by state on 3/7/23, 1:27 AM with 47 comments
by makeworld on 3/7/23, 4:15 AM
by harveywi on 3/7/23, 2:45 PM
by eulgro on 3/7/23, 2:59 AM
by red_admiral on 3/7/23, 11:34 AM
by jonstewart on 3/7/23, 3:59 AM
The paper makes no mention of compiler warnings… but shouldn’t this cast trigger a compiler warning?
by eterevsky on 3/7/23, 10:09 AM
This is such a critical part of the software stack, that we need a more reliable way of validation than just a bunch of people staring at the code written in C.
by rurban on 3/8/23, 7:22 AM
by Donckele on 3/7/23, 6:34 AM
I just can’t get my head round the idea that software written and reviewed by experts and submitted to the “National Institute of Standards and Technology” with a budget of 1 billion dollars can fuck up this way.
I’m no mathematician but I would have thought implementing pure number crunching code is not rocket science.
Buffer overflow, overwrite memory, run arbitrary code, seriously? LOL, WTF.