Where
-Infinity
0

Hi,

The below was misreported to lots of mailing lists at once on Jan 23, but didn't actually get to the public lists (was presumably spam-filtered), so I allowed for the maximum of 14 days of "embargo" on linux-distros. However, no one made any use of the "embargo", as far as I can tell.

The message was also badly misformatted. What I include below is my repaired version of the message - HTML entities converted back to their corresponding characters, the attached reproducer converted to a Unix text file with:

iconv -cf ucs-2 < repro.c.txt | tr -d '\r' > repro.c

I just learned today that a similar message had also been sent to other public lists on Jan 19, so granting the "embargo" was inappropriate:

https://lore.kernel.org/all/tencentA3FB116603B2596D123C55CCC8DC2E6E1F07 () qq com/

I am posting this to oss-security for consistency and transparency, because it was on linux-distros. I don't know whether this is actually a security issue or not.

A couple of days ago, I tried asking ffhgfv via private e-mail:

"Also, can you please clarify what security boundary is crossed by the PoC, if any? In other words, what privileges are required for running the PoC and does the bug allow for exceeding what's normally possible given those privileges?"

to which I got no reply yet.

Even though this wasn't actually on the proper upstream list ocfs2-devel, the subsystem maintainers were CC'ed on many of these messages. I am unaware of any replies from them. I'm going to forward this message to ocfs2-devel shortly (not CC'ing here so that it's a separate thread there, with any replies not CC'ed to oss-security).

ffhgfv and others - for uninvestigated or non-security-critical Linux kernel bugs, I second Greg KH's advice from the thread linked above:

"Please report this to the proper developers and mailing list as found by the scripts/getmaintainer.pl tool."

Way too many Linux kernel bugs are being found, including many by syzbot, and there's rarely a good reason to single out a bug for handling it as a security vulnerability under embargo. Only when you have specific reasons to claim that it's a security vulnerability should you report the bug to security at kernel org. And only once there's a fix, should you maybe report it to linux-distros (if the fix is still not public) or oss-security (otherwise).

Alexander

----- Forwarded message from ffhgfv <744439878 () qq com> -----

From: "ffhgfv" <744439878 () qq com> To: "security" "linux-distros" "oss-security" Subject: [vs-plain] Kernel bug found in the latest upstream relegated to ocfs2 CC: "mark" <mark () fasheh com>, "jlbec" <jlbec () evilplan org>, "joseph.qi" <joseph.qi () linux alibaba com>, "ocfs2-devel" <ocfs2-devel () lists linux dev>, "linux-kernel" <linux-kernel () vger kernel org>, "xrivendell7" <xrivendell7 () gmail com> Date: Thu, 23 Jan 2025 12:05:24 +0800

Hello, I found a bug titled ?? kernel BUG in ocfs2refcountcalcowclusters?? with modified syzkaller in the lasted upstream relegated to oracle cluster file system. If you fix this issue, please add the following tag to the commit: Reported-by:jianzhou zhao <xnxc22xnxc22 () qq com> , xingwei lee <xrivendell7 () gmail com>

