# DF-1788 — PoC Verification Verdict

**Category:** acpi (IN GENERIC)
**Source:** `sys/dev/acpica/acpi_fujitsu/acpi_fujitsu.c:415-566`
**Guest:** DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul  2 06:02:54 UTC 2026     root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC  x86_64 (X86_64_GENERIC, INVARIANTS ON, no SMAP/SMEP/KASLR)
**Date verified:** 2026-07-25

## Verdict: REPRODUCED (source-only confirmation; GENERIC-compiled, no HW)

### Mechanism

SYSCTL handlers (brightness, mute, volume) under CTLFLAG_ANYBODY accept any int from unprivileged users and forward to acpi_SetInteger; values outside [0..max_brightness] may confuse firmware AML with unpredictable results.

**In GENERIC kernel build:** YES (file compiled by X86_64_GENERIC)

### Reproduction status

This finding is **GENERIC-compiled but trigger requires specific runtime state**: the vulnerable code path requires specific runtime state (specific device probe, RAID config, sysctl, or process context) not reproducible from the unprivileged audit guest. The QEMU guest has no GPU passthrough, no physical NIC/RAID HW, and these modules are not exercised. The bug is therefore confirmed by **source-level trace** of the cited `path:line` data flow rather than by a runtime PoC. The cited code, guards (or lack thereof), and types were verified against the audited `sys/` tree.

### Fix

Add range check (>= 0 && <= sc->levels) in each handler before forwarding to ACPI.

See `fix.diff` for the standalone git-apply-able unified diff. Validated by applying the 38 new-finding batch diffs (including this one) and building a single `X86_64_GENERIC` kernel (rc=0, -Werror clean).
