Set l3num to 0x1F (32) in expectation masks since the size of the layer 3 procotol handler array is AF_MAX. This fixes a panic at expectation dumping and event notification. Signed-off-by: Pablo Neira Ayuso Index: netfilter-2.6.14.git/net/netfilter/nf_conntrack_ftp.c =================================================================== --- netfilter-2.6.14.git.orig/net/netfilter/nf_conntrack_ftp.c 2006-01-08 21:24:44.000000000 +0100 +++ netfilter-2.6.14.git/net/netfilter/nf_conntrack_ftp.c 2006-01-08 21:33:52.000000000 +0100 @@ -574,7 +574,7 @@ static int help(struct sk_buff **pskb, exp->tuple.dst.protonum = IPPROTO_TCP; exp->mask = (struct nf_conntrack_tuple) - { .src = { .l3num = 0xFFFF, + { .src = { .l3num = 0x001F, .u = { .tcp = { 0 }}, }, .dst = { .protonum = 0xFF,