summaryrefslogtreecommitdiff
path: root/net/ipv6/netfilter
AgeCommit message (Expand)Author
8 daysnetfilter: ip6t_hbh: reject oversized option listsZhengchuan Liang
8 daysnetfilter: ip6t_eui64: reject invalid MAC header for all packetsZhengchuan Liang
2026-04-18netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()Ren Wei
2025-08-28netfilter: nf_reject: don't leak dst refcount for loopback packetsFlorian Westphal
2025-08-28netfilter: nft_reject_inet: allow to use reject from inet ingressPablo Neira Ayuso
2025-06-27netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancyFlorian Westphal
2025-04-10netfilter: socket: Lookup orig tuple for IPv6 SNATMaxim Mikityanskiy
2024-10-17netfilter: ip6t_rpfilter: Fix regression with VRF interfacesPhil Sutter
2024-10-17netfilter: fib: check correct rtable in vrf setupsFlorian Westphal
2024-10-17netfilter: rpfilter/fib: Set ->flowic_uid correctly for user namespaces.Guillaume Nault
2024-10-17netfilter: rpfilter/fib: Populate flowic_l3mdev fieldPhil Sutter
2024-10-17netfilter: nf_tables: prevent nf_skb_duplicated corruptionEric Dumazet
2024-10-17netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()Eric Dumazet
2024-10-17inet: inet_defrag: prevent sk release while still in useFlorian Westphal
2024-05-02netfilter: complete validation of user inputEric Dumazet
2024-04-13netfilter: validate user input for expected lengthEric Dumazet
2023-10-10netfilter: nf_tables: add and use nft_sk helperFlorian Westphal
2023-10-10netfilter: use actual socket sk for REJECT actionJan Engelhardt
2023-03-17netfilter: tproxy: fix deadlock due to missing BH disableFlorian Westphal
2023-03-11netfilter: ebtables: fix table blob use-after-freeFlorian Westphal
2022-10-26netfilter: nft_fib: Fix for rpath check with VRF devicesPhil Sutter
2022-06-29netfilter: nftables: add nft_parse_register_load() and use itPablo Neira Ayuso
2022-06-09lsm,selinux: pass flowi_common instead of flowi to the LSM hooksPaul Moore
2021-10-27netfilter: ip6t_rt: fix rt0_hdr parsing in rt_mt6Xin Long
2021-10-17netfilter: ip6_tables: zero-initialize fragment offsetJeremy Sowden
2021-09-22netfilter: socket: icmp6: fix use-after-scopeBenjamin Hesmans
2021-06-23netfilter: nft_fib_ipv6: skip ipv6 packets from any to link-localFlorian Westphal
2021-04-16netfilter: x_tables: fix compat match/target pad out-of-bound writeFlorian Westphal
2021-03-30Revert "netfilter: x_tables: Update remaining dereference to RCU"Mark Tomlinson
2021-03-30Revert "netfilter: x_tables: Switch synchronization to RCU"Mark Tomlinson
2021-01-12netfilter: x_tables: Update remaining dereference to RCUSubash Abhinov Kasiviswanathan
2020-12-08netfilter: x_tables: Switch synchronization to RCUSubash Abhinov Kasiviswanathan
2020-11-19ipv6: Remove dependency of ipv6_frag_thdr_truncated on ipv6 moduleGeorg Kohmann
2020-11-16ipv6/netfilter: Discard first fragment not including all headersGeorg Kohmann
2020-10-30netfilter: use actual socket sk rather than skb sk when routing harderJason A. Donenfeld
2020-10-20netfilter: Drop fragmented ndisc packets assembled in netfilterGeorg Kohmann
2020-10-15Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
2020-10-14netfilter: nf_log: missing vlan offload tag and protoPablo Neira Ayuso
2020-08-28netfilter: ip6t_NPT: rewrite addresses in ICMPv6 original packetMichael Zhou
2020-08-05Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-nextLinus Torvalds
2020-08-03Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller
2020-07-29netfilter: ip6tables: Remove redundant null checksGaurav Singh
2020-07-28net: remove sockptr_advanceChristoph Hellwig
2020-07-24netfilter: switch nf_setsockopt to sockptr_tChristoph Hellwig
2020-07-24netfilter: switch xt_copy_counters to sockptr_tChristoph Hellwig
2020-07-19netfilter: remove the compat argument to xt_copy_counters_from_userChristoph Hellwig
2020-07-19netfilter/ip6_tables: clean up compat {get, set}sockopt handlingChristoph Hellwig
2020-07-16treewide: Remove uninitialized_var() usageKees Cook
2020-06-30netfilter: introduce support for reject at prerouting stageLaura Garcia Liebana
2020-06-25netfilter: ip6tables: Add a .pre_exit hook in all ip6table_foo.c.David Wilder