Commit 9c13886665c43600bd0af4b38e33c654e648e078
Committed by
Patrick McHardy
1 parent
55e0d7cf27
Exists in
master
and in
7 other branches
netfilter: ip6table_raw: fix table priority
The order of the IPv6 raw table is currently reversed, that makes impossible to use the NOTRACK target in IPv6: for example if someone enters ip6tables -t raw -A PREROUTING -p tcp --dport 80 -j NOTRACK and if we receive fragmented packets then the first fragment will be untracked and thus skip nf_ct_frag6_gather (and conntrack), while all subsequent fragments enter nf_ct_frag6_gather and reassembly will never successfully be finished. Singed-off-by: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu> Signed-off-by: Patrick McHardy <kaber@trash.net>
Showing 2 changed files with 2 additions and 1 deletions Side-by-side Diff
include/linux/netfilter_ipv6.h
net/ipv6/netfilter/ip6table_raw.c