Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Win64 backend can corrupt nonvolatile XMM registers

COMPCERT-584

Affected product
CompCert
Severity
Medium
Weakness
CWE-682
Disclosed

Summary

Generated Win64 functions could return the correct scalar result while corrupting nonvolatile XMM state expected by the caller.

Technical analysis

The accompanying research article explains the finding, reproduction, and remediation status.

Read the technical write-up

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References