I have 2 vlan interfaces (tag 101 and 102) and "accept all" rule in the forward chain.
Fragmented UDP packets are dropped and there is no way to match them (only the first fragment is matched with size=1500).
If I enable connection tracking the packets get forwarded and i see their "full" size (>1500).
Seems like a bug to me, i have no need in statefull firewall and there is no reason to drop transit fragments (unless, of course, there is a specific rule).
MT 2.9.44