Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Aug 2024 09:14:02 +0000
From:      bugzilla-noreply@freebsd.org
To:        net@FreeBSD.org
Subject:   [Bug 280701] FreeBSD-SA-24:05 fix breaks ICMP/ICMP6 states handling in pf firewall (ping, traceroute)
Message-ID:  <bug-280701-7501-FflBHM8VNv@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-280701-7501@https.bugs.freebsd.org/bugzilla/>
References:  <bug-280701-7501@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D280701

--- Comment #41 from Philip Paeps <philip@FreeBSD.org> ---
Problems with how FreeBSD code behaves when merged into a downstream product
are beyond the scope of this bug tracker.  As far as FreeBSD is concerned, =
an
issue is resolved when it no longer manifests on FreeBSD.

It is up to our downstreams to ensure that they do not introduce bugs in th=
eir
products when merging code from FreeBSD.

Unless a test case materialises that shows there is still a regression on
FreeBSD, we can proceed with a corrected security advisory for FreeBSD
SA-24:05.pf.

For what it's worth: FreeBSD.org firewalls run pf.  Can you quantify the
"heavily coupled with IPv6 connectivity" required for the issue to manifest?

Again: is there any evidence that this problem still manifests on FreeBSD?

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-280701-7501-FflBHM8VNv>