summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)Author
3 daysMerge tag 'net-7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/netd...Linus Torvalds
6 daysnetfilter: nftables: restrict checkum update offsetFlorian Westphal
6 daysnetfilter: nftables: restrict linklayer and network header writesFlorian Westphal
6 daysnetfilter: nfnetlink_queue: restrict writes to network headerFlorian Westphal
6 daysnetfilter: nft_fib: reject fib expression on the netdev egress hookTheodor Arsenij Larionov-Trichkine
6 daysnetfilter: nfnetlink_cthelper: cap to maximum number of expectation per masterPablo Neira Ayuso
6 daysnetfilter: nf_conntrack_sip: validate skb_dst() before accessing itPablo Neira Ayuso
6 daysnetfilter: ipset: fix race between dump and ip_set_list resizeXiang Mei
6 daysnetfilter: nft_set_pipapo: don't leak bad clone into future transactionFlorian Westphal
6 daysnetfilter: nf_conntrack_expect: zero at allocation timeFlorian Westphal
10 daysMerge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpfLinus Torvalds
12 daysnetfilter: nf_conntrack_helper: cap maximum number of expectation at helper r...Pablo Neira Ayuso
12 daysnetfilter: nft_ct: expectation timeouts are passed in millisecondsFlorian Westphal
12 daysnetfilter: nf_conntrack_expect: run expectation eviction with no helperPablo Neira Ayuso
12 daysnetfilter: nf_conntrack_expect: store master_tuple in expectationPablo Neira Ayuso
12 daysnetfilter: conntrack: add deprecation warnings for irc and pptp trackersFlorian Westphal
13 daysnetfilter: ctnetlink: do not allow to reset helper on existing conntrackPablo Neira Ayuso
13 daysnetfilter: nft_compat: ebtables emulation must reject non-bridge targetsFlorian Westphal
13 daysnetfilter: nft_synproxy: stop bypassing the priv->info snapshotRunyu Xiao
13 daysnetfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()Lorenzo Bianconi
13 daysnetfilter: nf_conncount: prevent connlimit drops for early confirmed ctFernando Fernandez Mancera
13 daysnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()Mathias Krause
13 daysbpf: Guard conntrack opts error writesYiyang Chen
2026-06-21netfilter: nf_conntrack_expect: use conntrack GC to reap expectationsPablo Neira Ayuso
2026-06-21netfilter: nft_flow_offload: zero device address for non-ether caseFlorian Westphal
2026-06-21netfilter: nft_meta_bridge: add validate callback for get operationsFlorian Westphal
2026-06-21netfilter: nft_payload: reject offsets exceeding 65535 bytesFlorian Westphal
2026-06-21netfilter: ipset: make sure gc is properly stoppedJozsef Kadlecsik
2026-06-21netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()Jozsef Kadlecsik
2026-06-21netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap typesJozsef Kadlecsik
2026-06-21netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash typesJozsef Kadlecsik
2026-06-19netfilter: flowtable: fix and simplify IP6IP6 tunnel handlingLorenzo Bianconi
2026-06-19netfilter: xt_cluster: reject template conntracks in hash matchWyatt Feng
2026-06-19netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dstHaoze Xie
2026-06-19netfilter: flowtable: fix offloaded ct timeout never being extendedAdrian Bente
2026-06-17Merge tag 'net-next-7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/net...Linus Torvalds
2026-06-15Merge tag 'nf-next-26-06-14' of git://git.kernel.org/pub/scm/linux/kernel/git...Jakub Kicinski
2026-06-15Merge tag 'timers-core-2026-06-13' of gitolite.kernel.org:pub/scm/linux/kerne...Linus Torvalds
2026-06-14netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use themPablo Neira Ayuso
2026-06-14netfilter: flowtable: bail out if forward path cannot be discoveredPablo Neira Ayuso
2026-06-14netfilter: conntrack: check NULL when retrieving ct extensionPablo Neira Ayuso
2026-06-14netfilter: nf_conncount: gc and rcu fixesFlorian Westphal
2026-06-14netfilter: nf_conncount: add sequence counter to detect tree modificationsFlorian Westphal
2026-06-14netfilter: nf_conncount: split count_tree_node rbtree walk into helperFlorian Westphal
2026-06-14netfilter: nf_conncount: use per nf_conncount_data spinlocksFlorian Westphal
2026-06-14netfilter: nf_conncount: callers must hold rcu read lockFlorian Westphal
2026-06-14netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control pathsFernando Fernandez Mancera
2026-06-14ipvs: Replace use of system_unbound_wq with system_dfl_long_wqMarco Crivellari
2026-06-11Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
2026-06-10netfilter: nft_fib: fix stale stack leak via the OIFNAME registerDavide Ornaghi