you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 3 days ago* (1 child)

Probably not even that.

For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073

The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn't.

A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.

A "vulnerability" fixed by:

-SYM_FUNC_START(__copy_user_nocache)
+SYM_FUNC_START(copy_to_nontemporal)
  • source
  • parent
  • hideshow 1 child comment