Show patches with: State = Action Required       |    Archived = No       |   145 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf,v3] netfilter: nft_payload: restrict checksum offsets to known values [nf,v3] netfilter: nft_payload: restrict checksum offsets to known values - 1 - - --- 2026-09-05 Florian Westphal New
[nf-next,v4,13/13] netfilter: ipset: improve lockdep coverage ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,12/13] netfilter: ipset: use plain rcu_read_lock ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,11/13] netfilter: ipset: remove trivial kvfree wrapper ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,10/13] netfilter: ipset: remove resize completely ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,09/13] netfilter: ipset: remove multi-flag ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,08/13] netfilter: ipset: remove last region lock usage ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,07/13] netfilter: ipset: remove obsolete data_next stubs ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,06/13] netfilter: ipset: also report mem size for cidr storage to userspace ipset: replace internal hash table with rhashtable - 1 - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,05/13] netfilter: ipset: re-add forceadd support ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,04/13] netfilter: ipset: replace internal hash table with rhashtable ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,03/13] netfilter: ipset: add rhltable boilerplate stubs ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,02/13] netfilter: ipset: add rhashtable boilerplate stubs ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf-next,v4,01/13] rhashtable: add rhashtable_flush_and_free helper ipset: replace internal hash table with rhashtable - - - - --- 2026-09-04 Florian Westphal New
[nf] netfilter: ipset: do not update comments from kernel-side adds [nf] netfilter: ipset: do not update comments from kernel-side adds - 1 - - --- 2026-09-04 Florian Westphal New
[nf-next] netfilter: conntrack: make filtering by zone discoverable [nf-next] netfilter: conntrack: make filtering by zone discoverable - - - - --- 2026-09-04 Ilya Maximets New
[nf,1/1] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read - 1 - - --- 2026-09-04 Ren Wei New
[net,2/2] selftests: forwarding: use KHDR_INCLUDES in CFLAGS selftests: net: use KHDR_INCLUDES in CFLAGS - 1 1 - --- 2026-09-04 Matthieu Baerts New
[net,1/2] selftests: netfilter: use KHDR_INCLUDES in CFLAGS selftests: net: use KHDR_INCLUDES in CFLAGS - 3 1 - --- 2026-09-04 Matthieu Baerts New
[nf,v3] netfilter: nfnetlink: Fix for interrupted hook dumps [nf,v3] netfilter: nfnetlink: Fix for interrupted hook dumps - 2 - - --- 2026-09-04 Phil Sutter New
net: netfilter: fix typo "specifiy" in comment net: netfilter: fix typo "specifiy" in comment - - - - --- 2026-09-04 Hemanth Selam New
[net] ipvs: shut down destination trash timer on netns cleanup [net] ipvs: shut down destination trash timer on netns cleanup - 1 - - --- 2026-09-04 Runyu Xiao New
[nf,v2] netfilter: nfnetlink: Fix for interrupted hook dumps [nf,v2] netfilter: nfnetlink: Fix for interrupted hook dumps - 2 - - --- 2026-09-03 Phil Sutter New
[net,v2] net/ipv6: don't route packets with unknown source address [net,v2] net/ipv6: don't route packets with unknown source address - 1 - - --- 2026-09-03 Íñigo Huguet New
[nf,v2,1/1] netfilter: nf_dup: disable duplication in user namespaces netfilter: nf_dup: disable duplication in user namespaces - 1 - - --- 2026-09-03 Zihan Xi New
[nf-next,v2,8/8] netfilter: ipset: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,7/8] netfilter: conncount: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,6/8] netfilter: nat: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,5/8] netfilter: sysctl: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,4/8] netfilter: synproxy: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,3/8] netfilter: nf_tables: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,2/8] netfilter: nfnetlink: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[net,12/12] netfilter: report NLM_F_DUMP_FILTERED when all is filtered out [net,01/12] ipvs: reject invalid states in connection template sync records - 1 1 - --- 2026-09-03 Pablo Neira Ayuso New
[net,11/12] netfilter: ip6_tables: set F_PROTO when proto value is nonzero [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,10/12] netfilter: arp_tables: remove the 32bit compat interface [net,01/12] ipvs: reject invalid states in connection template sync records - - - - --- 2026-09-03 Pablo Neira Ayuso New
