[Bug 280701] FreeBSD-SA-24:05 fix breaks ICMP/ICMP6 states handling in pf firewall (ping, traceroute)

[email protected]
Newsgroups gmane.os.freebsd.devel.net
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=280701

--- Comment #85 from [email protected] ---
A commit in branch releng/14.1 references this bug:

URL:
https://cgit.FreeBSD.org/src/commit/?id=84b57a4c5b848d44ec0918c28d8c27bec948a151

commit 84b57a4c5b848d44ec0918c28d8c27bec948a151
Author:     Kristof Provost <[email protected]>
AuthorDate: 2024-08-14 09:29:30 +0000
Commit:     Mark Johnston <[email protected]>
CommitDate: 2024-09-19 12:55:09 +0000

    pf: invert direction for inner icmp state lookups

    (e.g. traceroute with icmp)
    ok henning, jsing

    Also extend the test case to cover this scenario.

    Approved by:    so
    Security:       FreeBSD-EN-24:16.pf
    PR:             280701
    Obtained from:  OpenBSD
    MFC after:      1 week
    Sponsored by:   Rubicon Communications, LLC ("Netgate")

    (cherry picked from commit 89f6723288b0d27d3f14f93e6e83f672fa2b8aca)
    (cherry picked from commit 46c4fc50d3012ca3c8756df243589add36b70830)

 sys/netpfil/pf/pf.c | 21 +++++++++++----------
 1 file changed, 11 insertions(+), 10 deletions(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.