netfilter: nf_conntrack: fix a race in __nf_conntrack_confirm against nf_ct_get_next_...
authorJoerg Marx <joerg.marx@secunet.com>
Thu, 20 May 2010 13:55:30 +0000 (15:55 +0200)
committerPatrick McHardy <kaber@trash.net>
Thu, 20 May 2010 13:55:30 +0000 (15:55 +0200)
This race was triggered by a 'conntrack -F' command running in parallel
to the insertion of a hash for a new connection. Losing this race led to
a dead conntrack entry effectively blocking traffic for a particular
connection until timeout or flushing the conntrack hashes again.
Now the check for an already dying connection is done inside the lock.

Signed-off-by: Joerg Marx <joerg.marx@secunet.com>
Signed-off-by: Patrick McHardy <kaber@trash.net>

No differences found