A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.
A symlink following vulnerability was found in the ABRT post-create event handler scripts in /etc/libreport/events.d/abrtevent.conf. Event scripts write output files using shell redirections (e.g., "printf ... > $DUMPDIR/varlogmessages") which use open() with OWRONLY|OCREAT|OTRUNC without the ONOFOLLOW flag. If the target file is replaced with a symlink, the shell process (running as root in the abrthandleeventt SELinux domain, which is effectively unconfined) follows the symlink and writes content to the symlink target. In contrast, ddsavetext (used by SetElement) correctly uses ONOFOLLOW. An attacker who has gained filesystem control of the dump directory can replace output files with symlinks pointing to sensitive system files such as /var/spool/cron/root.
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
PHP is vulnerable to the Marvin Attack
Chromium: CVE-2024-6293 Use after free in Dawn
Argument Injection in PHP-CGI
Filter bypass in filtervar (FILTERVALIDATEURL)
Command injection via array-ish $command parameter of procopen() (bypass CVE-2024-1874 fix)
Chromium: CVE-2024-5499 Out of bounds write in Streams API
Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs
Chromium: CVE-2024-5493 Heap buffer overflow in WebRTC
Chromium: CVE-2024-5834 Inappropriate implementation in Dawn
Chromium: CVE-2024-5830 Type Confusion in V8
Chromium: CVE-2024-5833 Type Confusion in V8
Chromium: CVE-2024-5838 Type Confusion in V8
Chromium: CVE-2024-6292 Use after free in Dawn
Chromium: CVE-2024-5837 Type Confusion in V8
Chromium: CVE-2024-6290 Use after free in Dawn
Chromium: CVE-2024-5158 Type Confusion in V8
Chromium: CVE-2024-5835 Heap buffer overflow in Tab Groups
Chromium: CVE-2024-5836 Inappropriate Implementation in DevTools
In the Linux kernel, the following vulnerability has been resolved:
btrfs: make sure that WRITTEN is set on all metadata blocks
We previously would call btrfscheckleaf() if we had the check integrity code enabled, which meant that we could only run the extended leaf checks if we had WRITTEN set on the header flags.
This leaves a gap in our checking, because we could end up with corruption on disk where WRITTEN isn't set on the leaf, and then the extended leaf checks don't get run which we rely on to validate all of the item pointers to make sure we don't access memory outside of the extent buffer.
However, since 732fab95abe2 ("btrfs: check-integrity: remove CONFIGBTRFSFSCHECKINTEGRITY option") we no longer call btrfscheckleaf() from btrfsmarkbufferdirty(), which means we only ever call it on blocks that are being written out, and thus have WRITTEN set, or that are being read in, which should have WRITTEN set.
Add checks to make sure we have WRITTEN set appropriately, and then make sure btrfscheckleaf() always does the item checking. This will protect us from file systems that have been corrupted and no longer have WRITTEN set on some of the blocks.
This was hit on a crafted image tweaking the WRITTEN bit and reported by KASAN as out-of-bound access in the eb accessors. The example is a dir item at the end of an eb.
[2.042] BTRFS warning (device loop1): bad eb member start: ptr 0x3fff start 30572544 member offset 16410 size 2 [2.040] general protection fault, probably for non-canonical address 0xe0009d1000000003: 0000 [#1] PREEMPT SMP KASAN NOPTI [2.537] KASAN: maybe wild-memory-access in range [0x0005088000000018-0x000508800000001f] [2.729] CPU: 0 PID: 2587 Comm: mount Not tainted 6.8.2 #1 [2.729] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 [2.621] RIP: 0010:btrfsget16+0x34b/0x6d0 [2.621] RSP: 0018:ffff88810871fab8 EFLAGS: 00000206 [2.621] RAX: 0000a11000000003 RBX: ffff888104ff8720 RCX: ffff88811b2288c0 [2.621] RDX: dffffc0000000000 RSI: ffffffff81dd8aca RDI: ffff88810871f748 [2.621] RBP: 000000000000401a R08: 0000000000000001 R09: ffffed10210e3ee9 [2.621] R10: ffff88810871f74f R11: 205d323430333737 R12: 000000000000001a [2.621] R13: 000508800000001a R14: 1ffff110210e3f5d R15: ffffffff850011e8 [2.621] FS: 00007f56ea275840(0000) GS:ffff88811b200000(0000) knlGS:0000000000000000 [2.621] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [2.621] CR2: 00007febd13b75c0 CR3: 000000010bb50000 CR4: 00000000000006f0 [2.621] Call Trace: [2.621] <TASK> [2.621] ? showregs+0x74/0x80 [2.621] ? dieaddr+0x46/0xc0 [2.621] ? excgeneralprotection+0x161/0x2a0 [2.621] ? asmexcgeneralprotection+0x26/0x30 [2.621] ? btrfsget16+0x33a/0x6d0 [2.621] ? btrfsget16+0x34b/0x6d0 [2.621] ? btrfsget16+0x33a/0x6d0 [2.621] ? pfxbtrfsget16+0x10/0x10 [2.621] ? pfxmutexunlock+0x10/0x10 [2.621] btrfsmatchdiritemname+0x101/0x1a0 [2.621] btrfslookupdiritem+0x1f3/0x280 [2.621] ? pfxbtrfslookupdiritem+0x10/0x10 [2.621] btrfsgettree+0xd25/0x1910
[ copy more details from report ]
Chromium: CVE-2024-5274 Type Confusion in V8
In the Linux kernel, the following vulnerability has been resolved:
dyndbg: fix old BUGON in >control parser
Fix a BUGON from 2009. Even if it looks "unreachable" (I didn't really look), lets make sure by removing it, doing prerr and return -EINVAL instead.
Chromium: CVE-2024-5847 Use after free in PDFium
Chromium: CVE-2024-5846 Use after free in PDFium
Chromium: CVE-2024-4761 Out of bounds write in V8
Use after free issue in editcap could cause denial of service via crafted capture file
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file