netfilter: keep conntrack reference until IPsecv6 policy checks are done

[ Upstream commit b0e214d212 ]

Keep the conntrack reference until policy checks have been performed for
IPsec V6 NAT support, just like ipv4.

The reference needs to be dropped before a packet is
queued to avoid having the conntrack module unloadable.

Fixes: 58a317f106 ("netfilter: ipv6: add IPv6 NAT support")
Signed-off-by: Madhu Koriginja <madhu.koriginja@nxp.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
Madhu Koriginja 2023-03-21 21:28:44 +05:30 • committed by Greg Kroah-Hartman
commit 2361aee1c5
5 changed files with 13 additions and 11 deletions