As for libnftnl, this series aims at fixing a number of issues identified by covscan. And again, due to my limited overview of the code-base, some of them might as well be invalid although I tried to verify the issues as best as I can. Changes since v1: - Rebased onto current upstream master. - Reviewed and improved every patch (for details see each patch's changelog). Phil Sutter (4): evaluate: Fix datalen checks in expr_evaluate_string() netlink_delinearize: Avoid potential null pointer deref stmt_evaluate_reset: Have a generic fix for missing network context evaluate: Avoid undefined behaviour in concat_subtype_id() src/evaluate.c | 12 +++++++----- src/netlink_delinearize.c | 6 ++++++ 2 files changed, 13 insertions(+), 5 deletions(-) -- 2.8.2 -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html