Show patches with: State = Action Required       |   110 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize [nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize - 1 - 1 --- 2026-05-13 Ren Wei kadlec Needs Review / ACK
netfilter: ipset: harden payload calculation in call_ad() netfilter: ipset: harden payload calculation in call_ad() 1 - - - --- 2026-03-13 David Baum kadlec Under Review
netfilter: flowtable: publish GC-visible tuple last netfilter: flowtable: publish GC-visible tuple last - 1 - - --- 2026-08-08 Jérémy Jean New
[nft] tests: shell: use an unassigned protocol number in exclusive_start_cond [nft] tests: shell: use an unassigned protocol number in exclusive_start_cond - - - - --- 2026-08-08 Avinash Duduskar New
[nft] evaluate: reject negative values for unsigned datatypes [nft] evaluate: reject negative values for unsigned datatypes - 1 - - --- 2026-08-08 Avinash Duduskar New
[nf-next,v3,2/2] netfilter: nft_ct: move custom expectation support to helper [nf-next,v3,1/2] netfilter: nf_conntrack_helper: remove synchronize_rcu() on helper removal - 1 - - --- 2026-08-07 Pablo Neira Ayuso New
[nf-next,v3,1/2] netfilter: nf_conntrack_helper: remove synchronize_rcu() on helper removal [nf-next,v3,1/2] netfilter: nf_conntrack_helper: remove synchronize_rcu() on helper removal - - - - --- 2026-08-07 Pablo Neira Ayuso New
[nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers [nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers - - - - --- 2026-08-07 Zhixing Chen New
[net,v2] selftests: netfilter: conntrack_dump_flush: remove unused variables and fix typo [net,v2] selftests: netfilter: conntrack_dump_flush: remove unused variables and fix typo - - 2 - --- 2026-08-07 Qingshuang Fu New
[nf,v4] netfilter: ipset: remove need to allocate memory on delete operations operations [nf,v4] netfilter: ipset: remove need to allocate memory on delete operations operations - 1 - - --- 2026-08-07 Florian Westphal New
[nf-next,7/7] netfilter: flowtable: detach layer 2 encapsulation parser from lookup flowtable preparation for IPv4 over IPv6 and SIT 1 - - - --- 2026-08-06 Pablo Neira Ayuso New
[nf-next,6/7] netfilter: flowtable: move ipv4 and ipv6 xmit path to function flowtable preparation for IPv4 over IPv6 and SIT 1 - - - --- 2026-08-06 Pablo Neira Ayuso New
[nf-next,5/7] netfilter: flowtable: store ethertype in flowtable context flowtable preparation for IPv4 over IPv6 and SIT 1 - - - --- 2026-08-06 Pablo Neira Ayuso New
[nf-next,4/7] netfilter: flowtable: rename ctx.tun.proto to ctx.tun.inner_proto flowtable preparation for IPv4 over IPv6 and SIT 1 - - - --- 2026-08-06 Pablo Neira Ayuso New
[nf-next,3/7] netfilter: flowtable: rename tun.l3_proto to tun.inner_proto flowtable preparation for IPv4 over IPv6 and SIT 1 - - - --- 2026-08-06 Pablo Neira Ayuso New
[nf-next,2/7] net: netfilter: add ether_type to net_device_path_ctx and use it flowtable preparation for IPv4 over IPv6 and SIT 1 - - - --- 2026-08-06 Pablo Neira Ayuso New
[nf-next,1/7] net: pass net_device_path_ctx to dev_fill_forward_path() flowtable preparation for IPv4 over IPv6 and SIT - - - - --- 2026-08-06 Pablo Neira Ayuso New
[nft] netlink_linearize: size nat register allocation by address expression [nft] netlink_linearize: size nat register allocation by address expression - - - - --- 2026-08-06 Adrian Moisey New
[net] netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path [net] netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path - 1 - - --- 2026-08-06 Alexey Velichayshiy New
[nf] netfilter: ipset: let destroy callbacks adjust ext mem size [nf] netfilter: ipset: let destroy callbacks adjust ext mem size - 1 - - --- 2026-08-06 Florian Westphal New
[nf] netfilter: ipset: fix list type element drift bug [nf] netfilter: ipset: fix list type element drift bug - 1 - - --- 2026-08-06 Florian Westphal New
