1. fbcd580 netfilter: nft_nat: return EOPNOTSUPP if type or flags are not supported by Pablo Neira Ayuso · 4 years, 3 months ago
  2. 8efa59f netfilter: nf_conntrack_pptp: fix compilation warning with W=1 build by Pablo Neira Ayuso · 4 years, 2 months ago
  3. 9fb6b81 netfilter: nf_conntrack_pptp: prevent buffer overflows in debug code by Pablo Neira Ayuso · 4 years, 3 months ago
  4. e70fb3e netfilter: nfnetlink_cthelper: unbreak userspace helper support by Pablo Neira Ayuso · 4 years, 2 months ago
  5. 37bc21b netfilter: ipset: Fix subcounter update skip by Phil Sutter · 4 years, 3 months ago
  6. 3582543 netfilter: nft_set_rbtree: Introduce and use nft_rbtree_interval_start() by Stefano Brivio · 4 years, 4 months ago
  7. d2413ec netfilter: conntrack: avoid gcc-10 zero-length-bounds warning by Arnd Bergmann · 4 years, 3 months ago
  8. 412cb7a3 netfilter: nf_osf: avoid passing pointer to local var by Arnd Bergmann · 4 years, 3 months ago
  9. efc97a1 netfilter: nat: never update the UDP checksum when it's 0 by Guillaume Nault · 4 years, 3 months ago
  10. 79f784c netfilter: nf_tables: report EOPNOTSUPP on unsupported flags/object type by Pablo Neira Ayuso · 4 years, 4 months ago
  11. 24c290b netfilter: nft_fwd_netdev: validate family and chain type by Pablo Neira Ayuso · 4 years, 4 months ago
  12. 113df2c netfilter: flowtable: reload ip{v6}h in nf_flow_tuple_ip{v6} by Haishuang Yan · 4 years, 5 months ago
  13. 5ae2daf netfilter: nft_tunnel: add missing attribute validation for tunnels by Jakub Kicinski · 4 years, 5 months ago
  14. 64d4318 netfilter: nft_payload: add missing attribute validation for payload csum flags by Jakub Kicinski · 4 years, 5 months ago
  15. 5b425d3 netfilter: cthelper: add missing attribute validation for cthelper by Jakub Kicinski · 4 years, 5 months ago
  16. 80a12a6 netfilter: x_tables: xt_mttg_seq_next should increase position index by Vasily Averin · 4 years, 5 months ago
  17. 6fb92c6 netfilter: xt_recent: recent_seq_next should increase position index by Vasily Averin · 4 years, 5 months ago
  18. 4fbcbed netfilter: synproxy: synproxy_cpu_seq_next should increase position index by Vasily Averin · 4 years, 5 months ago
  19. 64cd059 netfilter: nf_conntrack: ct_cpu_seq_next should increase position index by Vasily Averin · 4 years, 5 months ago
  20. bc09b25 netfilter: nft_tunnel: no need to call htons() when dumping ports by Xin Long · 4 years, 8 months ago
  21. acbc507 netfilter: xt_hashlimit: limit the max size of hashtable by Cong Wang · 4 years, 6 months ago
  22. c6a5ba4 netfilter: nft_tunnel: add the missing ERSPAN_VERSION nla_policy by Xin Long · 4 years, 8 months ago
  23. 9f19727 netfilter: nft_tunnel: ERSPAN_VERSION must not be null by Florian Westphal · 4 years, 7 months ago
  24. 1f7a1bc netfilter: nf_tables: add __nft_chain_type_get() by Pablo Neira Ayuso · 4 years, 6 months ago
  25. 5b0d876 netfilter: ipset: use bitmap infrastructure completely by Kadlecsik József · 4 years, 6 months ago
  26. 666a530 netfilter: nft_osf: add missing check for DREG attribute by Florian Westphal · 4 years, 7 months ago
  27. 40b9085 netfilter: ctnetlink: honor IPS_OFFLOAD flag by Pablo Neira Ayuso · 5 years ago
  28. 8480fbe netfilter: nft_flow_offload: add entry to flowtable after confirmation by Pablo Neira Ayuso · 5 years ago
  29. abbfc53 netfilter: nft_set_hash: bogus element self comparison from deactivation path by Pablo Neira Ayuso · 5 years ago
  30. 9eebb67 netfilter: nft_set_hash: fix lookups with fixed size hash on big endian by Pablo Neira Ayuso · 5 years ago
  31. efac774 netfilter: nf_flow_table: do not remove offload when other netns's interface is down by Taehee Yoo · 6 years ago
  32. d2c0687 netfilter: nft_osf: usage from output path is not valid by Fernando Fernandez Mancera · 6 years ago
