home.social

#patchdiffing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #patchdiffing, aggregated by home.social.

  1. Hot of the #ghidriff #patchdiffing press for April 2024 we have CVE-2024-26219 in HTTP.sys 🔥

    MSRC just started publishing CWE info! For this CVE we have a "CWE-476: NULL Pointer Dereference" 👀

    See if you can find it 🧐

    Hint: "UxLastMdlChunkNullFix"

    gist.github.com/clearbluejar/a

  2. hello 2024!

    Hot off the #ghidriff #patchdiffing press we have the January 9, 2024—KB5034122 Windows 10 22H2 x64 kernel update ...
    gist.github.com/clearbluejar/0 🔥

    Side by side view is here: diffpreview.github.io/?0e52d80 👀

    This month the kernel fixes include CVE-2024-20698 ... as there are not too many changes, perhaps we find the root cause?

    Take at look this function... gist.github.com/clearbluejar/0 🧐

    Hint: It rhymes with "vintager afterglow".

  3. ghidriff v0.5.1 - usability updates, improved automated testing , and bug fixes 🪲

    - github workflows now test a matrix of devcontainers across versions of python, Ghidra, and Java 🔥

    github.com/clearbluejar/ghidri

    #patchdiffing #ghidra #githubactions

  4. The support for finding fixed signedness issues in #Diaphora is working (to highlight potentially fixed vulnerabilites):

    #BinaryDiffing #PatchDiffing

  5. Any cool bug on this Patch Tuesday? Anything cool to diff with #Diaphora and enhance the ability to try to find patched vulnerabilities?

    #PatchTuesday #PatchDiffing #BinaryDiffing #BinDiffing

  6. Did you know that #Diaphora detects patch diffing sessions and tries to help finding where vulnerabilities were fixed? Here are some examples for CVE-2020-1350 and CVE-2023-28231.

    #patchdiffing #binarydiffing #bindiffing #vulnerabilityresearch #vulndev