• jj4211@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    1 day ago

    Probably not even that.

    For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073

    The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn’t.

    A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.

    A “vulnerability” fixed by:

    -SYM_FUNC_START(__copy_user_nocache)
    +SYM_FUNC_START(copy_to_nontemporal)
    
    • Feathercrown@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      21 hours ago

      lmao that’s crazy

      I usually encounter it in NPM packages, it’s always like “200 critical vulns in your dependencies!” and then 199 of them are “if you pass a regex bomb it takes a long time lol”