)]}'
{
  "commit": "e0ba936287dfe9783426aac27e5fd76fe35b38c9",
  "tree": "ae64438b36f431297f454799b1e4cf358709560f",
  "parents": [
    "33d1469b0124cc0baaea7a2032123b77a81e0940"
  ],
  "author": {
    "name": "Kyle Zeng",
    "email": "kylebot@openai.com",
    "time": "Tue Aug 04 06:10:55 2026 +0000"
  },
  "committer": {
    "name": "Pablo Neira Ayuso",
    "email": "pablo@netfilter.org",
    "time": "Mon Aug 10 20:27:07 2026 +0200"
  },
  "message": "ipvs: clear IPv4 options after rebasing tunnel ICMP errors\n\nip_vs_in_icmp() rebases an skb from the outer ICMP packet to the\nquoted original request before passing it to icmp_send(). However,\nIPCB(skb)-\u003eopt still describes the outer IPv4 header.\n\nA timestamp option in the outer header can therefore leave an offset\nthat points into the quoted transport header after the rebase.\n__ip_options_echo() treats a byte at that stale location as the option\nlength and copies it into the fixed-size option storage on the\n__icmp_send() stack, causing a stack out-of-bounds write.\n\nClear the stale option metadata after resetting the network header.\nKeep the remaining control block fields, including the ingress\ninterface used by the ICMP response path.\n\nFixes: f2edb9f7706d (\"ipvs: implement passive PMTUD for IPIP packets\")\nCc: stable@vger.kernel.org\nAssisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber\nSigned-off-by: Kyle Zeng \u003ckylebot@openai.com\u003e\nCo-developed-by: David Lee \u003cdavid.lee@trailofbits.com\u003e\nSigned-off-by: David Lee \u003cdavid.lee@trailofbits.com\u003e\nAcked-by: Julian Anastasov \u003cja@ssi.bg\u003e\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "95af77b68851afa1c2e6b45ddd697f1209255a98",
      "old_mode": 33188,
      "old_path": "net/netfilter/ipvs/ip_vs_core.c",
      "new_id": "a46e7acdd8e1254866316a4698acf4f8c7f6dfc4",
      "new_mode": 33188,
      "new_path": "net/netfilter/ipvs/ip_vs_core.c"
    }
  ]
}
