It turns out, the records of the same, if the record is of the same site created as MAX_STRING_LEN, the hacker can actually provide user current password with exact the same length. And when the first user data was copied, we already use up the all the length of the regular buffer. And sort of the other column we override could be override the pointer. The remaining current password that is bring in by the hacker, could start override the counter, so the patch doesn't work. The better solution is to test the combined size of the user and cpw, current password, before we even attempt