Show patches with: State = Action Required       |   160 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf-next,4/4] netfilter: conntrack: Improve invalid packet stats netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,3/4] netfilter: conntrack: nf_ct_seq_adjust to return error cause netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,2/4] netfilter: conntrack: Untangle drop and invalid counters netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,1/4] netfilter: conntrack: Untangle insert_failed counter from others netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nft,v2] extend ct_label_set with a negative ct label match and switch to inline counter checks (.n… [nft,v2] extend ct_label_set with a negative ct label match and switch to inline counter checks (.n… - - - - --- 2026-09-08 Jiri Peska New
[nf] netfilter: xt_IDLETIMER: allocate timer with kzalloc() [nf] netfilter: xt_IDLETIMER: allocate timer with kzalloc() - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[nf] netfilter: flowtable: hold reference on ct until flow is released [nf] netfilter: flowtable: hold reference on ct until flow is released - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,8/8] netfilter: ipset: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,7/8] netfilter: conncount: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,6/8] netfilter: nat: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,5/8] netfilter: sysctl: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,4/8] netfilter: synproxy: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,3/8] netfilter: nf_tables: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,2/8] netfilter: nfnetlink: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf] ipvs: revalidate ihl before icmp_send [nf] ipvs: revalidate ihl before icmp_send - 2 - - --- 2026-09-07 Julian Anastasov New
[nf] ipvs: fix more races around the overload flag [nf] ipvs: fix more races around the overload flag - 1 - - --- 2026-09-07 Julian Anastasov New
[net,9/9] netfilter: report NLM_F_DUMP_FILTERED when all is filtered out [net,1/9] ipvs: reject invalid states in connection template sync records - 1 1 - --- 2026-09-07 Pablo Neira Ayuso New
[net,8/9] netfilter: ip6_tables: set F_PROTO when proto value is nonzero [net,1/9] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,7/9] netfilter: arp_tables: remove the 32bit compat interface [net,1/9] ipvs: reject invalid states in connection template sync records - - - - --- 2026-09-07 Pablo Neira Ayuso New
[net,6/9] netfilter: nfnetlink_log: cope with concurrent instance destruction [net,1/9] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,5/9] netfilter: nf_log: unregister loggers before per-net teardown [net,1/9] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,4/9] netfilter: cttimeout: prevent UAF during module unload [net,1/9] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,3/9] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() [net,1/9] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,2/9] ipvs: fix reversed sequence option serialization [net,1/9] ipvs: reject invalid states in connection template sync records 1 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,1/9] ipvs: reject invalid states in connection template sync records [net,1/9] ipvs: reject invalid states in connection template sync records 1 1 - - --- 2026-09-07 Pablo Neira Ayuso New
[net,v2,0/9] Netfilter/IPVS fixes for net - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf,1/1] netfilter: xt_IDLETIMER: restrict to init_net netfilter: xt_IDLETIMER: restrict to init_net - 1 - - --- 2026-09-07 Zhiling Zou New
[nf-next,v2,3/3] selftests: netfilter: fix typo "adress" in comment netfilter: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[nf-next,v2,2/3] netfilter: ipset: fix typo "artifical" in comment netfilter: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[nf-next,v2,1/3] netfilter: arp_tables: fix typo "alignement" in comment netfilter: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[nf-next,v2,6/6] net: netfilter: nf_flow_table: unify tunnel push for IPv4 and IPv6 net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,5/6] net: netfilter: nf_flow_table: refactor MTU check for tunnel offload net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,4/6] net: netfilter: add encap_proto to flow_offload_tunnel net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,3/6] net: netfilter: nf_flow_table: populate tunnel tuple regardless of inner protocol net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,2/6] net: netfilter: nf_flow_table: set inner protocol when popping tunnel header net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,1/6] net: netfilter: nf_flow_table: recognize IPv4/IPv6 in tunnel proto matching net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[3/3] selftests: net: fix typo "adress" in comment net: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[2/3] net: netfilter: fix typo "artifical" in comment net: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[1/3] net: ipv4: fix typo "alignement" in comment net: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
