summaryrefslogtreecommitdiffstats
path: root/net/netfilter
AgeCommit message (Expand)Author
2016-06-24netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal
2016-06-24netfilter: x_tables: do compat validation via translate_tableFlorian Westphal
2016-06-24netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal
2016-06-24netfilter: x_tables: don't reject valid target size on some architecturesFlorian Westphal
2016-06-24netfilter: x_tables: validate all offsets and sizes in a ruleFlorian Westphal
2016-06-24netfilter: x_tables: check for bogus target offsetFlorian Westphal
2016-06-24netfilter: x_tables: check standard target size tooFlorian Westphal
2016-06-24netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal
2016-06-24netfilter: x_tables: assert minimum target sizeFlorian Westphal
2016-06-24netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal
2016-05-11ipvs: correct initial offset of Call-ID header search in SIP persistence engineMarco Angaroni
2016-03-03netfilter: nf_tables: fix bogus warning in nft_data_uninit()Mirek Kratochvil
2015-10-22ipvs: fix crash with sync protocol v0 and FTPJulian Anastasov
2015-10-22ipvs: do not use random local source address for tunnelsJulian Anastasov
2015-10-22netfilter: nft_compat: skip family comparison in case of NFPROTO_UNSPECPablo Neira Ayuso
2015-10-22netfilter: ctnetlink: put back references to master ct and expect objectsPablo Neira Ayuso
2015-10-22netfilter: nf_conntrack: Support expectations in different zonesJoe Stringer
2015-07-03netfilter: nf_tables: allow to change chain policy without hook if it existsPablo Neira Ayuso
2015-07-03netfilter: nft_compat: set IP6T_F_PROTO flag if protocol is setPablo Neira Ayuso
2015-07-03netfilter: Zero the tuple in nfnl_cthelper_parse_tuple()Ian Wilson
2015-07-03netfilter: nfnetlink_cthelper: Remove 'const' and '&' to avoid warningsChen Gang
2015-04-29netfilter: conntrack: disable generic tracking for known protocolsFlorian Westphal
2015-03-26netfilter: xt_socket: fix a stack corruption bugEric Dumazet
2015-03-26netfilter: nft_compat: fix module refcount underflowPablo Neira Ayuso
2015-03-26ipvs: rerouting to local clients is not needed anymoreJulian Anastasov
2015-03-26ipvs: add missing ip_vs_pe_put in sync codeJulian Anastasov
2015-01-29ipvs: uninitialized data with IP_VS_IPV6Dan Carpenter
2015-01-29netfilter: nfnetlink: validate nfnetlink header from batchPablo Neira Ayuso
2015-01-27netfilter: ipset: small potential read beyond the end of bufferDan Carpenter
2014-11-21netfilter: nft_compat: fix wrong target lookup in nft_target_select_ops()Arturo Borrero
2014-11-21netfilter: nf_log: release skbuff on nlmsg put failureHoucheng Lin
2014-11-21netfilter: nfnetlink_log: fix maximum packet length logged to userspaceFlorian Westphal
2014-11-21netfilter: nf_log: account for size of NLMSG_DONE attributeFlorian Westphal
2014-11-21netfilter: ipset: off by one in ip_set_nfnl_get_byindex()Dan Carpenter
2014-10-05ipvs: fix ipv6 hook registration for local repliesJulian Anastasov
2014-10-05netfilter: x_tables: allow to use default cgroup matchDaniel Borkmann
2014-10-05ipvs: Maintain all DSCP and ECN bits for ipv6 tun forwardingAlex Gartrell
2014-10-05netfilter: xt_hashlimit: perform garbage collection from process contextEric Dumazet
2014-10-05ipvs: avoid netns exit crash on ip_vs_conn_drop_conntrackJulian Anastasov
2014-08-14inetpeer: get rid of ip_id_countEric Dumazet
2014-07-09netfilter: nf_nat: fix oops on netns removalFlorian Westphal
2014-07-06ipvs: Fix panic due to non-linear skbPeter Christensen
2014-06-26net: Use netlink_ns_capable to verify the permisions of netlink messagesEric W. Biederman
2014-06-11netfilter: nfnetlink: Fix use after free when it fails to process batchDenys Fedoryshchenko
2014-05-31netfilter: nf_tables: set names cannot be larger than 15 bytesPablo Neira Ayuso
2014-05-31netfilter: nf_tables: fix nft_cmp_fast failure on big endian for size < 4Patrick McHardy
2014-03-27core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errorsZoltan Kiss
2014-02-18netfilter: ctnetlink: force null nat binding on insertPablo Neira Ayuso
2014-02-17netfilter: nf_tables: check if payload length is a power of 2Nikolay Aleksandrov
2014-02-14netfilter: nft_meta: fix typo "CONFIG_NET_CLS_ROUTE"Paul Bolle