index
:
linux
for-next
master
Mirror of https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
net
/
netfilter
Age
Commit message (
Expand
)
Author
Lines
2026-03-26
netfilter: ctnetlink: use netlink policy range checks
David Carlier
-18
/
+8
2026-03-26
netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp
Weiming Shi
-4
/
+10
2026-03-26
netfilter: nf_conntrack_expect: skip expectations in other netns via proc
Pablo Neira Ayuso
-0
/
+4
2026-03-26
netfilter: nf_conntrack_expect: store netns and zone in expectation
Pablo Neira Ayuso
-3
/
+17
2026-03-26
netfilter: ctnetlink: ensure safe access to master conntrack
Pablo Neira Ayuso
-10
/
+30
2026-03-26
netfilter: nf_conntrack_expect: use expect->helper
Pablo Neira Ayuso
-21
/
+13
2026-03-26
netfilter: nf_conntrack_expect: honor expectation helper field
Pablo Neira Ayuso
-11
/
+28
2026-03-26
netfilter: nft_set_rbtree: revisit array resize logic
Pablo Neira Ayuso
-17
/
+75
2026-03-26
netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD
Weiming Shi
-6
/
+2
2026-03-25
netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
Florian Westphal
-10
/
+10
2026-03-19
nfnetlink_osf: validate individual option lengths in fingerprints
Weiming Shi
-0
/
+13
2026-03-19
netfilter: nf_tables: release flowtable after rcu grace period on error
Pablo Neira Ayuso
-0
/
+1
2026-03-19
netfilter: bpf: defer hook memory release until rcu readers are done
Florian Westphal
-1
/
+1
2026-03-13
netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
Jenny Guanni Qu
-0
/
+2
2026-03-13
netfilter: xt_time: use unsigned int for monthday bit shift
Jenny Guanni Qu
-2
/
+2
2026-03-13
netfilter: xt_CT: drop pending enqueued packets on template removal
Pablo Neira Ayuso
-0
/
+4
2026-03-13
netfilter: nft_ct: drop pending enqueued packets on removal
Pablo Neira Ayuso
-0
/
+4
2026-03-13
nf_tables: nft_dynset: fix possible stateful expression memleak in error path
Pablo Neira Ayuso
-3
/
+11
2026-03-13
netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
Jenny Guanni Qu
-0
/
+2
2026-03-13
netfilter: nf_flow_table_ip: reset mac header before vlan push
Eric Woudstra
-0
/
+1
2026-03-13
netfilter: revert nft_set_rbtree: validate open interval overlap
Florian Westphal
-78
/
+14
2026-03-13
netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()
Lukas Johannes Möller
-1
/
+5
2026-03-13
netfilter: conntrack: add missing netlink policy validations
Florian Westphal
-2
/
+3
2026-03-13
netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()
Hyunwoo Kim
-1
/
+25
2026-03-10
netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
Yuan Tan
-0
/
+6
2026-03-10
netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()
Hyunwoo Kim
-4
/
+4
2026-03-10
netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path
Hyunwoo Kim
-1
/
+3
2026-03-10
netfilter: x_tables: guard option walkers against 1-byte tail reads
David Dull
-4
/
+6
2026-03-10
netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()
Jenny Guanni Qu
-1
/
+2
2026-03-10
netfilter: nf_tables: always walk all pending catchall elements
Florian Westphal
-2
/
+0
2026-03-10
netfilter: nf_tables: Fix for duplicate device in netdev hooks
Phil Sutter
-2
/
+2
2026-03-05
netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
Florian Westphal
-13
/
+45
2026-03-05
netfilter: nf_tables: clone set on flush only
Pablo Neira Ayuso
-6
/
+24
2026-03-05
netfilter: nf_tables: unconditionally bump set->nelems before insertion
Pablo Neira Ayuso
-14
/
+16
2026-02-26
Merge tag 'net-7.0-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/netd...
Linus Torvalds
-1
/
+1
2026-02-26
netfilter: nf_conntrack_h323: fix OOB read in decode_choice()
Vahagn Vardanian
-1
/
+1
2026-02-22
Convert remaining multi-line kmalloc_obj/flex GFP_KERNEL uses
Kees Cook
-3
/
+3
2026-02-21
Convert more 'alloc_obj' cases to default GFP_KERNEL arguments
Linus Torvalds
-6
/
+3
2026-02-21
Convert 'alloc_flex' family to use the new default GFP_KERNEL argument
Linus Torvalds
-3
/
+3
2026-02-21
Convert 'alloc_obj' family to use the new default GFP_KERNEL argument
Linus Torvalds
-47
/
+47
2026-02-21
treewide: Replace kmalloc with kmalloc_obj for non-scalar types
Kees Cook
-118
/
+110
2026-02-17
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
Inseo An
-0
/
+1
2026-02-17
ipvs: do not keep dest_dst if dev is going down
Julian Anastasov
-10
/
+36
2026-02-17
ipvs: skip ipv6 extension headers for csum checks
Julian Anastasov
-39
/
+20
2026-02-17
netfilter: nf_conntrack_h323: don't pass uninitialised l3num value
Florian Westphal
-5
/
+5
2026-02-17
netfilter: nf_tables: revert commit_mutex usage in reset path
Brian Witte
-206
/
+42
2026-02-17
netfilter: nft_quota: use atomic64_xchg for reset
Brian Witte
-6
/
+7
2026-02-17
netfilter: nft_counter: serialize reset with spinlock
Brian Witte
-4
/
+16
2026-02-17
netfilter: annotate NAT helper hook pointers with __rcu
Sun Jian
-27
/
+29
2026-02-11
Merge tag 'net-next-7.0' of git://git.kernel.org/pub/scm/linux/kernel/git/net...
Linus Torvalds
-404
/
+1123
[next]