Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
pistolero :thispersondoesnotexist: (p@freespeechextremist.com)'s status on Tuesday, 19-Sep-2023 00:27:59 JST pistolero :thispersondoesnotexist:
@mint @graf @w Well, now that it's all disclosed, I can point to that and say that it's fucking stupid to say I was downplaying the issue. A malicious upstream server can make bloat exhaust its available memory: it's not a segfault, it's not remote execution, no exfiltration of tokens, no nop-sleds, nothing. bloat can't allocate more memory and falls over. That's it.