summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2016-06-24netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal1-0/+74
2016-06-24netfilter: x_tables: do compat validation via translate_tableFlorian Westphal1-0/+8
2016-06-24netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal1-3/+2
2016-06-24netfilter: x_tables: don't reject valid target size on some architecturesFlorian Westphal1-2/+2
2016-06-24netfilter: x_tables: validate all offsets and sizes in a ruleFlorian Westphal1-5/+76
2016-06-24netfilter: x_tables: check for bogus target offsetFlorian Westphal1-2/+15
2016-06-24netfilter: x_tables: check standard target size tooFlorian Westphal1-0/+15
2016-06-24netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal1-0/+22
2016-06-24netfilter: x_tables: assert minimum target sizeFlorian Westphal1-0/+3
2016-06-24netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal1-0/+34
2016-05-11ipvs: correct initial offset of Call-ID header search in SIP persistence engineMarco Angaroni1-1/+1
2016-03-04netfilter: nf_tables: fix bogus warning in nft_data_uninit()Mirek Kratochvil1-2/+2
2015-10-23ipvs: fix crash with sync protocol v0 and FTPJulian Anastasov1-1/+1
2015-10-23ipvs: do not use random local source address for tunnelsJulian Anastasov1-1/+0
2015-10-23netfilter: nft_compat: skip family comparison in case of NFPROTO_UNSPECPablo Neira Ayuso1-6/+18
2015-10-23netfilter: ctnetlink: put back references to master ct and expect objectsPablo Neira Ayuso1-5/+0
2015-10-23netfilter: nf_conntrack: Support expectations in different zonesJoe Stringer1-1/+2
2015-07-04netfilter: nf_tables: allow to change chain policy without hook if it existsPablo Neira Ayuso1-1/+4
2015-07-04netfilter: nft_compat: set IP6T_F_PROTO flag if protocol is setPablo Neira Ayuso1-0/+6
2015-07-04netfilter: Zero the tuple in nfnl_cthelper_parse_tuple()Ian Wilson1-0/+3
2015-07-04netfilter: nfnetlink_cthelper: Remove 'const' and '&' to avoid warningsChen Gang1-2/+2
2015-04-29netfilter: conntrack: disable generic tracking for known protocolsFlorian Westphal1-1/+25
2015-03-26netfilter: xt_socket: fix a stack corruption bugEric Dumazet1-9/+12
2015-03-26netfilter: nft_compat: fix module refcount underflowPablo Neira Ayuso1-2/+10
2015-03-26ipvs: rerouting to local clients is not needed anymoreJulian Anastasov1-11/+22
2015-03-26ipvs: add missing ip_vs_pe_put in sync codeJulian Anastasov1-0/+3
2015-01-30ipvs: uninitialized data with IP_VS_IPV6Dan Carpenter1-5/+5
2015-01-30netfilter: nfnetlink: validate nfnetlink header from batchPablo Neira Ayuso1-1/+2
2015-01-27netfilter: ipset: small potential read beyond the end of bufferDan Carpenter1-0/+6
2014-11-21netfilter: nft_compat: fix wrong target lookup in nft_target_select_ops()Arturo Borrero1-1/+1
2014-11-21netfilter: nf_log: release skbuff on nlmsg put failureHoucheng Lin1-9/+8
2014-11-21netfilter: nfnetlink_log: fix maximum packet length logged to userspaceFlorian Westphal1-3/+5
2014-11-21netfilter: nf_log: account for size of NLMSG_DONE attributeFlorian Westphal1-3/+3
2014-11-21netfilter: ipset: off by one in ip_set_nfnl_get_byindex()Dan Carpenter1-1/+1
2014-10-06ipvs: fix ipv6 hook registration for local repliesJulian Anastasov1-1/+1
2014-10-06netfilter: x_tables: allow to use default cgroup matchDaniel Borkmann1-1/+1
2014-10-06ipvs: Maintain all DSCP and ECN bits for ipv6 tun forwardingAlex Gartrell1-1/+1
2014-10-06netfilter: xt_hashlimit: perform garbage collection from process contextEric Dumazet1-15/+16
2014-10-06ipvs: avoid netns exit crash on ip_vs_conn_drop_conntrackJulian Anastasov1-1/+0
2014-08-14inetpeer: get rid of ip_id_countEric Dumazet1-1/+1
2014-07-09netfilter: nf_nat: fix oops on netns removalFlorian Westphal1-1/+34
2014-07-07ipvs: Fix panic due to non-linear skbPeter Christensen1-5/+10
2014-06-26net: Use netlink_ns_capable to verify the permisions of netlink messagesEric W. Biederman1-1/+1
2014-06-11netfilter: nfnetlink: Fix use after free when it fails to process batchDenys Fedoryshchenko1-4/+4
2014-06-01netfilter: nf_tables: set names cannot be larger than 15 bytesPablo Neira Ayuso1-1/+2
2014-06-01netfilter: nf_tables: fix nft_cmp_fast failure on big endian for size < 4Patrick McHardy2-3/+2
2014-03-27core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errorsZoltan Kiss1-2/+7
2014-02-18netfilter: ctnetlink: force null nat binding on insertPablo Neira Ayuso2-42/+49
2014-02-17netfilter: nf_tables: check if payload length is a power of 2Nikolay Aleksandrov1-1/+2
2014-02-14netfilter: nft_meta: fix typo "CONFIG_NET_CLS_ROUTE"Paul Bolle1-2/+2