Suraj Theekshana

Vulnerability Researcher & Offensive Security Engineer

About

Offensive security researcher specializing in low-level systems security, Windows, Mac, and Linux kernel/hypervisor infrastructure, memory safety, and C code auditing. Focused on upstream vulnerability discovery and responsible disclosure.

Vulnerabilities & Disclosures

CVE-2026-75900 CVSS 6.1 (Moderate)
swtpm (Software TPM Emulator)
Out-of-bounds read vulnerability in SWTPM_NVRAM_CheckHeader() caused by comparing length against the size of a pointer instead of the structure itself, leading to memory overread when processing untrusted state blobs.
[Read Full Writeup] | Upstream Fix: PR #1155 | Commit: dc5f5ee

Certifications

Technical Focus