Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-27553
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Information Disclosure via Schema Path Manipulation

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

Affected products

YL212CEI8M1IO
  • <1.7.4
YL212CPN8M1IO
  • <1.7.4
YN115CEI8RPIO
  • <1.7.4
YN115CPN8RPIO
  • <1.7.4
IOL MA8 PN DI8
  • <1.7.4
IOL MA8 EIP DI8
  • <1.7.4
ICE2-8IOL-G65L-V1D
  • <1.7.4
ICE3-8IOL-G65L-V1D
  • <1.7.4
ICE2-8IOL-K45P-RJ45
  • <1.7.4
ICE2-8IOL-K45S-RJ45
  • <1.7.4
ICE2-8IOL1-G65L-V1D
  • <1.7.4
ICE3-8IOL-K45P-RJ45
  • <1.7.4
ICE3-8IOL-K45S-RJ45
  • <1.7.4
ICE3-8IOL1-G65L-V1D
  • <1.7.4
ICE3-8IOL-G65L-V1D-Y
  • <1.7.4
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-89832
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
f2fs: fix to clear dirty flag on folio in error path

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to clear dirty flag on folio in error path If node block is corrupted due to chksum mismatch or inconsistent footer info, it needs to drop clear flag of node folio, in order to persist inconsistent node data to storage.

Affected products

Linux
  • ==8d7ebdd109b4654ec5e0e9c3c6f08b06d6558f10
  • =<7.2.*
  • <5b86eab84ac8e9289b5afc52ef88ab18ba5bacab
  • <ab35ae07f2b5b4e118ea47b88577fc7d0e797b17
  • <5.2
  • <4.20
  • =<6.18.*
  • =<*
  • ==b039536485970829918aa237a08417bd0ed5437c
  • <3923ec2b98c96dda4a8bfab81d22553dbf0dd6c2
  • <5.2
  • ==5.2
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-90046
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
mm/page_alloc: don't spin_trylock() in NMI on UP

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP". Pre-existing bugs found by Sashiko during review of this other series: https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/ I have not reproduced these bugs, and I suspect there is no real-world user that is affected by them. This patch (of 2): As noted in can_spin_trylock(), using this is unsafe in this context. commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side but missed the free side. Impact: If BPF programs using these features in NMI (probably tracing) are present on non-SMP builds this might crash the kernel and is probably exploitable by local attackers for privilege escalation.

Affected products

Linux
  • =<7.2.*
  • ==6.15
  • <6.15
  • <3105ae628fb785d48b49256468be4f21a7b3cfc0
  • =<6.18.*
  • =<*
  • <68a069b407303e71db371df85036101e8ff59280
  • <06c76d3c389ff504052f64b1acee44651bd847fa
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-89893
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
media: cx23885: cancel NetUP CI work before teardown

In the Linux kernel, the following vulnerability has been resolved: media: cx23885: cancel NetUP CI work before teardown netup_ci_exit() frees a netup_ci_state while its work item, netup_read_ci_status(), may still be pending or running on the system workqueue. The worker obtains the state with container_of() and dereferences it, so it must not outlive the state. netup_ci_init() queues the initial status read, and CI GPIO interrupts subsequently queue the same work from netup_ci_slot_status(). During remove, cx23885_finidev() calls free_irq() before the CI device is unregistered. free_irq() prevents further IRQ handlers from running, but does not drain work queued previously, so the worker can run after netup_ci_exit() frees the state. Call cancel_work_sync() before dvb_ca_en50221_release() and kfree(). This issue was found by an in-house static analysis tool.

Affected products

Linux
  • =<7.2.*
  • =<6.12.*
  • <5deec890ecfa04d21cfa9bb9a2fe5e9dc98db5c5
  • <aaf76794b870b0f391eff339252a2e2e22f33a4a
  • <ec82b0cf7f75fd95802592dcc9560fc7f529bba4
  • =<5.15.*
  • =<6.18.*
  • <2.6.30
  • =<*
  • <4e143d662ca94888b494b2427fc9e34494eb933a
  • <f7ff5adb63c1b277565afa54ccc0924d841b4a52
  • =<6.1.*
  • <99cd62b9b1c818d6d01a87be9a8e5796314150a2
  • <bf3f49273d5bf6acbdad18ff44c01ffcf7a7a146
  • <140ecbcbf978fbe60f83f8d4f8b1199029a5c763
  • =<6.6.*
  • =<5.10.*
  • ==2.6.30
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
powerpc/kexec_file: Prevent kexec range truncation

