- 120fb31 selinux: initialize proto variable in selinux_ip_postroute_compat() by Tom Rix · 2 years, 11 months ago
- a269586 smackfs: use netlbl_cfg_cipsov4_del() for deleting cipso_v4_doi by Tetsuo Handa · 3 years, 1 month ago
- 5e44e73 smackfs: use __GFP_NOFAIL for smk_cipso_doi() by Tetsuo Handa · 3 years, 1 month ago
- 7e175e3 smackfs: Fix use-after-free in netlbl_catmap_walk() by Pawan Gupta · 3 years, 3 months ago
- a5907f3 evm: mark evm_fixmode as __ro_after_init by Austin Kim · 3 years, 1 month ago
- 22d4a6d binder: use cred instead of task for selinux checks by Todd Kjos · 3 years, 1 month ago
- 687a0bf Smack: Fix wrong semantics in smk_access_entry() by Tianjia Zhang · 3 years, 4 months ago
- 749e646 IMA: remove -Wmissing-prototypes warning by Austin Kim · 3 years, 5 months ago
- 5f988040 smackfs: restrict bytes count in smk_set_cipso() by Tetsuo Handa · 3 years, 7 months ago
- a6414f9 selinux: use __GFP_NOWARN with GFP_NOWAIT in the AVC by Minchan Kim · 3 years, 5 months ago
- db89bac smackfs: restrict bytes count in smackfs write functions by Sabyrzhan Tasbolatov · 3 years, 10 months ago
- 22ac48d KEYS: trusted: Fix migratable=1 failing by Jarkko Sakkinen · 3 years, 10 months ago
- e8fbf06 dump_common_audit_data(): fix racy accesses to ->d_name by Al Viro · 3 years, 11 months ago
- ff0ad9d ima: Don't ignore errors from crypto_shash_update() by Roberto Sassu · 4 years, 3 months ago
- 51d729d selinux: sel_avc_get_stat_idx should increase position index by Vasily Averin · 4 years, 10 months ago
- 0433926 Smack: prevent underflow in smk_set_cipso() by Dan Carpenter · 4 years, 4 months ago
- 5edf79a Smack: fix another vsscanf out of bounds by Dan Carpenter · 4 years, 4 months ago
- 698080a Smack: fix use-after-free in smk_write_relabel_self() by Eric Biggers · 4 years, 5 months ago
- 3062787 selinux: fix double free by Tom Rix · 4 years, 5 months ago
- 4b9d238 evm: Fix possible memory leak in evm_calc_hmac_or_hash() by Roberto Sassu · 4 years, 7 months ago
- 63125a4 ima: Directly assign the ima_default_policy pointer to ima_rules by Roberto Sassu · 4 years, 6 months ago
- 446e391 ima: Fix ima digest hash table key calculation by Krzysztof Struczynski · 4 years, 7 months ago
- d901002 Smack: slab-out-of-bounds in vsscanf by Casey Schaufler · 4 years, 8 months ago
- 8a093d4 exec: Always set cap_ambient in cap_bprm_set_creds by Eric W. Biederman · 4 years, 6 months ago
- d8d4da8 ima: Fix return value of ima_write_policy() by Roberto Sassu · 4 years, 7 months ago
- ab97e5a evm: Check also if *tfm is an error pointer in init_desc() by Roberto Sassu · 4 years, 7 months ago
- 6affa87 selinux: properly handle multiple messages in selinux_netlink_send() by Paul Moore · 4 years, 7 months ago
- e7681c2 KEYS: reaching the keys quotas correctly by Yang Xu · 4 years, 9 months ago
- 23a0b5a selinux: ensure we cleanup the internal AVC counters on error in avc_update() by Jaihind Yadav · 5 years ago
- a9b6e55 keys: Timestamp new keys by David Howells · 6 years ago
- 1e42dec ima: always return negative code for error by Sascha Hauer · 5 years ago
- 1e4c7ce smack: use GFP_NOFS while holding inode_smack::smk_lock by Eric Biggers · 5 years ago