[nf] ipvs: revalidate ihl to prevent out-of-bounds access [nf] ipvs: revalidate ihl to prevent out-of-bounds access - 1 - - --- 2026-08-06 Julian Anastasov New
[nf-next,v2] netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct() [nf-next,v2] netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct() - - 1 - --- 2026-08-05 Pablo Neira Ayuso New
[nf,v2,2/2] netfilter: nf_tables: call set ops .commit when building new ruleset [nf,v2,1/2] netfilter: nf_tables: move set_update_list to nftables per-netns - - - - --- 2026-08-05 Pablo Neira Ayuso New
[nf,v2,1/2] netfilter: nf_tables: move set_update_list to nftables per-netns [nf,v2,1/2] netfilter: nf_tables: move set_update_list to nftables per-netns - - - - --- 2026-08-05 Pablo Neira Ayuso New
selftests: netfilter: add functional test for nft ct timeout policies selftests: netfilter: add functional test for nft ct timeout policies - - - - --- 2026-08-05 Valery Borovsky New
[net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path [net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path - - - - --- 2026-08-04 Alexandre Ferrieux New
[nf] netfilter: ipset: let destroy callbacks adjust ext mem size [nf] netfilter: ipset: let destroy callbacks adjust ext mem size - 1 - - --- 2026-08-04 Florian Westphal New
[nf] netfilter: nf_reject_ipv4: initialize IPCB at inet ingress [nf] netfilter: nf_reject_ipv4: initialize IPCB at inet ingress - 1 - - --- 2026-08-04 David Lee New
[nf,v2] ipvs: clear IPv4 options after rebasing tunnel ICMP errors [nf,v2] ipvs: clear IPv4 options after rebasing tunnel ICMP errors 1 1 - - --- 2026-08-04 David Lee New
[nf] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state [nf] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state - 1 - - --- 2026-08-03 Florian Westphal New
[nf,v4,1/1] netfilter: validate L4 headers after userspace packet writes [nf,v4,1/1] netfilter: validate L4 headers after userspace packet writes - 1 - - --- 2026-08-03 Zhiling Zou New
[nf,v4,1/1] netfilter: nf_conntrack: defer invalid log until after unlock netfilter: nf_conntrack: defer invalid log until after unlock - 3 1 - --- 2026-08-01 Zihan Xi New
[nf,1/1] netfilter: ipset: serialize kernel-side put-byindex with swap netfilter: ipset: serialize kernel-side put-byindex with swap - 1 - - --- 2026-08-01 Zhiling Zou Under Review
[nf-next] netfilter: conntrack: sctp: validate vtag before state changes [nf-next] netfilter: conntrack: sctp: validate vtag before state changes - - - - --- 2026-07-31 Yizhou Zhao New
[nf,v4,3/3] ipvs: separate destination availability state ipvs: fix destination overload state updates - 1 - - --- 2026-07-31 Yizhou Zhao New
[nf,v4,2/3] ipvs: properly update the overload flag on dest edit ipvs: fix destination overload state updates - 1 - - --- 2026-07-31 Yizhou Zhao New
[nf,v4,1/3] ipvs: add totalconns for dest ipvs: fix destination overload state updates - 1 - - --- 2026-07-31 Yizhou Zhao New
ipvs: clear IPv4 options after rebasing tunnel ICMP errors ipvs: clear IPv4 options after rebasing tunnel ICMP errors - 1 - - --- 2026-07-31 David Lee New
[nf,1/1] netfilter: bridge: release template ct on non-IP path netfilter: bridge: release template ct on non-IP path - 1 - - --- 2026-07-31 Zhiling Zou New
[6.1.y] netfilter: nf_conntrack_expect: restore helper propagation via expectation [6.1.y] netfilter: nf_conntrack_expect: restore helper propagation via expectation - 2 - 1 --- 2026-07-30 Ilya Maximets Under Review
[6.18.y] netfilter: nf_conntrack_expect: restore helper propagation via expectation [6.18.y] netfilter: nf_conntrack_expect: restore helper propagation via expectation - 2 - 1 --- 2026-07-30 Ilya Maximets Under Review
[conntrack-tools,v2] conntrack.8: Document --stats counters [conntrack-tools,v2] conntrack.8: Document --stats counters - - - - --- 2026-07-30 Phil Sutter New
[nf,1/1] netfilter: ebtables: avoid unbounded counter allocations netfilter: ebtables: avoid unbounded counter allocations - 1 - - --- 2026-07-27 Ren Wei New
