)]}'
{
  "commit": "78a4260f1fad5cfc6ad7cf6e01a93a2fed0d0e3e",
  "tree": "2d838c1da9ce2a187b53a069d01c33236bef8e7f",
  "parents": [
    "d57906c6850c5bb9a93841da3deb6df53135d133"
  ],
  "author": {
    "name": "Martin Schwidefsky",
    "email": "schwidefsky@de.ibm.com",
    "time": "Mon Apr 25 17:54:28 2016 +0200"
  },
  "committer": {
    "name": "Greg Kroah-Hartman",
    "email": "gregkh@linuxfoundation.org",
    "time": "Sun Sep 11 09:59:58 2016 +0200"
  },
  "message": "s390/sclp_ctl: fix potential information leak with /dev/sclp\n\ncommit 532c34b5fbf1687df63b3fcd5b2846312ac943c6 upstream.\n\nThe sclp_ctl_ioctl_sccb function uses two copy_from_user calls to\nretrieve the sclp request from user space. The first copy_from_user\nfetches the length of the request which is stored in the first two\nbytes of the request. The second copy_from_user gets the complete\nsclp request, but this copies the length field a second time.\nA malicious user may have changed the length in the meantime.\n\nReported-by: Pengfei Wang \u003cwpengfeinudt@gmail.com\u003e\nReviewed-by: Michael Holzheu \u003cholzheu@linux.vnet.ibm.com\u003e\nSigned-off-by: Martin Schwidefsky \u003cschwidefsky@de.ibm.com\u003e\nSigned-off-by: Juerg Haefliger \u003cjuerg.haefliger@hpe.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "648cb86afd427776abc0d109f0982284d094699a",
      "old_mode": 33188,
      "old_path": "drivers/s390/char/sclp_ctl.c",
      "new_id": "ea607a4a1bddaf3e41165aebed1fd787b87d754e",
      "new_mode": 33188,
      "new_path": "drivers/s390/char/sclp_ctl.c"
    }
  ]
}
