On Wed, Jan 15, 2025 at 11:40 PM Tomek CEDRO <to...@cedro.info> wrote:
> Google Summer of Code 2025 is coming, we already can and should
> register ideas for NuttX :-)

Okay, another idea that is quite important and security related is
Syscalls Parameters Validation.

We have several reports in this field. One is open and provided as
public Issue. Another is closed and aims for CVE (responsible
disclosure). Unfortunately the fix is left for us.

https://github.com/apache/nuttx/issues/15178

We really need to fix this. There are example implementations in
Zephyr and FreeRTOS that may server as reference points. Looks like a
very interesting task for a diploma thesis. Do you think anyone who
could be interested?

-- 
CeDeROM, SQ7MHZ, http://www.tomek.cedro.info

Reply via email to