Shreyas Penkar

2 exploits Active since Oct 2024
CVE-2024-38399 NOMISEC HIGH WORKING POC
Product <Version - Memory Corruption
Memory corruption while processing user packets to generate page faults.
25 stars
CVSS 8.4
CVE-2025-39965 GITHUB MEDIUM c WORKING POC
Linux Kernel 6.6.103-6.6.108 - Use-After-Free in xfrm_state_delete
In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this value. __xfrm_state_delete doesn't remove those states from the byspi list, since they shouldn't be there, and this shows up as a UAF the next time we go through the byspi list.
10 stars
CVSS 5.5