On Wed, Mar 30, 2016 at 11:34:35AM +0200, Jozsef Kadlecsik wrote: > Baozeng Ding reported a KASAN stack out of bounds issue - it uncovered that > the TCP option parsing routines in netfilter TCP connection tracking could > read one byte out of the buffer of the TCP options. Therefore in the patch > we check that the available data length is large enough to parse both TCP > option code and size. Applied, thanks Jozsef. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html