summaryrefslogtreecommitdiffstats
path: root/net/netfilter
AgeCommit message (Expand)AuthorLines
2026-05-08netfilter: nft_ct: fix missing expect put in obj evalLi Xiasong-0/+2
2026-05-08netfilter: nf_conntrack_sip: get helper before allocating expectationLi Xiasong-4/+4
2026-05-08netfilter: ctnetlink: check tuple and mask in expectations created via nfqueuePablo Neira Ayuso-0/+3
2026-05-08netfilter: nf_conntrack_expect: restore helper propagation via expectationPablo Neira Ayuso-11/+35
2026-05-08netfilter: x_tables: add and use xtables_unregister_table_exitFlorian Westphal-19/+62
2026-05-08netfilter: x_tables: add and use xt_unregister_table_pre_exitFlorian Westphal-0/+29
2026-05-08netfilter: x_tables: allocate hook ops while under mutexFlorian Westphal-8/+42
2026-05-08netfilter: x_tables: allow initial table replace without emitting audit log m...Florian Westphal-9/+20
2026-05-05ipvs: Guard access of HK_TYPE_KTHREAD cpumask with RCUWaiman Long-5/+8
2026-05-05ipvs: fix shift-out-of-bounds in ip_vs_rht_desired_sizeJulian Anastasov-1/+1
2026-05-05ipvs: fix races around est_mutex and est_cpulistJulian Anastasov-44/+90
2026-05-05ipvs: do not leak dest after get from dest trashJulian Anastasov-13/+24
2026-05-05ipvs: fix the spin_lock usage for RT buildJulian Anastasov-33/+41
2026-05-05ipvs: fix races around the conn_lfactor and svc_lfactor sysctl varsJulian Anastasov-4/+10
2026-05-05ipvs: fixes for the new ip_vs_status infoJulian Anastasov-15/+36
2026-05-01netfilter: flowtable: use skb_pull_rcsum() to pop vlan/pppoe headerPablo Neira Ayuso-2/+2
2026-05-01netfilter: flowtable: fix inline pppoe encapsulation in xmit pathPablo Neira Ayuso-4/+46
2026-05-01netfilter: flowtable: fix inline vlan encapsulation in xmit pathPablo Neira Ayuso-37/+73
2026-04-30netfilter: flowtable: ensure sufficient headroom in xmit pathPablo Neira Ayuso-2/+11
2026-04-30netfilter: xtables: fix L4 header parsing for non-first fragmentsFernando Fernandez Mancera-3/+23
2026-04-30netfilter: nf_tables: skip L4 header parsing for non-first fragmentsFernando Fernandez Mancera-7/+7
2026-04-30netfilter: nf_tables: fix netdev hook allocation memleak with dormant tablesFlorian Westphal-14/+20
2026-04-30netfilter: xt_CT: fix usersize for v1 and v2 revisionFlorian Westphal-4/+4
2026-04-30netfilter: nft_compat: run xt_check_hooks_{match,target}() from .validatePablo Neira Ayuso-10/+36
2026-04-30netfilter: x_tables: add .check_hooks to matches and targetsPablo Neira Ayuso-59/+179
2026-04-30netfilter: nft_fwd_netdev: use recursion counter in neigh egress pathWeiming Shi-16/+8
2026-04-30netfilter: nft_fwd_netdev: add device and headroom validate with neigh forwar...Pablo Neira Ayuso-2/+14
2026-04-30netfilter: replace skb_try_make_writable() by skb_ensure_writable()Pablo Neira Ayuso-4/+5
2026-04-28netfilter: skip recording stale or retransmitted INITXin Long-3/+7
2026-04-24netfilter: nf_conntrack_sip: don't use simple_strtoulFlorian Westphal-34/+119
2026-04-24netfilter: reject zero shift in nft_bitwiseKai Ma-1/+2
2026-04-24netfilter: xt_policy: fix strict mode inbound policy matchingJiexun Wang-1/+1
2026-04-21netfilter: nf_tables: add hook transactions for device deletionsPablo Neira Ayuso-60/+204
2026-04-21netfilter: nf_tables: join hook list via splice_list_rcu() in commit phasePablo Neira Ayuso-4/+4
2026-04-21netfilter: nf_tables: use list_del_rcu for netlink hooksFlorian Westphal-26/+18
2026-04-20netfilter: nfnetlink_osf: fix potential NULL dereference in ttl checkFernando Fernandez Mancera-15/+7
2026-04-20netfilter: nfnetlink_osf: fix out-of-bounds read on option matchingFernando Fernandez Mancera-11/+8
2026-04-20ipvs: fix MTU check for GSO packets in tunnel modeYingnan Zhang-4/+15
2026-04-20netfilter: nat: use kfree_rcu to release opsPablo Neira Ayuso-4/+6
2026-04-20netfilter: xtables: restrict several matches to inet familyPablo Neira Ayuso-34/+68
2026-04-20netfilter: conntrack: remove sprintf usageFlorian Westphal-16/+19
2026-04-20netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULOXiang Mei-0/+4
2026-04-20netfilter: nft_osf: restrict it to ipv4Pablo Neira Ayuso-1/+5
2026-04-10netfilter: require Ethernet MAC header before using eth_hdr()Zhengchuan Liang-12/+19
2026-04-10netfilter: nft_fwd_netdev: check ttl/hl before forwardingFlorian Westphal-0/+10
2026-04-10netfilter: x_tables: Avoid a couple -Wflex-array-member-not-at-end warningsGustavo A. R. Silva-4/+8
2026-04-10netfilter: conntrack: remove UDP-Lite conntrack supportFernando Fernandez Mancera-160/+0
2026-04-10netfilter: xt_socket: enable defrag after all other checksFlorian Westphal-17/+6
2026-04-10netfilter: xt_HL: add pr_fmt and checkentry validationMarino Dzalto-0/+27
2026-04-10netfilter: nfnetlink: prefer skb_mac_header helpersFlorian Westphal-22/+22