On Tue, Oct 19, 2021 at 2:16 PM Paul Moore <paul@xxxxxxxxxxxxxx> wrote: > > Unfortunately we can't rely on nf_hook_state->sk being the proper > originating socket so revert to using skb_to_full_sk(skb). > > Fixes: 1d1e1ded1356 ("1d1e1ded13568be81a0e19d228e310a48997bec8") > Reported-by: Linux Kernel Functional Testing <lkft@xxxxxxxxxx> > Suggested-by: Florian Westphal <fw@xxxxxxxxx> > Signed-off-by: Paul Moore <paul@xxxxxxxxxxxxxx> > --- > security/selinux/hooks.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) Merged into selinux/next, with the corrected Fixes line that Ondrej pointed out. -- paul moore www.paul-moore.com