------------[ cut here ]------------

[ 81.294928][ T9408] kernel BUG at fs/ocfs2/refcounttree.c:2678! [ 81.296140][ T9408] Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI [ 81.297446][ T9408] CPU: 0 UID: 0 PID: 9408 Comm: poc Not tainted 6.13.0 #1 [ 81.300604][ T9408] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 [ 81.302921][ T9408] RIP: 0010:ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.304727][ T9408] Code: 38 d0 7c 0c 84 d2 74 08 48 89 f7 e8 5a e7 7e fe 48 8b 44 24 08 44 8b 64 24 28 89 18 41 29 dc e9 72 f7 ff ff e8 b1 9e 1d fe 90 <0f> 0b ed [ 81.308312][ T9408] RSP: 0018:ffffc900136ef908 EFLAGS: 00010293 [ 81.309311][ T9408] RAX: 0000000000000000 RBX: ffff888011ba94d0 RCX: ffffffff837a87a9 [ 81.310697][ T9408] RDX: ffff888045e79cc0 RSI: ffffffff837a913f RDI: 0000000000000001 [ 81.312024][ T9408] RBP: 0000000000000000 R08: 00000000ffffffff R09: ffffc900136efaf8 [ 81.313524][ T9408] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001 [ 81.315066][ T9408] R13: 0000000000000000 R14: ffff888011ba94c0 R15: 0000000000000001 [ 81.316576][ T9408] FS: 0000000033bd23c0(0000) GS:ffff88802b800000(0000) knlGS:0000000000000000 [ 81.318582][ T9408] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 81.320052][ T9408] CR2: 000000002000d000 CR3: 000000004fd34000 CR4: 00000000000006f0 [ 81.321222][ T9408] Call Trace: [ 81.321777][ T9408] <TASK> [ 81.322325][ T9408] ? die+0x32/0x90 [ 81.323177][ T9408] ? dotrap+0x232/0x430 [ 81.323867][ T9408] ? ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.324870][ T9408] ? doerrortrap+0x107/0x240 [ 81.325641][ T9408] ? ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.326731][ T9408] ? ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.327754][ T9408] ? handleinvalidop+0x34/0x40 [ 81.328779][ T9408] ? ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.330053][ T9408] ? excinvalidop+0x5d/0x80 [ 81.331263][ T9408] ? asmexcinvalidop+0x1a/0x20 [ 81.332468][ T9408] ? ocfs2refcountcalcowclusters+0x469/0x14c0 [ 81.333701][ T9408] ? ocfs2refcountcalcowclusters+0xdff/0x14c0 [ 81.334841][ T9408] ? ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.336476][ T9408] ? ocfs2refcountcalcowclusters+0xdff/0x14c0 [ 81.337674][ T9408] ? pfxocfs2getclusters+0x10/0x10 [ 81.339205][ T9408] ? pfxlockacquire+0x10/0x10 [ 81.340459][ T9408] ? pfxocfs2refcountcalcowclusters+0x10/0x10 [ 81.342272][ T9408] ocfs2refcountcow+0x29c/0xef0 [ 81.343743][ T9408] ? rcuiswatching+0x12/0xc0 [ 81.345347][ T9408] ? tracelockacquire+0x14e/0x200 [ 81.347005][ T9408] ? pfxocfs2refcountcow+0x10/0x10 [ 81.347835][ T9408] ? lockacquire+0x32/0xc0 [ 81.348442][ T9408] ? downwrite+0x14e/0x200 [ 81.349092][ T9408] ? pfxdownwrite+0x10/0x10 [ 81.349782][ T9408] ? ocfs2inodeunlock+0x8d/0x170 [ 81.350474][ T9408] ocfs2filewriteiter+0x1ac6/0x22f0 [ 81.351371][ T9408] ? pfxocfs2filewriteiter+0x10/0x10 [ 81.352465][ T9408] ? rcuiswatching+0x12/0xc0 [ 81.353329][ T9408] ? tracelockacquire+0x14e/0x200 [ 81.354293][ T9408] vfswrite+0xbff/0x10d0 [ 81.355091][ T9408] ? pfxocfs2filewriteiter+0x10/0x10 [ 81.356051][ T9408] ? pfxvfswrite+0x10/0x10 [ 81.356959][ T9408] ? rcuiswatching+0x12/0xc0 [ 81.357835][ T9408] ksyswrite+0x122/0x240 [ 81.359060][ T9408] ? pfxksyswrite+0x10/0x10 [ 81.359924][ T9408] dosyscall64+0xcb/0x250 [ 81.360822][ T9408] entrySYSCALL64afterhwframe+0x77/0x7f [ 81.361842][ T9408] RIP: 0033:0x45377d [ 81.362967][ T9408] Code: c3 e8 27 21 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 08 [ 81.367066][ T9408] RSP: 002b:00007ffef72cf198 EFLAGS: 00000246 ORIGRAX: 0000000000000001 [ 81.368683][ T9408] RAX: ffffffffffffffda RBX: 00007ffef72cf408 RCX: 000000000045377d [ 81.370422][ T9408] RDX: 0000000000000001 RSI: 0000000020000280 RDI: 0000000000000009 [ 81.372352][ T9408] RBP: 00007ffef72cf1b0 R08: 00007ffef72cf1b0 R09: 00007ffef72cf1b0 [ 81.373797][ T9408] R10: 00007ffef72cf1b0 R11: 0000000000000246 R12: 0000000000000001 [ 81.375889][ T9408] R13: 00007ffef72cf3f8 R14: 00000000004d4710 R15: 0000000000000001 [ 81.377584][ T9408] </TASK> [ 81.378113][ T9408] Modules linked in: [ 81.379107][ T9408] ---[ end trace 0000000000000000 ]--- [ 81.380344][ T9408] RIP: 0010:ocfs2refcountcalcowclusters+0xe00/0x14c0 [ 81.381719][ T9408] Code: 38 d0 7c 0c 84 d2 74 08 48 89 f7 e8 5a e7 7e fe 48 8b 44 24 08 44 8b 64 24 28 89 18 41 29 dc e9 72 f7 ff ff e8 b1 9e 1d fe 90 <0f> 0b ed [ 81.384543][ T9408] RSP: 0018:ffffc900136ef908 EFLAGS: 00010293 [ 81.385617][ T9408] RAX: 0000000000000000 RBX: ffff888011ba94d0 RCX: ffffffff837a87a9 [ 81.387057][ T9408] RDX: ffff888045e79cc0 RSI: ffffffff837a913f RDI: 0000000000000001 [ 81.389023][ T9408] RBP: 0000000000000000 R08: 00000000ffffffff R09: ffffc900136efaf8 [ 81.390455][ T9408] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001 [ 81.391846][ T9408] R13: 0000000000000000 R14: ffff888011ba94c0 R15: 0000000000000001 [ 81.393398][ T9408] FS: 0000000033bd23c0(0000) GS:ffff88802b800000(0000) knlGS:0000000000000000 [ 81.395131][ T9408] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 81.397558][ T9408] CR2: 000000002000d000 CR3: 000000004fd34000 CR4: 00000000000006f0 [ 81.399091][ T9408] Kernel panic - not syncing: Fatal exception [ 81.401343][ T9408] Kernel Offset: disabled [ 81.402051][ T9408] Rebooting in 86400 seconds..

