summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)AuthorFilesLines
2026-03-04apparmor: fix aa_label to return state from compount and component matchJohn Johansen1-6/+6
2026-03-04apparmor: fix invalid deref of rawdata when export_binary is unsetGeorgia Garcia1-0/+9
2026-03-04apparmor: avoid per-cpu hold underflow in aa_get_bufferZhengmian Hu1-1/+2
2026-03-04apparmor: make label_match return a consistent valueJohn Johansen1-11/+9
2026-03-04apparmor: remove apply_modes_to_perms from label_matchJohn Johansen1-3/+0
2026-03-04apparmor: fix rlimit for posix cpu timersJohn Johansen1-0/+5
2026-03-04apparmor: return -ENOMEM in unpack_perms_table upon alloc failureRyan Lee1-2/+4
2026-03-04apparmor: Fix & Optimize table creation from possibly unaligned memoryHelge Deller2-9/+10
2026-03-04AppArmor: Allow apparmor to handle unaligned dfa tablesHelge Deller1-7/+8
2026-03-04apparmor: fix NULL sock in aa_sock_file_permJohn Johansen1-2/+4
2026-03-04evm: Use ordered xattrs list to calculate HMAC in evm_init_hmac()Roberto Sassu1-4/+10
2026-03-04smack: /smack/doi: accept previously used valuesKonstantin Andreev1-26/+45
2026-03-04smack: /smack/doi must be > 0Konstantin Andreev1-5/+7
2026-01-30keys/trusted_keys: fix handle passed to tpm_buf_append_name during unsealSrish Srinivasan1-2/+2
2026-01-17tpm2-sessions: Fix out of range indexing in name_sizeJarkko Sakkinen1-6/+23
2026-01-08KEYS: trusted: Fix a memory leak in tpm2_load_cmdJarkko Sakkinen1-2/+4
2025-12-18ima: Handle error code returned by ima_filter_rule_match()Zhao Yipeng1-1/+1
2025-12-18smack: fix bug: setting task label silently ignores input garbageKonstantin Andreev3-63/+148
2025-12-18smack: fix bug: unprivileged task can create labelsKonstantin Andreev1-14/+27
2025-12-18smack: fix bug: invalid label of unix socket fileKonstantin Andreev1-14/+44
2025-12-18smack: always "instantiate" inode in smack_inode_init_security()Konstantin Andreev1-3/+7
2025-12-18smack: deduplicate xattr setting in smack_inode_init_security()Konstantin Andreev1-27/+29
2025-12-18smack: fix bug: SMACK64TRANSMUTE set on non-directoryKonstantin Andreev1-12/+14
2025-12-18smack: deduplicate "does access rule request transmutation"Konstantin Andreev1-25/+32
2025-11-13ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattrCoiby Xu1-5/+18
2025-10-19KEYS: trusted_tpm1: Compare HMAC values in constant timeEric Biggers1-3/+4
2025-10-15lsm: CONFIG_LSM can depend on CONFIG_SECURITYRandy Dunlap1-0/+1
2025-08-28apparmor: Fix 8-byte alignment for initial dfa blob streamsHelge Deller1-2/+2
2025-08-20apparmor: fix x_table_lookup when stacking is not the first entryJohn Johansen1-23/+29
2025-08-20apparmor: use the condition in AA_BUG_FMT even with debug disabledMateusz Guzik1-1/+5
2025-08-20apparmor: shift ouid when mediating hard links in usernsGabriel Totev1-2/+4
2025-08-20securityfs: don't pin dentries twice, once is enough...Al Viro1-2/+0
2025-08-15apparmor: Fix unaligned memory accesses in KUnit testHelge Deller1-2/+4
2025-08-15apparmor: fix loop detection used in conflicting attachment resolutionRyan Lee2-15/+12
2025-08-15apparmor: ensure WB_HISTORY_SIZE value is a power of 2Ryan Lee2-1/+3
2025-07-10selinux: change security_compute_sid to return the ssid or tsid on matchStephen Smalley1-5/+11
2025-06-27selinux: fix selinux_xfrm_alloc_user() to set correct ctx_lenStephen Smalley1-1/+1
2025-05-29smack: Revert "smackfs: Added check catlen"Konstantin Andreev1-14/+3
2025-05-29smack: recognize ipv4 CIPSO w/o categoriesKonstantin Andreev1-0/+4
2025-05-29ima: process_measurement() needlessly takes inode_lock() on MAY_READFrederick Lawler1-1/+3
2025-04-20landlock: Prepare to add second errataMickaël Salaün1-0/+12
2025-04-20landlock: Always allow signals between threads of the same processMickaël Salaün3-6/+64
2025-04-20landlock: Add erratum for TCP fixMickaël Salaün1-0/+15
2025-04-20landlock: Add the errata interfaceMickaël Salaün4-4/+138
2025-04-20landlock: Move code to ease future backportsMickaël Salaün1-5/+5
2025-04-20ima: limit the number of ToMToU integrity violationsMimi Zohar2-4/+5
2025-04-20ima: limit the number of open-writers integrity violationsMimi Zohar2-2/+10
2025-04-10smack: ipv4/ipv6: tcp/dccp/sctp: fix incorrect child socket labelKonstantin Andreev1-24/+0
2025-04-10smack: dont compile ipv6 code unless ipv6 is configuredKonstantin Andreev2-1/+15
2025-03-29keys: Fix UAF in key_put()David Howells2-1/+5