@endrift@social.treehouse.systems
Post #835967
2026-03-25 11:50 UTC
Still pissed at Broadcom for not issuing a security advisory for that kernel vulnerability I found a decade ago that affected the Raspberry Pi. They silently refactored the code instead.
The offending code is still in FreeBSD, even after I told them to update it, since I never got around to providing a PoC. I should write that PoC I guess, since afaik FreeBSD (and possibly NetBSD) on Raspberry Pi is still vulnerable.
Replies (1)
-
@endrift@social.treehouse.systems 2026-03-25 11:53
It is "out of bounds memory write from userspace" level bad fwiw. Though control of where it's written to is basically nil.