[net,09/12] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,08/12] netfilter: nfnetlink_log: cope with concurrent instance destruction [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,07/12] netfilter: nft_payload: restrict checksum offsets to known values [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,06/12] ipvs: bound LBLCR and LBLC cache growth [net,01/12] ipvs: reject invalid states in connection template sync records 1 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,05/12] netfilter: nf_log: unregister loggers before per-net teardown [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,04/12] netfilter: cttimeout: prevent UAF during module unload [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,03/12] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,02/12] ipvs: fix reversed sequence option serialization [net,01/12] ipvs: reject invalid states in connection template sync records 1 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,01/12] ipvs: reject invalid states in connection template sync records [net,01/12] ipvs: reject invalid states in connection template sync records 1 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,00/12] Netfilter/IPVS fixes for net - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf,v3] netfilter: nf_nat: unregister and release hooks on error [nf,v3] netfilter: nf_nat: unregister and release hooks on error - 1 - - --- 2026-09-02 Pablo Neira Ayuso New
[nf-next,v2,2/2] selftests: netfilter: nft_flowtable.sh: check the priority a flow carries [nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload - - - - --- 2026-09-02 Julius Bairaktaris New
[nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload [nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload - - - - --- 2026-09-02 Julius Bairaktaris New
[nf-next,6/6] net: netfilter: nf_flow_table: unify tunnel push for IPv4 and IPv6 net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-01 Lorenzo Bianconi New
[nf-next,5/6] net: netfilter: add encap_proto to flow_offload_tunnel net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-01 Lorenzo Bianconi New
[nf-next,4/6] net: netfilter: nf_flow_table: refactor MTU check for tunnel offload net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-01 Lorenzo Bianconi New
[nf-next,3/6] net: netfilter: nf_flow_table: populate tunnel tuple regardless of inner protocol net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-01 Lorenzo Bianconi New
[nf-next,2/6] net: netfilter: nf_flow_table: set inner protocol when popping tunnel header net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-01 Lorenzo Bianconi New
[nf-next,1/6] net: netfilter: nf_flow_table: recognize IPv4/IPv6 in tunnel proto matching net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-01 Lorenzo Bianconi New
[nf,1/1] netfilter: x_tables: avoid holding mutex over faultable user copies netfilter: x_tables: avoid holding mutex over faultable user copies - 1 - - --- 2026-09-01 Zihan Xi New
[net] net/ipv6: don't route packets with unknown source address [net] net/ipv6: don't route packets with unknown source address - - - - --- 2026-09-01 Íñigo Huguet New
[nf,v3] netfilter: disable br_netfilter in user namespaces [nf,v3] netfilter: disable br_netfilter in user namespaces - - 1 - --- 2026-08-31 Florian Westphal New
[RESEND,nf-next] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() [RESEND,nf-next] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() - 1 - - --- 2026-08-31 luoqing New
[nf,1/1] netfilter: nf_dup: prevent asynchronous duplicate recursion netfilter: nf_dup: prevent asynchronous duplicate recursion - 1 - - --- 2026-08-29 Zihan Xi New
[nf] netfilter: nf_tables: Fix netdev hook sanity checks [nf] netfilter: nf_tables: Fix netdev hook sanity checks - 1 - - --- 2026-08-27 Phil Sutter New
[nf,v4] netfilter: nf_tables: fix device name and prefix match in hook lookup [nf,v4] netfilter: nf_tables: fix device name and prefix match in hook lookup - 1 - - --- 2026-08-27 Fernando Fernandez Mancera New
[nf,2/2] netfilter: flowtable: bump ct refcount before teardown [nf,v2,1/2] netfilter: flowtable: defer ct stats sync via worker - 1 - - --- 2026-08-26 Pablo Neira Ayuso New
[nf,v2,1/2] netfilter: flowtable: defer ct stats sync via worker [nf,v2,1/2] netfilter: flowtable: defer ct stats sync via worker - 1 - - --- 2026-08-26 Pablo Neira Ayuso New
[net,v2] netfilter: ipset: add synchronize_rcu() in destroy to close use-after-free race [net,v2] netfilter: ipset: add synchronize_rcu() in destroy to close use-after-free race - 1 - - --- 2026-08-25 Cen Zhang (Microsoft) New
[nft] payload: restore is_raw flag for th expressions parsed from udata [nft] payload: restore is_raw flag for th expressions parsed from udata - - - - --- 2026-08-25 Adrian Moisey New
netfilter: nft_nat: fully initialise new_addr in netmap setup netfilter: nft_nat: fully initialise new_addr in netmap setup - 1 - - --- 2026-08-25 Theodor Arsenij Larionov Trichkine New
[nf] netfilter: lwtunnel: expose read-only sysctl nf_hooks_lwtunnel for non init-netns [nf] netfilter: lwtunnel: expose read-only sysctl nf_hooks_lwtunnel for non init-netns - 1 - - --- 2026-08-24 Pablo Neira Ayuso New
[BUG] general protection fault in __instance_destroy [BUG] general protection fault in __instance_destroy - - - - --- 2026-08-24 Jaeyoung Chung New
