| ▲ | akoboldfrying 5 hours ago | ||||||||||||||||||||||
Do you have a specific library in mind? I think it would have to be an ancient, unmaintained C library. But I think most OSS code isn't like this -- even C code born long ago, if it's still in wide use, has been hardened by now. Examples: Linux kernel, GNU userland, PostgreSQL, Python. | |||||||||||||||||||||||
| ▲ | bigiain 4 hours ago | parent [-] | ||||||||||||||||||||||
> even C code born long ago, if it's still in wide use, has been hardened by now. Examples: Linux kernel There have been two LPE vulnerability and exploits in the Linux kernel announced today. After the one announced just last week. I don't think as much of the C code born long ago has been as carefully hardened as you think. (Copy Fail 2 and Dirty Frag today, and Copy Fail last week) | |||||||||||||||||||||||
| |||||||||||||||||||||||