Patch "netfilter: x_tables: add and use xt_check_proc_name" has been added to the 4.14-stable tree