SRU request for LP#239215

Colin Ian King colin.king at canonical.com
Mon Sep 22 18:20:38 UTC 2008


https://bugs.launchpad.net/ubuntu/hardy/+source/linux/+bug/239215

SRU justification:

Impact: Kernel panics when using 8.0.4 server for a pair of redundant
firewalls with keepalived and conntrackd. Specifically, running
conntrack -c the kernel oops and panics.

Fix: Backport of upstream commits:

86577c661bc01d5c4e477d74567df4470d6c5138
 - [NETFILTER]: nf_conntrack: fix ct_extend ->move operation
019f692ea719a2da17606511d2648b8cc1762268
 - [NETFILTER]: nf_conntrack: replace horrible hack with ksize()
ceeff7541e5a4ba8e8d97ffbae32b3f283cb7a3f
 - netfilter: nf_conntrack: fix ctnetlink related crash in
nf_nat_setup_info()
68b80f11380889996aa7eadba29dbbb5c29a5864
 - netfilter: nf_nat: fix RCU races

Testing:
https://bugs.launchpad.net/ubuntu/hardy/+source/linux/+bug/239215/comments/6

Patch tested in my PPA by Rainer Sabelka:

https://bugs.launchpad.net/ubuntu/hardy/+source/linux/+bug/239215/comments/4

Attached: The patch

Note: This patch modifies include/net/netfilter/nf_conntrack_extend.h
and is an ABI bumper.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-UBUNTU-netfilter-fix-kernel-panic-from-conntrackd.patch
Type: text/x-patch
Size: 5304 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20080922/59ef7cb5/attachment.bin>


More information about the kernel-team mailing list