- 128373c Smack: Don't ignore other bprm->unsafe flags if LSM_UNSAFE_PTRACE is set by Jann Horn · 5 years ago
- 5f0b9f0 security: smack: Fix possible null-pointer dereferences in smack_socket_sock_rcv_skb() by Jia-Ju Bai · 5 years ago
- b94178b keys: Fix missing null pointer check in request_key_auth_describe() by Hillf Danton · 5 years ago
- ae190f0 selinux: fix memory leak in policydb_init() by Ondrej Mosnacek · 5 years ago
- 4a60589 apparmor: enforce nullbyte at end of tag string by Jann Horn · 5 years ago
- 869d1e4 selinux: never allow relabeling on context mounts by Ondrej Mosnacek · 6 years ago
- b2b2862 device_cgroup: fix RCU imbalance in error case by Jann Horn · 6 years ago
- 992baf5 selinux: do not override context on context mounts by Ondrej Mosnacek · 6 years ago
- 713b91c missing barriers in some of unix_sock ->addr and ->path accesses by Al Viro · 6 years ago
- ccc2aae KEYS: restrict /proc/keys by credentials at open time by Eric Biggers · 7 years ago
- dc070cd KEYS: always initialize keyring_index_key::desc_len by Eric Biggers · 6 years ago
- 6704b9d KEYS: allow reaching the keys quotas exactly by Eric Biggers · 6 years ago
- f096ede smack: fix access permissions for keyring by Zoran Markovic · 6 years ago
- 62044cb selinux: always allow mounting submounts by Ondrej Mosnacek · 6 years ago
- aedbb45 selinux: fix GPF on invalid policy by Stephen Smalley · 6 years ago
- a017e39 LSM: Check for NULL cred-security on free by James Morris · 6 years ago
- 4fd72a1 Yama: Check for pid death before checking ancestry by Kees Cook · 6 years ago
- 1f89834 ima: re-initialize iint->atomic_flags by Mimi Zohar · 7 years ago
- 166f454 ima: re-introduce own integrity cache lock by Dmitry Kasatkin · 7 years ago
- 87043e4 EVM: Add support for portable signature format by Matthew Garrett · 7 years ago
- 5f9fb1a ima: always measure and audit files in policy by Mimi Zohar · 7 years ago
- 5fed1ff Revert "evm: Translate user/group ids relative to s_user_ns when computing HMAC" by Eric W. Biederman · 8 years ago
- 47ff762 selinux: Add __GFP_NOWARN to allocation at str_read() by Tetsuo Handa · 6 years ago
- 53de32d ima: fix showing large 'violations' or 'runtime_measurements_count' by Eric Biggers · 6 years ago
- eddbab1 evm: Don't deadlock if a crypto algorithm is unavailable by Matthew Garrett · 6 years ago
- a64fa27 Smack: Fix handling of IPv4 traffic received by PF_INET6 sockets by Piotr Sawicki · 6 years ago
- d1f534f selinux: use GFP_NOWAIT in the AVC kmem_caches by Michal Hocko · 7 years ago
- ebc6dcb Smack: Mark inode instant in smack_task_to_inode by Casey Schaufler · 6 years ago
- 81be552 ima: based on policy verify firmware signatures (pre-allocated buffer) by Mimi Zohar · 7 years ago
- c738c80 selinux: KASAN: slab-out-of-bounds in xattr_getsecurity by Sachin Grover · 6 years ago
- 28fffa9 Revert "ima: limit file hash setting by user to fix and log modes" by Mimi Zohar · 8 years ago
- 99d8240 ima: Fallback to the builtin hash algorithm by Petr Vorel · 7 years ago
- 8a5a436 integrity/security: fix digsig.c build error with header file by Randy Dunlap · 7 years ago
- b983b2a selinux: do not check open permission on sockets by Stephen Smalley · 8 years ago
