From mboxrd@z Thu Jan 1 00:00:00 1970 From: Adrian Bunk Subject: Re: [NETFILTER -stable]: nf_conntrack: don't track locally generated special ICMP error Date: Mon, 23 Jul 2007 00:48:05 +0200 Message-ID: <20070722224805.GI26212@stusta.de> References: <469CDF56.80600@trash.net> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Cc: Netfilter Development Mailinglist , stable@kernel.org, Yasuyuki KOZAKAI , "David S. Miller" To: Patrick McHardy Return-path: Content-Disposition: inline In-Reply-To: <469CDF56.80600@trash.net> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org On Tue, Jul 17, 2007 at 05:25:10PM +0200, Patrick McHardy wrote: > Attached are two patches (stable.diff, applies to stable-2.6.21 and > stable-2.6.22 and 2.6.16.diff for stable-2.6.16) fixing incorrect > conntrack association of ICMP errors generated in response to INVALID > packets, causing incorrect address translation in combination with NAT. > > Please apply, thanks. Thanks, applied to 2.6.16. cu Adrian -- "Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been need of rain for many days. "Only a promise," Lao Er said. Pearl S. Buck - Dragon Seed