ART OF VECTOR

CVE Patch Diffing

CVE-XXXX is a label. The diff is the evidence.

The flagship series. Each future CVE note will start from a public fix and stop at the invariant the vendor enforced. Identifiers are used only after they are official. No live exploit.
  1. → Vulnerable version
  2. ↓ Fixed version
  3. ↓ Git diff
  4. ↓ Changed function
  5. ↓ Security check
  6. ↓ Root cause
  7. ↓ Impact

GitHub Security Lab describes discovery and verification on public open source — clone, query, confirm. This program is that habit, written as a journal: the check that was added, the callers that remain, the impact class that is actually justified.

Notes

FAQ

Questions

What is the CVE patch-diffing method?
Vulnerable version → fixed version → git diff → changed function → security check → root cause → impact. The CVE identifier is the index key, not the research product.
Do you invent CVE numbers?
No. Identifiers appear only after official assignment and coordinated disclosure. Until then the note describes a class or a public, already-assigned record.