summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2026-03-04netfilter: nf_conntrack_h323: fix OOB read in decode_choice()Vahagn Vardanian1-1/+1
2026-03-04netfilter: xt_tcpmss: check remaining length before reading optlenFlorian Westphal1-1/+1
2026-03-04netfilter: nf_conntrack: Add allow_clash to generic protocol handlerYuto Hamaguchi1-0/+1
2026-03-04netfilter: nf_tables: fix use-after-free in nf_tables_addchain()Inseo An1-0/+1
2026-03-04ipvs: do not keep dest_dst if dev is going downJulian Anastasov1-10/+36
2026-03-04netfilter: nf_conntrack_h323: don't pass uninitialised l3num valueFlorian Westphal1-5/+5
2026-03-04netfilter: nft_set_rbtree: check for partial overlaps in anonymous setsPablo Neira Ayuso1-5/+25
2026-03-04netfilter: nft_set_rbtree: fix bogus EEXIST with NLM_F_CREATE with null intervalPablo Neira Ayuso2-0/+18
2026-03-04netfilter: nft_counter: fix reset of counters on 32bit archsAnders Grahn1-2/+2
2026-03-04netfilter: nft_set_hash: fix get operation on big endianFlorian Westphal1-2/+7
2026-03-04netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentationFlorian Westphal1-49/+74
2026-03-04netfilter: nfnetlink_queue: optimize verdict lookup with hash tableScott Mitchell1-30/+116
2026-03-04netfilter: nf_conncount: fix tracking of connections from localhostFernando Fernandez Mancera1-2/+13
2026-03-04netfilter: nft_compat: add more restrictions on netlink attributesFlorian Westphal1-3/+10
2026-03-04netfilter: nf_conncount: increase the connection clean up limit to 64Fernando Fernandez Mancera1-5/+10
2026-03-04netfilter: nf_conncount: make nf_conncount_gc_list() to disable BHFernando Fernandez Mancera2-13/+18
2026-03-04netfilter: nf_tables: reset table validation state on abortFlorian Westphal1-0/+7
2026-02-11netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()Andrew Fasano1-1/+1
2026-02-11netfilter: replace -EEXIST with -EBUSYDaniel Gomez2-3/+3
2026-01-17netfilter: nf_tables: avoid chain re-validation if possibleFlorian Westphal1-4/+65
2026-01-17netfilter: nf_conncount: update last_gc only when GC has been performedFernando Fernandez Mancera1-1/+1
2026-01-17netfilter: nf_tables: fix memory leak in nf_tables_newrule()Zilin Guan1-1/+2
2026-01-17netfilter: nft_synproxy: avoid possible data-race on update operationFernando Fernandez Mancera1-3/+3
2026-01-17netfilter: nft_set_pipapo: fix range overlap detectionFlorian Westphal1-2/+2
2026-01-08netfilter: nft_ct: add seqadj extension for natted connectionsAndrii Melnychenko1-0/+5
2026-01-08netfilter: nf_tables: remove redundant chain validation on register storePablo Neira Ayuso1-11/+0
2026-01-08netfilter: nf_nat: remove bogus direction checkFlorian Westphal1-13/+1
2026-01-08ipvs: fix ipv4 null-ptr-deref in route error pathSlavin Liu1-0/+3
2026-01-08netfilter: nf_conncount: fix leaked ct in error pathsFernando Fernandez Mancera1-11/+14
2025-12-18netfilter: nft_connlimit: update the count if add was skippedFernando Fernandez Mancera2-6/+19
2025-12-18netfilter: nf_conncount: rework API to use sk_buff directlyFernando Fernandez Mancera3-86/+126
2025-12-18netfilter: flowtable: check for maximum number of encapsulations in bridge vlanPablo Neira Ayuso1-1/+8
2025-11-24netfilter: nf_tables: reject duplicate device on updatesPablo Neira Ayuso1-0/+30
2025-11-24Revert "netfilter: nf_tables: Reintroduce shortened deletion notifications"Pablo Neira Ayuso1-34/+2
2025-10-19netfilter: nft_objref: validate objref and objrefmap expressionsFernando Fernandez Mancera1-0/+39
2025-10-15netfilter: nfnetlink: reset nlh pointer during batch replayFernando Fernandez Mancera1-0/+2
2025-10-15ipvs: Defer ip_vs_ftp unregister during netns cleanupSlavin Liu1-1/+3
2025-10-15ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enableZhang Tengfei4-20/+17
2025-10-15netfilter: ipset: Remove unused htable_bits in macro ahash_regionZhen Ni1-4/+4
2025-09-19netfilter: nft_set_pipapo: fix null deref for empty setFlorian Westphal1-3/+2
2025-09-19netfilter: nf_tables: restart set lookup on base_seq changeFlorian Westphal2-2/+32
2025-09-19netfilter: nf_tables: make nft_set_do_lookup available unconditionallyFlorian Westphal1-5/+12
2025-09-19netfilter: nf_tables: place base_seq in struct netFlorian Westphal1-32/+33
2025-09-19netfilter: nf_tables: Reintroduce shortened deletion notificationsPhil Sutter1-17/+50
2025-09-19netfilter: nft_set_rbtree: continue traversal if element is inactiveFlorian Westphal1-3/+3
2025-09-19netfilter: nft_set_pipapo: don't check genbit from packetpath lookupsFlorian Westphal2-5/+19
2025-09-19netfilter: nft_set_pipapo: don't return bogus extension pointerFlorian Westphal1-6/+6
2025-09-19netfilter: nft_set_pipapo: merge pipapo_get/lookupFlorian Westphal1-130/+58
2025-09-19netfilter: nft_set: remove one argument from lookup and update functionsFlorian Westphal8-91/+95
2025-09-19netfilter: nft_set_pipapo: remove unused argumentsFlorian Westphal1-9/+5