From fd2d3e9645c5178d9dc8b1f74fec5a4bb6c371cf Mon Sep 17 00:00:00 2001 From: Xe Iaso Date: Thu, 21 May 2026 11:36:38 -0400 Subject: [PATCH] chore: CVE-2026-45250 Signed-off-by: Xe Iaso --- .../no-way-to-prevent-this/CVE-2026-45250.md | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 lume/src/shitposts/no-way-to-prevent-this/CVE-2026-45250.md diff --git a/lume/src/shitposts/no-way-to-prevent-this/CVE-2026-45250.md b/lume/src/shitposts/no-way-to-prevent-this/CVE-2026-45250.md new file mode 100644 index 00000000..2c32980b --- /dev/null +++ b/lume/src/shitposts/no-way-to-prevent-this/CVE-2026-45250.md @@ -0,0 +1,20 @@ +--- +title: '"No way to prevent this" say users of only language where this regularly happens' +date: 2026-05-21 +series: "no-way-to-prevent-this" +type: blog +hero: + ai: "Photo by Andrea Piacquadio, source: Pexels" + file: sad-business-man + prompt: A forlorn business man resting his head on a brown wall next to a window. +--- + +In the hours following the release of [CVE-2026-45250](https://www.freebsd.org/security/advisories/FreeBSD-SA-26:18.setcred.asc) for the project [FreeBSD](https://www.freebsd.org/), site reliability workers +and systems administrators scrambled to desperately rebuild and patch all their systems to fix a kernel stack overflow when validating permissions of the setcred(2) system call, allowing arbitrary code execution in the context of the kernel. This is due to the affected components being +written in C++, the only programming language where these vulnerabilities regularly happen. "This was a terrible tragedy, but sometimes +these things just happen and there's nothing anyone can do to stop them," said programmer Mrs. Gregoria Doyle, echoing statements +expressed by hundreds of thousands of programmers who use the only language where 90% of the world's memory safety vulnerabilities have +occurred in the last 50 years, and whose projects are 20 times more likely to have security vulnerabilities. "It's a shame, but what can +we do? There really isn't anything we can do to prevent memory safety vulnerabilities from happening if the programmer doesn't want to +write their code in a robust manner." At press time, users of the only programming language in the world where these vulnerabilities +regularly happen once or twice per quarter for the last eight years were referring to themselves and their situation as "helpless." -- 2.51.2