cat looks inside meme template: DSA 6528-1: "Several vulnerabilities have been discovered in the Linux kernel" / looks inside / 1,313 CVEs
you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 9 hours ago

Yeah, just to add some context, you can detect potential buffer overruns in code by looking for patterns but just because you find potential buffer overruns doesn't mean they are exploitable. The user needs to be able to inject not just code or parameters but also a return address that causes the injected code to run or triggers another function call with the injected parameters. With randomized code and stack addresses, this can be difficult or practically impossible, even if it's easy to customize what bytes go into the overrun part of the buffer.

It's like finding small parts of dangerous patterns but those small parts aren't necessarily dangerous on their own and need more of the pattern to be an issue, but if you fix the small parts you find, you're less likely run into those bigger patterns, so it's worthwhile to fix the small patterns when they come up, but without fitting into a larger pattern, it wasn't an actual security hole, just a potential one.

  • source
  • parent