Please disclose security vulnerabilities as security advisory.
Security: project-oak/oak
Security
SECURITY.md
-
setup_high_allocator() integer overflow/underflow: host-controlled E820 entry produces a wild pointer fed to a real allocator's init()GHSA-pj9q-pv45-xq8g published
Jul 29, 2026 by conradgroblerModerate -
Restricted Kernel ELF extent overflow allows ring-3 overwrite of guest physical memoryGHSA-ffp2-6m26-mg2c published
Aug 24, 2026 by andrisaarHigh -
Noise KK handshake: `se` DH term uses static key instead of ephemeral - forward secrecy weakenedGHSA-3238-pp48-6m3j published
Jul 6, 2026 by conradgroblerModerate
Learn more about advisories related to project-oak/oak in the GitHub Advisory Database