ipset (trusty) fails to support large timeouts; known issue -- patch available

Bug #1413242 reported by darx
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ipset (Ubuntu)
Fix Released
Medium
Unassigned
Trusty
Triaged
Medium
Unassigned
Utopic
Won't Fix
Medium
Unassigned
Vivid
Fix Released
Medium
Unassigned

Bug Description

current trusty ships ipset v 6.20.1-1 (http://packages.ubuntu.com/trusty/ipset).

this version fails to support large timeouts, arbitrarily & incorrectly changing set timeout values on x86_64.

in effect, a security-relaed paramenter is set by admin, and it's either ignored or changed arbitrarily.

it's apparently a known issue,

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=764328%3E
http://marc.info/?l=netfilter-devel&m=141293197611273&w=2
http://marc.info/?l=netfilter-devel&m=141351695203549&w=2

with a fix already in upstream for (iiuc) v > 6.23.x.

could we get a packaged version for trusty that either

(1) applies the patch
(2) backports the current ipset version, 6.24?

thanks.

darx (darx)
information type: Private Security → Public Security
Revision history for this message
James Page (james-page) wrote :

Thanks for the bug report; targeting to impacted series.

Changed in ipset (Ubuntu Trusty):
importance: Undecided → Medium
Changed in ipset (Ubuntu Utopic):
importance: Undecided → Medium
Changed in ipset (Ubuntu Vivid):
importance: Undecided → Medium
status: New → Fix Released
Changed in ipset (Ubuntu Utopic):
status: New → Triaged
Changed in ipset (Ubuntu Trusty):
status: New → Triaged
Revision history for this message
Rolf Leggewie (r0lf) wrote :

utopic has seen the end of its life and is no longer receiving any updates. Marking the utopic task for this ticket as "Won't Fix".

Changed in ipset (Ubuntu Utopic):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.