Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

More info on the exploit that was patched found here: https://cwe.mitre.org/data/definitions/787.html.

An application may be able to execute arbitrary code with kernel privileges.



Did you mean to link to a CWE page? This isn't about a specific bug.


Isn’t it? The patch is specifically to address:

> An out-of-bounds write issue was addressed with improved bounds checking. (CVE-2022-22675)

Which sounds exactly like a CWE-787 candidate.


gzer0's comment is a bit confusing. It could either be interpreted as saying "here's more info about this exact vulnerability" or "here's more info about this category of vulnerabilities". EE84M3i interpreted the comment as the first, but then saw the link is actually the second, and thought maybe EE84M3i made a mistake with the comment.


I read it as the second as well just due to the link, but

> More info on the <type of> exploit that was patched found here

might have inferred the category of vulnerabilities more.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: