Are these real vulnerabilities or are these “When Mars and Jupiter are aligned next to each other and you compile the kernel backwards X might crash” ones?
We use Copilot to review PRs at work. It loves these kinds of scenarios.
The other day, I was adjusting a drop-down site filter to only show options that would work for the given user. It threw up a “critical vulnerability alert” complaining that I “validated” the user’s selection based on all options, not just the ones they can view.
First off, it wasn’t validation. It was me getting the value of the option. Second, they literally couldn’t do anything if they did select one of those options. And third, the user could bypass it about a dozen other ways, even if I designed it to be a validator.
The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn’t.
A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.
Yeah, CVEs are usually nothing when you get down to understanding, especially kernel CVEs, which almost always declares a CVE for almost any bug, because it is easier that trying to think if it is a security issue or not and basically just assume it could be.
Huge pain as in my work we have a security policy where any unpatched CVEs that cannot be updated away must have a fairly significant writeup delving into the nuance of the CVE and what mitigation has been applied or a rationalization of why it isn’t a risk and by policy we have to second guess every CVE assessment from our vendor, who we explicitly pay to triage and fix this stuff so we don’t have to… They used to at least allow us a pass on “low severity” (that’s still pretty flawed), but they decided that didn’t sound “tough” enough and now every single one must have an answer. So every month a few people have to spend a few days just reading tons of CVEs that are not yet (and frequently never will be) patched by vendor and rationalize it away for the security team. Sometimes the security team will get odd and demand we build our own from upstream (most recently, vim of all things we were mandated to build from source).
Gravity equation says everything with a mass does… Compiling Gentoo removes the sun from the equation anyway (I chose this over a yo mamma joke, I’m getting wiser it seems)
Are these real vulnerabilities or are these “When Mars and Jupiter are aligned next to each other and you compile the kernel backwards X might crash” ones?
We use Copilot to review PRs at work. It loves these kinds of scenarios.
The other day, I was adjusting a drop-down site filter to only show options that would work for the given user. It threw up a “critical vulnerability alert” complaining that I “validated” the user’s selection based on all options, not just the ones they can view.
First off, it wasn’t validation. It was me getting the value of the option. Second, they literally couldn’t do anything if they did select one of those options. And third, the user could bypass it about a dozen other ways, even if I designed it to be a validator.
Probably not even that.
For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073
The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn’t.
A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.
A “vulnerability” fixed by:
-SYM_FUNC_START(__copy_user_nocache) +SYM_FUNC_START(copy_to_nontemporal)Yeah, CVEs are usually nothing when you get down to understanding, especially kernel CVEs, which almost always declares a CVE for almost any bug, because it is easier that trying to think if it is a security issue or not and basically just assume it could be.
Huge pain as in my work we have a security policy where any unpatched CVEs that cannot be updated away must have a fairly significant writeup delving into the nuance of the CVE and what mitigation has been applied or a rationalization of why it isn’t a risk and by policy we have to second guess every CVE assessment from our vendor, who we explicitly pay to triage and fix this stuff so we don’t have to… They used to at least allow us a pass on “low severity” (that’s still pretty flawed), but they decided that didn’t sound “tough” enough and now every single one must have an answer. So every month a few people have to spend a few days just reading tons of CVEs that are not yet (and frequently never will be) patched by vendor and rationalize it away for the security team. Sometimes the security team will get odd and demand we build our own from upstream (most recently, vim of all things we were mandated to build from source).
I’m so sorry. I hope the pay is good.
Like the tide, only the moon affects kernel compilation
Hate to break it to you, but the sun also affects tides.
Tap for spoiler
Gravity equation says everything with a mass does… Compiling Gentoo removes the sun from the equation anyway (I chose this over a yo mamma joke, I’m getting wiser it seems)
May I still get the yo mama joke?
Yo mamma so fat it’s always high tide when she’s at the beach
Oh yeah? Well yo mama teeth are so yellow, when she smiles the traffic slows down!
Oh yeah? Yo mama so stubborn, Waze added a “fine, you drive” instruction
Oh yeah? Yo mama so dumb, she left your dad for her ChatGPT-borne boyfriend