Tom Eastep | 19 Aug 00:11 2011

[PATCH] Parsing bug in libxt_conntrack.c 1.4.12

Just discovered this little gem:

sami:/home/teastep/iptables# iptables -N foo
sami:/home/teastep/iptables# iptables -A foo -m conntrack --ctorigdstport 22
iptables v1.4.12: conntrack rev 2 does not support port ranges
Try `iptables -h' or 'iptables --help' for more information.

The attached seems to correct it.



Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car \________________________________________________

commit 57c7c7995326a37c983ac6ca4026eb176595fb37
Author: Tom Eastep <teastep <at>>
Date:   Thu Aug 18 15:09:14 2011 -0700

    Correct parsing bug in libxt_conntrack.c
    Signed-off-by: Tom Eastep <teastep <at>>

diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index be95529..6a79e37 100644
(Continue reading)

Jan Engelhardt | 27 Aug 18:12 2011

Re: [PATCH] Parsing bug in libxt_conntrack.c 1.4.12

On Friday 2011-08-19 00:11, Tom Eastep wrote:

>Just discovered this little gem:
>sami:/home/teastep/iptables# iptables -N foo
>sami:/home/teastep/iptables# iptables -A foo -m conntrack --ctorigdstport 22
>iptables v1.4.12: conntrack rev 2 does not support port ranges
>Try `iptables -h' or 'iptables --help' for more information.

Thanks for your reminder (via priv). I have taken your patch, but also 
the liberty to fix the actual cause.

Pending merge, you can see the tree/commits at 
git:// fixes-2
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo <at>
More majordomo info at