)]}'
{
  "commit": "c37553067958b690ccd23ca9c8945ae097300a51",
  "tree": "da79b618d48242bc71dfe59e8e8d603a50a2d054",
  "parents": [
    "cb90d8cd1d1bcafc354e135cb43815da8436105c"
  ],
  "author": {
    "name": "Ranjan Kumar",
    "email": "kumarranja@google.com",
    "time": "Thu Jul 16 13:15:43 2026"
  },
  "committer": {
    "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Tue Jul 28 04:25:14 2026"
  },
  "message": "libevdev: Clamp slot_count to MAX_SLOT_COUNT in MTB_Init\n\nA malicious HID device advertising more than 64 contact slots can\ncause an out-of-bounds stack read in MT_Slot_Sync because the loop\nbounds were dictated by the unclamped device limits while iterating\nover a fixed-size stack buffer.\n\nClamp evstate-\u003eslot_count to MAX_SLOT_COUNT during initialization\nto prevent OOB stack access.\n\nBUG\u003db:524107665\nTEST\u003dBuilt and verified using the project fortify ASAN PoC.\n\nChange-Id: I03881b67469dbdd12cf57c33e41bf8ce87fce372\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/libevdev/+/8124614\nTested-by: Ranjan Kumar (xWF) \u003ckumarranja@google.com\u003e\nReviewed-by: Henry Barnor \u003chbarnor@chromium.org\u003e\nReviewed-by: Jingyuan Liang \u003cjingyliang@chromium.org\u003e\nReviewed-by: Sean O\u0027Brien \u003cseobrien@chromium.org\u003e\nCommit-Queue: Ranjan Kumar (xWF) \u003ckumarranja@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "fef31194d7e7c85bf2d2c946141e54006be67d58",
      "old_mode": 33188,
      "old_path": "src/libevdev_mt.c",
      "new_id": "629ec24ff622025bca774f6e895fd955a9686cb6",
      "new_mode": 33188,
      "new_path": "src/libevdev_mt.c"
    }
  ]
}