In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Prevent kexec range truncation Sashiko AI review pointed out the following issue. The __merge_memory_ranges() function incorrectly handles overlapping memory ranges when merging them. Although sort_memory_ranges() sorts all ranges by their start address in ascending order beforehand, the merge logic remains defective in two ways: 1. It compares the current range's start against the previous element (i-1) instead of the running target index (idx) 2. It unconditionally overwrites 'ranges[idx].end' with 'ranges[i].end'. This logic flaw leads to critical memory truncation when a larger memory range completely subsumes subsequent smaller ranges. For example, consider a sorted input array with three ranges: Range A (idx=0): [0x1000 - 0x9000] Range B (i=1): [0x2000 - 0x5000] (completely inside Range A) Range C (i=2): [0x6000 - 0x8000] (completely inside Range A) 1. When i=1 (Range B): ranges[1].start (0x2000) <= ranges[0].end + 1 (0x9001) is TRUE. The code executes: ranges[0].end = ranges[1].end, which erroneously shrinks Range A's end from 0x9000 down to 0x5000. 2. When i=2 (Range C): ranges[2].start (0x6000) <= ranges[1].end + 1 (0x5001) is FALSE. The code falls into the else block, creating a broken new range. As a result, valid memory fragments [0x5001 - 0x5fff] and [0x8001 - 0x9000] are completely lost from the kexec exclude lists, potentially allowing the crash kernel to overwrite active memory, causing data corruption or crashes. Fix this by ensuring the start of the current range is compared against the end of the active merged range (idx), and use max() to safely prevent the outer boundary from being truncated.

Affected products

Linux
  • =<7.2.*
  • <c4cb547f26d9b73b489c5278d0c8db837c5a174f
  • =<6.12.*
  • =<6.18.*
  • <5.9
  • =<*
  • <9ef63622e6cee588ea4b763a6afc87065254b36a
  • <da88a2a2119e4fd0e8919a7a2448682f574e1545
  • ==5.9
  • <fa40f9dbdd4af53e7445d9135b5b207eb8adf372
Dismissed
(no matching packages found)
Permalink CVE-2026-20325
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.

Affected products

Cisco Nexus Dashboard
  • ==3.2(2f)
  • ==2.1(2f)
  • ==2.3(1c)
  • ==3.2(1e)
  • ==2.2(1e)
  • ==2.3(2b)
  • ==2.3(2e)
  • ==2.3(2c)
  • ==3.0(1i)
  • ==2.1(1e)
  • ==2.1(2d)
  • ==4.2.1
  • ==3.3(2b)
  • ==3.2(1i)
  • ==3.2(2g)
  • ==2.3(2d)
  • ==2.2(2d)
  • ==3.1(1k)
  • ==3.1(1n)
  • ==3.3(1b)
  • ==3.2(2m)
  • ==3.1(1l)
  • ==2.2(1h)
  • ==2.1(1d)
  • ==4.1(1g)
  • ==4.0(1i)
  • ==3.3(2g)
  • ==3.3(1a)
  • ==3.0(1f)
Dismissed
(no matching packages found)
Permalink CVE-2026-20329
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.

