3 ms·
Could this be an issue of not appropriately identifying the impact of the bug? If it was reported by an automated tool and easy to fix perhaps the developer fa
by edoo 7y ago
Could this be an issue of not appropriately identifying the impact of the bug? If it was reported by an automated tool and easy to fix perhaps the developer failed to fully investigate the problem, failing to realize it is a critical vulnerability and have the fix back ported.
- hannob 7y agoKASAN identified it as a use after free bug. That makes it very plausibly a security vuln. What more do you want to automate? The problem is there are so many of those.