On Thu, 2016-01-28 at 21:14 +0800, Zhouyi Zhou wrote: > My patch is intend to prevent kernel panic, to prevent reading garbage > or read data from a prior frame and leak secrets, the prototypes of the > get_h2x5_addr functions and the functions that call get_h2x5_addr should > be changed, should we do this? In term of security, panics are better than allowing attacker to read data from other people, like a password. BTW, are you able to trigger any panic ? I am not familiar with this code, it is not obvious. If a fix is needed, better doing it right. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html