[nf,1/1] netfilter: h323: keep NAT mangling aligned with parsed transport netfilter: h323: fix helper NAT mangling - 1 - - --- 2026-07-27 Ren Wei New
[nf,1/1] ipvs: guard estimator enqueue until limits are set ipvs: guard estimator enqueue until limits are set - 1 - - --- 2026-07-27 Ren Wei New
[net,v2] net: flow_offload: serialize driver callback lists [net,v2] net: flow_offload: serialize driver callback lists - 1 - - --- 2026-07-26 Weiming Shi New
[nf] netfilter: ipset: fix refcount race between list:set GC and swap [nf] netfilter: ipset: fix refcount race between list:set GC and swap 1 1 - - --- 2026-07-22 Xiang Mei New
[net] netfilter: nf_conntrack_h323: fix get_bitmap() overread [net] netfilter: nf_conntrack_h323: fix get_bitmap() overread - 1 - - --- 2026-07-22 Sangho Lee New
[iptables] nft: fix out-of-bounds read listing an old-revision match [iptables] nft: fix out-of-bounds read listing an old-revision match - 1 - - --- 2026-07-17 Omkhar Arasaratnam New
[iptables] nft: bridge: fix among buffer overflow when set has no size [iptables] nft: bridge: fix among buffer overflow when set has no size - 1 - - --- 2026-07-17 Omkhar Arasaratnam New
[nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay [nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay - 1 - - --- 2026-07-13 Weiming Shi New
[nf-next,v6,6/6] selftests: netfilter: nft_flowtable.sh: add SIT flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,5/6] net: netfilter: add SIT tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,4/6] selftests: netfilter: nft_flowtable.sh: add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,3/6] net: netfilter: add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,2/6] net: netfilter: add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,1/6] net: netfilter: add ether_type to net_device_path_ctx Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v5] netfilter: flowtable: initial bridge support [nf-next,v5] netfilter: flowtable: initial bridge support - - - - --- 2026-07-13 Pablo Neira Ayuso New
[nf,v2,2/2] netfilter: nf_conntrack_expect: reject reinsertion of DEAD expectations [nf,v2,1/2] netfilter: nf_nat: stop reusing DEAD RTP expectations - 1 - - --- 2026-07-12 Jaeyeong Lee New
[nf-next,v3,4/4] netfilter: nfnetlink_hook: Fix for concurrent NAT hooks dump and change Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,3/4] netfilter: nfnetlink_hook: Handle multipart NAT hook dumps Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,2/4] netfilter: nfnetlink_hook: Address hook ops using READ_ONCE() Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,1/4] netfilter: nfnetlink_hook: Pass cb object to nfnl_hook_dump_nat() Address Sashiko review of NAT hook dump code - - - - --- 2026-07-10 Phil Sutter New
[net,v3] netfilter: nf_nat: recalculate TCP TS offset after SNAT port rewrite [net,v3] netfilter: nf_nat: recalculate TCP TS offset after SNAT port rewrite - 1 - - --- 2026-07-10 xietangxin New
[nf,v2] ipvs: make destination flags atomic [nf,v2] ipvs: make destination flags atomic - 1 - - --- 2026-07-08 Yizhou Zhao Needs Review / ACK
[nf,1/1] netfilter: xt_time: reject pre-epoch calendar matching [nf,1/1] netfilter: xt_time: reject pre-epoch calendar matching - 1 2 - --- 2026-07-03 Ren Wei New
[nft,v2,5/5] libnftables: support for several reset commands support for several list and reset commands - 1 - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,4/5] src: allow reset commands in batch with list and get commands only support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,3/5] libnftables: use nft_run_cmds() in nft_run_cmd_from_filename() support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,2/5] libnftables: split nft_run_cmd_from_buffer() in helper functions support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,1/5] libnftables: add nft_run_cmd_release() helper and use it support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nf,v3,2/2] selftests: netfilter: add bridge tunnel flowtable regression [nf,v3,1/2] netfilter: nf_flow_table: separate tunnel route state from direct xmit - - - - --- 2026-06-22 Ren Wei New
