Florian Weimer <fw@deneb.enyo.de> writes: > Thanks. Do you think we should treat this as a vulnerability? Can > this code path be reached in a default configuration? I think that triggering this as an exploit would require too much dependence on the system-as-a-whole state to be considered a risk.