summaryrefslogtreecommitdiffstats
path: root/net/netfilter
Commit message (Expand)AuthorAgeFilesLines
* netfilter: conntrack: revisit the gc initial rescheduling biasAntoine Tenart2022-10-261-4/+6
* netfilter: conntrack: fix the gc rescheduling delayAntoine Tenart2022-10-261-2/+8
* netfilter: nf_tables: fix percpu memory leak at nf_tables_addchain()Tetsuo Handa2022-09-281-0/+1
* netfilter: nf_tables: fix nft_counters_enabled underflow at nf_tables_addchain()Tetsuo Handa2022-09-281-4/+3
* netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()Pablo Neira Ayuso2022-09-281-1/+3
* netfilter: nf_conntrack_irc: Tighten matching on DCC messageDavid Leadbeater2022-09-281-6/+28
* netfilter: nf_conntrack_sip: fix ct_sip_walk_headersIgor Ryzhov2022-09-281-2/+2
* netfilter: nf_conntrack_irc: Fix forged IP logicDavid Leadbeater2022-09-151-2/+3
* netfilter: nf_tables: clean up hook list when offload flags check failsPablo Neira Ayuso2022-09-151-1/+3
* netfilter: conntrack: work around exceeded receive windowFlorian Westphal2022-09-151-0/+31
* netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to yGeert Uytterhoeven2022-09-051-1/+0
* net: Fix data-races around sysctl_[rw]mem_(max|default).Kuniyuki Iwashima2022-08-311-2/+2
* netfilter: flowtable: fix stuck flows on cleanup due to pending workPablo Neira Ayuso2022-08-312-4/+11
* netfilter: flowtable: add function to invoke garbage collection immediatelyPablo Neira Ayuso2022-08-311-3/+9
* netfilter: nf_tables: disallow binding to already bound chainPablo Neira Ayuso2022-08-311-0/+2
* netfilter: nf_tables: disallow jump to implicit chain from set elementPablo Neira Ayuso2022-08-311-0/+4
* netfilter: nf_tables: upfront validation of data via nft_data_init()Pablo Neira Ayuso2022-08-315-113/+124
* netfilter: bitwise: improve error goto labelsJeremy Sowden2022-08-311-5/+6
* netfilter: nft_cmp: optimize comparison for 16-bytesPablo Neira Ayuso2022-08-312-2/+116
* netfilter: nf_tables: consolidate rule verdict trace callPablo Neira Ayuso2022-08-311-7/+32
* netfilter: nft_tunnel: restrict it to netdev familyPablo Neira Ayuso2022-08-311-0/+1
* netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet familiesPablo Neira Ayuso2022-08-311-3/+15
* netfilter: nf_tables: do not leave chain stats enabled on errorPablo Neira Ayuso2022-08-311-2/+4
* netfilter: nft_payload: do not truncate csum_offset and csum_typePablo Neira Ayuso2022-08-311-6/+13
* netfilter: nft_payload: report ERANGE for too long offset and lengthPablo Neira Ayuso2022-08-311-2/+8
* netfilter: nf_tables: make table handle allocation per-netns friendlyPablo Neira Ayuso2022-08-311-2/+1
* netfilter: nf_tables: disallow updates of implicit chainPablo Neira Ayuso2022-08-311-0/+3
* netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specifiedPablo Neira Ayuso2022-08-251-0/+5
* netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVA...Pablo Neira Ayuso2022-08-251-0/+3
* netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flagsPablo Neira Ayuso2022-08-251-0/+24
* netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flagPablo Neira Ayuso2022-08-251-4/+9
* netfilter: nf_tables: really skip inactive sets when allocating namePablo Neira Ayuso2022-08-251-1/+1
* netfilter: nf_tables: possible module reference underflow in error pathPablo Neira Ayuso2022-08-251-1/+1
* netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERV...Pablo Neira Ayuso2022-08-251-0/+1
* netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id a...Pablo Neira Ayuso2022-08-251-7/+13
* netfilter: nf_tables: fix null deref due to zeroed list headFlorian Westphal2022-08-171-0/+1
* netfilter: nf_tables: do not allow RULE_ID to refer to another chainThadeu Lima de Souza Cascardo2022-08-171-2/+5
* netfilter: nf_tables: do not allow CHAIN_ID to refer to another tableThadeu Lima de Souza Cascardo2022-08-171-2/+4
* netfilter: nf_tables: do not allow SET_ID to refer to another tableThadeu Lima de Souza Cascardo2022-08-171-1/+3
* netfilter: nf_queue: do not allow packet truncation below transport header of...Florian Westphal2022-08-031-1/+6
* net: netfilter: use kfree_drop_reason() for NF_DROPMenglong Dong2022-07-291-1/+2
* ip: Fix data-races around sysctl_ip_default_ttl.Kuniyuki Iwashima2022-07-291-1/+1
* netfilter: nf_tables: replace BUG_ON by element length checkPablo Neira Ayuso2022-07-211-21/+51
* netfilter: nf_log: incorrect offset to network headerPablo Neira Ayuso2022-07-211-4/+4
* netfilter: nft_payload: don't allow th access for fragmentsFlorian Westphal2022-07-122-5/+6
* netfilter: nft_payload: support for inner header matching / manglingPablo Neira Ayuso2022-07-121-2/+54
* netfilter: nf_tables: convert pktinfo->tprot_set to flags fieldPablo Neira Ayuso2022-07-124-6/+6
* netfilter: nf_tables: stricter validation of element dataPablo Neira Ayuso2022-07-121-1/+8
* netfilter: nft_set_pipapo: release elements in clone from abort pathPablo Neira Ayuso2022-07-121-15/+33
* netfilter: nft_dynset: restore set element counter when failing to updatePablo Neira Ayuso2022-07-071-0/+2