Something that bothered me: The author mentions that the worst case of VLA usage is an exploitable vulnerability, then goes on to call malloc with n * size, where n is controlled by the user. This should either be bounds checked or calloc should be used instead, since the "fix" presented may also introduce an exploitable vulnerability.