Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions vulns/CVE-2025-40297.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
reachability: Local
memory_corruption: true
bug_class: UaF
impact: LPE, DoS
privileges_required: false
notes: |2-
Use after free in net/bridge leading to DoS and LPE. Reachable by
unprivileged user through namespaces
author: Oracle Corporation
version: v0.1
11 changes: 11 additions & 0 deletions vulns/CVE-2025-40328.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
reachability: Local
memory_corruption: true
bug_class: UaF
impact: DoS, LPE
privileges_required: true
notes: |2-
Assuming that many systems have CIFS shares mounted at boot-time, then an
unprivileged user can issue ordinary fs operations on that share and trigger
the vulnerability
author: Oracle Corporation
version: v0.1