==================================================================

I use the same kernel as syzbot instance upstream: c4b9570cfb63501638db720f3bee9f6dfd044b82

Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=899f38f532606c8e Complier: gcc 11.4.0 The repro is shown in annex repro.c.txt

I hope it helps. Best regards Jianzhou Zhao, Xingwei Lee.

----- End forwarded message -----

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

First published (updated )
Severity
7.8
EPSS
0.04%
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the Linux kernel, the following vulnerability has been resolved:

iouring/sqpoll: zero sqd->thread on tctx errors

Syzkeller reports:

BUG: KASAN: slab-use-after-free in threadgroupcputime+0x409/0x700 kernel/sched/cputime.c:341 Read of size 8 at addr ffff88803578c510 by task syz.2.3223/27552 Call Trace: <TASK> ... kasanreport+0x143/0x180 mm/kasan/report.c:602 threadgroupcputime+0x409/0x700 kernel/sched/cputime.c:341 threadgroupcputimeadjusted+0xa6/0x340 kernel/sched/cputime.c:639 getrusage+0x1000/0x1340 kernel/sys.c:1863 iouringshowfdinfo+0xdfe/0x1770 iouring/fdinfo.c:197 seqshow+0x608/0x770 fs/proc/fd.c:68 ...

That's due to sqd->task not being cleared properly in cases where SQPOLL task tctx setup fails, which can essentially only happen with fault injection to insert allocation errors.

1 / 5
Source: NVD
First published (updated )

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of the Linux Kernel. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-50285.

First published (updated )
Advisory
ZDI-24-1726

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of the Linux Kernel. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-50285.

First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

First published (updated )
Advisory
ZDI-24-1688

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

First published (updated )
Advisory
ZDI-24-1648

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

First published (updated )

This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.8. The following CVEs are assigned: CVE-2024-42070.

First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L

A flaw was found within the handling of SMB2READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

1 / 3
Source: MITRE
First published (updated )
Severity
1

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

The specific flaw exists within the handling of SMB2READ commands. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

Reference: https://www.zerodayinitiative.com/advisories/ZDI-24-589/

First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L

A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

1 / 3
Source: MITRE
First published (updated )
Severity
1

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable.

The specific flaw exists within the handling of SMB2 read requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.

Reference: https://www.zerodayinitiative.com/advisories/ZDI-24-588/

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

1 / 3
Source: MITRE
First published (updated )
Severity
1

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable.

The specific flaw exists within the parsing of SMB2 requests that have a transform header. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.

Reference: https://www.zerodayinitiative.com/advisories/ZDI-24-586/

First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

1 / 3
Source: MITRE
First published (updated )
Severity
1

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Linux Kernel. Authentication may or may not be required to exploit this vulnerability, depending upon configuration. Furthermore, only systems with ksmbd enabled are vulnerable.

