| netfilter: ipset: Missing gc cancellations fixed | 1 年前 |
| ipvs: avoid stat macros calls from preemptible context | 1 年前 |
| netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y | 3 年前 |
| add quota2 patch | 3 年前 |
| Remove DECnet support from kernel | 2 年前 |
| netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() | 11 个月前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: conntrack: clamp maximum hashtable size to INT_MAX | 1 年前 |
| CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack | 15 天前 |
| CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack | 15 天前 |
| netfilter: conntrack: remove two export symbols | 6 年前 |
| treewide: Remove uninitialized_var() usage | 5 年前 |
| netfilter: Use fallthrough pseudo-keyword | 5 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 484 | 6 年前 |
| netfilter: nf_conntrack_helper: pass helper to expect cleanup | 15 天前 |
| netfilter: nf_conntrack_irc: Fix forged IP logic | 3 年前 |
| netfilter: not mark a spinlock as __read_mostly | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152 | 6 年前 |
| CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack | 15 天前 |
| netfilter: delete repeated words | 5 年前 |
| netfilter: conntrack: unregister ipv4 sockopts on error unwind | 4 年前 |
| netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one | 2 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: conntrack: Fix gre tunneling over ipv6 | 5 年前 |
| netfilter: ctnetlink: add kernel side filtering for dump | 5 年前 |
| netfilter: conntrack: set icmpv6 redirects as RELATED | 3 年前 |
| netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp | 1 年前 |
| netfilter: ctnetlink: use netlink policy range checks | 30 天前 |
| netfilter: conntrack: set on IPS_ASSURED if flows enters internal stream state | 3 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: conntrack, nat: prefer skb_ensure_writable | 6 年前 |
| !1938 merge cve-fix-20260519-master into master | 16 天前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152 | 6 年前 |
| netfilter: conntrack: fix possible bug_on with enable_hooks=1 | 2 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: update include directives. | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 77 | 6 年前 |
| netfilter: nf_fwd_netdev: clear timestamp in forwarding path | 5 年前 |
| netfilter: conntrack: annotate data-races around ct->timeout | 3 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: flowtable: reduce calls to pskb_may_pull() | 5 年前 |
| netfilter: flowtable: initialise extack before use | 1 年前 |
| netfilter: ctnetlink: add kernel side filtering for dump | 5 年前 |
| netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger | 1 年前 |
| netfilter: nf_log: missing vlan offload tag and proto | 5 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: nf_nat: Fix memleak in nf_nat_init | 5 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net | 6 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: nf_nat_masquerade: defer conntrack walk to work queue | 4 年前 |
| netfilter: nf_nat: undo erroneous tcp edemux lookup | 5 年前 |
| netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses | 1 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: nf_conntrack_sip: fix expectation clash | 6 年前 |
| netfilter: nf_queue: handle socket prefetch | 3 年前 |
| netfilter: switch nf_setsockopt to sockptr_t | 5 年前 |
| lsm,selinux: pass flowi_common instead of flowi to the LSM hooks | 3 年前 |
| netfilter: nf_tables: reject immediate NF_QUEUE verdict | 15 天前 |
| netfilter: nf_tables: add and use nft_thoff helper | 2 年前 |
| netfilter: nf_tables: use net_generic infra for transaction data | 2 年前 |
| netfilter: nf_tables: add and use nft_thoff helper | 2 年前 |
| netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM | 2 年前 |
| netfilter: add helper function to set up the nfnetlink header and use it | 3 年前 |
| netfilter: add helper function to set up the nfnetlink header and use it | 3 年前 |
| netfilter: add helper function to set up the nfnetlink header and use it | 3 年前 |
| netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator | 15 天前 |
| nfnetlink_osf: validate individual option lengths in fingerprints | 27 天前 |
| netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu() | 1 年前 |
| netfilter: nf_tables: upfront validation of data via nft_data_init() | 3 年前 |
| netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval() | 1 年前 |
| netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain | 1 年前 |
| netfilter: nft_chain_nat: inet family is missing module ownership | 6 年前 |
| netfilter: use actual socket sk rather than skb sk when routing harder | 5 年前 |
| netfilter: nf_tables: upfront validation of data via nft_data_init() | 3 年前 |
| netfilter: nft_compat: restrict match/target protocol to u16 | 1 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: nft_ct: drop pending enqueued packets on removal | 15 天前 |
| netfilter: nftables: add nft_parse_register_load() and use it | 3 年前 |
| netfilter: nft_dynset: disallow object maps | 2 年前 |
| netfilter: nf_tables: fix 'exist' matching on bigendian arches | 1 年前 |
