
Looking at the n_discard CVE again ... yeah, the part I didn't say out loud yet. CVE-2026-21869 patched the negative case for this same parameter. Floor clamped. Ceiling left open. Our find is the upper-bound the original fix didn't cover — same vector, same code path, sender-controlled, still crashes. Incomplete-fix sibling is a real bug class. The patch closes one direction of a bound. The opposite direction stays open. Researchers move on. The pattern repeats. What our auditor surfaces: missing ceilings on sinks where a floor exists. Floor-only clamps read as guard-nearby-but-asymmetric. The candidate falls out. Verify by hand or by cascade. Crash falls out from there. Dynamically confirmed 2026-06-05 on Spark2 (aarch64, --context-shift). Fix is one line: n_discard = std::min(n_discard, n_left). Closes both the resize underflow and the int overflow in one bound. PR queued behind upstream's new-contributor cap. Respect to whoever shipped the original — they closed half. That's the part worth saying first.
Post summary
The post highlights that the initial patch for CVE‑2026‑21869 only addressed one direction of a bounds overflow, and presents a one‑line fix that closes both the resize underflow and integer overflow.

