On Wed, Apr 07, 2021 at 09:38:57PM +0200, Florian Westphal wrote: > xt_compat_match/target_from_user doesn't check that zeroing the area > to start of next rule won't write past end of allocated ruleset blob. > > Remove this code and zero the entire blob beforehand. Applied.