Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
A malicious value of size in a structure of packed libnv can cause an…
… integer overflow, leading to the allocation of a smaller buffer than required for the parsed data. The introduced check was incorrect, as it took into account the size of the pointer, not the structure. This vulnerability affects both kernel and userland.
- Loading branch information