Hi Pablo, Please consider applying the next patch to nf-next. It's possibly a candidate for nf too. Best regards, Jozsef Jozsef Kadlecsik (1): netfilter: Ignore bogus SACK option values in TCP conntrack net/netfilter/nf_conntrack_proto_tcp.c | 5 +++++ 1 files changed, 5 insertions(+), 0 deletions(-) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html