• carrylex@lemmy.world
    link
    fedilink
    arrow-up
    89
    ·
    2 days ago

    Are these real vulnerabilities or are these “When Mars and Jupiter are aligned next to each other and you compile the kernel backwards X might crash” ones?

    • droans@lemmy.world
      link
      fedilink
      arrow-up
      15
      ·
      19 hours ago

      We use Copilot to review PRs at work. It loves these kinds of scenarios.

      The other day, I was adjusting a drop-down site filter to only show options that would work for the given user. It threw up a “critical vulnerability alert” complaining that I “validated” the user’s selection based on all options, not just the ones they can view.

      First off, it wasn’t validation. It was me getting the value of the option. Second, they literally couldn’t do anything if they did select one of those options. And third, the user could bypass it about a dozen other ways, even if I designed it to be a validator.

      • jj4211@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        7 hours ago

        Probably not even that.

        For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073

        The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn’t.

        A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.

        A “vulnerability” fixed by:

        -SYM_FUNC_START(__copy_user_nocache)
        +SYM_FUNC_START(copy_to_nontemporal)
        
    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      20 hours ago

      Yeah, CVEs are usually nothing when you get down to understanding, especially kernel CVEs, which almost always declares a CVE for almost any bug, because it is easier that trying to think if it is a security issue or not and basically just assume it could be.

      Huge pain as in my work we have a security policy where any unpatched CVEs that cannot be updated away must have a fairly significant writeup delving into the nuance of the CVE and what mitigation has been applied or a rationalization of why it isn’t a risk and by policy we have to second guess every CVE assessment from our vendor, who we explicitly pay to triage and fix this stuff so we don’t have to… They used to at least allow us a pass on “low severity” (that’s still pretty flawed), but they decided that didn’t sound “tough” enough and now every single one must have an answer. So every month a few people have to spend a few days just reading tons of CVEs that are not yet (and frequently never will be) patched by vendor and rationalize it away for the security team. Sometimes the security team will get odd and demand we build our own from upstream (most recently, vim of all things we were mandated to build from source).