Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <38e5d24d-80a9-4f56-9d6d-153cba1ef040@schafweide.org>
Date: Mon, 17 Nov 2025 14:14:40 +0100
From: Bjoern Franke <bjo@...afweide.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2025-40300 / VMScape

Hi Alan,


> 
> The CPU vendors have their own methods for alerting OS & Hypervisor makers of
> CPU-level security issues in advance of publication, that don't flow through
> the distros lists or this list, so fixes for those often happen without any
> notice here.
> 
> For other CVEs, it really depends on whether the project includes this list
> in their notification process, or some volunteer notices them and forwards
> the information to the list.  Many still slip through the cracks.

Thanks for your explanation!

Regards
Bjoern

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.