10363
],
10464
"enisaIdVendor": [

advisories/2025/04/EUVD-2025-11167.json

Lines changed: 50 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,53 +2,91 @@
22
"id": "EUVD-2025-11167",
33
"enisaUuid": "ecebafb7-8c29-368f-ae93-5bdbb66f3987",
44
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadloop in prepare_compress_overwrite()\n\nJan Prusakowski reported a kernel hang issue as below:\n\nWhen running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I\nencountered a problem in generic/475 test where fsstress process\ngets blocked in __f2fs_write_data_pages() and the test hangs.\nThe options I used are:\n\nMKFS_OPTIONS -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc\nMOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc\n\nINFO: task kworker/u8:0:11 blocked for more than 122 seconds.\n Not tainted 6.14.0-rc3-xfstests-lockdep #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:0 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208160 flags:0x00004000\nWorkqueue: writeback wb_workfn (flush-253:0)\nCall Trace:\n <TASK>\n __schedule+0x309/0x8e0\n schedule+0x3a/0x100\n schedule_preempt_disabled+0x15/0x30\n __mutex_lock+0x59a/0xdb0\n __f2fs_write_data_pages+0x3ac/0x400\n do_writepages+0xe8/0x290\n __writeback_single_inode+0x5c/0x360\n writeback_sb_inodes+0x22f/0x570\n wb_writeback+0xb0/0x410\n wb_do_writeback+0x47/0x2f0\n wb_workfn+0x5a/0x1c0\n process_one_work+0x223/0x5b0\n worker_thread+0x1d5/0x3c0\n kthread+0xfd/0x230\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nThe root cause is: once generic/475 starts toload error table to dm\ndevice, f2fs_prepare_compress_overwrite() will loop reading compressed\ncluster pages due to IO error, meanwhile it has held .writepages lock,\nit can block all other writeback tasks.\n\nLet's fix this issue w/ below changes:\n- add f2fs_handle_page_eio() in prepare_compress_overwrite() to\ndetect IO error.\n- detect cp_error earler in f2fs_read_multi_pages().",
5-
"datePublished": "Apr 16, 2025, 3:34:46 PM",
6-
"dateUpdated": "Nov 3, 2025, 6:31:15 PM",
5+
"datePublished": "Apr 16, 2025, 2:13:10 PM",
6+
"dateUpdated": "Sep 7, 2026, 3:44:44 PM",
77
"baseScore": 0.0,
8-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-22127\nhttps://git.kernel.org/stable/c/3147ee567dd9004a49826ddeaf0a4b12865d4409\nhttps://git.kernel.org/stable/c/7215cf8ef54bdc9082dffac4662416d54961e258\n",
8+
"references": "https://git.kernel.org/stable/c/7cd460bd9e7c6e6c30a33982603f65fb5deab1e4\nhttps://git.kernel.org/stable/c/7215cf8ef54bdc9082dffac4662416d54961e258\nhttps://git.kernel.org/stable/c/3147ee567dd9004a49826ddeaf0a4b12865d4409\n",
99
"aliases": "CVE-2025-22127\nGHSA-gj5h-7fq5-56p5\n",
1010
"assigner": "Linux",
11-
"epss": 0.07,
11+
"epss": 0.12,
1212
"enisaIdProduct": [
1313
{
1414
"id": "22ef79a2-a95e-3eee-8e39-03c19ce076f6",
1515
"product": {
16-
"name": "Linux"
16+
"name": "Linux",
17+
"vendor": {
18+
"name": "Linux"
19+
}
1720
},
1821
"product_version": "patch: 0"
1922
},
2023
{
2124
"id": "3a9b705f-56e8-3eb1-9d0f-5de8d1fa1952",
2225
"product": {
23-
"name": "Linux"
26+
"name": "Linux",
27+
"vendor": {
28+
"name": "Linux"
29+
}
2430
},
2531
"product_version": "4c8ff7095bef64fc47e996a938f7d57f9e077da3 <3147ee567dd9004a49826ddeaf0a4b12865d4409"
2632
},
2733
{
28-
"id": "7a4619ee-8642-3e4e-8865-8cb17c9bae2a",
34+
"id": "84e3fbe8-cdd7-3653-9023-7fc686be14ae",
2935
"product": {
30-
"name": "Linux"
36+
"name": "Linux",
37+
"vendor": {
38+
"name": "Linux"
39+
}
40+
},
41+
"product_version": "patch: 6.15"
42+
},
43+
{
44+
"id": "8b9d670c-3a0c-3128-94fc-c16f98073db9",
45+
"product": {
46+
"name": "Linux",
47+
"vendor": {
48+
"name": "Linux"
49+
}
3150
},
32-
"product_version": "patch: 6.15-rc1"
51+
"product_version": "4c8ff7095bef64fc47e996a938f7d57f9e077da3 <7cd460bd9e7c6e6c30a33982603f65fb5deab1e4"
3352
},
3453
{
3554
"id": "ae30530a-cb4a-38f2-a8ea-d2457ed1f419",
3655
"product": {
37-
"name": "Linux"
56+
"name": "Linux",
57+
"vendor": {
58+
"name": "Linux"
59+
}
3860
},
3961
"product_version": "patch: 6.14.2"
4062
},
63+
{
64+
"id": "ae6cb242-b262-312e-9f01-0a41f65f08c4",
65+
"product": {
66+
"name": "Linux",
67+
"vendor": {
68+
"name": "Linux"
69+
}
70+
},
71+
"product_version": "patch: 6.12.109"
72+
},
4173
{
4274
"id": "ca9a642d-3a34-30d0-963d-3be1f096a617",
4375
"product": {
44-
"name": "Linux"
76+
"name": "Linux",
77+
"vendor": {
78+
"name": "Linux"
79+
}
4580
},
4681
"product_version": "5.6"
4782
},
4883
{
4984
"id": "f18106d6-0683-3171-8c80-db29959dfcb7",
5085
"product": {
51-
"name": "Linux"
86+
"name": "Linux",
87+
"vendor": {
88+
"name": "Linux"
89+
}
5290
},
5391
"product_version": "4c8ff7095bef64fc47e996a938f7d57f9e077da3 <7215cf8ef54bdc9082dffac4662416d54961e258"
5492
}

