SRU justification:

Impact: Kernel panics when using 8.0.4 server for a pair of redundant
firewalls with keepalived and conntrackd. Specifically, running
conntrack -c the kernel oops and panics.

Fix: Backport of upstream commits:

 - [NETFILTER]: nf_conntrack: fix ct_extend ->move operation
 - [NETFILTER]: nf_conntrack: replace horrible hack with ksize()
 - netfilter: nf_conntrack: fix ctnetlink related crash in
 - netfilter: nf_nat: fix RCU races


Patch tested in my PPA by Rainer Sabelka:

Attached: The patch

Note: This patch modifies include/net/netfilter/nf_conntrack_extend.h
and is an ABI bumper.
