Conversation

1) it’s impressive this was done before the patch was even out — proving again that silent fixes can easily be discovered 2) bugs like these (integer overflows!!), in one of the most exposed kernel drivers out there, continue to make me doubt how much code review/analysis happens
Quote Tweet
Since MSRC just published a fix for CVE-2020-0796, here's @_lucas_georges_ quick and dirty root cause analysis on it: synacktiv.com/posts/exploit/ #sambadijaneiro
114
This Tweet was deleted by the Tweet author. Learn more
The issue is that's essentially saying that the solution to developers making mistakes is for the developers not to make the mistakes. If they had realized an overflow could occur, they'd have added a check. Performing the checks via reusable functions is just common sense.
1
1
Show replies