• jj4211@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      8 hours ago

      Probably not even that.

      For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073

      The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn’t.

      A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.

      A “vulnerability” fixed by:

      -SYM_FUNC_START(__copy_user_nocache)
      +SYM_FUNC_START(copy_to_nontemporal)