summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)Author
2 daysnetfilter: ipset: stop hash:* range iteration at endNan Li
2 daysnetfilter: nft_ct: fix missing expect put in obj evalLi Xiasong
2 daysnetfilter: skip recording stale or retransmitted INITXin Long
2 daysnetfilter: nf_conntrack_sip: don't use simple_strtoulFlorian Westphal
2 daysnetfilter: xt_policy: fix strict mode inbound policy matchingJiexun Wang
2 daysnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl checkFernando Fernandez Mancera
2 daysnetfilter: nfnetlink_osf: fix out-of-bounds read on option matchingFernando Fernandez Mancera
2 daysipvs: fix MTU check for GSO packets in tunnel modeYingnan Zhang
2 daysnetfilter: xtables: restrict several matches to inet familyPablo Neira Ayuso
2 daysnetfilter: conntrack: remove sprintf usageFlorian Westphal
2 daysnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULOXiang Mei
2 daysnetfilter: nft_osf: restrict it to ipv4Pablo Neira Ayuso
2 daysnetfilter: nft_fwd_netdev: check ttl/hl before forwardingFlorian Westphal
2 daysnetfilter: reject zero shift in nft_bitwiseKai Ma
2 daysnetfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTRFlorian Westphal
2 daysnetfilter: conntrack: add missing netlink policy validationsFlorian Westphal
2 daysnetfilter: xt_multiport: validate range encoding in checkentryRen Wei
2 daysnetfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminatorXiang Mei
2 daysnetfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiryFlorian Westphal
2026-04-18netfilter: nft_ct: fix use-after-free in timeout object destroyTuan Do
2026-04-18netfilter: ipset: drop logically empty buckets in mtype_delYifan Wu
2026-04-18netfilter: nf_tables: reject immediate NF_QUEUE verdictPablo Neira Ayuso
2026-04-18netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for N...Pablo Neira Ayuso
2026-04-18netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absentQi Tang
2026-04-18netfilter: nf_conntrack_helper: pass helper to expect cleanupQi Tang
2026-04-18netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attrFlorian Westphal
2026-04-18netfilter: x_tables: ensure names are nul-terminatedFlorian Westphal
2026-04-18netfilter: nfnetlink_log: account for netlink header sizeFlorian Westphal
2026-04-18netfilter: ctnetlink: use netlink policy range checksDavid Carlier
2026-04-18netlink: introduce bigendian integer typesFlorian Westphal
2026-04-18netfilter: nft_payload: reject out-of-range attributes via policyFlorian Westphal
2026-04-18netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdpWeiming Shi
2026-04-18netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOADWeiming Shi
2026-04-18netfilter: nft_set_pipapo: split gc into unlink and reclaim phaseFlorian Westphal
2026-04-18nfnetlink_osf: validate individual option lengths in fingerprintsWeiming Shi
2026-04-18netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()Jenny Guanni Qu
2026-04-18netfilter: xt_time: use unsigned int for monthday bit shiftJenny Guanni Qu
2026-04-18netfilter: xt_CT: drop pending enqueued packets on template removalPablo Neira Ayuso
2026-04-18netfilter: nft_ct: drop pending enqueued packets on removalPablo Neira Ayuso
2026-04-18netfilter: nft_ct: add seqadj extension for natted connectionsAndrii Melnychenko
2026-04-18netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS caseJenny Guanni Qu
2026-04-18netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()Lukas Johannes Möller
2026-04-18netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()Hyunwoo Kim
2026-04-18netfilter: ctnetlink: remove refcounting in expectation dumpersFlorian Westphal
2026-04-18netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labelsYuan Tan
2026-04-18netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()Hyunwoo Kim
2026-04-18netfilter: nfnetlink_queue: fix entry leak in bridge verdict error pathHyunwoo Kim
2026-04-18netfilter: x_tables: guard option walkers against 1-byte tail readsDavid Dull
2026-04-18netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()Jenny Guanni Qu
2026-03-04netfilter: nf_conntrack_h323: fix OOB read in decode_choice()Vahagn Vardanian