Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #84843 > unrolled thread

Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1

Started byTibor <oomtig@gmail.com>
First post2024-12-16 15:50 +0100
Last post2024-12-17 14:00 +0100
Articles 4 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 Tibor <oomtig@gmail.com> - 2024-12-16 15:50 +0100
    Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 Salvatore Bonaccorso <carnil@debian.org> - 2024-12-16 18:00 +0100
    Processed: Re: Bug#1090183: nftables connection tracking fails  after kernel update to 6.1.119-1 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-12-16 18:00 +0100
    Bug#1090183: Info received (Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1) Tibor <oomtig@gmail.com> - 2024-12-17 14:00 +0100

#84843 — Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1

FromTibor <oomtig@gmail.com>
Date2024-12-16 15:50 +0100
SubjectBug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1
Message-ID<JUkA1-hyMh-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: linux-image-6.1.0-28-amd64
Version: 6.1.119-1
Severity: important

After upgrading from linux-image-6.1.0-27-amd64 to
linux-image-6.1.0-28-amd64, nftables connection tracking ('ct state')
functionality stopped working. The issue appears to be related to recent
netfilter security patches.

Steps to reproduce:
1. Update kernel to 6.1.119-1
2. Reboot system
3. Attempt to use nftables rules with 'ct state'

Current behavior:
- Error message: "could not process rule: No such file or directory"
- nftables rules using 'ct state' fail to load
- Basic firewall functionality without connection tracking works

Expected behavior:
- nftables rules with 'ct state' should load and function properly
- Connection tracking should work as it did in previous kernel version

System information:
- Debian 12 (bookworm)
- Previous kernel: linux-image-6.1.0-27-amd64 (6.1.115-1)
- Current kernel: linux-image-6.1.0-28-amd64 (6.1.119-1)
- nftables version: 1.0.6

Related changes in current version:
- Security fixes for netfilter IPv6 (use-after-free in ip6table_nat)
- Changes to nf_reject_ipv6 TCP header handling

nf_conntrack and related modules are loaded:
[output of lsmod | grep -E 'nf_|netfilter|nft']

Additional notes:
- System has module loading disabled (kernel.modules_disabled=1)
- Required modules are preloaded in initramfs
- Configuration worked correctly in previous kernel version

Proposed temporary solution:
Reverting to linux-image-6.1.0-27-amd64 restores functionality.

Please advise on proper configuration for connection tracking with the new
security patches, or confirm if this is a regression that needs to be
addressed.

This report has been co authored with AI support.

Kind regards,

[toc] | [next] | [standalone]


#84845

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-12-16 18:00 +0100
Message-ID<JUmBQ-hA3D-7@gated-at.bofh.it>
In reply to#84843
Control: tags -1 + moreinfo

Hi,

On Mon, Dec 16, 2024 at 02:43:47PM +0000, Tibor wrote:
> Package: linux-image-6.1.0-28-amd64
> Version: 6.1.119-1
> Severity: important
> 
> After upgrading from linux-image-6.1.0-27-amd64 to
> linux-image-6.1.0-28-amd64, nftables connection tracking ('ct state')
> functionality stopped working. The issue appears to be related to recent
> netfilter security patches.
> 
> Steps to reproduce:
> 1. Update kernel to 6.1.119-1
> 2. Reboot system
> 3. Attempt to use nftables rules with 'ct state'
> 
> Current behavior:
> - Error message: "could not process rule: No such file or directory"
> - nftables rules using 'ct state' fail to load
> - Basic firewall functionality without connection tracking works
> 
> Expected behavior:
> - nftables rules with 'ct state' should load and function properly
> - Connection tracking should work as it did in previous kernel version
> 
> System information:
> - Debian 12 (bookworm)
> - Previous kernel: linux-image-6.1.0-27-amd64 (6.1.115-1)
> - Current kernel: linux-image-6.1.0-28-amd64 (6.1.119-1)
> - nftables version: 1.0.6
> 
> Related changes in current version:
> - Security fixes for netfilter IPv6 (use-after-free in ip6table_nat)
> - Changes to nf_reject_ipv6 TCP header handling
> 
> nf_conntrack and related modules are loaded:
> [output of lsmod | grep -E 'nf_|netfilter|nft']
> 
> Additional notes:
> - System has module loading disabled (kernel.modules_disabled=1)
> - Required modules are preloaded in initramfs
> - Configuration worked correctly in previous kernel version
> 
> Proposed temporary solution:
> Reverting to linux-image-6.1.0-27-amd64 restores functionality.
> 
> Please advise on proper configuration for connection tracking with the new
> security patches, or confirm if this is a regression that needs to be
> addressed.

Can you please provide an ideally as minimal as possible example which
fails. A simple example using ct state from
https://wiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minutes#Simple_IP/IPv6_Firewall
works as expected, so we need more information here.

If you are able to to reproduce the issue with the upstream version
6.1.115 and 6.1.119 can you please as well bisect the changes?

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#84847 — Processed: Re: Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-12-16 18:00 +0100
SubjectProcessed: Re: Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1
Message-ID<JUmBQ-hA3D-15@gated-at.bofh.it>
In reply to#84843
Processing control commands:

> tags -1 + moreinfo
Bug #1090183 [src:linux] nftables connection tracking fails after kernel update to 6.1.119-1
Added tag(s) moreinfo.

-- 
1090183: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1090183
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#84855 — Bug#1090183: Info received (Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1)

FromTibor <oomtig@gmail.com>
Date2024-12-17 14:00 +0100
SubjectBug#1090183: Info received (Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1)
Message-ID<JUFl7-dJu-9@gated-at.bofh.it>
In reply to#84843

[Multipart message — attachments visible in raw view] — view raw

Seems the issue comes with an incorrect/mismatching GRUB configuration:

The connection tracking feature does not work if:

in the /etc/default/grub

The

GRUB_DEFAULT="Debian GNU/Linux. with Linux 6.1.0-27-amd64"

But The system actually boots the 6.1.0-28 kernel,

If the GRUB_DEFAULT entry is changed to
GRUB_DEFAULT="Debian GNU/Linux. with Linux 6.1.0-28-amd64"

The issue seems to resolve.

- Always starting the default entry

On Tue, Dec 17, 2024 at 11:45 AM Debian Bug Tracking System <
owner@bugs.debian.org> wrote:

> Thank you for the additional information you have supplied regarding
> this Bug report.
>
> This is an automatically generated reply to let you know your message
> has been received.
>
> Your message is being forwarded to the package maintainers and other
> interested parties for their attention; they will reply in due course.
>
> Your message has been sent to the package maintainer(s):
>  Debian Kernel Team <debian-kernel@lists.debian.org>
>
> If you wish to submit further information on this problem, please
> send it to 1090183@bugs.debian.org.
>
> Please do not send mail to owner@bugs.debian.org unless you wish
> to report a problem with the Bug-tracking system.
>
> --
> 1090183: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1090183
> Debian Bug Tracking System
> Contact owner@bugs.debian.org with problems
>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web