Solutionunvalidated
Stop using attacker-controlled command strings as printf format strings — Patch gdevupd.c so each of the four call sites emits the parameter as raw bytes.
fffa84c7-40c4-4c07-aec5-1969c26dd800
Stop using attacker-controlled command strings as printf format strings — Patch gdevupd.c so each of the four call sites emits the parameter as raw bytes.