)]}'
{
  "commit": "fc52ee68eb28fbb3d7451ad556f2571f729deac8",
  "tree": "6cdee10d27cded6815072c8b35f95f88faf8183d",
  "parents": [
    "f3567042b10a7ef4d60edb2a9ab904297f091355"
  ],
  "author": {
    "name": "Florian Westphal",
    "email": "fw@strlen.de",
    "time": "Sat Aug 12 13:05:16 2023 +0200"
  },
  "committer": {
    "name": "Oleksandr Tymoshenko",
    "email": "ovt@google.com",
    "time": "Thu Sep 21 22:29:50 2023 +0000"
  },
  "message": "netfilter: nf_tables: deactivate catchall elements in next generation\n\n[ Upstream commit 90e5b3462efa37b8bba82d7c4e63683856e188af ]\n\nWhen flushing, individual set elements are disabled in the next\ngeneration via the -\u003eflush callback.\n\nCatchall elements are not disabled.  This is incorrect and may lead to\ndouble-deactivations of catchall elements which then results in memory\nleaks:\n\nWARNING: CPU: 1 PID: 3300 at include/net/netfilter/nf_tables.h:1172 nft_map_deactivate+0x549/0x730\nCPU: 1 PID: 3300 Comm: nft Not tainted 6.5.0-rc5+ #60\nRIP: 0010:nft_map_deactivate+0x549/0x730\n [..]\n ? nft_map_deactivate+0x549/0x730\n nf_tables_delset+0xb66/0xeb0\n\n(the warn is due to nft_use_dec() detecting underflow).\n\nBUG\u003db/298762236\nTEST\u003dpresubmit\nRELEASE_NOTE\u003dFixed CVE-2023-4569 in the Linux kernel\n\ncos-patch: security-high\nFixes: aaa31047a6d2 (\"netfilter: nftables: add catch-all set element support\")\nReported-by: lonial con \u003ckongln9170@gmail.com\u003e\nSigned-off-by: Florian Westphal \u003cfw@strlen.de\u003e\nSigned-off-by: Sasha Levin \u003csashal@kernel.org\u003e\nChange-Id: I4245c6d5257b19c3ed3839ce25c0cdfe4c66487f\nReviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/57507\nTested-by: Cusky Presubmit Bot \u003cpresubmit@cos-infra-prod.iam.gserviceaccount.com\u003e\nReviewed-by: Michael Kochera \u003ckochera@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "d625cbb1405305fce1deca4ed4ee5e9d171e1ab7",
      "old_mode": 33188,
      "old_path": "net/netfilter/nf_tables_api.c",
      "new_id": "40d1d9bf60e20806b0ae12a311c0b58284bf956f",
      "new_mode": 33188,
      "new_path": "net/netfilter/nf_tables_api.c"
    }
  ]
}
