)]}'
{
  "commit": "a91740ef94ac4a908ecb4143b27551e11f0941ae",
  "tree": "53c4631cfc6157d9e1b418b6ae33de0cfeae9ff3",
  "parents": [
    "d3ec5cf44d8011bb5ce1ecb52d616635f1e4188b"
  ],
  "author": {
    "name": "Eric Dumazet",
    "email": "edumazet@google.com",
    "time": "Wed Jan 26 17:10:22 2022 -0800"
  },
  "committer": {
    "name": "Meena Shanmugam",
    "email": "meenashanmugam@google.com",
    "time": "Mon Mar 21 21:01:00 2022 +0000"
  },
  "message": "ipv4: avoid using shared IP generator for connected sockets\n\ncommit 23f57406b82de51809d5812afd96f210f8b627f3 upstream.\n\nip_select_ident_segs() has been very conservative about using\nthe connected socket private generator only for packets with IP_DF\nset, claiming it was needed for some VJ compression implementations.\n\nAs mentioned in this referenced document, this can be abused.\n(Ref: Off-Path TCP Exploits of the Mixed IPID Assignment)\n\nBefore switching to pure random IPID generation and possibly hurt\nsome workloads, lets use the private inet socket generator.\n\nNot only this will remove one vulnerability, this will also\nimprove performance of TCP flows using pmtudisc\u003d\u003dIP_PMTUDISC_DONT\n\nBUG\u003db/223552660\nTEST\u003dpresubmit\nRELEASE_NOTE\u003dFixes CVE-2020-36516.\nSOURCE\u003dUPSTREAM(23f57406b82de51809d5812afd96f210f8b627f3)\n\nFixes: 73f156a6e8c1 (\"inetpeer: get rid of ip_id_count\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: David Ahern \u003cdsahern@kernel.org\u003e\nReported-by: Ray Che \u003cxijiache@gmail.com\u003e\nCc: Willy Tarreau \u003cw@1wt.eu\u003e\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\ncos-patch: security-moderate\nChange-Id: Ied0e8cf142444a888b1be4be0a473c643d6c7b1b\nReviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/30863\nTested-by: Cusky Presubmit Bot \u003cpresubmit@cos-infra-prod.iam.gserviceaccount.com\u003e\nReviewed-by: Roy Yang \u003croyyang@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "52abfc00b5e3d3154cfd1b779ed81a00aef8d3c8",
      "old_mode": 33188,
      "old_path": "include/net/ip.h",
      "new_id": "3f3ea86b2173c7b6e651da927a42eaedbe656216",
      "new_mode": 33188,
      "new_path": "include/net/ip.h"
    }
  ]
}
