Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <kuba@xxxxxxxxxx>: On Tue, 9 Apr 2024 12:07:41 +0000 you wrote: > In my recent commit, I missed that do_replace() handlers > use copy_from_sockptr() (which I fixed), followed > by unsafe copy_from_sockptr_offset() calls. > > In all functions, we can perform the @optlen validation > before even calling xt_alloc_table_info() with the following > check: > > [...] Here is the summary with links: - [net] netfilter: complete validation of user input https://git.kernel.org/netdev/net/c/65acf6e0501a You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html