summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)Author
3 daysnetfilter: ipset: drop logically empty buckets in mtype_delYifan Wu
3 daysnetfilter: nf_tables: reject immediate NF_QUEUE verdictPablo Neira Ayuso
3 daysnetfilter: x_tables: restrict xt_check_match/xt_check_target extensions for N...Pablo Neira Ayuso
3 daysnetfilter: ctnetlink: ignore explicit helper on new expectationsPablo Neira Ayuso
3 daysnetfilter: nf_conntrack_expect: store netns and zone in expectationPablo Neira Ayuso
3 daysnetfilter: nf_conntrack_expect: use expect->helperPablo Neira Ayuso
3 daysnetfilter: nf_conntrack_expect: honor expectation helper fieldPablo Neira Ayuso
3 daysnetfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absentQi Tang
3 daysnetfilter: nf_conntrack_helper: pass helper to expect cleanupQi Tang
3 daysnetfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attrFlorian Westphal
3 daysnetfilter: x_tables: ensure names are nul-terminatedFlorian Westphal
3 daysnetfilter: nfnetlink_log: account for netlink header sizeFlorian Westphal
3 daysnetfilter: flowtable: strictly check for maximum number of actionsPablo Neira Ayuso
12 daysnetfilter: ctnetlink: use netlink policy range checksDavid Carlier
12 daysnetfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdpWeiming Shi
12 daysnetfilter: nf_conntrack_expect: skip expectations in other netns via procPablo Neira Ayuso
12 daysnetfilter: nft_set_rbtree: revisit array resize logicPablo Neira Ayuso
12 daysnetfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOADWeiming Shi
2026-03-25nfnetlink_osf: validate individual option lengths in fingerprintsWeiming Shi
2026-03-25netfilter: nf_tables: release flowtable after rcu grace period on errorPablo Neira Ayuso
2026-03-25netfilter: bpf: defer hook memory release until rcu readers are doneFlorian Westphal
2026-03-25netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()Jenny Guanni Qu
2026-03-25netfilter: xt_time: use unsigned int for monthday bit shiftJenny Guanni Qu
2026-03-25netfilter: xt_CT: drop pending enqueued packets on template removalPablo Neira Ayuso
2026-03-25netfilter: nft_ct: drop pending enqueued packets on removalPablo Neira Ayuso
2026-03-25nf_tables: nft_dynset: fix possible stateful expression memleak in error pathPablo Neira Ayuso
2026-03-25netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS caseJenny Guanni Qu
2026-03-25netfilter: nf_flow_table_ip: reset mac header before vlan pushEric Woudstra
2026-03-25netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()Lukas Johannes Möller
2026-03-25netfilter: conntrack: add missing netlink policy validationsFlorian Westphal
2026-03-25netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()Hyunwoo Kim
2026-03-19netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labelsYuan Tan
2026-03-19netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()Hyunwoo Kim
2026-03-19netfilter: nfnetlink_queue: fix entry leak in bridge verdict error pathHyunwoo Kim
2026-03-19netfilter: x_tables: guard option walkers against 1-byte tail readsDavid Dull
2026-03-19netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()Jenny Guanni Qu
2026-03-19netfilter: nf_tables: always walk all pending catchall elementsFlorian Westphal
2026-03-19netfilter: nf_tables: Fix for duplicate device in netdev hooksPhil Sutter
2026-03-12netfilter: nft_set_pipapo: split gc into unlink and reclaim phaseFlorian Westphal
2026-03-12netfilter: nf_tables: clone set on flush onlyPablo Neira Ayuso
2026-03-12netfilter: nf_tables: unconditionally bump set->nelems before insertionPablo Neira Ayuso
2026-03-12Revert "netfilter: nft_set_rbtree: validate open interval overlap"Greg Kroah-Hartman
2026-03-04netfilter: nf_conntrack_h323: fix OOB read in decode_choice()Vahagn Vardanian
2026-03-04netfilter: xt_tcpmss: check remaining length before reading optlenFlorian Westphal
2026-03-04netfilter: nf_conntrack: Add allow_clash to generic protocol handlerYuto Hamaguchi
2026-02-27netfilter: nf_tables: add .abort_skip_removal flag for set typesPablo Neira Ayuso
2026-02-26netfilter: nf_tables: fix use-after-free in nf_tables_addchain()Inseo An
2026-02-26ipvs: do not keep dest_dst if dev is going downJulian Anastasov
2026-02-26ipvs: skip ipv6 extension headers for csum checksJulian Anastasov
2026-02-26netfilter: nf_conntrack_h323: don't pass uninitialised l3num valueFlorian Westphal