It is wild that it was in that state for so long. It probably took just about as long to write that comment as it would have to implement the proper solution.
grep --include=*.{c,h} -rnw -B3 -A15 'XXX' ./ | claude -p 'Analyze each code snippet and pick the five most concerning, from a security perspective.'
The fix consists of implementing an XXX present since the code was added:
https://www.freebsd.org/security/patches/SA-25:12/rtsold.pat...