From cd5f6aa65739421ce1ccca1ed7dd59f7f83f75d2 Mon Sep 17 00:00:00 2001 From: Viktor Oreshkin Date: Mon, 13 Oct 2025 20:10:06 +0300 Subject: [PATCH] Improve GHSA-96vr-jxmc-x8jc --- .../GHSA-96vr-jxmc-x8jc.json | 30 ++++++++++++++++--- 1 file changed, 26 insertions(+), 4 deletions(-) diff --git a/advisories/unreviewed/2025/09/GHSA-96vr-jxmc-x8jc/GHSA-96vr-jxmc-x8jc.json b/advisories/unreviewed/2025/09/GHSA-96vr-jxmc-x8jc/GHSA-96vr-jxmc-x8jc.json index 0285aa8132778..173439608c654 100644 --- a/advisories/unreviewed/2025/09/GHSA-96vr-jxmc-x8jc/GHSA-96vr-jxmc-x8jc.json +++ b/advisories/unreviewed/2025/09/GHSA-96vr-jxmc-x8jc/GHSA-96vr-jxmc-x8jc.json @@ -1,24 +1,46 @@ { "schema_version": "1.4.0", "id": "GHSA-96vr-jxmc-x8jc", - "modified": "2025-09-16T18:31:23Z", + "modified": "2025-09-16T18:32:31Z", "published": "2025-09-16T00:30:26Z", "aliases": [ "CVE-2025-43359" ], + "summary": "sendmsg with PKTINFO leads to UDP bound to a local interface binding to all interfaces", "details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 26, macOS Sonoma 14.8, macOS Sequoia 15.7, iOS 18.7 and iPadOS 18.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. A UDP server socket bound to a local interface may become bound to all interfaces.", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "SwiftURL", + "name": "" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43359" }, + { + "type": "WEB", + "url": "https://stek29.rocks/2025/10/13/xnu-udp-pktinfo-cve" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/125108" @@ -56,7 +78,7 @@ "cwe_ids": [ "CWE-670" ], - "severity": "CRITICAL", + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-09-15T23:15:37Z"