  33. 8260ce5 netfilter: nf_tables: fix flowtable list del corruption by Florian Westphal · 4 years, 7 months ago
  34. 7ed065b netfilter: nf_tables: store transaction list locally while requesting module by Pablo Neira Ayuso · 4 years, 7 months ago
  35. 1632efb netfilter: nf_tables: remove WARN and add NLA_STRING upper limits by Florian Westphal · 4 years, 7 months ago
  36. 6de941c netfilter: nft_tunnel: fix null-attribute check by Florian Westphal · 4 years, 7 months ago
  37. dcefdef netfilter: fix a use-after-free in mtype_destroy() by Cong Wang · 4 years, 7 months ago
  38. 28de8b9 netfilter: ipset: avoid null deref when IPSET_ATTR_LINENO is present by Florian Westphal · 4 years, 7 months ago
  39. df39bb2 netfilter: conntrack: dccp, sctp: handle null timeout argument by Florian Westphal · 4 years, 7 months ago
  40. 84133b6 netfilter: nf_tables: validate NFT_DATA_VALUE after nft_data_init() by Pablo Neira Ayuso · 4 years, 8 months ago
  41. dc330d9 netfilter: nf_tables: validate NFT_SET_ELEM_INTERVAL_END by Pablo Neira Ayuso · 4 years, 8 months ago
  42. 80a035e netfilter: nft_set_rbtree: bogus lookup/get on consecutive elements in named sets by Pablo Neira Ayuso · 4 years, 8 months ago
  43. 9e0f4d2 netfilter: ctnetlink: netns exit must wait for callbacks by Florian Westphal · 4 years, 9 months ago
  44. da7504b netfilter: nft_tproxy: Fix port selector on Big Endian by Phil Sutter · 4 years, 8 months ago
  45. 8bf95f2 net: add bool confirm_neigh parameter for dst_ops.update_pmtu by Hangbin Liu · 4 years, 7 months ago
  46. 766e42d6 netfilter: nf_queue: enqueue skbs with NULL dst by Marco Oliverio · 4 years, 8 months ago
  47. 2d48408 netfilter: nf_tables: don't use position attribute on rule replacement by Florian Westphal · 6 years ago
  48. d398807 netfilter: nf_tables: fix a missing check of nla_put_failure by Kangjie Lu · 6 years ago
  49. d1dbff4 netfilter: nf_nat_sip: fix RTP/RTCP source port translations by Alin Nastac · 6 years ago
  50. 9089b2f netfilter: nft_compat: do not dump private area by Pablo Neira Ayuso · 6 years ago
  51. e97d092 netfilter: nf_tables: avoid BUG_ON usage by Florian Westphal · 6 years ago
  52. d32629d netfilter: ipset: Copy the right MAC address in hash:ip,mac IPv6 sets by Stefano Brivio · 4 years, 10 months ago
  53. 50e3131 ipvs: move old_secure_tcp into struct netns_ipvs by Eric Dumazet · 4 years, 9 months ago
  54. 102f407 ipvs: don't ignore errors in case refcounting ip_vs module fails by Davide Caratti · 4 years, 10 months ago
  55. 81de0b5 netfilter: nf_flow_table: set timeout before insertion into hashes by Pablo Neira Ayuso · 4 years, 10 months ago
  56. 64997ee netfilter: ipset: Fix an error code in ip_set_sockfn_get() by Dan Carpenter · 5 years ago
  57. d8187ff netfilter: ipset: Make invalid MAC address checks consistent by Stefano Brivio · 6 years ago
  58. a16a9c1 netfilter: nft_connlimit: disable bh on garbage collection by Pablo Neira Ayuso · 4 years, 10 months ago
  59. f7ace7f netfilter: nf_tables: allow lookups in dynamic sets by Florian Westphal · 4 years, 11 months ago
  60. 6934809 netfilter: nft_socket: fix erroneous socket assignment by Fernando Fernandez Mancera · 5 years ago
  61. 6075729 netfilter: nf_conntrack_ftp: Fix debug output by Thomas Jarosch · 5 years ago
  62. 7ac5947 netfilter: xt_physdev: Fix spurious error message in physdev_mt_check by Todd Seidelmann · 5 years ago
  63. 4e5fbcb netfilter: xt_nfacct: Fix alignment mismatch in xt_nfacct_match_info by Juliana Rodrigueiro · 5 years ago
  64. a02c676 netfilter: nft_flow_offload: missing netlink attribute policy by Pablo Neira Ayuso · 5 years ago
  65. 2a0aa8a netfilter: nf_flow_table: set default timeout after successful insertion by Pablo Neira Ayuso · 5 years ago
