diff --git a/vulns/CVE-2025-40149.yml b/vulns/CVE-2025-40149.yml new file mode 100644 index 0000000..179d3b0 --- /dev/null +++ b/vulns/CVE-2025-40149.yml @@ -0,0 +1,8 @@ +reachability: Local +memory_corruption: true +bug_class: Use-after-free +impact: LPE +privileges_required: false +notes: Use-after-free in ktls code which could lead to LPE. +author: Oracle Corporation +version: v0.1 diff --git a/vulns/CVE-2025-40158.yml b/vulns/CVE-2025-40158.yml new file mode 100644 index 0000000..53929fa --- /dev/null +++ b/vulns/CVE-2025-40158.yml @@ -0,0 +1,8 @@ +reachability: Local +memory_corruption: true +bug_class: Use-after-free +impact: LPE +privileges_required: false +notes: Use-after-free in ipv6 code which could lead to LPE. +author: Oracle Corporation +version: v0.1