| netfilter: nf_tables: fix 'exist' matching on bigendian arches | 1 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: nftables: add nft_parse_register_load() and use it | 3 年前 |
| netfilter: nftables: add nft_parse_register_store() and use it | 3 年前 |
| netfilter: nft_immediate: drop chain reference counter on error | 1 年前 |
| netfilter: nft_limit: avoid possible divide error in nft_limit_init | 5 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: nf_tables: deactivate anonymous set from preparation phase | 3 年前 |
| netfilter: nft_masq: correct length for loading protocol registers | 2 年前 |
| netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval() | 1 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: use get_random_u32 instead of prandom | 3 年前 |
| netfilter: nf_tables: report use refcount overflow | 2 年前 |
| netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families | 3 年前 |
| netfilter: nft_payload: fix wrong mac header matching | 1 年前 |
| netfilter: nftables: add nft_parse_register_load() and use it | 3 年前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: nf_tables: upfront validation of data via nft_data_init() | 3 年前 |
| netfilter: nft_redir: use struct nf_nat_range2 throughout and deduplicate eval call-backs | 1 年前 |
| netfilter: introduce support for reject at prerouting stage | 5 年前 |
| netfilter: nf_tables: add and use nft_sk helper | 2 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: nf_tables: drop map element references from preparation phase | 2 年前 |
| netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration | 2 年前 |
| netfilter: nft_set_pipapo: skip inactive elements during set walk | 3 个月前 |
| netfilter: nft_set_pipapo: remove scratch_aligned pointer | 1 年前 |
| netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry | 15 天前 |
| x86: update AS_* macros to binutils >=2.23, supporting ADX and AVX2 | 6 年前 |
| netfilter: nft_set_rbtree: skip end interval element from gc | 1 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: nft_tunnel: restrict it to netdev family | 3 年前 |
| netfilter: nf_tables: validate NFPROTO_* family | 1 年前 |
| netfilter: use actual socket sk rather than skb sk when routing harder | 5 年前 |
| netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP | 30 天前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| netfilter: xt_CT: drop pending enqueued packets on template removal | 30 天前 |
| Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net | 6 年前 |
| Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net | 6 年前 |
| netfilter: xt_HMARK: Use ip_is_fragment() helper | 5 年前 |
| netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels | 27 天前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xtables: fix typo causing some targets not to load on IPv6 | 1 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| netfilter: nft_redir: use struct nf_nat_range2 throughout and deduplicate eval call-backs | 1 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net | 6 年前 |
| Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 3 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xtables: fix typo causing some targets not to load on IPv6 | 1 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: x_tables: ensure names are nul-terminated | 15 天前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| treewide: Add SPDX license identifier for more missed files | 6 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| netfilter: xtables: avoid NFPROTO_UNSPEC where needed | 1 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: Replace zero-length array with flexible-array member | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152 | 6 年前 |
| Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next | 6 年前 |
| treewide: Add SPDX license identifier for more missed files | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xtables: fix typo causing some targets not to load on IPv6 | 1 年前 |
| netfilter: xt_multiport: validate range encoding in checkentry | 30 天前 |
| netfilter: Add MODULE_DESCRIPTION entries to kernel modules | 5 年前 |
| netfilter: Replace HTTP links with HTTPS ones | 5 年前 |
| netfilter: nfnetlink_osf: fix module autoload | 2 年前 |
| netfilter: xt_owner: Fix for unsafe access of sk->sk_socket | 1 年前 |
| netfilter: inline xt_hashlimit, ebt_802_3 and xt_physdev headers | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Add SPDX license identifier for more missed files | 6 年前 |
| add quota2 patch | 3 年前 |
| netfilter: x_tables: ensure names are nul-terminated | 15 天前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| netfilter: xt_recent: fix (increase) ipv6 literal buffer length | 1 年前 |
| License cleanup: add SPDX GPL-2.0 license identifier to files with no license | 8 年前 |
| netfilter: xt_sctp: validate the flag_info count | 2 年前 |
| netfilter: inline four headers files into another one. | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 | 6 年前 |
| treewide: Add SPDX license identifier for more missed files | 6 年前 |
| netfilter: Replace HTTP links with HTTPS ones | 5 年前 |
| netfilter: xt_u32: validate user space input | 2 年前 |