Affected products

Cisco Secure Firewall Management Center (FMC)
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.7.12
  • ==7.2.8.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.2.10.1
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.6.3
  • ==10.0.1
  • ==7.2.2
  • ==7.2.4
  • ==7.2.0.1
  • ==7.2.9
  • ==7.2.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.2.6
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.5
  • ==7.4.2.2
  • ==7.2.3.1
  • ==7.2.5.2
  • ==7.2.3
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.6.4
  • ==7.0.0
  • ==7.2.10
  • ==10.0.0
  • ==7.0.6.2
  • ==7.4.6
  • ==7.2.11
  • ==7.6.2
  • ==7.2.0
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.2.5
  • ==7.0.6
  • ==7.2.8
  • ==7.0.7
  • ==7.4.3
  • ==7.7.11
  • ==7.2.7
  • ==7.3.1.2
  • ==7.6.5
  • ==7.2.10.2
  • ==7.2.5.1
  • ==7.4.1
  • ==7.4.1.1
  • ==7.2.4.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.2.2
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.6.4
  • ==10.0.0
  • ==7.0.6.2
  • ==7.6.2
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.0.6
  • ==7.7.11
  • ==7.0.7
  • ==7.4.3
  • ==7.3.1.2
  • ==7.4.1
  • ==7.4.1.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • ==9.22.2
  • ==9.18.4.47
  • ==9.16.3.14
  • ==9.16.4.55
  • ==9.22.2.14
  • ==9.23.1.22
  • ==9.20.4.19
  • ==9.18.4.68
  • ==9.16.4.71
  • ==9.23.1.19
  • ==9.19.1.42
  • ==9.23.1.32
  • ==9.18.4.5
  • ==9.18.1.3
  • ==9.22.1.6
  • ==9.20.4.22
  • ==9.20.3
  • ==9.18.4.67
  • ==9.18.4.24
  • ==9.18.4.53
  • ==9.22.2.13
  • ==9.24.1.221
  • ==9.20.4.30
  • ==9.23.1.211
  • ==9.18.2.7
  • ==9.18.4
  • ==9.16.4.18
  • ==9.22.1.2
  • ==9.20.1.5
  • ==9.23.1.26
  • ==9.16.4.61
  • ==9.16.4.92
  • ==9.18.4.29
  • ==9.22.2.9
  • ==9.24.1.9
  • ==9.18.4.57
  • ==9.18.3.55
  • ==9.18.2.5
  • ==9.23.1.13
  • ==9.16.2.13
  • ==9.20.3.4
  • ==9.16.3
  • ==9.22.2.20
  • ==9.23.1.195
  • ==9.16.4.82
  • ==9.20.2.21
  • ==9.22.2.32
  • ==9.20.4.34
  • ==9.16.4.85
  • ==9.18.4.40
  • ==9.22.1.3
  • ==9.20.3.20
  • ==9.18.4.82
  • ==9.22.3.191
  • ==9.16.3.19
  • ==9.16.2
  • ==9.18.4.50
  • ==9.23.1.7
  • ==9.20.4.7
  • ==9.16.4.89
  • ==9.20.3.7
  • ==9.16.4.67
  • ==9.20.4.28
  • ==9.16.3.15
  • ==9.16.3.23
  • ==9.18.4.76
  • ==9.20.4.10
  • ==9.18.4.71
  • ==9.24.1.5
  • ==9.16.4.70
  • ==9.16.4.62
  • ==9.22.2.4
  • ==9.20.3.16
  • ==9.16.4.19
  • ==9.16.4.39
  • ==9.20.1
  • ==9.22.3
  • ==9.24.1
  • ==9.18.4.66
  • ==9.16.4.9
  • ==9.24.1.155
  • ==9.16.2.7
  • ==9.16.4.48
  • ==9.20.2.22
  • ==9.16.4.38
  • ==9.24.1.11
  • ==9.16.4.27
  • ==9.23.1
  • ==9.20.3.10
  • ==9.16.4
  • ==9.16.4.76
  • ==9.18.3.39
  • ==9.16.4.84
  • ==9.18.3.46
  • ==9.18.4.52
  • ==9.16.2.14
  • ==9.23.1.3
  • ==9.18.2.8
  • ==9.16.1.28
  • ==9.16.2.3
  • ==9.18.2
  • ==9.16.2.11
  • ==9.18.4.8
  • ==9.22.1.1
  • ==9.22.3.5
  • ==9.16.4.14
  • ==9.20.4
  • ==9.20.3.13
  • ==9.18.4.22
  • ==9.18.4.34
  • ==9.20.4.14
  • ==9.20.2.10
  • ==9.18.3
  • ==9.16.4.57
  • ==9.16.3.3
  • ==9.20.3.9
  • ==9.18.3.56
  • ==9.16.1
  • ==9.18.4.135
  • ==9.20.4.235
  • ==9.20.2
  • ==9.24.10
  • ==9.16.4.42
  • ==9.18.3.53
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() qla2x00_error_entry() reads ha->req_q_map[que] twice: once for the NULL check and again when assigning it to req. The map slot is cleared by qla25xx_free_req_que() (ha->req_q_map[que_id] = NULL under mq_lock) during queue teardown, while the response-queue interrupt that drives qla2x00_error_entry() is still registered (the IRQ is released later in qla25xx_free_rsp_que()). If the slot is set to NULL between the two reads, req becomes NULL and is dereferenced. Read the slot once into req and NULL-check the local before use. mq_lock is a mutex and cannot be taken from interrupt context, so the single read plus local check is the appropriate fix for the reported NULL dereference.

