summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2026-04-03selinux: fix overlayfs mmap() and mprotect() access checksPaul Moore
2026-04-03lsm: add backing_file LSM hooksPaul Moore
2026-04-02Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
2026-04-01evm: Enforce signatures version 3 with new EVM policy 'bit 3'Stefan Berger
2026-04-01integrity: Allow sigv3 verification on EVM_XATTR_PORTABLE_DIGSIGStefan Berger
2026-04-01ima: add support to require IMA sigv3 signaturesMimi Zohar
2026-04-01ima: add regular file data hash signature version 3 supportMimi Zohar
2026-04-01ima: Define asymmetric_verify_v3() to verify IMA sigv3 signaturesMimi Zohar
2026-03-26Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
2026-03-26Merge tag 'landlock-7.0-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git...Linus Torvalds
2026-03-24module: Give MODULE_SIG_STRING a more descriptive nameThomas Weißschuh
2026-03-23crypto: sm3 - Rename CRYPTO_SM3_GENERIC to CRYPTO_SM3Eric Biggers
2026-03-20xen/privcmd: add boot control for restricted usage in domUJuergen Gross
2026-03-17ima: remove buggy support for asynchronous hashesEric Biggers
2026-03-17securityfs: use kstrdup_const() to manage symlink targetsDmitry Antipov
2026-03-17EVM: add comment describing why ino field is still unsigned longJeff Layton
2026-03-13smack: Remove IPPROTO_UDPLITE support in security_sock_rcv_skb().Kuniyuki Iwashima
2026-03-13integrity: Eliminate weak definition of arch_get_secureboot()Nathan Chancellor
2026-03-11ima: Add code comments to explain IMA iint cache atomic_flagsCoiby Xu
2026-03-11ima_fs: Correctly create securityfs files for unsupported hash algosDmitry Safonov
2026-03-10landlock: Clean up interrupted thread logic in TSYNCYihan Ding
2026-03-10landlock: Serialize TSYNC thread restrictionYihan Ding
2026-03-09apparmor: fix race between freeing data and fs accessing itJohn Johansen
2026-03-09apparmor: fix race on rawdata dereferenceJohn Johansen
2026-03-09apparmor: fix differential encoding verificationJohn Johansen
2026-03-09apparmor: fix unprivileged local user can do privileged policy managementJohn Johansen
2026-03-09apparmor: Fix double free of ns_name in aa_replace_profiles()John Johansen
2026-03-09apparmor: fix missing bounds check on DEFAULT table in verify_dfa()Massimiliano Pellizzer
2026-03-09apparmor: fix side-effect bug in match_char() macro usageMassimiliano Pellizzer
2026-03-09apparmor: fix: limit the number of levels of policy namespacesJohn Johansen
2026-03-09apparmor: replace recursive profile removal with iterative approachMassimiliano Pellizzer
2026-03-09apparmor: fix memory leak in verify_headerMassimiliano Pellizzer
2026-03-09apparmor: validate DFA start states are in bounds in unpack_pdbMassimiliano Pellizzer
2026-03-09ima: check return value of crypto_shash_final() in boot aggregateDaniel Hodges
2026-03-08ima: Define and use a digest_size field in the ima_algo_desc structureRoberto Sassu
2026-03-08ima: efi: Drop unnecessary check for CONFIG_MODULE_SIG/CONFIG_KEXEC_SIGThomas Weißschuh
2026-03-08ima: fallback to using i_version to detect file changeMimi Zohar
2026-03-06treewide: change inode->i_ino from unsigned long to u64Jeff Layton
2026-03-06selinux: Use simple_start_creating() / simple_done_creating()NeilBrown
2026-03-06Apparmor: Use simple_start_creating() / simple_done_creating()NeilBrown
2026-03-05evm: fix security.evm for a file with IMA signatureCoiby Xu
2026-03-05evm: Don't enable fix mode when secure boot is enabledCoiby Xu
2026-03-05integrity: Make arch_ima_get_secureboot integrity-wideCoiby Xu
2026-03-04landlock: Improve TSYNC typesMickaël Salaün
2026-03-04landlock: Fully release unused TSYNC work entriesMickaël Salaün
2026-03-04landlock: Fix formattingMickaël Salaün
2026-02-23apparmor: return error on namespace mismatch in verify_headerMassimiliano Pellizzer
2026-02-23apparmor: use target task's context in apparmor_getprocattr()Cengiz Can
2026-02-23selinux: annotate intentional data race in inode_doinit_with_dentry()Christian Göttsche
2026-02-22Convert remaining multi-line kmalloc_obj/flex GFP_KERNEL usesKees Cook