From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> Hi David, The following patchset contains small updates for net-next, more relevantly: * One fix for potential NULL dereference in xt_HMARK by Dan Carpenter. * Conversion to use _ALL macro in xt_hashlimit as you suggested by Florian Westphal. * One fix for timeout overflow from Jozsef Kadlecsik. * Replace usage of modulus for hash calculation in xt_HMARK as you suggested from myself. You can pull these changes from: git://1984.lsi.us.es/net-next master Thanks! Dan Carpenter (1): netfilter: xt_HMARK: potential NULL dereference in get_inner_hdr() Eldad Zack (1): netfilter: xt_CT: remove redundant header include Florian Westphal (1): netfilter: xt_hashlimit: use _ALL macro to reject unknown flag bits Jozsef Kadlecsik (1): netfilter: ipset: fix timeout value overflow bug Pablo Neira Ayuso (3): netfilter: xt_HMARK: modulus is expensive for hash calculation netfilter: nf_ct_tcp: extend log message for invalid ignored packets netfilter: nf_ct_h323: fix usage of MODULE_ALIAS_NFCT_HELPER include/linux/netfilter/ipset/ip_set_timeout.h | 4 ++++ include/linux/netfilter/xt_hashlimit.h | 6 ++++-- net/netfilter/nf_conntrack_h323_main.c | 4 +++- net/netfilter/nf_conntrack_proto_tcp.c | 3 ++- net/netfilter/xt_CT.c | 1 - net/netfilter/xt_HMARK.c | 4 ++-- net/netfilter/xt_hashlimit.c | 2 +- net/netfilter/xt_set.c | 15 +++++++++++++-- 8 files changed, 29 insertions(+), 10 deletions(-) -- 1.7.10 -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html