Skip to content

Commit c0bf1d2

Browse files
Sync Collecting Fix Commits: Tue Aug 4 01:34:36 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 4040583 commit c0bf1d2

11 files changed

Lines changed: 199 additions & 81 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 120 additions & 47 deletions
Large diffs are not rendered by default.

data/fix-commits/angular-cli-4a405ed0.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,8 @@
22
"vcs_url": "https://github.com/angular/angular-cli",
33
"vulnerabilities": {
44
"GHSA-FXQJ-RQCC-2CMP": {
5+
"0b4008f17d76c821d9f075b86da80b826f085d23": "fix(@angular-devkit/build-angular): upgrade postcss to 8.5.23\n\nThis addresses https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp",
6+
"fc861affcd8866b71b81c8ba90f7a63890b6577c": "fix(@angular/build): upgrade postcss to 8.5.23\n\nThis addresses https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp",
57
"972f6db7e9ccf3c4b0e895341a49b104a8b0ac9b": "fix(@angular-devkit/build-angular): upgrade postcss to 8.5.23\n\nThis addresses https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp\n\nTAG=agy\n\nCONV=63a146aa-f34e-4200-88d1-90537150adb0",
68
"8de75ada503d4182af7f0be957e58fe678a63b98": "fix(@angular/build): upgrade postcss to 8.5.23\n\nThis addresses https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp\n\nTAG=agy\n\nCONV=63a146aa-f34e-4200-88d1-90537150adb0"
79
},

data/fix-commits/buildroot-0b809119.json

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,21 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-8376": {
5+
"e3ff7a6f0204a2ec92a0666485c9f4f5d0d066bf": "package/perl: security bump to version 5.42.3\n\nfix CVE-2026-8376 - Buffer overflow in Perl_study_chunk\nfix CVE-2026-57432 - Buffer overflow in S_measure_struct\nfix CVE-2026-13221 - Regex trie 16-bit field overflow\n\nFor release notes, see:\nhttps://perldoc.perl.org/5.42.3/perl5423delta\n\nSigned-off-by: Francois Perrad <francois.perrad.86@gmail.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-57432": {
8+
"e3ff7a6f0204a2ec92a0666485c9f4f5d0d066bf": "package/perl: security bump to version 5.42.3\n\nfix CVE-2026-8376 - Buffer overflow in Perl_study_chunk\nfix CVE-2026-57432 - Buffer overflow in S_measure_struct\nfix CVE-2026-13221 - Regex trie 16-bit field overflow\n\nFor release notes, see:\nhttps://perldoc.perl.org/5.42.3/perl5423delta\n\nSigned-off-by: Francois Perrad <francois.perrad.86@gmail.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-13221": {
11+
"e3ff7a6f0204a2ec92a0666485c9f4f5d0d066bf": "package/perl: security bump to version 5.42.3\n\nfix CVE-2026-8376 - Buffer overflow in Perl_study_chunk\nfix CVE-2026-57432 - Buffer overflow in S_measure_struct\nfix CVE-2026-13221 - Regex trie 16-bit field overflow\n\nFor release notes, see:\nhttps://perldoc.perl.org/5.42.3/perl5423delta\n\nSigned-off-by: Francois Perrad <francois.perrad.86@gmail.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-52761": {
14+
"b98fac95a92924ccf3e2e8ebb137bb00cd30d8fe": "package/libmodsecurity: security bump version to 3.0.16\n\nhttps://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.16/CHANGES\n\nFixes CVE-2026-52761 & CVE-2026-52747\n\nSigned-off-by: Frank Vanbever <fvb@funkworks.be>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"CVE-2026-52747": {
17+
"b98fac95a92924ccf3e2e8ebb137bb00cd30d8fe": "package/libmodsecurity: security bump version to 3.0.16\n\nhttps://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.16/CHANGES\n\nFixes CVE-2026-52761 & CVE-2026-52747\n\nSigned-off-by: Frank Vanbever <fvb@funkworks.be>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
419
"CVE-2026-17544": {
520
"af3e7a4b128688bc89d814cfa0f8c28ff2735510": "package/php: security bump version to 8.5.9\n\nhttps://www.php.net/ChangeLog-8.php#8.5.9\nhttps://news-web.php.net/php.announce/500\nhttps://github.com/php/php-src/blob/php-8.5.9/NEWS\n\nFixes CVE-2026-17544, CVE-2026-17543, CVE-2026-9672 & CVE-2026-7260.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
621
},

data/fix-commits/git-e83ef8ed.json

Lines changed: 19 additions & 20 deletions
Large diffs are not rendered by default.

