)]}'
{
  "commit": "9f8e9895c504149d7048e9fc5eb5cbb34b16e49a",
  "tree": "4d13c798595979f4650e00acfb74a03fc54047da",
  "parents": [
    "3476436a44c29725efef0cabf5b3ea4e70054d57"
  ],
  "author": {
    "name": "Michael S. Tsirkin",
    "email": "mst@redhat.com",
    "time": "Thu Apr 03 19:52:25 2014 +0300"
  },
  "committer": {
    "name": "Juan Quintela",
    "email": "quintela@redhat.com",
    "time": "Mon May 05 22:15:03 2014 +0200"
  },
  "message": "usb: sanity check setup_index+setup_len in post_load\n\nCVE-2013-4541\n\ns-\u003esetup_len and s-\u003esetup_index are fed into usb_packet_copy as\nsize/offset into s-\u003edata_buf, it\u0027s possible for invalid state to exploit\nthis to load arbitrary data.\n\nsetup_len and setup_index should be checked to make sure\nthey are not negative.\n\nCc: Gerd Hoffmann \u003ckraxel@redhat.com\u003e\nSigned-off-by: Michael S. Tsirkin \u003cmst@redhat.com\u003e\nReviewed-by: Gerd Hoffmann \u003ckraxel@redhat.com\u003e\nSigned-off-by: Juan Quintela \u003cquintela@redhat.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "fe70429304d1dcddcb230a07d81c254e7ccbfe50",
      "old_mode": 33188,
      "old_path": "hw/usb/bus.c",
      "new_id": "e48b19fc29bd9f831cc05990be73ddf49936d6a9",
      "new_mode": 33188,
      "new_path": "hw/usb/bus.c"
    }
  ]
}
