)]}'
{
  "commit": "bab9efc206ba89766c53a9042eb771e87e68c42b",
  "tree": "7413fe6517587d631fca96960ec806d5e8b7e61a",
  "parents": [
    "f3a71df05082c84d1408129084736c5f742a6165"
  ],
  "author": {
    "name": "Xi Wang",
    "email": "xi.wang@gmail.com",
    "time": "Mon Nov 28 12:25:43 2011 +0100"
  },
  "committer": {
    "name": "Dave Airlie",
    "email": "airlied@redhat.com",
    "time": "Fri Dec 02 10:49:41 2011 +0000"
  },
  "message": "vmwgfx: integer overflow in vmw_kms_update_layout_ioctl()\n\nThere are two issues in vmw_kms_update_layout_ioctl().  First, the\nfor loop forgets to index rects and only checks the first element.\nSecond, there is a potential integer overflow if userspace passes\nin a large arg-\u003enum_outputs.  The call to kzalloc() would allocate\na small buffer, leading to out-of-bounds read.\n\nReported-by: Haogang Chen \u003chaogangchen@gmail.com\u003e\nSigned-off-by: Xi Wang \u003cxi.wang@gmail.com\u003e\nSigned-off-by: Thomas Hellstrom \u003cthellstrom@vmware.com\u003e\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "880e285d7578afa3ebeae75de4dad77443d754ce",
      "old_mode": 33188,
      "old_path": "drivers/gpu/drm/vmwgfx/vmwgfx_kms.c",
      "new_id": "37d40545ed77347007d1051689895d40b116cd1d",
      "new_mode": 33188,
      "new_path": "drivers/gpu/drm/vmwgfx/vmwgfx_kms.c"
    }
  ]
}
