summaryrefslogtreecommitdiffstats
path: root/security
AgeCommit message (Expand)Author
2022-11-10capabilities: fix potential memleak on error path from vfs_getxattr_alloc()Gaosheng Cui
2022-10-30selinux: enable use of both GFP_KERNEL and GFP_ATOMIC in convert_context()GONG, Ruiqi
2022-10-26hardening: Remove Clang's enable flag for -ftrivial-auto-var-init=zeroKees Cook
2022-10-26hardening: Avoid harmless Clang option under CONFIG_INIT_STACK_ALL_ZEROKees Cook
2022-10-26hardening: Clarify Kconfig text for auto-var-initKees Cook
2022-10-15efi: Correct Macmini DMI match in uefi cert quirkOrlando Chamberlain
2022-08-25apparmor: Fix memleak in aa_simple_write_to_buffer()Xiu Jianfeng
2022-08-25apparmor: fix reference count leak in aa_pivotroot()Xin Xiong
2022-08-25apparmor: fix overlapping attachment computationJohn Johansen
2022-08-25apparmor: fix setting unconfined mode on a loaded profileJohn Johansen
2022-08-25apparmor: fix aa_label_asxprint return checkTom Rix
2022-08-25apparmor: Fix failed mount permission check error messageJohn Johansen
2022-08-25apparmor: fix absroot causing audited secids to begin with =John Johansen
2022-08-25apparmor: fix quiet_denied for file rulesJohn Johansen
2022-08-21selinux: Add boundary check in put_entry()Xiu Jianfeng
2022-07-29lockdown: Fix kexec lockdown bypass with ima policyEric Snowberg
2022-07-25x86/retbleed: Add fine grained Kconfig knobsPeter Zijlstra
2022-07-21ima: Fix potential memory leak in ima_init_crypto()Jianglei Nie
2022-07-21ima: Fix a potential integer overflow in ima_appraise_measurementHuaxin Lu
2022-07-21Revert "evm: Fix memleak in init_desc"Xiu Jianfeng
2022-06-09ima: remove the IMA_TEMPLATE Kconfig optionGUO Zihua
2022-06-09efi: Do not import certificates from UEFI Secure Boot for T2 MacsAditya Garg
2022-06-09lsm,selinux: pass flowi_common instead of flowi to the LSM hooksPaul Moore
2022-05-30lockdown: also lock down previous kgdb useDaniel Thompson
2022-05-25include/uapi/linux/xfrm.h: Fix XFRM_MSG_MAPPING ABI breakageEugene Syromiatnikov
2022-05-25selinux: fix bad cleanup on error in hashtab_duplicate()Ondrej Mosnacek
2022-04-08Fix incorrect type in assignment of ipv6 port for auditCasey Schaufler
2022-04-08selinux: allow FIOCLEX and FIONCLEX with policy capabilityRichard Haines
2022-04-08selinux: use correct type for context lengthChristian Göttsche
2022-04-08LSM: general protection fault in legacy_parse_paramCasey Schaufler
2022-04-08TOMOYO: fix __setup handlers return valuesRandy Dunlap
2022-04-08EVM: fix the evm= __setup handler return valueRandy Dunlap
2022-04-08selinux: check return value of sel_make_avc_filesChristian Göttsche
2022-04-08KEYS: fix length validation in keyctl_pkey_params_get_2()Eric Biggers
2022-02-16ima: Do not print policy rule with inactive LSM labelsStefan Berger
2022-02-16ima: Allow template selection with ima_template[_fmt]= after ima_hash=Roberto Sassu
2022-02-16ima: Remove ima_policy file before directoryStefan Berger
2022-02-16integrity: check the return value of audit_log_start()Xiaoke Wang
2022-02-08selinux: fix double free of cond_list on error pathsVratislav Bendel
2022-01-27selinux: fix potential memleak in selinux_add_opt()Bernard Zhao
2022-01-05selinux: initialize proto variable in selinux_ip_postroute_compat()Tom Rix
2022-01-05tomoyo: use hwight16() in tomoyo_domain_quota_is_ok()Tetsuo Handa
2022-01-05tomoyo: Check exceeded quota early in tomoyo_domain_quota_is_ok().Dmitry Vyukov
2021-11-26selinux: fix NULL-pointer dereference when hashtab allocation failsOndrej Mosnacek
2021-11-21fortify: Explicitly disable Clang supportKees Cook
2021-11-18apparmor: fix error checkTom Rix
2021-11-18smackfs: use netlbl_cfg_cipsov4_del() for deleting cipso_v4_doiTetsuo Handa
2021-11-18smackfs: use __GFP_NOFAIL for smk_cipso_doi()Tetsuo Handa
2021-11-18smackfs: Fix use-after-free in netlbl_catmap_walk()Pawan Gupta
2021-11-18evm: mark evm_fixmode as __ro_after_initAustin Kim