data/fix-commits/imagemagick-b15feb65.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/imagemagick/imagemagick",
33
"vulnerabilities": {
4+
"GHSA-WXW6-98RJ-HJFR": {
5+
"19bce64e3667ff0348d559e2526c850f8fbe2b5a": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr"
6+
},
47
"GHSA-6RVV-36HW-5RGF": {
58
"297c894d33956fbbba9e573ebe5647d7f5aec76b": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6rvv-36hw-5rgf"
69
},

data/fix-commits/linux-next.git-786af98a.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"vcs_url": "https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git",
33
"vulnerabilities": {
44
"CVE-2017-5753": {
5+
"5273183b6362cad9584bdfb5dddb2df30e4f5477": "platform/x86/amd/hsmp: Add IOCTL_GET_TELEMETRY_DATA for metric table reads\n\nThe metric table needs to be delivered to userspace as a single\natomic snapshot, but the current sysfs metrics_bin path is a file\nread: userspace can read it in chunks and observe a torn snapshot\nif an SMU refresh happens between read() calls. The same path is\nalso bounded by PAGE_SIZE, so the ~13 KB table used by HSMP protocol\nversion 7 on Family 1Ah Model 50h-5Fh cannot be returned at all,\nregardless of how userspace reads it. Rather than extend sysfs to\nlift both restrictions, expose the metric table through the\nexisting HSMP character device using a new ioctl that always copies\nthe table in one shot.\n\nAdd struct hsmp_telemetry_data and HSMP_IOCTL_GET_TELEMETRY_DATA\nto the UAPI header. Under the surrounding #pragma pack(4), placing\nthe __u64 user pointer first gives a tight 16-byte layout that is\nidentical for 32- and 64-bit callers, and the trailing __u16\nreserved field is rejected with -EINVAL if non-zero so future\nkernels can repurpose it without breaking already-deployed\nuserspace. The command is encoded with _IOW because the kernel only\nreads the request struct; the snapshot travels through the user\npointer it carries.\n\nThe requested size may be anything from one byte up to the size\nfirmware reported for that socket's table. A short request returns\nthe leading bytes of the snapshot, so userspace built against an\nolder table layout keeps working on firmware that grew the table,\nmirroring the relaxed response_sz rule applied to HSMP messages\nearlier in this series. A request larger than the firmware table is\nrejected with -EINVAL rather than short-written, so a caller can\nnever mistake a partial copy for a full one.\n\nDispatch hsmp_ioctl() on the ioctl command: the existing message\nhandler is factored out as hsmp_ioctl_msg() for HSMP_IOCTL_CMD, and\nHSMP_IOCTL_GET_TELEMETRY_DATA goes to a new\nhsmp_ioctl_get_telemetry() helper.\n\n/dev/hsmp is a singleton character device that outlives an\nindividual socket unbind, so an ioctl issued on an already-open fd\ncan run concurrently with socket teardown. hsmp_sock_rwsem is the\ndriver's contract for that: the data plane takes it for read, and\nprobe and remove take it for write to drain the data plane before\nfreeing the socket array, unmapping the metric tables and\ndestroying the per-socket mutexes. hsmp_ioctl_get_telemetry() takes\nit for read across the socket lookup, the checks on that socket's\nmetric-table state and the table read itself, so none of that state\ncan be torn down underneath it. Without this the handler would\nsleep in its kvmalloc() holding no lock at all, and could resume\nwith a freed socket, locking a destroyed mutex and reading from an\nunmapped iomem region.\n\nThe lock is dropped before the copy_to_user(), because faulting in\nthe destination can block indefinitely on a userfaultfd-backed\nbuffer and would otherwise leave a socket unbind waiting for the\nwrite lock.