netfilter: flowtable: flush delete work after final GC netfilter: flowtable: flush delete work after final GC - 1 - - --- 2026-08-24 Chengfeng Ye New
[net-next,v2] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() [net-next,v2] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() - - - - --- 2026-08-24 luoqing New
netfilter: nf_conntrack: avoid truncating IPv6 nexthdr offset netfilter: nf_conntrack: avoid truncating IPv6 nexthdr offset - 1 - - --- 2026-08-22 Jérémy Jean New
netfilter: bpf: disallow conntrack kfuncs for token programs netfilter: bpf: disallow conntrack kfuncs for token programs - 1 - - --- 2026-08-22 Jérémy Jean New
[nf-next,v2] netfilter: osf: remove unreachable break in nf_osf_ttl() [nf-next,v2] netfilter: osf: remove unreachable break in nf_osf_ttl() - - - - --- 2026-08-21 Linkui Xiao New
netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation - - - - --- 2026-08-20 Shaojie Sun New
[net] netfilter: ipset: list:set: defer ip_set_put_byindex to RCU callback [net] netfilter: ipset: list:set: defer ip_set_put_byindex to RCU callback - 1 - - --- 2026-08-20 Cen Zhang (Microsoft) New
[2/2,nf-next] netfilter: synproxy: fix reset of ct seqadj when reopening a connection [1/2,nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL - 1 - - --- 2026-08-19 Fernando Fernandez Mancera New
[1/2,nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL [1/2,nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL - - - - --- 2026-08-19 Fernando Fernandez Mancera New
netfilter: flowtable: publish HW_DEAD after worker is done netfilter: flowtable: publish HW_DEAD after worker is done - 1 - - --- 2026-08-18 Jérémy Jean New
[4/4] lib/ts_fsm: document that a match must consume the remaining data lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - - - - --- 2026-08-16 Bernard Ladenthin Under Review
[3/4] textsearch: align ts_state.cb like skb->cb lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - - - - --- 2026-08-16 Bernard Ladenthin Under Review
[2/4] lib/tests: add KUnit tests for the textsearch infrastructure lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - - - - --- 2026-08-16 Bernard Ladenthin Under Review
[1/4] lib/ts_bm: advance state->offset past the reported match lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - 1 - - --- 2026-08-16 Bernard Ladenthin Under Review
[nft,v2] evaluate: reject negative values for unsigned datatypes [nft,v2] evaluate: reject negative values for unsigned datatypes - 1 - - --- 2026-08-14 Avinash Duduskar New
[net,v2] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() [net,v2] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() - - - - --- 2026-08-14 Joas Antonio dos Santos New
[nft,2/2] tests: shell: add JSON delete test for ct stateful objects parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nft,1/2] parser_json: fix CMD_OBJ/NFT_OBJECT mismatch in delete path parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
netfilter: nf_conntrack: validate template helper protocol netfilter: nf_conntrack: validate template helper protocol - 1 - - --- 2026-08-10 Kyle Zeng Under Review
[nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress [nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress - 1 - - --- 2026-08-10 David Lee New
[nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers [nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers - - - - --- 2026-08-07 Zhixing Chen New
selftests: netfilter: add functional test for nft ct timeout policies selftests: netfilter: add functional test for nft ct timeout policies - - - - --- 2026-08-05 Valery Borovsky New
[net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path [net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path - - - - --- 2026-08-04 Alexandre Ferrieux New
[nf-next] netfilter: conntrack: sctp: validate vtag before state changes [nf-next] netfilter: conntrack: sctp: validate vtag before state changes - - - - --- 2026-07-31 Yizhou Zhao New
ipvs: clear IPv4 options after rebasing tunnel ICMP errors ipvs: clear IPv4 options after rebasing tunnel ICMP errors - 1 - - --- 2026-07-31 David Lee New
[conntrack-tools,v2] conntrack.8: Document --stats counters [conntrack-tools,v2] conntrack.8: Document --stats counters - - 1 - --- 2026-07-30 Phil Sutter New
[nf,1/1] netfilter: ebtables: avoid unbounded counter allocations netfilter: ebtables: avoid unbounded counter allocations - 1 - - --- 2026-07-27 Ren Wei New
[nf,1/1] ipvs: guard estimator enqueue until limits are set ipvs: guard estimator enqueue until limits are set - 1 - - --- 2026-07-27 Ren Wei New
[net,v2] net: flow_offload: serialize driver callback lists [net,v2] net: flow_offload: serialize driver callback lists - 1 - - --- 2026-07-26 Weiming Shi New
[nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay [nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay - 1 - - --- 2026-07-13 Weiming Shi New
[nf-next,v5] netfilter: flowtable: initial bridge support [nf-next,v5] netfilter: flowtable: initial bridge support - - - - --- 2026-07-13 Pablo Neira Ayuso New
« 1 2 »