On Thu, Jul 11, 2013 at 07:22:19PM -0700, Eric Dumazet wrote: > From: Eric Dumazet <edumazet@xxxxxxxxxx> > > commit 681f130f39e10 ("netfilter: xt_socket: add XT_SOCKET_NOWILDCARD > flag") added a potential NULL dereference if an old iptables package > uses v0 of the match. > > Fix this by removing the test on @info in fast path. > > IPv6 can remove the test as well, as it uses v1 or v2. Applied, thanks Eric. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html