On 8/18/2026 5:04 PM, [email protected] wrote: > Thank you for your contribution! Sashiko AI review found 2 potential issue(s) > to consider: > > Pre-existing issues: > - [High] An integer overflow when evaluating `cur + expr_len` bypasses bounds > checks, allowing an attacker to move the instruction pointer backward and > trap the kernel in an infinite loop. > - [High] The CFI interpreter loop does not impose a maximum execution limit, > allowing an attacker to stall the CPU by providing a maliciously crafted, > highly padded sequence of CFI instructions.
Will address in respective patches in next version. Regards, Jens -- Jens Remus Linux on Z Development (D3303) [email protected] / [email protected] IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: Ehningen; Registergericht: Amtsgericht Stuttgart, HRB 243294 IBM Data Privacy Statement: https://www.ibm.com/privacy/
