CVE-2026-72423: bpf: Guard conntrack opts error writes
In the Linux kernel, the following vulnerability has been resolved:
bpf: Guard conntrack opts error writes
The conntrack lookup and allocation kfuncs take an opts pointer together with an optssz argument. The verifier checks only the memory range described by optssz, but the wrappers unconditionally write opts->error whenever the internal lookup or allocation helper returns an error.
For an invalid size smaller than the end of opts->error, that write can land outside the verifier-checked range. Keep returning NULL for invalid arguments, but only report the error through opts->error when the supplied size includes the field.
This preserves error reporting for the supported 12-byte and 16-byte layouts, and for other invalid sizes that still include opts->error.