The History of a Security Hole

(os2museum.com)

23 points | by st_goliath 3 days ago

1 comments

  • amabito 3 days ago
    IOPB bit semantics are inverted from what you might expect: 0 means permitted, 1 means denied. So zeroed pcb memory silently grants access to every port in range -- that's why this was consistently reproducible, not flaky. One sizeof() away from correct the whole time.