summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
8 daysselinux: fix incorrect execmem checks on overlayfsOndrej Mosnacek
8 daysselinux: check connect-related permissions on TCP Fast OpenStephen Smalley
8 daysapparmor: fix label can not be immediately before a declarationJohn Johansen
8 daysapparmor: put secmark label after secid lookupZygmunt Krynicki
8 daysapparmor: aa_getprocattr free procattr leak on format failureZygmunt Krynicki
8 daysapparmor: fix potential UAF in aa_replace_profilesMaxime Bélair
8 daysapparmor: grab ns lock and refresh when looking up changehat child profilesRyan Lee
8 daysapparmor: fix rawdata_f_data implicit flex arrayJohn Johansen
8 daysapparmor: aa_label_alloc use aa_label_free on alloc failureZygmunt Krynicki
8 daysapparmor: check label build before no_new_privs testRuoyu Wang
8 dayssecurity/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()Andrew Morton
8 daysKEYS: Use acquire when reading state in keyring searchGui-Dong Han
8 daysevm: terminate and bound the evm_xattrs read bufferPengpeng Hou
8 daysapparmor: advertise the tcp fast open fix is appliedJohn Johansen
2026-07-04keys: Pin request_key_auth payload in instantiate pathsShaomin Chen
2026-07-04KEYS: fix overflow in keyctl_pkey_params_get_2()Jarkko Sakkinen
2026-07-04apparmor: fix use-after-free in rawdata dedup loopRuslan Valiyev
2026-07-04apparmor: mediate the implicit connect of TCP fast open sendmsgBryam Vargas
2026-07-04selinux: fix overlayfs mmap() and mprotect() access checksPaul Moore
2026-07-04lsm: add backing_file LSM hooksPaul Moore
2026-06-19landlock: Fix handling of disconnected directoriesMickaël Salaün
2026-06-19ima: verify the previous kernel's IMA buffer lies in addressable RAMHarshit Mogalapalli
2026-06-01security/keys: fix missed RCU read section on lookupLinus Torvalds
2026-05-23ima: check return value of crypto_shash_final() in boot aggregateDaniel Hodges
2026-05-17selinux: prune /sys/fs/selinux/disableStephen Smalley
2026-05-17selinux: shrink critical section in sel_write_load()Stephen Smalley
2026-05-17selinux: don't reserve xattr slot when we won't fill itDavid Windsor
2026-03-25xen/privcmd: add boot control for restricted usage in domUJuergen Gross
2026-03-25apparmor: fix race between freeing data and fs accessing itJohn Johansen
2026-03-25apparmor: fix race on rawdata dereferenceJohn Johansen
2026-03-25apparmor: fix differential encoding verificationJohn Johansen
2026-03-25apparmor: fix unprivileged local user can do privileged policy managementJohn Johansen
2026-03-25apparmor: Fix double free of ns_name in aa_replace_profiles()John Johansen
2026-03-25apparmor: fix missing bounds check on DEFAULT table in verify_dfa()Massimiliano Pellizzer
2026-03-25apparmor: fix side-effect bug in match_char() macro usageMassimiliano Pellizzer
2026-03-25apparmor: fix: limit the number of levels of policy namespacesJohn Johansen
2026-03-25apparmor: replace recursive profile removal with iterative approachMassimiliano Pellizzer
2026-03-25apparmor: fix memory leak in verify_headerMassimiliano Pellizzer
2026-03-25apparmor: validate DFA start states are in bounds in unpack_pdbMassimiliano Pellizzer
2026-03-04apparmor: fix aa_label to return state from compount and component matchJohn Johansen
2026-03-04apparmor: fix invalid deref of rawdata when export_binary is unsetGeorgia Garcia
2026-03-04apparmor: make label_match return a consistent valueJohn Johansen
2026-03-04apparmor: remove apply_modes_to_perms from label_matchJohn Johansen
2026-03-04apparmor: refcount the pdbJohn Johansen
2026-03-04apparmor: provide separate audit messages for file and policy checksJohn Johansen
2026-03-04apparmor: use passed in gfp flags in aa_alloc_null()Dan Carpenter
2026-03-04apparmor: fix rlimit for posix cpu timersJohn Johansen
2026-03-04apparmor: return -ENOMEM in unpack_perms_table upon alloc failureRyan Lee
2026-03-04apparmor: fix NULL sock in aa_sock_file_permJohn Johansen
2026-03-04smack: /smack/doi: accept previously used valuesKonstantin Andreev