netfilter: nf_conntrack_h323: fix OOB read in decode_enum() netfilter: nf_conntrack_h323: fix OOB read in decode_enum() - 1 - - --- 2026-09-07 Aamir Ahmed New
netfilter: conntrack_amanda: fix port value truncation netfilter: conntrack_amanda: fix port value truncation - 1 1 - --- 2026-09-06 Aamir Ahmed New
netfilter: conntrack_irc: fix port value truncation in parse_dcc() netfilter: conntrack_irc: fix port value truncation in parse_dcc() - 1 - - --- 2026-09-06 Aamir Ahmed New
[nf] netfilter: flowtable: advertise the vlan match in used_keys [nf] netfilter: flowtable: advertise the vlan match in used_keys - 1 - - --- 2026-09-06 Julius Bairaktaris New
[nf,v2,1/1] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read - 1 - - --- 2026-09-06 Ren Wei New
[nf,v2] netfilter: ip6t_rpfilter: reject routes without inet6_dev [nf,v2] netfilter: ip6t_rpfilter: reject routes without inet6_dev - 1 - - --- 2026-09-06 Weiming Shi New
[nf,v3] netfilter: nft_payload: restrict checksum offsets to known values [nf,v3] netfilter: nft_payload: restrict checksum offsets to known values - 1 - - --- 2026-09-05 Florian Westphal New
[nf] netfilter: ipset: do not update comments from kernel-side adds [nf] netfilter: ipset: do not update comments from kernel-side adds - 1 - - --- 2026-09-04 Florian Westphal New
[nf-next] netfilter: conntrack: make filtering by zone discoverable [nf-next] netfilter: conntrack: make filtering by zone discoverable - - - - --- 2026-09-04 Ilya Maximets New
[nf,v3] netfilter: nfnetlink: Fix for interrupted hook dumps [nf,v3] netfilter: nfnetlink: Fix for interrupted hook dumps - 2 - - --- 2026-09-04 Phil Sutter New
net: netfilter: fix typo "specifiy" in comment net: netfilter: fix typo "specifiy" in comment - - - - --- 2026-09-04 Hemanth Selam New
[net] ipvs: shut down destination trash timer on netns cleanup [net] ipvs: shut down destination trash timer on netns cleanup - 1 - - --- 2026-09-04 Runyu Xiao New
[nf,v2] netfilter: nfnetlink: Fix for interrupted hook dumps [nf,v2] netfilter: nfnetlink: Fix for interrupted hook dumps - 2 - - --- 2026-09-03 Phil Sutter New
[net,v2] net/ipv6: don't route packets with unknown source address [net,v2] net/ipv6: don't route packets with unknown source address - 1 - - --- 2026-09-03 Íñigo Huguet New
[nf,v2,1/1] netfilter: nf_dup: disable duplication in user namespaces netfilter: nf_dup: disable duplication in user namespaces - 1 - - --- 2026-09-03 Zihan Xi New
[nf-next,v2,8/8] netfilter: ipset: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,7/8] netfilter: conncount: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,6/8] netfilter: nat: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,5/8] netfilter: sysctl: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,4/8] netfilter: synproxy: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,3/8] netfilter: nf_tables: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,2/8] netfilter: nfnetlink: use GFP_KERNEL_ACCOUNT [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target [nf-next,v2,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-03 Pablo Neira Ayuso New
[net,09/12] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,07/12] netfilter: nft_payload: restrict checksum offsets to known values [net,01/12] ipvs: reject invalid states in connection template sync records - 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[net,06/12] ipvs: bound LBLCR and LBLC cache growth [net,01/12] ipvs: reject invalid states in connection template sync records 1 1 - - --- 2026-09-03 Pablo Neira Ayuso New
[nf,v3] netfilter: nf_nat: unregister and release hooks on error [nf,v3] netfilter: nf_nat: unregister and release hooks on error - 1 - - --- 2026-09-02 Pablo Neira Ayuso New
[nf-next,v2,2/2] selftests: netfilter: nft_flowtable.sh: check the priority a flow carries [nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload - - - - --- 2026-09-02 Julius Bairaktaris New
[nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload [nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload - - - - --- 2026-09-02 Julius Bairaktaris New
[nf,1/1] netfilter: x_tables: avoid holding mutex over faultable user copies netfilter: x_tables: avoid holding mutex over faultable user copies - 1 - - --- 2026-09-01 Zihan Xi New
[net] net/ipv6: don't route packets with unknown source address [net] net/ipv6: don't route packets with unknown source address - - - - --- 2026-09-01 Íñigo Huguet New
