Hi Pablo, Please apply the next patch against the nf tree: - Julia Lawall pointed out that IPSET_ATTR_ETHER netlink attribute length was not checked explicitly. The patch adds the missing checkings. The patch should be applied to the older stable kernel branches too. Best regards, Jozsef The following changes since commit 45040978c8994d1401baf5cc5ac71c1495d4e120: netfilter: ipset: Fix set:list type crash when flush/dump set in parallel (2016-02-24 20:32:21 +0100) are available in the git repository at: git://blackhole.kfki.hu/nf master for you to fetch changes up to d8aacd87180141ff6b812b53de77a4336e87c91a: netfilter: ipset: Check IPSET_ATTR_ETHER netlink attribute length (2016-03-08 20:36:17 +0100) ---------------------------------------------------------------- Jozsef Kadlecsik (1): netfilter: ipset: Check IPSET_ATTR_ETHER netlink attribute length net/netfilter/ipset/ip_set_bitmap_ipmac.c | 2 ++ net/netfilter/ipset/ip_set_hash_mac.c | 3 ++- 2 files changed, 4 insertions(+), 1 deletion(-) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html