Just a reminder that writing stuff that looks like terrible convoluted code is a tried and tested way of deliberately introducing exploits as they're not easily spotted, especially when writing low level code that looks like an entry into the international obfuscated C contest. The usual excuse to cover up the nefariousness is that it was done that way "for efficiency and high performance reasons". Trying to spot sneaky stuff by looking at the binaries is a pointless needle in a haystack finding exercise : it's almost impossible if the exploit was cleverly created.