[nf,v3] netfilter: disable br_netfilter in user namespaces [nf,v3] netfilter: disable br_netfilter in user namespaces - - 1 - --- 2026-08-31 Florian Westphal New
[RESEND,nf-next] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() [RESEND,nf-next] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() - 1 - - --- 2026-08-31 luoqing New
[nf,1/1] netfilter: nf_dup: prevent asynchronous duplicate recursion netfilter: nf_dup: prevent asynchronous duplicate recursion - 1 - - --- 2026-08-29 Zihan Xi New
[nf] netfilter: nf_tables: Fix netdev hook sanity checks [nf] netfilter: nf_tables: Fix netdev hook sanity checks - 1 - - --- 2026-08-27 Phil Sutter New
[nf,v4] netfilter: nf_tables: fix device name and prefix match in hook lookup [nf,v4] netfilter: nf_tables: fix device name and prefix match in hook lookup - 1 - - --- 2026-08-27 Fernando Fernandez Mancera New
[nf,2/2] netfilter: flowtable: bump ct refcount before teardown [nf,v2,1/2] netfilter: flowtable: defer ct stats sync via worker - 1 - - --- 2026-08-26 Pablo Neira Ayuso New
[nf,v2,1/2] netfilter: flowtable: defer ct stats sync via worker [nf,v2,1/2] netfilter: flowtable: defer ct stats sync via worker - 1 - - --- 2026-08-26 Pablo Neira Ayuso New
[net,v2] netfilter: ipset: add synchronize_rcu() in destroy to close use-after-free race [net,v2] netfilter: ipset: add synchronize_rcu() in destroy to close use-after-free race - 1 - - --- 2026-08-25 Cen Zhang (Microsoft) New
[nft] payload: restore is_raw flag for th expressions parsed from udata [nft] payload: restore is_raw flag for th expressions parsed from udata - - - - --- 2026-08-25 Adrian Moisey New
netfilter: nft_nat: fully initialise new_addr in netmap setup netfilter: nft_nat: fully initialise new_addr in netmap setup - 1 - - --- 2026-08-25 Theodor Arsenij Larionov Trichkine New
[nf] netfilter: lwtunnel: expose read-only sysctl nf_hooks_lwtunnel for non init-netns [nf] netfilter: lwtunnel: expose read-only sysctl nf_hooks_lwtunnel for non init-netns - 1 - - --- 2026-08-24 Pablo Neira Ayuso New
[BUG] general protection fault in __instance_destroy [BUG] general protection fault in __instance_destroy - - - - --- 2026-08-24 Jaeyoung Chung New
netfilter: flowtable: flush delete work after final GC netfilter: flowtable: flush delete work after final GC - 1 - - --- 2026-08-24 Chengfeng Ye New
[net-next,v2] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() [net-next,v2] netfilter: nf_conntrack_h323: fix double cursor advance in decode_int() - - - - --- 2026-08-24 luoqing New
netfilter: nf_conntrack: avoid truncating IPv6 nexthdr offset netfilter: nf_conntrack: avoid truncating IPv6 nexthdr offset - 1 - - --- 2026-08-22 Jérémy Jean New
netfilter: bpf: disallow conntrack kfuncs for token programs netfilter: bpf: disallow conntrack kfuncs for token programs - 1 - - --- 2026-08-22 Jérémy Jean New
[nf-next,v2] netfilter: osf: remove unreachable break in nf_osf_ttl() [nf-next,v2] netfilter: osf: remove unreachable break in nf_osf_ttl() - - - - --- 2026-08-21 Linkui Xiao New
netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation - - - - --- 2026-08-20 Shaojie Sun New
[net] netfilter: ipset: list:set: defer ip_set_put_byindex to RCU callback [net] netfilter: ipset: list:set: defer ip_set_put_byindex to RCU callback - 1 - - --- 2026-08-20 Cen Zhang (Microsoft) New
[2/2,nf-next] netfilter: synproxy: fix reset of ct seqadj when reopening a connection [1/2,nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL - 1 - - --- 2026-08-19 Fernando Fernandez Mancera New
[1/2,nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL [1/2,nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL - - - - --- 2026-08-19 Fernando Fernandez Mancera New
netfilter: flowtable: publish HW_DEAD after worker is done netfilter: flowtable: publish HW_DEAD after worker is done - 1 - - --- 2026-08-18 Jérémy Jean New
[nft,v2] evaluate: reject negative values for unsigned datatypes [nft,v2] evaluate: reject negative values for unsigned datatypes - 1 - - --- 2026-08-14 Avinash Duduskar New
[net,v2] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() [net,v2] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() - - - - --- 2026-08-14 Joas Antonio dos Santos New
[nft,2/2] tests: shell: add JSON delete test for ct stateful objects parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nft,1/2] parser_json: fix CMD_OBJ/NFT_OBJECT mismatch in delete path parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress [nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress - 1 - - --- 2026-08-10 David Lee New
[nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers [nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers - - - - --- 2026-08-07 Zhixing Chen New
selftests: netfilter: add functional test for nft ct timeout policies selftests: netfilter: add functional test for nft ct timeout policies - - - - --- 2026-08-05 Valery Borovsky New
« 1 2 »