Skip to content

Commit cd5f6aa

Browse files
committed
1 parent 157c830 commit cd5f6aa

File tree

1 file changed

+26
-4
lines changed

1 file changed

+26
-4
lines changed

advisories/unreviewed/2025/09/GHSA-96vr-jxmc-x8jc/GHSA-96vr-jxmc-x8jc.json

Lines changed: 26 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,24 +1,46 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-96vr-jxmc-x8jc",
4-
"modified": "2025-09-16T18:31:23Z",
4+
"modified": "2025-09-16T18:32:31Z",
55
"published": "2025-09-16T00:30:26Z",
66
"aliases": [
77
"CVE-2025-43359"
88
],
9+
"summary": "sendmsg with PKTINFO leads to UDP bound to a local interface binding to all interfaces",
910
"details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 26, macOS Sonoma 14.8, macOS Sequoia 15.7, iOS 18.7 and iPadOS 18.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. A UDP server socket bound to a local interface may become bound to all interfaces.",
1011
"severity": [
1112
{
1213
"type": "CVSS_V3",
13-
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "SwiftURL",
21+
"name": ""
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
}
30+
]
31+
}
32+
]
1433
}
1534
],
16-
"affected": [],
1735
"references": [
1836
{
1937
"type": "ADVISORY",
2038
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43359"
2139
},
40+
{
41+
"type": "WEB",
42+
"url": "https://stek29.rocks/2025/10/13/xnu-udp-pktinfo-cve"
43+
},
2244
{
2345
"type": "WEB",
2446
"url": "https://support.apple.com/en-us/125108"
@@ -56,7 +78,7 @@
5678
"cwe_ids": [
5779
"CWE-670"
5880
],
59-
"severity": "CRITICAL",
81+
"severity": "HIGH",
6082
"github_reviewed": false,
6183
"github_reviewed_at": null,
6284
"nvd_published_at": "2025-09-15T23:15:37Z"

0 commit comments

Comments
 (0)