- 1978d82 selinux: Remove redundant check for unknown labeling behavior by Matthias Kaehlcke · 8 years ago
- 00972ac selinux: Remove unnecessary check of array base in selinux_set_mapping() by Matthias Kaehlcke · 8 years ago
- 27a0856 ima: relax requiring a file signature for new files with zero length by Mimi Zohar · 7 years ago
- d55a55b apparmor: Make path_max parameter readonly by John Johansen · 8 years ago
- b243aa8 selinux: check for address length in selinux_socket_bind() by Alexander Potapenko · 8 years ago
- 077463b security/keys: BIG_KEY requires CONFIG_CRYPTO by Arnd Bergmann · 7 years ago
- 5e6f51a selinux: skip bounded transition processing if the policy isn't loaded by Paul Moore · 7 years ago
- fe1cb58 selinux: ensure the context is NUL terminated in security_context_to_sid_core() by Paul Moore · 7 years ago
- 9692602 KEYS: encrypted: fix buffer overread in valid_master_desc() by Eric Biggers · 7 years ago
- e71fac0 KPTI: Rename to PAGE_TABLE_ISOLATION by Kees Cook · 7 years ago
- 2c27217 x86/kaiser: Reenable PARAVIRT by Borislav Petkov · 7 years ago
- 1ce27de kaiser: delete KAISER_REAL_SWITCH option by Hugh Dickins · 7 years ago
- 639c005 kaiser: KAISER depends on SMP by Hugh Dickins · 7 years ago
- 8f0baad kaiser: merged update by Dave Hansen · 7 years ago
- 13be448 KAISER: Kernel Address Isolation by Richard Fellner · 8 years ago
- 982707e KEYS: add missing permission check for request_key() destination by Eric Biggers · 7 years ago
- b0a4608 ima: fix hash algorithm initialization by Boshi Wang · 7 years ago
- 2cfbb32 ima: do not update security.ima if appraisal status is not INTEGRITY_PASS by Roberto Sassu · 7 years ago
- 31c8c49 security/keys: add CONFIG_KEYS_COMPAT to Kconfig by Bilal Amarni · 7 years ago
- 419ec34 KEYS: trusted: fix writing past end of buffer in trusted_read() by Eric Biggers · 7 years ago
- 64a2345 KEYS: trusted: sanitize all key material by Eric Biggers · 7 years ago
- ab71bee apparmor: fix undefined reference to `aa_g_hash_policy' by John Johansen · 8 years ago
- 0be72ae KEYS: return full count in keyring_read() if buffer is too small by Eric Biggers · 7 years ago
- 63c8e45 KEYS: Fix race between updating and finding a negative key by David Howells · 7 years ago
- da0c750 KEYS: don't let add_key() update an uninstantiated key by David Howells · 7 years ago
- fec442e KEYS: encrypted: fix dereference of NULL user_key_payload by Eric Biggers · 7 years ago
- 88c195d lsm: fix smack_inode_removexattr and xattr_getsecurity memleak by Casey Schaufler · 7 years ago
- dda70d2 KEYS: prevent KEYCTL_READ on negative key by Eric Biggers · 7 years ago
- bfe9d7b KEYS: prevent creating a different user's keyrings by Eric Biggers · 7 years ago
- 47e8bd1 KEYS: fix writing past end of user-supplied buffer in keyring_read() by Eric Biggers · 7 years ago
- 0c70fb8 security/keys: rewrite all of big_key crypto by Jason A. Donenfeld · 7 years ago
- 2f9be92 security/keys: properly zero out sensitive key material in big_key by Jason A. Donenfeld · 7 years ago
- 73a0a68 KEYS: Fix an error code in request_master_key() by Dan Carpenter · 8 years ago
- d24c1c1 KEYS: encrypted: avoid encrypting/decrypting stack buffers by Eric Biggers · 7 years ago