Description: Corrupted offset allows for arbitrary decrements in compat IPT_SO_SET_REPLACE setsockopt References: Notes: Bugs: upstream: released (4.7-rc1) [fc1221b3a163d1386d1052184202d5dc50d302d1, ce683e5f9d045e5d67d1312a42b359cb2ab2a13c] 3.16-upstream-stable: released (3.16.37) [netfilter-x_tables-add-compat-version-of-xt_check_entry_offsets.patch, netfilter-x_tables-check-for-bogus-target-offset.patch] 3.2-upstream-stable: ignored "too many changes required, and netfilter is not exposed to unprivileged users" sid: released (4.6.2-2) [bugfix/all/netfilter-x_tables-add-compat-version-of-xt_check_en.patch, bugfix/all/netfilter-x_tables-check-for-bogus-target-offset.patch] 3.16-jessie-security: released (3.16.7-ckt25-2+deb8u1) [bugfix/all/netfilter-x_tables-add-compat-version-of-xt_check_en.patch, bugfix/all/netfilter-x_tables-check-for-bogus-target-offset.patch] 3.2-wheezy-security: ignored "too many changes required, and netfilter is not exposed to unprivileged users"