• jj4211@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      23 hours ago

      Probably not even that.

      For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073

      The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn’t.

      A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.

      A “vulnerability” fixed by:

      -SYM_FUNC_START(__copy_user_nocache)
      +SYM_FUNC_START(copy_to_nontemporal)
      
      • Feathercrown@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        15 hours ago

        lmao that’s crazy

        I usually encounter it in NPM packages, it’s always like “200 critical vulns in your dependencies!” and then 199 of them are “if you pass a regex bomb it takes a long time lol”