Exploiting the Wii U's USB Descriptor parsing
garyodernichts.blogspot.com
garyodernichts.blogspot.com
However the PSJailbreak writeup doesn't actually go into details of the buffer overflow (it wasn't written by the original exploiter, just by people re-implementing it; They didn't care enough to fully work out how it worked) so it's not clear if it's the byte-swapping function that was overflowing, or some other function.