|
|
Message-ID: <aRdpw5ss1eltT1FV@inutil.org>
Date: Fri, 14 Nov 2025 17:41:23 +0000
From: Moritz Mühlenhoff <jmm@...til.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2025-40300 / VMScape
Alan Coopersmith wrote:
> The CPU vendors have their own methods for alerting OS & Hypervisor makers of
> CPU-level security issues in advance of publication, that don't flow through
> the distros lists or this list, so fixes for those often happen without any
> notice here.
Most major CPU architecture issues have reached the list via the excellent Xen
advisories (which are also posted to this list).
But in the case of CVE-2025-40300, Xen isn't affected
(https://virtualize.sh/blog/vmscape-and-why-xen-dodged-it/), so there was never
a respective Xen advisory.
Cheers,
Moritz
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.