check reflector peer-tag length before subtracting the header size
partially fixed publicly
details
Finding IDs
F-TGDESKTOP-REFLECTOR-001
Status
partially fixed publicly
Disclosure date
Note
both constructors subtract four only when the raw peer tag is 16 bytes. This closes the matched length-underflow path, not every issue in the broader report. Desktop release inclusion and the full report were not independently retested.
F-TGDESKTOP-REFLECTOR-001: Memory safety. Peer-tag length arithmetic underflows before memory access. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.