Patch for Linux kernel 3.10: netfilter: nf_conntrack: avoid large timeout for mid-stream pickup

Bug #1336559 reported by Pavel Chekin
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mirantis OpenStack
Fix Committed
Critical
Alexei Sheplyakov

Bug Description

There is a patch (https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6547a221871f139cc56328a38105d47c14874cbe) included in kernel 3.11.

We need to patch CentOS kernel, which is 3.10.30.

Tags: mos-linux
Pavel Chekin (pchekin)
tags: added: mos-linux
Revision history for this message
Alexei Sheplyakov (asheplyakov) wrote :

We are going to update the -lt kernel to 3.10.46 (in order to address several security issues). I'll check if the patch in question has been backported

Changed in mos:
assignee: MOS Linux (mos-linux) → Alexei Sheplyakov (asheplyakov)
Revision history for this message
Alexei Sheplyakov (asheplyakov) wrote :

Security update for kernel-lt (basically update to the latest upstream version, which is 3.10.46 at the time of writing):
http://gerrit.mirantis.com/17642
The patch in question is NOT included in the upstream version, I'm working on a backport.

Revision history for this message
Alexei Sheplyakov (asheplyakov) wrote :

Upd: the patch is being reviewed at the moment: https://gerrit.mirantis.com/#/c/17642

Revision history for this message
Alexei Sheplyakov (asheplyakov) wrote :

The fix has been merged

Changed in mos:
status: New → In Progress
Changed in mos:
status: In Progress → Fix Committed
Revision history for this message
OSCI Robot (oscirobot) wrote :

Package kernel-lt has been built from changeset: http://gerrit.mirantis.com/29557
RPM Repository URL: http:///osci-obs.vm.mirantis.net:82/centos-fuel-6.0-stable-29557/centos

Revision history for this message
OSCI Robot (oscirobot) wrote :

Package kernel-lt has been built from changeset: http://gerrit.mirantis.com/29557
RPM Repository URL: http:///osci-obs.vm.mirantis.net:82/centos-fuel-6.0-stable/centos

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.