so gnutls is BACKDOORED backdoored
@hipsterelectron how did this happen?
@RosaCtrl yes! LLM commits to the ceph cluster fs were also how red hat engineer david howells obfuscated his string of backdated changes to crypto/ which included an early exit from a checksum validation function used in module signature verification, so that any users selecting the new ML-DSA cryptographic keypair type to sign modules with would end up with a kernel that accepts literally any kernel module at all (back in march during the 7.0 rc cycle)
@RosaCtrl gnutls is particularly desperate. in addition to backdating you'll find they just repeat a set of very large commits and subsequent reverts and just do that back and forth spaced out by 10-15 intermediate shorter commits with complete bullshit
@RosaCtrl and of course people still accept "claude found a vuln" as if it's more likely that an LLM inferred something the human maintainers who wrote the broken code had missed, than the alternative explanation where the maintainers with the most expertise in their codebase's build system and non-local interactions are simply adding backdoors to their own codebase because the US declared war again
https://gitlab.com/gnutls/gnutls/-/work_items/1783
Tbh, I just threw Gemini CLI at
lib/and it reported this:Looking at the code, not knowing if there are any string size limiters on the caller side, I'd say that Gemini is right.
I'd suggest a simple overflow check withINT_MULTIPLY_OVERFLOW.
It has a negligible performance impact and stops any discussion.
"stops any discussion" is a ridiculous thing to say
i still can't find the last good commit