[Bug 815182] New: security:netfilter/iptables: Bug
https://bugzilla.novell.com/show_bug.cgi?id=815182 https://bugzilla.novell.com/show_bug.cgi?id=815182#c0 Summary: security:netfilter/iptables: Bug Classification: openSUSE Product: openSUSE.org Version: unspecified Platform: x86-64 OS/Version: SLES 11 Status: NEW Severity: Normal Priority: P5 - None Component: 3rd party software AssignedTo: jengelh@inai.de ReportedBy: novell-web@zmi.at QAContact: opensuse-communityscreening@forge.provo.novell.com CC: vcizek@suse.com Found By: Customer Blocker: Yes http://download.opensuse.org/repositories/security:/netfilter/SLE_11_SP2/x86... Installing this package on SLES 11 SP2 causes ip6tables (ipv6!) to NOT load module xt_state correctly, leading to non-working rulesets that are otherwise good. Rules needing the "state" module don't load anymore, like this: ip6tables -A Access -p tcp -m tcp --dport 5666 -m state --state NEW -j Cid2 When I returned to default iptables-1.4.6-2.11.4 the rules load perfectly again. So the bug is definitely in iptables-1.4.18-75 from OBS. Could you please fix? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=815182 https://bugzilla.novell.com/show_bug.cgi?id=815182#c1 --- Comment #1 from Jan Engelhardt <jengelh@inai.de> 2013-04-15 01:34:09 CEST --- What messages did you observe on screen? What did you expect instead? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=815182 https://bugzilla.novell.com/show_bug.cgi?id=815182#c2 Michael Monnerie <novell-web@zmi.at> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |novell-web@zmi.at --- Comment #2 from Michael Monnerie <novell-web@zmi.at> 2013-04-15 05:31:22 UTC --- We use fwbuilder to generate rules. Starting that script works fine with iptables-1.4.6-2.11.4, but with iptables-1.4.18-75, it says: ------------------------------------- ip6tables v1.4.18: Couldn't load match `state':No such file or directory Try `ip6tables -h' or 'ip6tables --help' for more information. ------------------------------------- So the "state" module doesn't get loaded. Manually doing "modprobe xt_state" works, but even then the script from fwbuilder doesn't load, neither does a manual ip6tables -A Access -p tcp -m tcp --dport 5666 -m state --state NEW -j Cid2 call work. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=815182 https://bugzilla.novell.com/show_bug.cgi?id=815182#c Jan Engelhardt <jengelh@inai.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED Component|3rd party software |Basesystem Version|unspecified |13.1 Milestone 0 Product|openSUSE.org |openSUSE Factory Target Milestone|--- |13.1 Milestone 0 OS/Version|SLES 11 |Linux -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=815182 https://bugzilla.novell.com/show_bug.cgi?id=815182#c3 Jan Engelhardt <jengelh@inai.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |RESOLVED Resolution| |FIXED --- Comment #3 from Jan Engelhardt <jengelh@inai.de> 2013-04-15 09:38:39 CEST --- resolved in xtables-plugins-1.4.18-76.1.x86_64.rpm. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=815182 https://bugzilla.novell.com/show_bug.cgi?id=815182#c4 --- Comment #4 from Bernhard Wiedemann <bwiedemann@suse.com> 2013-04-16 10:00:22 CEST --- This is an autogenerated message for OBS integration: This bug (815182) was mentioned in https://build.opensuse.org/request/show/170988 Factory / iptables -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com