)]}'
{
  "commit": "2c33156b2d2f5efe820d8efdd610fb168c9acf72",
  "tree": "1a59d9779903ad63dd8d037b702cbb3690d2d663",
  "parents": [
    "07b7b1c823d602d0e5d3596387d7f0e67a7e9b5e"
  ],
  "author": {
    "name": "Young Xiao",
    "email": "YangX92@hotmail.com",
    "time": "Fri Apr 12 15:24:30 2019 +0800"
  },
  "committer": {
    "name": "Greg Kroah-Hartman",
    "email": "gregkh@linuxfoundation.org",
    "time": "Fri May 10 17:53:15 2019 +0200"
  },
  "message": "Bluetooth: hidp: fix buffer overflow\n\ncommit a1616a5ac99ede5d605047a9012481ce7ff18b16 upstream.\n\nStruct ca is copied from userspace. It is not checked whether the \"name\"\nfield is NULL terminated, which allows local users to obtain potentially\nsensitive information from kernel stack memory, via a HIDPCONNADD command.\n\nThis vulnerability is similar to CVE-2011-1079.\n\nSigned-off-by: Young Xiao \u003cYangX92@hotmail.com\u003e\nSigned-off-by: Marcel Holtmann \u003cmarcel@holtmann.org\u003e\nCc: stable@vger.kernel.org\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "008ba439bd62ae2e55a7ff92900ebb88339d67d1",
      "old_mode": 33188,
      "old_path": "net/bluetooth/hidp/sock.c",
      "new_id": "cc80c76177b6e3f5e3343c758ebc462eee201fae",
      "new_mode": 33188,
      "new_path": "net/bluetooth/hidp/sock.c"
    }
  ]
}
