文件最后提交记录最后更新时间
netfilter: ipset: Missing gc cancellations fixed1 年前
ipvs: avoid stat macros calls from preemptible context1 年前
netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y3 年前
add quota2 patch3 年前
Remove DECnet support from kernel2 年前
netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()11 个月前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: conntrack: clamp maximum hashtable size to INT_MAX1 年前
CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack15 天前
CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack15 天前
netfilter: conntrack: remove two export symbols6 年前
treewide: Remove uninitialized_var() usage5 年前
netfilter: Use fallthrough pseudo-keyword5 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 4846 年前
netfilter: nf_conntrack_helper: pass helper to expect cleanup15 天前
netfilter: nf_conntrack_irc: Fix forged IP logic3 年前
netfilter: not mark a spinlock as __read_mostly6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 1526 年前
CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack15 天前
netfilter: delete repeated words5 年前
netfilter: conntrack: unregister ipv4 sockopts on error unwind4 年前
netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one2 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: conntrack: Fix gre tunneling over ipv65 年前
netfilter: ctnetlink: add kernel side filtering for dump5 年前
netfilter: conntrack: set icmpv6 redirects as RELATED3 年前
netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp1 年前
netfilter: ctnetlink: use netlink policy range checks30 天前
netfilter: conntrack: set on IPS_ASSURED if flows enters internal stream state3 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: conntrack, nat: prefer skb_ensure_writable6 年前
!1938 merge cve-fix-20260519-master into master16 天前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 1526 年前
netfilter: conntrack: fix possible bug_on with enable_hooks=12 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: update include directives.6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 776 年前
netfilter: nf_fwd_netdev: clear timestamp in forwarding path5 年前
netfilter: conntrack: annotate data-races around ct->timeout3 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: flowtable: reduce calls to pskb_may_pull()5 年前
netfilter: flowtable: initialise extack before use1 年前
netfilter: ctnetlink: add kernel side filtering for dump5 年前
netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger1 年前
netfilter: nf_log: missing vlan offload tag and proto5 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: nf_nat: Fix memleak in nf_nat_init5 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net6 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: nf_nat_masquerade: defer conntrack walk to work queue4 年前
netfilter: nf_nat: undo erroneous tcp edemux lookup5 年前
netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses1 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: nf_conntrack_sip: fix expectation clash6 年前
netfilter: nf_queue: handle socket prefetch3 年前
netfilter: switch nf_setsockopt to sockptr_t5 年前
lsm,selinux: pass flowi_common instead of flowi to the LSM hooks3 年前
netfilter: nf_tables: reject immediate NF_QUEUE verdict15 天前
netfilter: nf_tables: add and use nft_thoff helper2 年前
netfilter: nf_tables: use net_generic infra for transaction data2 年前
netfilter: nf_tables: add and use nft_thoff helper2 年前
netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM2 年前
netfilter: add helper function to set up the nfnetlink header and use it3 年前
netfilter: add helper function to set up the nfnetlink header and use it3 年前
netfilter: add helper function to set up the nfnetlink header and use it3 年前
netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator15 天前
nfnetlink_osf: validate individual option lengths in fingerprints27 天前
netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()1 年前
netfilter: nf_tables: upfront validation of data via nft_data_init()3 年前
netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()1 年前
netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain1 年前
netfilter: nft_chain_nat: inet family is missing module ownership6 年前
netfilter: use actual socket sk rather than skb sk when routing harder5 年前
netfilter: nf_tables: upfront validation of data via nft_data_init()3 年前
netfilter: nft_compat: restrict match/target protocol to u161 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: nft_ct: drop pending enqueued packets on removal15 天前
netfilter: nftables: add nft_parse_register_load() and use it3 年前
netfilter: nft_dynset: disallow object maps2 年前
netfilter: nf_tables: fix 'exist' matching on bigendian arches1 年前
netfilter: nf_tables: fix 'exist' matching on bigendian arches1 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: nftables: add nft_parse_register_load() and use it3 年前
netfilter: nftables: add nft_parse_register_store() and use it3 年前
netfilter: nft_immediate: drop chain reference counter on error1 年前
netfilter: nft_limit: avoid possible divide error in nft_limit_init5 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: nf_tables: deactivate anonymous set from preparation phase3 年前
netfilter: nft_masq: correct length for loading protocol registers2 年前
netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()1 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: use get_random_u32 instead of prandom3 年前
netfilter: nf_tables: report use refcount overflow2 年前
netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families3 年前
netfilter: nft_payload: fix wrong mac header matching1 年前
netfilter: nftables: add nft_parse_register_load() and use it3 年前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: nf_tables: upfront validation of data via nft_data_init()3 年前
netfilter: nft_redir: use struct nf_nat_range2 throughout and deduplicate eval call-backs1 年前
netfilter: introduce support for reject at prerouting stage5 年前
netfilter: nf_tables: add and use nft_sk helper2 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: nf_tables: drop map element references from preparation phase2 年前
netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration2 年前
netfilter: nft_set_pipapo: skip inactive elements during set walk3 个月前
netfilter: nft_set_pipapo: remove scratch_aligned pointer1 年前
netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry15 天前
x86: update AS_* macros to binutils >=2.23, supporting ADX and AVX26 年前
netfilter: nft_set_rbtree: skip end interval element from gc1 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: nft_tunnel: restrict it to netdev family3 年前
netfilter: nf_tables: validate NFPROTO_* family1 年前
netfilter: use actual socket sk rather than skb sk when routing harder5 年前
netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP30 天前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
netfilter: xt_CT: drop pending enqueued packets on template removal30 天前
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net6 年前
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net6 年前
netfilter: xt_HMARK: Use ip_is_fragment() helper5 年前
netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels27 天前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xtables: fix typo causing some targets not to load on IPv61 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
netfilter: nft_redir: use struct nf_nat_range2 throughout and deduplicate eval call-backs1 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net6 年前
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 36 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xtables: fix typo causing some targets not to load on IPv61 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: x_tables: ensure names are nul-terminated15 天前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
treewide: Add SPDX license identifier for more missed files6 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
netfilter: xtables: avoid NFPROTO_UNSPEC where needed1 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: Replace zero-length array with flexible-array member6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 1526 年前
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next6 年前
treewide: Add SPDX license identifier for more missed files6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xtables: fix typo causing some targets not to load on IPv61 年前
netfilter: xt_multiport: validate range encoding in checkentry30 天前
netfilter: Add MODULE_DESCRIPTION entries to kernel modules5 年前
netfilter: Replace HTTP links with HTTPS ones5 年前
netfilter: nfnetlink_osf: fix module autoload2 年前
netfilter: xt_owner: Fix for unsafe access of sk->sk_socket1 年前
netfilter: inline xt_hashlimit, ebt_802_3 and xt_physdev headers6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Add SPDX license identifier for more missed files6 年前
add quota2 patch3 年前
netfilter: x_tables: ensure names are nul-terminated15 天前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
netfilter: xt_recent: fix (increase) ipv6 literal buffer length1 年前
License cleanup: add SPDX GPL-2.0 license identifier to files with no license8 年前
netfilter: xt_sctp: validate the flag_info count2 年前
netfilter: inline four headers files into another one.6 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 5006 年前
treewide: Add SPDX license identifier for more missed files6 年前
netfilter: Replace HTTP links with HTTPS ones5 年前
netfilter: xt_u32: validate user space input2 年前