[PATCH v2] Add advisory text for CVE-2026-0861

Siddhesh Poyarekar siddhesh@gotplt.org
Fri Jan 16 13:01:11 GMT 2026


On 2026-01-16 07:52, Wilco Dijkstra wrote:
> Hi Siddhesh,
> 
> The text only mentions alignment - my point was that you need a bogus
> alignment *and* a bogus size (at least 10 million times larger than available
> memory on the largest servers, or a billion time for a typical PC).
> 
> On a 64-bit system there are only about 64 out of 2^128 possible inputs
> that could result in overflow, so you'd need to have full control over *both*
> parameters in order to force an overflow.

Thanks, I'll clarify that.

Sid


More information about the Libc-alpha mailing list