Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <a6aa04d0-eb96-4d87-b7d4-b37838b05ce0@oracle.com>
Date: Fri, 14 Nov 2025 09:01:01 -0800
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2025-40300 / VMScape

On 11/13/25 23:48, Bjoern Franke wrote:
> Hi,
> 
> I stumbled at work upon CVE-2025-40300 (as it caused Ubuntus USN-7860-1) and was 
> wondering that it wasn't mentioned on this list. Usually CVEs are posted here 
> before some distro specific fixes appear.

The CPU vendors have their own methods for alerting OS & Hypervisor makers of
CPU-level security issues in advance of publication, that don't flow through
the distros lists or this list, so fixes for those often happen without any
notice here.

For other CVEs, it really depends on whether the project includes this list
in their notification process, or some volunteer notices them and forwards
the information to the list.  Many still slip through the cracks.

-- 
         -Alan Coopersmith-                 alan.coopersmith@...cle.com
          Oracle Solaris Engineering - https://blogs.oracle.com/solaris

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.