  66. a54fa5d netfilter: nft_flow_offload: skip tcp rst and fin packets by Pablo Neira Ayuso · 5 years ago
  67. 5776970 netfilter: nf_tables: use-after-free in failing rule with bound set by Pablo Neira Ayuso · 5 years ago
  68. 63dd147 netfilter: ipset: Fix rename concurrency with listing by Jozsef Kadlecsik · 5 years ago
  69. ea08214 netfilter: ipset: Copy the right MAC address in bitmap:ip,mac and hash:ip,mac sets by Stefano Brivio · 5 years ago
  70. 5a072ef netfilter: ipset: Actually allow destination MAC address for hash:ip,mac sets too by Stefano Brivio · 5 years ago
  71. 28ff7d3 netfilter: conntrack: Use consistent ct id hash calculation by Dirk Morris · 5 years ago
  72. 36b6458 netfilter: nft_hash: fix symhash with modulus one by Laura Garcia Liebana · 5 years ago
  73. 6f1d7f0 netfilter: conntrack: always store window size un-scaled by Florian Westphal · 5 years ago
  74. bb312b4 netfilter: nfnetlink: avoid deadlock due to synchronous request_module by Florian Westphal · 5 years ago
  75. 832d0ea net: make skb_dst_force return true when dst is refcounted by Florian Westphal · 5 years ago
  76. fe2ceeb ipvs: fix tinfo memory leak in start_sync_thread by Julian Anastasov · 5 years ago
  77. 57de3c7 ipvs: defer hook registration to avoid leaks by Julian Anastasov · 5 years ago
  78. ac51028 ipset: Fix memory accounting for hash types on resize by Stefano Brivio · 5 years ago
  79. c549680 netfilter: nft_flow_offload: IPCB is only valid for ipv4 family by Florian Westphal · 5 years ago
  80. 041c181 netfilter: nft_flow_offload: don't offload when sequence numbers need adjustment by Florian Westphal · 5 years ago
  81. 48f611e netfilter: nft_flow_offload: set liberal tracking mode for tcp by Florian Westphal · 5 years ago
  82. 3b2734b netfilter: nf_flow_table: ignore DF bit setting by Florian Westphal · 5 years ago
  83. 61c83de6 ipvs: Fix use-after-free in ip_vs_in by YueHaibing · 5 years ago
  84. 883ce78 netfilter: nf_queue: fix reinject verdict handling by Jagdish Motwani · 5 years ago
  85. 028b3d8 netfilter: nf_flow_table: fix netdev refcnt leak by Taehee Yoo · 5 years ago
  86. 650a4b7 netfilter: nf_flow_table: check ttl value in flow offload data path by Taehee Yoo · 5 years ago
  87. dc58e40 netfilter: nf_tables: fix base chain stat rcu_dereference usage by Florian Westphal · 5 years ago
  88. 2aed9df netfilter: nf_conntrack_h323: restore boundary check correctness by Jakub Jankowski · 5 years ago
  89. d094198 netfilter: nf_flow_table: fix missing error check for rhashtable_insert_fast by Taehee Yoo · 5 years ago
  90. 0276ebf jump_label: move 'asm goto' support test to Kconfig by Masahiro Yamada · 6 years ago
  91. c18731c netfilter: nf_tables: add missing ->release_ops() in error path of newrule() by Taehee Yoo · 5 years ago
  92. 5014aa9 netfilter: nf_tables: use-after-free in dynamic operations by Pablo Neira Ayuso · 5 years ago
  93. 3a53fa4 netfilter: fix nf_l4proto_log_invalid to log invalid packets by Andrei Vagin · 5 years ago
  94. 743a5a9 netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook() by Dan Carpenter · 5 years ago
  95. 7b11575 netfilter: ctnetlink: don't use conntrack/expect object addresses as id by Florian Westphal · 5 years ago
  96. 4e1994e ipvs: do not schedule icmp errors from tunnels by Julian Anastasov · 5 years ago
  97. 506375f netfilter: fix NETFILTER_XT_TARGET_TEE dependencies by Arnd Bergmann · 5 years ago
  98. 5f7e5b9b netfilter: nft_set_rbtree: check for inactive element after flag mismatch by Pablo Neira Ayuso · 5 years ago
  99. ae5e0c7 ipvs: fix warning on unused variable by Andrea Claudi · 5 years ago
  100. ffc1d85 netfilter: nf_tables: bogus EBUSY in helper removal from transaction by Pablo Neira Ayuso · 5 years ago