On Fri, Sep 20, 2024 at 12:11:46PM +0200, Florian Westphal wrote:
Hello,
please consider picking up: 7f3287db6543 ("netfilter: nft_socket: make cgroupsv2 matching work with namespaces") and its followup fix, 7052622fccb1 ("netfilter: nft_socket: Fix a NULL vs IS_ERR() bug in nft_socket_cgroup_subtree_level()")
It should cherry-pick fine for 6.1 and later. I'm not sure a 5.15 backport is worth it, as its not a crash fix and noone has reported this problem so far with a 5.15 kernel.
I can take of these backports.