Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #84843 > unrolled thread
| Started by | Tibor <oomtig@gmail.com> |
|---|---|
| First post | 2024-12-16 15:50 +0100 |
| Last post | 2024-12-17 14:00 +0100 |
| Articles | 4 — 3 participants |
Back to article view | Back to linux.debian.kernel
Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 Tibor <oomtig@gmail.com> - 2024-12-16 15:50 +0100
Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 Salvatore Bonaccorso <carnil@debian.org> - 2024-12-16 18:00 +0100
Processed: Re: Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-12-16 18:00 +0100
Bug#1090183: Info received (Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1) Tibor <oomtig@gmail.com> - 2024-12-17 14:00 +0100
| From | Tibor <oomtig@gmail.com> |
|---|---|
| Date | 2024-12-16 15:50 +0100 |
| Subject | Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 |
| Message-ID | <JUkA1-hyMh-5@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Package: linux-image-6.1.0-28-amd64
Version: 6.1.119-1
Severity: important
After upgrading from linux-image-6.1.0-27-amd64 to
linux-image-6.1.0-28-amd64, nftables connection tracking ('ct state')
functionality stopped working. The issue appears to be related to recent
netfilter security patches.
Steps to reproduce:
1. Update kernel to 6.1.119-1
2. Reboot system
3. Attempt to use nftables rules with 'ct state'
Current behavior:
- Error message: "could not process rule: No such file or directory"
- nftables rules using 'ct state' fail to load
- Basic firewall functionality without connection tracking works
Expected behavior:
- nftables rules with 'ct state' should load and function properly
- Connection tracking should work as it did in previous kernel version
System information:
- Debian 12 (bookworm)
- Previous kernel: linux-image-6.1.0-27-amd64 (6.1.115-1)
- Current kernel: linux-image-6.1.0-28-amd64 (6.1.119-1)
- nftables version: 1.0.6
Related changes in current version:
- Security fixes for netfilter IPv6 (use-after-free in ip6table_nat)
- Changes to nf_reject_ipv6 TCP header handling
nf_conntrack and related modules are loaded:
[output of lsmod | grep -E 'nf_|netfilter|nft']
Additional notes:
- System has module loading disabled (kernel.modules_disabled=1)
- Required modules are preloaded in initramfs
- Configuration worked correctly in previous kernel version
Proposed temporary solution:
Reverting to linux-image-6.1.0-27-amd64 restores functionality.
Please advise on proper configuration for connection tracking with the new
security patches, or confirm if this is a regression that needs to be
addressed.
This report has been co authored with AI support.
Kind regards,
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2024-12-16 18:00 +0100 |
| Message-ID | <JUmBQ-hA3D-7@gated-at.bofh.it> |
| In reply to | #84843 |
Control: tags -1 + moreinfo
Hi,
On Mon, Dec 16, 2024 at 02:43:47PM +0000, Tibor wrote:
> Package: linux-image-6.1.0-28-amd64
> Version: 6.1.119-1
> Severity: important
>
> After upgrading from linux-image-6.1.0-27-amd64 to
> linux-image-6.1.0-28-amd64, nftables connection tracking ('ct state')
> functionality stopped working. The issue appears to be related to recent
> netfilter security patches.
>
> Steps to reproduce:
> 1. Update kernel to 6.1.119-1
> 2. Reboot system
> 3. Attempt to use nftables rules with 'ct state'
>
> Current behavior:
> - Error message: "could not process rule: No such file or directory"
> - nftables rules using 'ct state' fail to load
> - Basic firewall functionality without connection tracking works
>
> Expected behavior:
> - nftables rules with 'ct state' should load and function properly
> - Connection tracking should work as it did in previous kernel version
>
> System information:
> - Debian 12 (bookworm)
> - Previous kernel: linux-image-6.1.0-27-amd64 (6.1.115-1)
> - Current kernel: linux-image-6.1.0-28-amd64 (6.1.119-1)
> - nftables version: 1.0.6
>
> Related changes in current version:
> - Security fixes for netfilter IPv6 (use-after-free in ip6table_nat)
> - Changes to nf_reject_ipv6 TCP header handling
>
> nf_conntrack and related modules are loaded:
> [output of lsmod | grep -E 'nf_|netfilter|nft']
>
> Additional notes:
> - System has module loading disabled (kernel.modules_disabled=1)
> - Required modules are preloaded in initramfs
> - Configuration worked correctly in previous kernel version
>
> Proposed temporary solution:
> Reverting to linux-image-6.1.0-27-amd64 restores functionality.
>
> Please advise on proper configuration for connection tracking with the new
> security patches, or confirm if this is a regression that needs to be
> addressed.
Can you please provide an ideally as minimal as possible example which
fails. A simple example using ct state from
https://wiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minutes#Simple_IP/IPv6_Firewall
works as expected, so we need more information here.
If you are able to to reproduce the issue with the upstream version
6.1.115 and 6.1.119 can you please as well bisect the changes?
Regards,
Salvatore
[toc] | [prev] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2024-12-16 18:00 +0100 |
| Subject | Processed: Re: Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1 |
| Message-ID | <JUmBQ-hA3D-15@gated-at.bofh.it> |
| In reply to | #84843 |
Processing control commands: > tags -1 + moreinfo Bug #1090183 [src:linux] nftables connection tracking fails after kernel update to 6.1.119-1 Added tag(s) moreinfo. -- 1090183: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1090183 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [next] | [standalone]
| From | Tibor <oomtig@gmail.com> |
|---|---|
| Date | 2024-12-17 14:00 +0100 |
| Subject | Bug#1090183: Info received (Bug#1090183: nftables connection tracking fails after kernel update to 6.1.119-1) |
| Message-ID | <JUFl7-dJu-9@gated-at.bofh.it> |
| In reply to | #84843 |
[Multipart message — attachments visible in raw view] — view raw
Seems the issue comes with an incorrect/mismatching GRUB configuration: The connection tracking feature does not work if: in the /etc/default/grub The GRUB_DEFAULT="Debian GNU/Linux. with Linux 6.1.0-27-amd64" But The system actually boots the 6.1.0-28 kernel, If the GRUB_DEFAULT entry is changed to GRUB_DEFAULT="Debian GNU/Linux. with Linux 6.1.0-28-amd64" The issue seems to resolve. - Always starting the default entry On Tue, Dec 17, 2024 at 11:45 AM Debian Bug Tracking System < owner@bugs.debian.org> wrote: > Thank you for the additional information you have supplied regarding > this Bug report. > > This is an automatically generated reply to let you know your message > has been received. > > Your message is being forwarded to the package maintainers and other > interested parties for their attention; they will reply in due course. > > Your message has been sent to the package maintainer(s): > Debian Kernel Team <debian-kernel@lists.debian.org> > > If you wish to submit further information on this problem, please > send it to 1090183@bugs.debian.org. > > Please do not send mail to owner@bugs.debian.org unless you wish > to report a problem with the Bug-tracking system. > > -- > 1090183: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1090183 > Debian Bug Tracking System > Contact owner@bugs.debian.org with problems >
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web