summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2017-07-05netfilter: synproxy: fix conntrackd interactionEric Leblond1-0/+4
2017-07-05netfilter: xt_TCPMSS: add more sanity tests on tcph->doffEric Dumazet1-1/+5
2017-02-08netfilter; Add some missing default cases to switch statements in nft_reject.David S. Miller2-0/+4
2017-02-08netfilter: Fix switch statement warnings with recent gcc.David Miller2-3/+11
2016-08-03netfilter: x_tables: speed up jump target validationFlorian Westphal1-0/+50
2016-07-12netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal1-0/+74
2016-07-12netfilter: x_tables: do compat validation via translate_tableFlorian Westphal1-0/+8
2016-07-12netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal1-3/+2
2016-07-12netfilter: x_tables: don't reject valid target size on some architecturesFlorian Westphal1-2/+2
2016-07-12netfilter: x_tables: validate all offsets and sizes in a ruleFlorian Westphal1-5/+76
2016-07-12netfilter: x_tables: check for bogus target offsetFlorian Westphal1-2/+15
2016-07-12netfilter: x_tables: check standard target size tooFlorian Westphal1-0/+15
2016-07-12netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal1-0/+22
2016-07-12netfilter: x_tables: assert minimum target sizeFlorian Westphal1-0/+3
2016-07-12netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal1-0/+34
2016-07-12ipvs: correct initial offset of Call-ID header search in SIP persistence engineMarco Angaroni1-1/+1
2016-05-18nf_conntrack: avoid kernel pointer value leak in slab nameLinus Torvalds1-1/+3
2015-10-28ipvs: fix crash with sync protocol v0 and FTPJulian Anastasov1-1/+1
2015-10-28ipvs: skb_orphan in case of forwardingAlex Gartrell1-0/+27
2015-10-28ipvs: fix crash if scheduler is changedJulian Anastasov3-37/+69
2015-10-28ipvs: do not use random local source address for tunnelsJulian Anastasov1-1/+0
2015-10-28netfilter: nf_log: don't zap all loggers on unregisterFlorian Westphal1-2/+6
2015-10-28netfilter: nf_log: Introduce nft_log_dereference() macroMarcelo Leitner1-12/+9
2015-10-28netfilter: nft_compat: skip family comparison in case of NFPROTO_UNSPECPablo Neira Ayuso1-6/+26
2015-10-28netfilter: nf_log: wait for rcu grace after logger unregistrationPablo Neira Ayuso1-0/+1
2015-10-28netfilter: ctnetlink: put back references to master ct and expect objectsPablo Neira Ayuso1-5/+0
2015-10-28netfilter: nf_conntrack: Support expectations in different zonesJoe Stringer1-1/+2
2015-10-28netfilter: nfnetlink: work around wrong endianess in res_id fieldPablo Neira Ayuso1-1/+7
2015-07-13netfilter: nf_tables: allow to change chain policy without hook if it existsPablo Neira Ayuso1-1/+4
2015-07-13netfilter: nft_compat: set IP6T_F_PROTO flag if protocol is setPablo Neira Ayuso1-0/+6
2015-07-13netfilter: Zero the tuple in nfnl_cthelper_parse_tuple()Ian Wilson1-0/+3
2015-07-12netfilter: nfnetlink_cthelper: Remove 'const' and '&' to avoid warningsChen Gang1-2/+2
2015-07-05netfilter: nf_qeueue: Drop queue entries on nf_unregister_hookEric W. Biederman4-1/+42
2015-06-28netfilter: x_tables: fix cgroup matching on non-full sksDaniel Borkmann1-1/+1
2015-01-30ipvs: uninitialized data with IP_VS_IPV6Dan Carpenter1-5/+5
2015-01-30netfilter: conntrack: fix race between confirmation and flushPablo Neira Ayuso1-11/+9
2015-01-30netfilter: nfnetlink: relax strict multicast group check from netlink_bindPablo Neira Ayuso1-1/+1
2015-01-30netfilter: nf_tables: fix flush ruleset chain dependenciesPablo Neira Ayuso1-5/+9
2015-01-30netfilter: nfnetlink: validate nfnetlink header from batchPablo Neira Ayuso1-1/+2
2014-11-25Revert "netfilter: conntrack: fix race in __nf_conntrack_confirm against get_...Pablo Neira1-8/+6
2014-11-17netfilter: nfnetlink: fix insufficient validation in nfnetlink_bindPablo Neira Ayuso1-1/+11
2014-11-14netfilter: conntrack: fix race in __nf_conntrack_confirm against get_next_corpsebill bonaparte1-6/+8
2014-11-12netfilter: nf_tables: restore synchronous object release from commit/abortPablo Neira Ayuso1-16/+8
2014-11-12netfilter: nft_compat: use the match->table to validate dependenciesPablo Neira Ayuso1-2/+2
2014-11-12netfilter: nft_compat: relax chain type validationPablo Neira Ayuso1-30/+2
2014-11-12netfilter: nft_compat: use current net namespacePablo Neira Ayuso1-2/+2
2014-11-12ipvs: Keep skb->sk when allocating headroom on tunnel xmitCalvin Owens1-0/+2
2014-11-11netfilter: ipset: small potential read beyond the end of bufferDan Carpenter1-0/+6
2014-10-28ipvs: Avoid null-pointer deref in debug codeAlex Gartrell1-2/+2
2014-10-28netfilter: nft_compat: fix wrong target lookup in nft_target_select_ops()Arturo Borrero1-1/+1