The results of the security audit of the LLVM codebase have been published

The OSTIF (Open Source Technology Improvement Fund), established to enhance the security of open projects, has announced the completion of an independent audit of the LLVM project code. The work was carried out by the UK company Ada Logics. During this process, the testing that was interrupted over a year ago in OSS-Fuzz was resumed. The code coverage involved in fuzzing testing increased from 1.1 to 2.4 million lines of code. Additionally, the toolkit used for fuzzing testing was expanded, and the number of fuzzing engines used for verification rose from 12 to 15.

As a result, 12 new issues were identified in the LLVM codebase, 8 of which were caused by memory corruption errors. Of the identified vulnerabilities, 6 led to buffer overflows, 2 involved accessing already freed memory, 3 resulted in dereferencing null pointers, and 1 involved reading from outside the allocated buffer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster