summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)AuthorFilesLines
2024-02-23lsm: new security_file_ioctl_compat() hookAlfred Piccioni4-0/+47
2024-01-26apparmor: avoid crash when parsed profile name is emptyFedor Pchelkin1-0/+4
2024-01-26selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socketMickaël Salaün1-0/+7
2023-12-08ima: detect changes to the backing overlay fileMimi Zohar3-1/+22
2023-12-08ima: annotate iint mutex to avoid lockdep false positive warningsAmir Goldstein1-11/+37
2023-10-10smack: Record transmuting in smk_transmutedRoberto Sassu2-12/+30
2023-10-10smack: Retrieve transmuting information in smack_inode_getsecurity()Roberto Sassu1-4/+18
2023-10-10Smack:- Use overlay inode label in smack_inode_copy_up()Vishal Goel1-1/+1
2023-09-23smackfs: Prevent underflow in smk_set_cipso()Dan Carpenter1-1/+1
2023-09-23security: keys: perform capable check only on privileged operationsChristian Göttsche1-3/+8
2023-08-30IMA: allow/fix UML buildsRandy Dunlap1-1/+1
2023-08-11integrity: Fix possible multiple allocation in integrity_inode_get()Tianjia Zhang1-6/+9
2023-08-11evm: Complete description of evm_inode_setattr()Roberto Sassu1-0/+2
2023-06-09selinux: don't use make's grouped targets feature yetPaul Moore1-1/+5
2023-05-17selinux: ensure av_permissions.h is built when neededPaul Moore1-1/+1
2023-05-17selinux: fix Makefile dependencies of flask.hOndrej Mosnacek1-2/+2
2023-03-11ima: Align ima_file_mmap() parameters with mmap_file LSM hookRoberto Sassu2-5/+9
2023-02-06tomoyo: fix broken dependency on *.conf.defaultMasahiro Yamada1-1/+1
2023-01-18device_cgroup: Roll back to original exceptions after copy failureWang Weiyang1-4/+29
2023-01-18ima: Fix a potential NULL pointer access in ima_restore_measurement_listHuaxin Lu1-1/+4
2023-01-18apparmor: Fix abi check to include v8 abiJohn Johansen1-1/+1
2023-01-18apparmor: fix lockdep warning when removing a namespaceJohn Johansen1-1/+1
2023-01-18apparmor: fix a memleak in multi_transaction_new()Gaosheng Cui1-1/+3
2023-01-18ima: Fix misuse of dereference of pointer in template_desc_init_fields()Xiu Jianfeng1-2/+2
2022-11-10capabilities: fix potential memleak on error path from vfs_getxattr_alloc()Gaosheng Cui1-2/+4
2022-10-05ima: Free the entire rule if it fails to parseTyler Hicks1-1/+2
2022-10-05ima: Free the entire rule when deleting a list of rulesTyler Hicks1-7/+16
2022-10-05ima: Have the LSM free its audit ruleTyler Hicks2-1/+8
2022-08-25apparmor: Fix memleak in aa_simple_write_to_buffer()Xiu Jianfeng1-1/+1
2022-08-25apparmor: fix reference count leak in aa_pivotroot()Xin Xiong1-0/+1
2022-08-25apparmor: fix overlapping attachment computationJohn Johansen2-2/+2
2022-08-25apparmor: fix aa_label_asxprint return checkTom Rix1-3/+3
2022-08-25apparmor: Fix failed mount permission check error messageJohn Johansen1-3/+4
2022-08-25apparmor: fix absroot causing audited secids to begin with =John Johansen2-3/+9
2022-08-25apparmor: fix quiet_denied for file rulesJohn Johansen1-1/+1
2022-08-25selinux: Add boundary check in put_entry()Xiu Jianfeng1-0/+2
2022-07-29ima: remove the IMA_TEMPLATE Kconfig optionGUO Zihua1-7/+5
2022-04-15Fix incorrect type in assignment of ipv6 port for auditCasey Schaufler1-1/+1
2022-04-15selinux: use correct type for context lengthChristian Göttsche1-1/+1
2022-04-15TOMOYO: fix __setup handlers return valuesRandy Dunlap1-2/+2
2022-02-16ima: Allow template selection with ima_template[_fmt]= after ima_hash=Roberto Sassu1-3/+7
2022-02-16ima: Remove ima_policy file before directoryStefan Berger1-1/+1
2022-02-16integrity: check the return value of audit_log_start()Xiaoke Wang1-0/+2
2022-01-05selinux: initialize proto variable in selinux_ip_postroute_compat()Tom Rix1-1/+1
2021-11-26fortify: Explicitly disable Clang supportKees Cook1-0/+3
2021-11-26apparmor: fix error checkTom Rix1-2/+2
2021-11-26smackfs: use netlbl_cfg_cipsov4_del() for deleting cipso_v4_doiTetsuo Handa1-1/+1
2021-11-26smackfs: use __GFP_NOFAIL for smk_cipso_doi()Tetsuo Handa1-3/+1
2021-11-26smackfs: Fix use-after-free in netlbl_catmap_walk()Pawan Gupta1-1/+4
2021-11-26evm: mark evm_fixmode as __ro_after_initAustin Kim1-1/+1