Affected products

Linux
  • =<7.2.*
  • <c845f2597787ef70159a32566669e308b2807a56
  • <5dd9bec8004ba93cee8b689bf54ce294f59e5e3c
  • <3.4
  • =<6.6.*
  • =<6.12.*
  • <deb8abde83a799d2501f3977f6d6051000253f5e
  • <fe04b31e386aee4cc3a18f07462af146037dc389
  • =<6.18.*
  • =<5.15.*
  • =<*
  • ==3.4
  • <d79376fbd2a076de82c1cd8aa0b600b300c75a44
  • =<6.1.*
  • <1b995cf4157465357d66ba096e7cdaafab9972e7
  • <35124cfa9898b2088ee72859e573e0876aff66fc
  • =<5.10.*
  • <1c90b74e484ba48f31944fe04963d99e01ac3767
Dismissed
(no matching packages found)
Permalink CVE-2026-76449
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Identity Services Engine SQL Injection Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected products

Cisco ISE Passive Identity Connector
  • ==3.3.0
  • ==3.5.0
  • ==3.4.0
  • ==3.2.0
  • ==3.1.0
Cisco Identity Services Engine Software
  • ==3.1.0 p8
  • ==3.2 Patch 8
  • ==3.3 Patch 9
  • ==3.3.0
  • ==3.4 Patch 3
  • ==3.3 Patch 7
  • ==3.3 Patch 10
  • ==3.2.0
  • ==3.2.0 p4
  • ==3.3 Patch 8
  • ==3.5 Patch 1
  • ==3.3 Patch 2
  • ==3.3 Patch 6
  • ==3.4 Patch 1
  • ==3.1.0 p3
  • ==3.4 Patch 2
  • ==3.1.0 p2
  • ==3.3 Patch 5
  • ==3.2.0 p2
  • ==3.4 Patch 6
  • ==3.2.0 p6
  • ==3.1.0
  • ==3.2.0 p3
  • ==3.2.0 p7
  • ==3.1.0 p4
  • ==3.1.0 p7
  • ==3.3 Patch 4
  • ==3.4 Patch 5
  • ==3.5 Patch 3
  • ==3.4 Patch 7
  • ==3.1.0 p72
  • ==3.2.0 p1
  • ==3.1.0 p6
  • ==3.3 Patch 1
  • ==3.4.0
  • ==3.2.0 p5
  • ==3.3 Patch 12
  • ==3.1.0 p10
  • ==3.4 Patch 4
  • ==3.2 Patch 10
  • ==3.1.0 p9
  • ==3.3 Patch 3
  • ==3.5.0
  • ==3.1.0 p11
  • ==3.5 Patch 2
  • ==3.1.0 p1
  • ==3.2 Patch 9
  • ==3.3 Patch 11
  • ==3.1.0 p5
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
scsi: qla2xxx: Fix BSG job leak on validate flash image error path

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver owns and will complete the request. But bsg_job_done() is guarded by "if (!rval)", so on the error path (rval == -EINVAL) neither the driver nor the transport completes the job. The request dangles until it times out, leaking block layer resources. Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double free") added the "if (!rval)" guard to a batch of BSG handlers. That is correct for handlers that also return the error code (the transport then completes the job once via fail_host_msg), but this function returns QLA_SUCCESS unconditionally, so the guard turned a correct single completion into a leak. Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is reported in vendor_rsp[0], and since the function returns 0 the transport will not complete the job a second time.

Affected products

Linux
  • ==74e7458537cd9349cf019862e51491f670871707
  • ==f2bbb4db0e4a4fbd5e649c0b5d8733f61da24720
  • ==31f33b856d2324d86bcaef295f4d210477a1c018
  • ==871f6236da96c4a9712b8a29d7f555f767a47e95
  • <7.0
  • <5.16
  • =<*
  • ==708003e1bc857dd014d4c44278d7d77c26f91b1c
  • <6.2
  • ==057a5bdc481e58ab853117254867ffb22caf9f6e
  • <6.13
  • <6.20
  • ==27ac9679c43a09e54e2d9aae9980ada045b428e0
  • <0fb52cc632464b0cd07f970341330466d772efe1
  • <6.7
  • =<7.2.*
  • ==7.0
  • <6.19
  • <e25241f9fa01fb0c088381a156d84a725b71c1ef
  • <5.11