summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2015-11-14netfilter: xt_NFQUEUE: fix --queue-bypass regressionHolger Eitzenberger1-1/+6
2015-10-28ipvs: fix crash with sync protocol v0 and FTPJulian Anastasov1-1/+1
2015-10-28ipvs: do not use random local source address for tunnelsJulian Anastasov1-1/+0
2015-10-28netfilter: ctnetlink: put back references to master ct and expect objectsPablo Neira Ayuso1-5/+0
2015-10-28netfilter: nf_conntrack: Support expectations in different zonesJoe Stringer1-1/+2
2015-09-14netfilter: nf_conntrack: don't release a conntrack with non-zero refcntPablo Neira Ayuso3-14/+32
2015-09-14netfilter: nf_conntrack: fix RCU race in nf_conntrack_find_getAndrey Vagin1-4/+17
2015-07-30netfilter: nfnetlink_cthelper: Remove 'const' and '&' to avoid warningsChen Gang1-2/+2
2015-05-20netfilter: Zero the tuple in nfnl_cthelper_parse_tuple()Ian Wilson1-0/+3
2015-04-27netfilter: conntrack: disable generic tracking for known protocolsFlorian Westphal1-1/+25
2015-04-13core, nfqueue, openvswitch: fix compilation warningJiri Slaby1-1/+1
2015-04-09core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errorsZoltan Kiss1-8/+21
2015-03-10netfilter: xt_socket: fix a stack corruption bugEric Dumazet1-9/+12
2015-03-10ipvs: rerouting to local clients is not needed anymoreJulian Anastasov1-11/+22
2015-03-10ipvs: add missing ip_vs_pe_put in sync codeJulian Anastasov1-0/+3
2015-01-29ipvs: uninitialized data with IP_VS_IPV6Dan Carpenter1-5/+5
2015-01-26ipvs: correct usage/allocation of seqadj ext in ipvsJesper Dangaard Brouer1-0/+6
2015-01-26netfilter: ipset: small potential read beyond the end of bufferDan Carpenter1-0/+6
2014-11-19netfilter: nf_log: release skbuff on nlmsg put failureHoucheng Lin1-9/+8
2014-11-19netfilter: nfnetlink_log: fix maximum packet length logged to userspaceFlorian Westphal1-3/+5
2014-11-19netfilter: nf_log: account for size of NLMSG_DONE attributeFlorian Westphal1-3/+3
2014-09-26ipvs: fix ipv6 hook registration for local repliesJulian Anastasov1-1/+1
2014-09-26ipvs: Maintain all DSCP and ECN bits for ipv6 tun forwardingAlex Gartrell1-1/+1
2014-09-26ipvs: avoid netns exit crash on ip_vs_conn_drop_conntrackJulian Anastasov1-1/+0
2014-08-19inetpeer: get rid of ip_id_countEric Dumazet1-1/+1
2014-07-17ipvs: Fix panic due to non-linear skbPeter Christensen1-5/+10
2014-07-16netfilter: nf_nat: fix oops on netns removalFlorian Westphal1-1/+34
2014-07-16ipvs: stop tot_stats estimator only under CONFIG_SYSCTLJulian Anastasov1-1/+1
2014-06-23net: Use netlink_ns_capable to verify the permisions of netlink messagesEric W. Biederman1-1/+1
2014-04-03netfilter: nf_conntrack_dccp: fix skb_header_pointer API usagesDaniel Borkmann1-3/+3
2014-04-03ipvs: fix AF assignment in ip_vs_conn_new()Michal Kubecek1-4/+4
2014-01-16netfilter: nf_nat: fix access to uninitialized buffer in IRC NAT helperDaniel Borkmann1-5/+27
2014-01-16netfilter: fix wrong byte order in nf_ct_seqadj_set internal informationPhil Oester1-2/+2
2013-12-08netfilter: push reasm skb through instead of original frag skbsJiri Pirko2-61/+2
2013-10-22netfilter: nf_conntrack: fix rt6i_gateway checks for H.323 helperJulian Anastasov1-2/+2
2013-10-01Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nfDavid S. Miller9-145/+125
2013-09-30netfilter: synproxy: fix BUG_ON triggered by corrupt TCP packetsPatrick McHardy1-5/+7
2013-09-19ip: generate unique IP identificator if local fragmentation is allowedAnsis Atteka1-1/+1
2013-09-18ipvs: stats should not depend on CPU 0Julian Anastasov1-1/+3
2013-09-18ipvs: do not use dest after ip_vs_dest_put in LBLCRJulian Anastasov1-30/+20
2013-09-18ipvs: do not use dest after ip_vs_dest_put in LBLCJulian Anastasov1-37/+31
2013-09-18ipvs: make the service replacement more robustJulian Anastasov2-53/+45
2013-09-18ipvs: fix overflow on dest weight multiplySimon Kirby5-19/+19
2013-09-17netfilter: nfnetlink_queue: use network skb for sequence adjustmentGao feng1-1/+1
2013-09-16netfilter: ipset: Fix serious failure in CIDR trackingOliver Smith1-12/+16
2013-09-16netfilter: ipset: Validate the set family and not the set type family at swap...Jozsef Kadlecsik1-1/+1
2013-09-16netfilter: ipset: Consistent userspace testing with nomatch flagJozsef Kadlecsik5-10/+9
2013-09-16netfilter: ipset: Skip really non-first fragments for IPv6 when getting port/...Jozsef Kadlecsik1-2/+2
2013-09-05netfilter: Fix build errors with xt_socket.cDavid S. Miller1-0/+1
2013-09-04netfilter: xt_TCPMSS: correct return value in tcpmss_mangle_packetPhil Oester1-1/+1