On Sun, Jul 19, 2026, Jarkko Sakkinen wrote:
> As said, code changes themselves look reasonable but the commit message
> is painting a picture of impact that this bug really does not have.
>
> If possible strip down the paragraph and add fixes tags (if possible,
> I can dig it up too). With those requests send v2.

Agreed, thanks. You and Richard are right that this is not an
exploitable OOB due to the struct layout. 

For v2 I'll:
  - reframe the commit message as a correctness/hardening fix and drop
    the exploitation and "how this was found" paragraphs;
  - add the Fixes: tags myself (they both trace to the DCP trusted-keys
    introduction) so you don't have to dig them up;
  - keep the code changes as-is.

Will send v2 shortly.

Thanks,
Fabrice

Reply via email to