summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
5 daysnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl checkFernando Fernandez Mancera1-15/+7
5 daysnetfilter: nfnetlink_osf: fix out-of-bounds read on option matchingFernando Fernandez Mancera1-11/+8
5 daysipvs: fix MTU check for GSO packets in tunnel modeYingnan Zhang1-4/+15
5 daysnetfilter: nat: use kfree_rcu to release opsPablo Neira Ayuso1-4/+6
5 daysnetfilter: xtables: restrict several matches to inet familyPablo Neira Ayuso4-34/+68
5 daysnetfilter: conntrack: remove sprintf usageFlorian Westphal2-16/+19
5 daysnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULOXiang Mei1-0/+4
5 daysnetfilter: nft_osf: restrict it to ipv4Pablo Neira Ayuso1-1/+5
2026-04-10netfilter: require Ethernet MAC header before using eth_hdr()Zhengchuan Liang5-12/+19
2026-04-10netfilter: nft_fwd_netdev: check ttl/hl before forwardingFlorian Westphal1-0/+10
2026-04-10netfilter: x_tables: Avoid a couple -Wflex-array-member-not-at-end warningsGustavo A. R. Silva1-4/+8
2026-04-10netfilter: conntrack: remove UDP-Lite conntrack supportFernando Fernandez Mancera9-160/+0
2026-04-10netfilter: xt_socket: enable defrag after all other checksFlorian Westphal1-17/+6
2026-04-10netfilter: xt_HL: add pr_fmt and checkentry validationMarino Dzalto1-0/+27
2026-04-10netfilter: nfnetlink: prefer skb_mac_header helpersFlorian Westphal2-22/+22
2026-04-10netfilter: x_physdev: reject empty or not-nul terminated device namesFlorian Westphal1-0/+22
2026-04-10ipvs: add conn_lfactor and svc_lfactor sysctl varsJulian Anastasov1-0/+76
2026-04-10ipvs: add ip_vs_status infoJulian Anastasov1-0/+145
2026-04-10ipvs: show the current conn_tab size to usersJulian Anastasov1-4/+22
2026-04-09Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski5-100/+84
2026-04-08netfilter: nfnetlink_queue: make hash table per queueFlorian Westphal1-90/+49
2026-04-08netfilter: nft_ct: fix use-after-free in timeout object destroyTuan Do1-1/+1
2026-04-08netfilter: xt_multiport: validate range encoding in checkentryRen Wei1-4/+30
2026-04-08netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminatorXiang Mei1-4/+4
2026-04-08ipvs: fix NULL deref in ip_vs_add_service error pathWeiming Shi1-1/+0
2026-04-08netfilter: nf_tables_offload: add nft_flow_action_entry_next() and use itPablo Neira Ayuso2-2/+7
2026-04-08netfilter: nf_conntrack_h323: Correct indentation when H323_TRACE definedDavid Laight1-19/+19
2026-04-08netfilter: nft_meta: add double-tagged vlan and pppoe supportPablo Neira Ayuso3-3/+55
2026-04-08netfilter: nft_set_pipapo_avx2: remove redundant loop in lookup_slowFlorian Westphal1-23/+9
2026-04-08netfilter: nft_set_pipapo: increment data in one stepFlorian Westphal2-6/+1
2026-04-08netfilter: nf_tables: add netlink policy based cap on registersFlorian Westphal19-28/+28
2026-04-08netfilter: add more netlink-based policy range checksFlorian Westphal23-30/+43
2026-04-08netfilter: nf_conntrack_h323: remove unreliable debug code in decode_octstrFlorian Westphal1-7/+0
2026-04-08netfilter: add deprecation warning for dccp supportFlorian Westphal2-0/+6
2026-04-08netfilter: nf_conntrack_sip: remove net variable shadowingFlorian Westphal1-2/+1
2026-04-08netfilter: use function typedefs for __rcu NAT helper hook pointersSun Jian5-34/+10
2026-04-02Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski11-120/+191
2026-04-01netfilter: nf_tables: reject immediate NF_QUEUE verdictPablo Neira Ayuso1-2/+5
2026-04-01netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for N...Pablo Neira Ayuso1-0/+23
2026-04-01netfilter: ipset: drop logically empty buckets in mtype_delYifan Wu1-1/+1
2026-04-01netfilter: ctnetlink: ignore explicit helper on new expectationsPablo Neira Ayuso1-45/+9
2026-04-01netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absentQi Tang1-0/+6
2026-04-01netfilter: nf_conntrack_helper: pass helper to expect cleanupQi Tang1-1/+1
2026-04-01netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attrFlorian Westphal2-4/+4
2026-04-01netfilter: x_tables: ensure names are nul-terminatedFlorian Westphal2-0/+11
2026-04-01netfilter: nfnetlink_log: account for netlink header sizeFlorian Westphal1-1/+1
2026-04-01netfilter: flowtable: strictly check for maximum number of actionsPablo Neira Ayuso1-66/+130
2026-03-29netfilter: remove nf_ipv6_ops and use direct function callsFernando Fernandez Mancera4-27/+20
2026-03-29ipv6: convert CONFIG_IPV6 to built-in only and clean up KconfigsFernando Fernandez Mancera1-8/+0
2026-03-26Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski11-99/+196