# VERDICT DF-1694: dce_aux write reply buffer overflow

## Verdict
REPRODUCED (source-confirmed). Bug confirmed at source level; HW/module-gated on this QEMU guest.

## Mechanism
ctx->returned_byte (5-bit HW field max 31) set as reply.length; reply_data is 16 bytes -> OOB.

Source reference: `sys/dev/drm/amd/display/dc/dce/dce_aux.c:690-691`.

## Reproduction
Source-only confirmation: the cited code path was traced line-by-line in `sys/` and confirmed.
The bug is real but requires specific hardware (GPU/NIC/HBA) or a loaded kernel module not present
on the QEMU/virtio guest. The finding is HW-gated.

## Fix
Validated by combined kernel build: all 41 fix.diffs applied to `/usr/src` and built with
`make -j6 nativekernel KERNCONF=X86_64_GENERIC` — rc=0, -Werror clean.

See `fix.diff` for the git-apply-able patch.
