On 8/18/2026 5:04 PM, [email protected] wrote:
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) 
> to consider:
> 
> Pre-existing issues:
> - [High] An integer overflow when evaluating `cur + expr_len` bypasses bounds 
> checks, allowing an attacker to move the instruction pointer backward and 
> trap the kernel in an infinite loop.
> - [High] The CFI interpreter loop does not impose a maximum execution limit, 
> allowing an attacker to stall the CPU by providing a maliciously crafted, 
> highly padded sequence of CFI instructions.

Will address in respective patches in next version.

Regards,
Jens
-- 
Jens Remus
Linux on Z Development (D3303)
[email protected] / [email protected]

IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: 
Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: 
Ehningen; Registergericht: Amtsgericht Stuttgart, HRB 243294
IBM Data Privacy Statement: https://www.ibm.com/privacy/


Reply via email to