On Sun, 1 Feb 2026 at 16:17, Guy Harris <[email protected]> wrote:
>
> On Jan 31, 2026, at 4:24 AM, Amit <[email protected]> wrote:

> > https://nvd.nist.gov/vuln/detail/CVE-2026-1251: Missing validation on
> > a user controlled key.
>
> That's an input validation issue, but it does not appear to be a "make sure 
> the string isn't too long" issue.
>

There are two issues: length/size of the input and sanitization of the input.

For now, I am focussed on the length/size of the input. At least with
this, we will
be able to reduce some insecurity. Something is better than nothing.

But, since the Open group is not open for a new security oriented
POSIX standard,
so then there is no point in me continuing this discussion.

So, I am stopping this discussion here.

Amit

  • Will the Open Gro... Amit via austin-group-l at The Open Group
    • Re: Will the... Amit via austin-group-l at The Open Group
    • Re: Will the... Guy Harris via austin-group-l at The Open Group
      • Re: Will... Amit via austin-group-l at The Open Group
        • Re: ... Jonathan Wakely via austin-group-l at The Open Group
          • ... Amit via austin-group-l at The Open Group
        • Re: ... Guy Harris via austin-group-l at The Open Group
          • ... Amit via austin-group-l at The Open Group
    • Re: Will the... David A. Wheeler via austin-group-l at The Open Group
      • Re: Will... Amit via austin-group-l at The Open Group
        • Re: ... David A. Wheeler via austin-group-l at The Open Group
          • ... Guy Harris via austin-group-l at The Open Group
          • ... Amit via austin-group-l at The Open Group
            • ... Niu Danny via austin-group-l at The Open Group
              • ... Amit via austin-group-l at The Open Group
            • ... Amit via austin-group-l at The Open Group
              • ... G. Branden Robinson via austin-group-l at The Open Group
                • ... Amit via austin-group-l at The Open Group

Reply via email to