On Mon, May 08, 2017 at 11:48:42AM +0200, Simon Horman wrote: > Hi Pablo, > > please consider this fix to IPVS for v4.12. > > * It is a fix from Julian Anastasov to only SNAT SNAT packet replies only for > NATed connections > > > My understanding is that this fix is appropriate for 4.9.25, 4.10.13, 4.11 > as well as the nf tree. Julian has separately posted backports for other > -stable kernels; please see: > > * [PATCH 3.2.88,3.4.113 -stable 1/3] ipvs: SNAT packet replies only for > NATed connections > * [PATCH 3.10.105,3.12.73,3.16.43,4.1.39 -stable 2/3] ipvs: SNAT packet > replies only for NATed connections > * [PATCH 4.4.65 -stable 3/3] ipvs: SNAT packet replies only for NATed > connections Pulled, thanks. Please, resubmit your stable backport patches once this patch hits Linus' linux.git tree, Cc: stable@xxxxxxxxxxxxxxxx, I'll be glad to ack them. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html