summaryrefslogtreecommitdiffstats
path: root/security
AgeCommit message (Expand)Author
2023-05-17selinux: ensure av_permissions.h is built when neededPaul Moore
2023-05-17selinux: fix Makefile dependencies of flask.hOndrej Mosnacek
2023-04-05keys: Do not cache key in task struct if key is requested from kernel threadDavid Howells
2023-03-11ima: Align ima_file_mmap() parameters with mmap_file LSM hookRoberto Sassu
2023-02-01tomoyo: fix broken dependency on *.conf.defaultMasahiro Yamada
2023-01-14device_cgroup: Roll back to original exceptions after copy failureWang Weiyang
2023-01-14ima: Fix a potential NULL pointer access in ima_restore_measurement_listHuaxin Lu
2023-01-14efi: Add iMac Pro 2017 to uefi skip cert quirkAditya Garg
2023-01-14ima: Simplify ima_lsm_copy_ruleGUO Zihua
2023-01-14LoadPin: Ignore the "contents" argument of the LSM hooksKees Cook
2023-01-14apparmor: Fix memleak in alloc_ns()Xiu Jianfeng
2023-01-14apparmor: Use pointer to struct aa_label for lbs_credXiu Jianfeng
2023-01-14apparmor: Fix abi check to include v8 abiJohn Johansen
2023-01-14apparmor: fix lockdep warning when removing a namespaceJohn Johansen
2023-01-14apparmor: fix a memleak in multi_transaction_new()Gaosheng Cui
2023-01-14ima: Fix misuse of dereference of pointer in template_desc_init_fields()Xiu Jianfeng
2023-01-14integrity: Fix memory leakage in keyring allocation error pathGUO Zihua
2023-01-14ima: Handle -ESTALE returned by ima_filter_rule_match()GUO Zihua
2023-01-14ima: Fix fall-through warnings for ClangGustavo A. R. Silva
2022-11-10capabilities: fix potential memleak on error path from vfs_getxattr_alloc()Gaosheng Cui
2022-10-30selinux: enable use of both GFP_KERNEL and GFP_ATOMIC in convert_context()GONG, Ruiqi
2022-10-26hardening: Remove Clang's enable flag for -ftrivial-auto-var-init=zeroKees Cook
2022-10-26hardening: Avoid harmless Clang option under CONFIG_INIT_STACK_ALL_ZEROKees Cook
2022-10-26hardening: Clarify Kconfig text for auto-var-initKees Cook
2022-10-15efi: Correct Macmini DMI match in uefi cert quirkOrlando Chamberlain
2022-08-25apparmor: Fix memleak in aa_simple_write_to_buffer()Xiu Jianfeng
2022-08-25apparmor: fix reference count leak in aa_pivotroot()Xin Xiong
2022-08-25apparmor: fix overlapping attachment computationJohn Johansen
2022-08-25apparmor: fix setting unconfined mode on a loaded profileJohn Johansen
2022-08-25apparmor: fix aa_label_asxprint return checkTom Rix
2022-08-25apparmor: Fix failed mount permission check error messageJohn Johansen
2022-08-25apparmor: fix absroot causing audited secids to begin with =John Johansen
2022-08-25apparmor: fix quiet_denied for file rulesJohn Johansen
2022-08-21selinux: Add boundary check in put_entry()Xiu Jianfeng
2022-07-29lockdown: Fix kexec lockdown bypass with ima policyEric Snowberg
2022-07-25x86/retbleed: Add fine grained Kconfig knobsPeter Zijlstra
2022-07-21ima: Fix potential memory leak in ima_init_crypto()Jianglei Nie
2022-07-21ima: Fix a potential integer overflow in ima_appraise_measurementHuaxin Lu
2022-07-21Revert "evm: Fix memleak in init_desc"Xiu Jianfeng
2022-06-09ima: remove the IMA_TEMPLATE Kconfig optionGUO Zihua
2022-06-09efi: Do not import certificates from UEFI Secure Boot for T2 MacsAditya Garg
2022-06-09lsm,selinux: pass flowi_common instead of flowi to the LSM hooksPaul Moore
2022-05-30lockdown: also lock down previous kgdb useDaniel Thompson
2022-05-25include/uapi/linux/xfrm.h: Fix XFRM_MSG_MAPPING ABI breakageEugene Syromiatnikov
2022-05-25selinux: fix bad cleanup on error in hashtab_duplicate()Ondrej Mosnacek
2022-04-08Fix incorrect type in assignment of ipv6 port for auditCasey Schaufler
2022-04-08selinux: allow FIOCLEX and FIONCLEX with policy capabilityRichard Haines
2022-04-08selinux: use correct type for context lengthChristian Göttsche
2022-04-08LSM: general protection fault in legacy_parse_paramCasey Schaufler
2022-04-08TOMOYO: fix __setup handlers return valuesRandy Dunlap