summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)AuthorFilesLines
2020-01-27keys: Timestamp new keysDavid Howells1-0/+1
2020-01-27apparmor: don't try to replace stale label in ptrace access checkJann Horn2-2/+4
2020-01-27apparmor: Fix network performance issue in aa_label_sk_permTony Jones1-6/+9
2020-01-23LSM: generalize flag passing to security_capableMicah Morton9-39/+37
2020-01-09apparmor: fix aa_xattrs_match() may sleep while holding a RCU lockJohn Johansen3-42/+46
2020-01-04apparmor: fix unsigned len comparison with less than zeroColin Ian King1-5/+7
2019-12-05apparmor: delete the dentry in aafs_remove() to avoid a leakChris Coulson1-0/+1
2019-10-11ima: fix freeing ongoing ahash_requestSascha Hauer1-0/+5
2019-10-11ima: always return negative code for errorSascha Hauer1-1/+4
2019-10-07smack: use GFP_NOFS while holding inode_smack::smk_lockEric Biggers2-4/+4
2019-10-07Smack: Don't ignore other bprm->unsafe flags if LSM_UNSAFE_PTRACE is setJann Horn1-1/+2
2019-10-07security: smack: Fix possible null-pointer dereferences in smack_socket_sock_...Jia-Ju Bai1-0/+2
2019-09-21keys: Fix missing null pointer check in request_key_auth_describe()Hillf Danton1-0/+6
2019-09-16apparmor: reset pos on failure to unpack for various functionsMike Salvatore1-7/+33
2019-08-06selinux: fix memory leak in policydb_init()Ondrej Mosnacek1-1/+5
2019-07-26selinux: fix empty write to keycreate fileOndrej Mosnacek1-5/+6
2019-06-25apparmor: enforce nullbyte at end of tag stringJann Horn1-1/+1
2019-06-25apparmor: fix PROFILE_MEDIATES for untrusted inputJohn Johansen1-1/+10
2019-06-09evm: check hash algorithm passed to init_desc()Roberto Sassu1-0/+3
2019-06-09ima: show rules with IMA_INMASK correctlyRoberto Sassu1-9/+12
2019-05-31selinux: avoid uninitialized variable warningArnd Bergmann1-9/+5
2019-05-25apparmorfs: fix use-after-free on symlink traversalAl Viro1-4/+9
2019-05-25securityfs: fix use-after-free on symlink traversalAl Viro1-4/+9
2019-05-16selinux: do not report error on connect(AF_UNSPEC)Paolo Abeni1-4/+4
2019-05-08selinux: never allow relabeling on context mountsOndrej Mosnacek1-9/+31
2019-05-08selinux: avoid silent denials in permissive mode under RCU walkStephen Smalley3-3/+25
2019-05-04selinux: use kernel linux/socket.h for genheaders and mdpPaulo Alcantara1-0/+1
2019-04-27device_cgroup: fix RCU imbalance in error caseJann Horn1-1/+1
2019-04-05selinux: do not override context on context mountsOndrej Mosnacek1-1/+8
2019-03-23security/selinux: fix SECURITY_LSM_NATIVE_LABELS on reused superblockJ. Bruce Fields1-1/+4
2019-03-23selinux: add the missing walk_size + len check in selinux_sctp_bind_connectXin Long1-0/+3
2019-03-23keys: Fix dependency loop between construction record and auth keyDavid Howells5-62/+41
2019-03-19missing barriers in some of unix_sock ->addr and ->path accessesAl Viro1-4/+6
2019-03-14apparmor: Fix aa_label_build() error handling for failed mergesJohn Johansen1-1/+4
2019-02-27KEYS: always initialize keyring_index_key::desc_lenEric Biggers4-6/+4
2019-02-27KEYS: allow reaching the keys quotas exactlyEric Biggers1-2/+2
2019-02-12smack: fix access permissions for keyringZoran Markovic1-3/+9
2019-01-26selinux: always allow mounting submountsOndrej Mosnacek1-1/+1
2019-01-22selinux: fix GPF on invalid policyStephen Smalley1-1/+2
2019-01-22LSM: Check for NULL cred-security on freeJames Morris1-0/+7
2019-01-22Yama: Check for pid death before checking ancestryKees Cook1-1/+3
2019-01-13selinux: policydb - fix byte order and alignment issuesOndrej Mosnacek1-15/+36
2018-12-08selinux: add support for RTM_NEWCHAIN, RTM_DELCHAIN, and RTM_GETCHAINPaul Moore1-1/+12
2018-12-01selinux: Add __GFP_NOWARN to allocation at str_read()Tetsuo Handa1-1/+1
2018-11-27apparmor: Fix uninitialized value in aa_split_fqnameZubin Mithra1-2/+4
2018-11-21selinux: check length properly in SCTP bind hookOndrej Mosnacek1-0/+3
2018-11-13ima: open a new file instance if no read permissionsGoldwyn Rodrigues1-20/+34
2018-11-13ima: fix showing large 'violations' or 'runtime_measurements_count'Eric Biggers1-3/+3
2018-11-13selinux: fix mounting of cgroup2 under older policiesStephen Smalley1-0/+5
2018-11-13Smack: ptrace capability use fixesCasey Schaufler1-3/+10