Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit ffed53d2 authored by Patrick McHardy's avatar Patrick McHardy Committed by David S. Miller
Browse files

[NETFILTER]: nf_nat: fix hanging connections when loading the NAT module



When loading the NAT module, existing connection tracking entries don't
have room for NAT information allocated and packets are dropped, causing
hanging connections. They really should be entered into the NAT table
as NULL mappings, but the current allocation scheme doesn't allow this.

For now simply accept those packets to avoid the hanging connections.

Signed-off-by: default avatarPatrick McHardy <kaber@trash.net>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent 8c82d8df
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -123,7 +123,7 @@ nf_nat_fn(unsigned int hooknum,

	nat = nfct_nat(ct);
	if (!nat)
		return NF_DROP;
		return NF_ACCEPT;

	switch (ctinfo) {
	case IP_CT_RELATED: