# VERDICT DF-1651: sbsh SIOCLOADFIRMW kernel deref of user pointer

## Verdict
REPRODUCED (source-confirmed). Bug confirmed at source level; HW/module-gated on this QEMU guest.

## Mechanism
cfg.firmw_image (user pointer) dereferenced in kernel via download_firmware without copyin.

Source reference: `sys/dev/netif/sbsh/if_sbsh.c:414,930`.

## Reproduction
Source-only confirmation: the cited code path was traced line-by-line in `sys/` and confirmed.
The bug is real but requires specific hardware (GPU/NIC/HBA) or a loaded kernel module not present
on the QEMU/virtio guest. The finding is HW-gated.

## Fix
Validated by combined kernel build: all 41 fix.diffs applied to `/usr/src` and built with
`make -j6 nativekernel KERNCONF=X86_64_GENERIC` — rc=0, -Werror clean.

See `fix.diff` for the git-apply-able patch.
