This is a note to let you know that I've just added the patch titled netfilter: conntrack: do not print icmpv6 as unknown via /proc to the 5.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: netfilter-conntrack-do-not-print-icmpv6-as-unknown-via-proc.patch and it can be found in the queue-5.4 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From fbea31808ca124dd73ff6bb1e67c9af4607c3e32 Mon Sep 17 00:00:00 2001 From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> Date: Wed, 31 Mar 2021 01:04:45 +0200 Subject: netfilter: conntrack: do not print icmpv6 as unknown via /proc From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> commit fbea31808ca124dd73ff6bb1e67c9af4607c3e32 upstream. /proc/net/nf_conntrack shows icmpv6 as unknown. Fixes: 09ec82f5af99 ("netfilter: conntrack: remove protocol name from l4proto struct") Signed-off-by: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- net/netfilter/nf_conntrack_standalone.c | 1 + 1 file changed, 1 insertion(+) --- a/net/netfilter/nf_conntrack_standalone.c +++ b/net/netfilter/nf_conntrack_standalone.c @@ -266,6 +266,7 @@ static const char* l4proto_name(u16 prot case IPPROTO_GRE: return "gre"; case IPPROTO_SCTP: return "sctp"; case IPPROTO_UDPLITE: return "udplite"; + case IPPROTO_ICMPV6: return "icmpv6"; } return "unknown"; Patches currently in stable-queue which might be from pablo@xxxxxxxxxxxxx are queue-5.4/netfilter-bridge-add-pre_exit-hooks-for-ebtable-unregistration.patch queue-5.4/netfilter-arp_tables-add-pre_exit-hook-for-table-unregister.patch queue-5.4/netfilter-nft_limit-avoid-possible-divide-error-in-nft_limit_init.patch queue-5.4/netfilter-conntrack-do-not-print-icmpv6-as-unknown-via-proc.patch