Alexey Kodanev <alexey.kodanev@xxxxxxxxxx> wrote: > The patch moves the "trans->msg_type == NFT_MSG_NEWSET" check before > using nft_trans_set(trans). Otherwise we can get out of bounds read. Indeed, thanks for fixining this. Acked-by: Florian Westphal <fw@xxxxxxxxx> -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html