The specific flaw exists within the parsing of extended attributes. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.

Reference: https://www.zerodayinitiative.com/advisories/ZDI-24-590/

First published (updated )
Severity
4

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxtre: Fix a bug while setting up Level-2 PBL pages

Avoid memory corruption while setting up Level-2 PBL pages for the non MR resources when numpages > 256K.

There will be a single PDE page address (contiguous pages in the case of > PAGESIZE), but, current logic assumes multiple pages, leading to invalid memory access after 256K PBL entries in the PDE.

First published (updated )
Severity
4

In the Linux kernel, the following vulnerability has been resolved:

xfrm: validate new SA's prefixlen using SA family when sel.family is unset

This expands the validation introduced in commit 07bf7908950a ("xfrm: Validate address prefix lengths in the xfrm selector.")

syzbot created an SA with usersa.sel.family = AFUNSPEC usersa.sel.prefixlens = 128 usersa.family = AFINET

Because of the AFUNSPEC selector, verifynewsainfo doesn't put limits on prefixlen{s,d}. But then copyfromuserstate sets x->sel.family to usersa.family (AFINET). Do the same conversion in verifynewsainfo before validating prefixlen{s,d}, since that's how prefixlen is going to be used later on.

First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

First published (updated )
Advisory
ZDI-24-1456

This vulnerability allows local attackers to escalate privileges on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

First published (updated )
Advisory
ZDI-24-1454

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

First published (updated )
Advisory
ZDI-24-1455

This vulnerability allows local attackers to escalate privileges on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

First published (updated )
Severity
4
Use After Free

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix use-after-free in bpfuprobemultilinkattach()

If bpflinkprime() fails, bpfuprobemultilinkattach() goes to the errorfree label and frees the array of bpfuprobe's without calling bpfuprobeunregister().

This leaks bpfuprobe->uprobe and worse, this frees bpfuprobe->consumer without removing it from the uprobe->consumers list.

First published (updated )
Severity
4

In the Linux kernel, the following vulnerability has been resolved:

ELF: fix kernel.randomizevaspace double read

ELF loader uses "randomizevaspace" twice. It is sysctl and can change at any moment, so 2 loads could see 2 different values in theory with unpredictable consequences.

Issue exactly one load for consistent value across one exec.

First published (updated )
Severity
4

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix a kernel verifier crash in stacksafe()

Daniel Hodges reported a kernel verifier crash when playing with sched-ext. Further investigation shows that the crash is due to invalid memory access in stacksafe(). More specifically, it is the following code:

if (exact != NOTEXACT && old->stack[spi].slottype[i % BPFREGSIZE] != cur->stack[spi].slottype[i % BPFREGSIZE]) return false;

The 'i' iterates old->allocatedstack. If cur->allocatedstack < old->allocatedstack the out-of-bound access will happen.

To fix the issue add 'i >= cur->allocatedstack' check such that if the condition is true, stacksafe() should fail. Otherwise, cur->stack[spi].slottype[i % BPFREGSIZE] memory access is legal.

First published (updated )
Severity
4

In the Linux kernel, the following vulnerability has been resolved:

x86/mm: Fix pticlonepgtable() alignment assumption

Guenter reported dodgy crashes on an i386-nosmp build using GCC-11 that had the form of endless traps until entry stack exhaust and then #DF from the stack guard.

It turned out that pticlonepgtable() had alignment assumptions on the start address, notably it hard assumes start is PMD aligned. This is true on x8664, but very much not true on i386.

These assumptions can cause the end condition to malfunction, leading to a 'short' clone. Guess what happens when the user mapping has a short copy of the entry text?

Use the correct increment form for addr to avoid alignment assumptions.

First published (updated )
Severity
1

In the Linux kernel, the following vulnerability has been resolved:

fuse: Initialize beyond-EOF page contents before setting uptodate

fusenotifystore(), unlike fusedoreadpage(), does not enable page zeroing (because it can be used to change partial page contents).

So fusenotifystore() must be more careful to fully initialize page contents (including parts of the page that are beyond end-of-file) before marking the page uptodate.

The current code can leave beyond-EOF page contents uninitialized, which makes these uninitialized page contents visible to userspace via mmap().

This is an information leak, but only affects systems which do not enable init-on-alloc (via CONFIGINITONALLOCDEFAULTON=y or the corresponding kernel command line parameter).

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203