Patrick McHardy wrote: > Chuck Ebbert wrote: >> Reported at https://bugzilla.redhat.com/show_bug.cgi?id=449315 >> >> In find_appropriate_src(): >> >> hlist_for_each_entry_rcu(nat, n, &bysource[h], bysource) { >> ct = nat->ct; >> if (same_src(ct, tuple)) { >> >> Dereference of ct in same_src() causes the oops. This only seems to >> happen on heavily loaded firewall machines. Kernel 2.6.24.7 works. >> >> The reporter identifies commit 4d354c5782dc352cec187845d17eedc2c2bfcf67 >> ("[NETFILTER]: nf_nat: use RCU for bysource hash") as a possible cause >> of the problem. > > We have a similar looking report, but that one also affects 2.6.24: > > http://bugzilla.kernel.org/show_bug.cgi?id=10875 > > Anyways, does this patch help? When reallocating storage > for a conntrack, it is replaced in the list before assigning > the nat->ct pointer. I'm afraid we also need this one on top - when reallocating an extension, we must not free the old storage since it may still be used in a RCU read side.