[nf-next] netfilter: flowtable: remove inline segmentation [nf-next] netfilter: flowtable: remove inline segmentation - - - - --- 2026-06-03 Qingfang Deng New
[9/9,nf-next] netfilter: conncount: use DEBUG_NET_WARN_ON_ONCE on reaching count limit netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[8/9,nf-next] netfilter: flowtable: use DEBUG_NET_WARN_ON_ONCE in offload path netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[7/9,nf-next] netfilter: bpf: use DEBUG_NET_WARN_ON_ONCE for missing BTF structures netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[6/9,nf-next] netfilter: tproxy: use DEBUG_NET_WARN_ON_ONCE for protocol fallbacks netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[5/9,nf-next] netfilter: nat: use DEBUG_NET_WARN_ON_ONCE in core and helper paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[4/9,nf-next] netfilter: conntrack: use DEBUG_NET_WARN_ON_ONCE on packet paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[3/9,nf-next] netfilter: nfnetlink: use DEBUG_NET_WARN_ON_ONCE for attribute validation netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[1/9,nf-next] netfilter: xtables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh [v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,2/2] netfilter: bridge: Add conntrack double vlan and pppoe conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,1/2] netfilter: utils: nf_ip(6)_checksum(_partial) correct data!=networkheader conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[net-next,v3,4/4] netfilter: nf_conntrack_sip: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 Rahul New
[net-next,v3,3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 Rahul New
[net-next,v3,2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 Rahul New
[net-next,v3,1/4] netfilter: conntrack: add shared port and uint parsers for helpers netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 Rahul New
[BUG] KASAN: slab-use-after-free in hash_ipportip6_resize [BUG] KASAN: slab-use-after-free in hash_ipportip6_resize - - - - --- 2026-04-23 Eulgyu Kim Under Review
[libnftnl,v4] expr: add support to math expression [libnftnl,v4] expr: add support to math expression - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[nf-next,v5] netfilter: nf_tables: add math expression support [nf-next,v5] netfilter: nf_tables: add math expression support - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[nft] json: output set/map element count [nft] json: output set/map element count - - - - --- 2026-04-19 Niklas Fiekas New
[nft,2/2] parser_bison: Accept non-constant binop on LHS of relationals A bit of non-constant binop follow-up - - - - --- 2026-04-02 Phil Sutter New
[nft,1/2] parser_json: Accept non-RHS expressions in binop RHS A bit of non-constant binop follow-up - 1 - - --- 2026-04-02 Phil Sutter New
[nf-next,v2,2/2] net: dsa: update net_device stats with HW offloaded flows stats Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nf-next,v2,1/2] netfilter: flowtable: update netdev stats with HW_OFFLOAD flows Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[v12,nf-next] bridge: Introduce DEV_PATH_BR_VLAN_KEEP_HW [v12,nf-next] bridge: Introduce DEV_PATH_BR_VLAN_KEEP_HW - - - - --- 2026-03-17 Eric Woudstra Needs Review / ACK
[v12,nf-next] netfilter: nft_flow_offload: Add DEV_PATH_MTK_WDMA to nft_dev_path_info() [v12,nf-next] netfilter: nft_flow_offload: Add DEV_PATH_MTK_WDMA to nft_dev_path_info() - - 1 - --- 2026-03-17 Eric Woudstra Needs Review / ACK
[nf-next,2/2] netfilter: nf_tables: add netlink policy based cap on registers [nf-next,1/2] netfilter: add more netlink-based policy range checks - - - - --- 2026-03-16 Florian Westphal Under Review
« 1 2 »