advisories/2025/04/EUVD-2025-11184.json

Lines changed: 22 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,11 @@
33
"enisaUuid": "ede4ea4e-ea95-3289-a8e1-aaa4f59a2c20",
44
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Mask the bd_cnt field in the TX BD properly\n\nThe bd_cnt field in the TX BD specifies the total number of BDs for\nthe TX packet. The bd_cnt field has 5 bits and the maximum number\nsupported is 32 with the value 0.\n\nCONFIG_MAX_SKB_FRAGS can be modified and the total number of SKB\nfragments can approach or exceed the maximum supported by the chip.\nAdd a macro to properly mask the bd_cnt field so that the value 32\nwill be properly masked and set to 0 in the bd_cnd field.\n\nWithout this patch, the out-of-range bd_cnt value will corrupt the\nTX BD and may cause TX timeout.\n\nThe next patch will check for values exceeding 32.",
55
"datePublished": "Apr 16, 2025, 2:12:55 PM",
6-
"dateUpdated": "Aug 5, 2026, 11:56:48 AM",
6+
"dateUpdated": "Sep 7, 2026, 3:44:43 PM",
77
"baseScore": 8.6,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
10-
"references": "https://git.kernel.org/stable/c/f60b41b815826f15c4d0323f923f398c423178d0\nhttps://git.kernel.org/stable/c/107b25db61122d8f990987895c2912927b8b6e3f\n",
10+
"references": "https://git.kernel.org/stable/c/9ee185e0f15594017a6f1a191ebe6630cfea5f74\nhttps://git.kernel.org/stable/c/f60b41b815826f15c4d0323f923f398c423178d0\nhttps://git.kernel.org/stable/c/107b25db61122d8f990987895c2912927b8b6e3f\n",
1111
"aliases": "GHSA-c4fx-3whg-2g7m\nCVE-2025-22108\n",
1212
"assigner": "Linux",
1313
"epss": 0.26,
@@ -62,6 +62,16 @@
6262
},
6363
"product_version": "3948b05950fdd64002a5f182c65ba5cf2d53cf71 <107b25db61122d8f990987895c2912927b8b6e3f"
6464
},
65+
{
66+
"id": "f5020280-94f3-37cb-9a5b-d27ec252ec82",
67+
"product": {
68+
"name": "Linux",
69+
"vendor": {
70+
"name": "Linux"
71+
}
72+
},
73+
"product_version": "patch: 6.12.109"
74+
},
6575
{
6676
"id": "fa856420-ffc9-3b01-98eb-b627054d9e0b",
6777
"product": {
@@ -71,6 +81,16 @@
7181
}
7282
},
7383
"product_version": "3948b05950fdd64002a5f182c65ba5cf2d53cf71 <f60b41b815826f15c4d0323f923f398c423178d0"
84+
},
85+
{
86+
"id": "fbecdef8-1b8b-3872-8150-9f3bd2fb134a",
87+
"product": {
88+
"name": "Linux",
89+
"vendor": {
90+
"name": "Linux"
91+
}
92+
},
93+
"product_version": "3948b05950fdd64002a5f182c65ba5cf2d53cf71 <9ee185e0f15594017a6f1a191ebe6630cfea5f74"
7494
}
7595
],
7696
"enisaIdVendor": [

advisories/2025/04/EUVD-2025-9524.json

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "3c00498b-7691-3e1b-9a72-54b485f418e6",
44
"description": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.",
55
"datePublished": "Apr 2, 2025, 11:07:43 AM",
6-
"dateUpdated": "Sep 6, 2026, 9:45:59 PM",
6+
"dateUpdated": "Sep 7, 2026, 9:37:17 PM",
77
"baseScore": 4.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
@@ -13,19 +13,19 @@
1313
"epss": 0.36,
1414
"enisaIdProduct": [
1515
{
16-
"id": "7999fca7-c8f9-3311-a5da-85d393bfec7c",
16+
"id": "606ba873-2cbc-3041-bea0-6c2aa6f643c0",
1717
"product": {
18-
"name": "Red Hat OpenShift distributed tracing 3.5.3",
18+
"name": "Red Hat OpenShift distributed tracing 3.5",
1919
"vendor": {
2020
"name": "Red Hat"
2121
}
2222
},
2323
"product_version": "patch: rhosdt-3.5-1743162265"
2424
},
2525
{
26-
"id": "d495c522-e886-3e1c-811f-510a7b2f711c",
26+
"id": "f7e11426-2ff1-3725-b2f0-e891d7c393e3",
2727
"product": {
28-
"name": "Red Hat OpenShift distributed tracing 3.5.3",
28+
"name": "Red Hat OpenShift distributed tracing 3.5",
2929
"vendor": {
3030
"name": "Red Hat"
3131
}

0 commit comments

Comments
 (0)