)]}'
{
  "commit": "6ff435b8f1fa494c3daba3754053d06740affdee",
  "tree": "36b83086eed1daaa7e2805cab620da9ba2a0110a",
  "parents": [
    "ca873ea8026bf5d632f75f32a91a6337fc214042"
  ],
  "author": {
    "name": "Pablo Neira Ayuso",
    "email": "pablo@netfilter.org",
    "time": "Sun Jul 23 16:41:48 2023 +0200"
  },
  "committer": {
    "name": "He Gao",
    "email": "hegao@google.com",
    "time": "Fri Aug 18 18:25:47 2023 +0000"
  },
  "message": "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID\n\n[ Upstream commit 0ebc1064e4874d5987722a2ddbc18f94aa53b211 ]\n\nBail out with EOPNOTSUPP when adding rule to bound chain via\nNFTA_RULE_CHAIN_ID. The following warning splat is shown when\nadding a rule to a deleted bound chain:\n\n WARNING: CPU: 2 PID: 13692 at net/netfilter/nf_tables_api.c:2013 nf_tables_chain_destroy+0x1f7/0x210 [nf_tables]\n CPU: 2 PID: 13692 Comm: chain-bound-rul Not tainted 6.1.39 #1\n RIP: 0010:nf_tables_chain_destroy+0x1f7/0x210 [nf_tables]\n\nBUG\u003db/296200356\nTEST\u003dpresubmit\nSOURCE\u003dUPSTREAM(0ebc1064e487)\nRELEASE_NOTE\u003dFixed CVE-2023-4147 in the Linux kernel.\n\ncos-patch: security-high\nFixes: d0e2c7de92c7 (\"netfilter: nf_tables: add NFT_CHAIN_BINDING\")\nReported-by: Kevin Rich \u003ckevinrich1337@gmail.com\u003e\nChange-Id: I05651e01101695c0c960f04348007410395c79f8\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\nSigned-off-by: Florian Westphal \u003cfw@strlen.de\u003e\nSigned-off-by: Sasha Levin \u003csashal@kernel.org\u003e\nReviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/55327\nReviewed-by: Oleksandr Tymoshenko \u003covt@google.com\u003e\nTested-by: Cusky Presubmit Bot \u003cpresubmit@cos-infra-prod.iam.gserviceaccount.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "ecde497368ec4e2d5c4047e1ffd2e923f448cabc",
      "old_mode": 33188,
      "old_path": "net/netfilter/nf_tables_api.c",
      "new_id": "d625cbb1405305fce1deca4ed4ee5e9d171e1ab7",
      "new_mode": 33188,
      "new_path": "net/netfilter/nf_tables_api.c"
    }
  ]
}
