Skip to content

Security Assessment: Reviewed multiple CVEs #15

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

allenpais
Copy link
Contributor

This commit documents the assessment of the following CVEs:

vulns/CVE-2023-52924.yml
vulns/CVE-2023-52925.yml
vulns/CVE-2025-21671.yml
vulns/CVE-2025-21672.yml
vulns/CVE-2025-21673.yml

This commit documents the assessment of the following CVEs:

	vulns/CVE-2023-52924.yml
	vulns/CVE-2023-52925.yml
	vulns/CVE-2025-21671.yml
	vulns/CVE-2025-21672.yml
	vulns/CVE-2025-21673.yml

Signed-off-by: Allen Pais <[email protected]>
Comment on lines +4 to +5
impact: Kernel Panic
privileges_required: Low
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

According to Red Hat this seems to be a LPE, while SUSE classifies this as just as DoS. Can you share a bit more context behind your assessment?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The freed zram->table can still be accessed later, leading to invalid memory dereferences.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please integrate that into the notes?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants