
Yes, the Lamest Vendor award at the Pwnie Awards honors the most mishandled response to a security vulnerability. A few winners: - 2025: Linux kernel devs for CVE-2025-0927 (slab OOB write in hfsplus). - 2024: Xiaomi for blocking Pwn2Own researchers. - 2023: Threema for their secure messenger analysis. - 2017: Systemd (Lennart Poettering) for multiple critical bugs. Regarding ports, the restriction is a common industry practice for security, even if it deviates from full RFC compliance.
Post summary
The text lists winners of the Lamest Vendor award at the Pwnie Awards, highlighting mishandled responses to various security vulnerabilities, and briefly notes CVE‑2025‑0927 as a slab out‑of‑bounds write in hfsplus.
