summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2019-05-16netfilter: nf_tables: add missing ->release_ops() in error path of newrule()Taehee Yoo1-1/+4
2019-05-16netfilter: nf_tables: use-after-free in dynamic operationsPablo Neira Ayuso1-1/+3
2019-05-16netfilter: fix nf_l4proto_log_invalid to log invalid packetsAndrei Vagin1-1/+1
2019-05-16netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()Dan Carpenter1-1/+1
2019-05-16netfilter: ctnetlink: don't use conntrack/expect object addresses as idFlorian Westphal2-5/+64
2019-05-16ipvs: do not schedule icmp errors from tunnelsJulian Anastasov1-1/+1
2019-05-04netfilter: fix NETFILTER_XT_TARGET_TEE dependenciesArnd Bergmann1-0/+1
2019-05-04netfilter: nft_set_rbtree: check for inactive element after flag mismatchPablo Neira Ayuso1-4/+3
2019-05-02ipvs: fix warning on unused variableAndrea Claudi1-1/+2
2019-05-02netfilter: nf_tables: bogus EBUSY in helper removal from transactionPablo Neira Ayuso1-3/+16
2019-05-02netfilter: nf_tables: bogus EBUSY when deleting set after flushPablo Neira Ayuso4-13/+54
2019-05-02netfilter: nf_tables: fix set double-free in abort pathPablo Neira Ayuso1-6/+11
2019-05-02netfilter: nft_compat: use .release_ops and remove list of extensionPablo Neira Ayuso2-227/+61
2019-05-02netfilter: nft_compat: don't use refcount_inc on newly allocated entryFlorian Westphal1-39/+23
2019-05-02netfilter: nf_tables: unbind set in rule from commit pathPablo Neira Ayuso6-79/+72
2019-05-02netfilter: nf_tables: warn when expr implements only one of activate/deactivateFlorian Westphal1-0/+19
2019-05-02netfilter: nft_compat: destroy function must not have side effectsFlorian Westphal1-1/+47
2019-05-02netfilter: nf_tables: split set destruction in deactivate and destroy phaseFlorian Westphal4-14/+83
2019-05-02netfilter: nft_compat: make lists per netnsFlorian Westphal1-40/+89
2019-05-02netfilter: nft_compat: use refcnt_t type for nft_xt reference countFlorian Westphal1-8/+8
2019-04-20netfilter: nf_flow_table: remove flowtable hook flush routine in netns exit r...Taehee Yoo1-3/+0
2019-04-20netfilter: xt_cgroup: shrink size of v2 pathPablo Neira Ayuso1-0/+72
2019-04-17netfilter: nfnetlink_cttimeout: fetch timeouts for udplite and gre, tooFlorian Westphal2-14/+15
2019-04-17netfilter: nfnetlink_cttimeout: pass default timeout policy to obj_to_nlattrPablo Neira Ayuso1-6/+40
2019-04-05netfilter: physdev: relax br_netfilter dependencyFlorian Westphal1-2/+7
2019-04-05netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrac...Chieh-Min Wang1-3/+11
2019-04-05netfilter: conntrack: tcp: only close if RST matches exact sequenceFlorian Westphal1-10/+40
2019-04-05netfilter: nf_tables: check the result of dereferencing base_chain->statsLi RongQing1-6/+8
2019-03-23ipvs: fix dependency on nf_defrag_ipv6Andrea Claudi3-6/+15
2019-03-23netfilter: compat: initialize all fields in xt_initFrancesco Ruggeri1-1/+1
2019-03-14netfilter: xt_TEE: add missing code to get interface index in checkentry.Taehee Yoo1-0/+7
2019-03-14netfilter: xt_TEE: fix wrong interface selectionTaehee Yoo1-17/+52
2019-03-14netfilter: nf_nat: skip nat clash resolution for same-origin entriesMartynas Pumputis1-0/+16
2019-03-14ipvs: Fix signed integer overflow when setsockopt timeoutZhangXiaoxu1-0/+12
2019-02-27netfilter: nfnetlink_osf: add missing fmatch checkFernando Fernandez Mancera1-0/+4
2019-02-27netfilter: nft_compat: use-after-free when deleting targetsPablo Neira Ayuso1-1/+2
2019-02-27netfilter: nf_tables: fix flush after rule deletion in the same batchPablo Neira Ayuso1-0/+3
2019-02-27netfilter: nft_flow_offload: fix checking method of conntrack helperHenry Yen1-1/+4
2019-02-27netfilter: nft_flow_offload: fix interaction with vrf slave devicewenxu2-4/+5
2019-02-27netfilter: nft_flow_offload: Fix reverse route lookupwenxu1-2/+2
2019-02-27netfilter: nf_tables: fix leaking object reference countTaehee Yoo1-0/+2
2019-01-26netfilter: ipset: Allow matching on destination MAC address for mac and ipmac...Stefano Brivio3-16/+20
2019-01-22netfilter: nf_conncount: fix argument order to find_next_bitFlorian Westphal1-1/+1
2019-01-22netfilter: nf_conncount: speculative garbage collection on empty listsPablo Neira Ayuso1-32/+15
2019-01-22netfilter: nf_conncount: move all list iterations under spinlockPablo Neira Ayuso1-26/+20
2019-01-22netfilter: nf_conncount: merge lookup and add functionsFlorian Westphal2-91/+69
2019-01-22netfilter: nf_conncount: restart search when nodes have been erasedFlorian Westphal1-11/+7
2019-01-22netfilter: nf_conncount: split gc in two phasesFlorian Westphal1-3/+19
2019-01-22netfilter: nf_conncount: don't skip eviction when age is negativeFlorian Westphal1-1/+1
2019-01-22netfilter: nf_conncount: replace CONNCOUNT_LOCK_SLOTS with CONNCOUNT_SLOTSShawn Bohrer1-14/+5