Alakesh Haloi <alakeshh@xxxxxxxxxx> wrote: > > But In case you can't reproduce, its possible your patch is still needed > > for stable. > > Thanks Florian! I have tested linus's tree and i do not see the issue happening > there. I have not been able to test nf.git yet. Do you suggest that I should > start working on backporting relevant patches from mainline or it should be > possible to apply this patch to stable branches directly? The relevant mainline fix is probably b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 ("netfilter: nf_conncount: fix garbage collection confirm race"). But 1. I don't like this fix (i could not come up with anything better...) 2. It will not apply to older stable branches. So I think you might want to look at this commit, see if you have a better idea, and if not, apply similar strategy to older stable kernel, then pass this as a backport to stable maintainers. I can review the patch.