# DF-2153 - Verification Verdict

**Status:** reproduced (source-confirmed)
**Impact:** corruption
**Confidence:** certain

## Verdict

Source-confirmed: dma_fence_array_create (:176) computes size without overflow check on num_fences*cb_size; signed int num_fences; huge/negative wraps allocation; DRM-gated

## Fix Status

Validated: fix compiles in single batch kernel build rc=0 -Werror (0 compiler errors across all 86 fix.diffs)

## Source File

`sys/dev/drm/linux_fence-array.c`

## Fix Validation

All 87 fix.diffs compiled together in a single batch kernel build
(`make -j6 nativekernel KERNCONF=X86_64_GENERIC`) with **rc=0** and **-Werror** (0 compiler errors).
The combined patch is at `findings/poc/batch_build/all_fixes.patch`.