\n\nSince hsmp_metric_tbl_read() reached the mailbox through\nhsmp_send_message(), which takes hsmp_sock_rwsem itself, calling it\nwith the lock already held would recursively take the read side and\ncan deadlock against a queued writer. Split out\nhsmp_metric_tbl_read_locked(), which asserts the lock and uses\nhsmp_send_message_locked(), and leave hsmp_metric_tbl_read() as a\nwrapper that takes the read lock for the sysfs callers. This also\nbrings the whole fill-and-copy under the rwsem for those callers,\nwhere the memcpy_fromio() previously ran outside it, and makes the\nlock order uniformly hsmp_sock_rwsem -> metric_read_lock ->\nhsmp_sem.\n\nThe user-controlled socket index in HSMP_IOCTL_GET_TELEMETRY_DATA is\nclamped with array_index_nospec() before indexing hsmp_pdev.sock[],\nmitigating Spectre v1 (CVE-2017-5753). Include linux/nospec.h, which\nthe file relied on getting transitively.\n\nCo-developed-by: Muthusamy Ramalingam <muthusamy.ramalingam@amd.com>\nSigned-off-by: Muthusamy Ramalingam <muthusamy.ramalingam@amd.com>\nSigned-off-by: Muralidhara M K <muralidhara.mk@amd.com>\nLink: https://patch.msgid.link/20260727141542.3370108-5-muralidhara.mk@amd.com\nReviewed-by: Ilpo J\u00e4rvinen <ilpo.jarvinen@linux.intel.com>\nSigned-off-by: Ilpo J\u00e4rvinen <ilpo.jarvinen@linux.intel.com>",
56
"d20457b46eca76b9bb716dd31af591cad21607b5": "platform/x86/amd/hsmp: Clamp ioctl/send_message indices (Spectre v1)\n\nAlthough validate_message() checks msg_id, a mispredicted branch can\nstill allow speculative indexing into hsmp_msg_desc_table[]. Clamp\nmsg.msg_id with array_index_nospec() at entry to hsmp_ioctl_msg() so\ndownstream dereferences (including via is_get_msg() and\nhsmp_send_message()) see a bounded index.\n\nSimilarly, hsmp_send_message() bounds-checks msg->sock_ind before\nindexing hsmp_pdev.sock[], but a mispredicted branch can still\nspeculatively use the raw index (Spectre v1, CVE-2017-5753). Apply\narray_index_nospec() after the check so every caller that reaches\nhsmp_pdev.sock[] through this helper sees a clamped socket\nindex\u2014including hsmp_ioctl_msg() and any other path that hands a\nuser-derived struct hsmp_message to hsmp_send_message().\n\nReviewed-by: Muthusamy Ramalingam <muthusamy.ramalingam@amd.com>\nSigned-off-by: Muralidhara M K <muralidhara.mk@amd.com>\nLink: https://patch.msgid.link/20260612042610.1629037-7-muralidhara.mk@amd.com\nReviewed-by: Ilpo J\u00e4rvinen <ilpo.jarvinen@linux.intel.com>\nSigned-off-by: Ilpo J\u00e4rvinen <ilpo.jarvinen@linux.intel.com>",
67
"3214d01f139b7544e870fc0b7fcce8da13c1cb51": "KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds\n\nThis adds a new ioctl, KVM_PPC_GET_CPU_CHAR, that gives userspace\ninformation about the underlying machine's level of vulnerability\nto the recently announced vulnerabilities CVE-2017-5715,\nCVE-2017-5753 and CVE-2017-5754, and whether the machine provides\ninstructions to assist software to work around the vulnerabilities.\n\nThe ioctl returns two u64 words describing characteristics of the\nCPU and required software behaviour respectively, plus two mask\nwords which indicate which bits have been filled in by the kernel,\nfor extensibility. The bit definitions are the same as for the\nnew H_GET_CPU_CHARACTERISTICS hypercall.\n\nThere is also a new capability, KVM_CAP_PPC_GET_CPU_CHAR, which\nindicates whether the new ioctl is available.\n\nSigned-off-by: Paul Mackerras <paulus@ozlabs.org>",
78
"05992edc279237d5803d64578e0c72b604970a49": "Merge branch 'kvm-insert-lfence'\n\nTopic branch for CVE-2017-5753, avoiding conflicts in the next merge window.",

data/fix-commits/opa-8ab59e31.json

Lines changed: 10 additions & 0 deletions
Large diffs are not rendered by default.

0 commit comments

Comments
 (0)