Re: [PATCH net 1/9] netfilter: xt_nat: reject unsupported target families

[email protected] Fri, 17 Jul 2026 09:30:19 +0000
Newsgroups gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network
Message-ID <178428061915.1629459.3441388363052531602.git-patchwork-notify@kernel.org>
Hello:

This series was applied to netdev/net.git (main)
by Florian Westphal <[email protected]>:

On Fri, 10 Jul 2026 16:37:25 +0200 you wrote:
> From: Wyatt Feng <[email protected]>
> 
> xt_nat SNAT and DNAT target handlers assume IP-family conntrack state
> is present and can dereference a NULL pointer when instantiated from an
> unsupported family through nft_compat. A bridge-family compat rule can
> therefore trigger a NULL-dereference in nf_nat_setup_info().
> 
> [...]

Here is the summary with links:
  - [net,1/9] netfilter: xt_nat: reject unsupported target families
    https://git.kernel.org/netdev/net/c/5d1a2240935e
  - [net,2/9] netfilter: ecache: fix inverted time_after() check
    https://git.kernel.org/netdev/net/c/b06163ce52ec
  - [net,3/9] netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
    https://git.kernel.org/netdev/net/c/86f3ce81dd2b
  - [net,4/9] netfilter: nf_conncount: fix zone comparison in tuple dedup
    https://git.kernel.org/netdev/net/c/f62c41b4910e
  - [net,5/9] selftests: netfilter: add bridge tunnel flowtable regression
    https://git.kernel.org/netdev/net/c/bd0bdfae1cf0
  - [net,6/9] netfilter: flowtable: use correct direction to set up tunnel route
    https://git.kernel.org/netdev/net/c/90941d9c925d
  - [net,7/9] ipvs: reload ip header after head reallocation
    https://git.kernel.org/netdev/net/c/a2f57827bf7c
  - [net,8/9] ipvs: fix more places with wrong ipv6 transport offsets
    https://git.kernel.org/netdev/net/c/b3fe4cbd5838
  - [net,9/9] netfilter: xt_physdev: masks are not c-strings
    https://git.kernel.org/netdev/net/c/f468c48d488d

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html