summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)Author
2026-03-04netfilter: nf_conntrack_h323: fix OOB read in decode_choice()Vahagn Vardanian
2026-03-04netfilter: xt_tcpmss: check remaining length before reading optlenFlorian Westphal
2026-03-04netfilter: nf_conntrack: Add allow_clash to generic protocol handlerYuto Hamaguchi
2026-03-04netfilter: nf_tables: fix use-after-free in nf_tables_addchain()Inseo An
2026-03-04netfilter: nf_conntrack_h323: don't pass uninitialised l3num valueFlorian Westphal
2026-03-04netfilter: nft_set_rbtree: check for partial overlaps in anonymous setsPablo Neira Ayuso
2026-03-04netfilter: nft_counter: fix reset of counters on 32bit archsAnders Grahn
2026-03-04netfilter: nft_set_hash: fix get operation on big endianFlorian Westphal
2026-03-04netfilter: nf_conncount: fix tracking of connections from localhostFernando Fernandez Mancera
2026-03-04netfilter: nft_compat: add more restrictions on netlink attributesFlorian Westphal
2026-03-04netfilter: nf_conncount: increase the connection clean up limit to 64Fernando Fernandez Mancera
2026-03-04netfilter: nf_conncount: make nf_conncount_gc_list() to disable BHFernando Fernandez Mancera
2026-03-04netfilter: nf_tables: reset table validation state on abortFlorian Westphal
2026-02-16netfilter: nft_set_pipapo: prevent overflow in lookup table allocationPablo Neira Ayuso
2026-02-16netfilter: nf_tables: missing objects with no memcg accountingPablo Neira Ayuso
2026-02-11netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()Andrew Fasano
2026-02-11netfilter: replace -EEXIST with -EBUSYDaniel Gomez
2026-02-11netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAXPablo Neira Ayuso
2026-01-17netfilter: nf_tables: avoid chain re-validation if possibleFlorian Westphal
2026-01-17netfilter: nf_conncount: update last_gc only when GC has been performedFernando Fernandez Mancera
2026-01-17netfilter: nf_tables: fix memory leak in nf_tables_newrule()Zilin Guan
2026-01-17netfilter: nft_synproxy: avoid possible data-race on update operationFernando Fernandez Mancera
2026-01-11netfilter: nf_tables: remove redundant chain validation on register storePablo Neira Ayuso
2026-01-11netfilter: nf_tables: allow loads only when register is initializedFlorian Westphal
2026-01-11netfilter: nf_tables: pass context structure to nft_parse_register_loadFlorian Westphal
2026-01-11ipvs: fix ipv4 null-ptr-deref in route error pathSlavin Liu
2026-01-11netfilter: nf_conncount: fix leaked ct in error pathsFernando Fernandez Mancera
2026-01-11netfilter: nft_connlimit: update the count if add was skippedFernando Fernandez Mancera
2026-01-11netfilter: nf_conncount: rework API to use sk_buff directlyFernando Fernandez Mancera
2026-01-11netfilter: flowtable: check for maximum number of encapsulations in bridge vlanPablo Neira Ayuso
2025-11-24netfilter: nf_tables: reject duplicate device on updatesPablo Neira Ayuso
2025-10-19netfilter: nft_objref: validate objref and objrefmap expressionsFernando Fernandez Mancera
2025-10-19netfilter: nf_tables: drop unused 3rd argument from validate callback opsFlorian Westphal
2025-10-15ipvs: Defer ip_vs_ftp unregister during netns cleanupSlavin Liu
2025-10-15ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enableZhang Tengfei
2025-10-15netfilter: ipset: Remove unused htable_bits in macro ahash_regionZhen Ni
2025-09-09netfilter: conntrack: helper: Replace -EEXIST by -EBUSYPhil Sutter
2025-08-28netfilter: ctnetlink: fix refcount leak on table dumpFlorian Westphal
2025-08-15bpf: Check netfilter ctx accesses are alignedPaul Chaignon
2025-08-15netfilter: xt_nfacct: don't assume acct name is null-terminatedFlorian Westphal
2025-08-15bpf: Disable migration in nf_hook_run_bpf().Kuniyuki Iwashima
2025-08-15netfilter: nf_tables: adjust lockdep assertions handlingFedor Pchelkin
2025-08-15netfilter: nf_tables: Drop dead code from fill_*_info routinesPhil Sutter
2025-07-24netfilter: nf_conntrack: fix crash due to removal of uninitialised entryFlorian Westphal
2025-06-19netfilter: nf_nat: also check reverse tuple to obtain clashing entryFlorian Westphal
2025-06-19netfilter: nf_set_pipapo_avx2: fix initial map fillFlorian Westphal
2025-06-19netfilter: nft_tunnel: fix geneve_opt dumpFernando Fernandez Mancera
2025-06-19netfilter: nft_quota: match correctly when the quota just depletedZhongqiu Duan
2025-06-04netfilter: conntrack: Bound nf_conntrack sysctl writesNicolas Bouchinet
2025-05-18netfilter: ipset: fix region locking in hash typesJozsef Kadlecsik