Show patches with: State = Action Required       |    Archived = No       |   150 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[1/2] netfilter fix u16 overflow in get_port() [1/2] netfilter fix u16 overflow in get_port() - - - - --- 2026-04-10 Cyber-JA New
[2/2] netfilter: validate values parsed by try_number [1/2] netfilter fix u16 overflow in get_port() - - - - --- 2026-04-10 Cyber-JA New
[4/3,nf,v4] netfilter: nf_conntrack_helper: call .destroy() when helper is unregistered Untitled series #504819 - 1 - - --- 2026-05-18 Pablo Neira Ayuso New
[BUG] KASAN: slab-use-after-free in hash_ipportip6_resize [BUG] KASAN: slab-use-after-free in hash_ipportip6_resize - - - - --- 2026-04-23 Eulgyu Kim New
[RFC,net-next,1/4] net: flow_offload: let drivers report byte counter semantics improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC,net-next,2/4] nf_flow_table: track sub-interface and bridge ifindex in flow tuple improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC,net-next,3/4] nf_flow_table: convert hw byte counts and update sub-interface stats improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC,net-next,4/4] net: ethernet: mtk_eth_soc: report INGRESS_L2 byte_type in flow stats improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC] netfilter: disable payload mangling in userns [RFC] netfilter: disable payload mangling in userns - - - - --- 2026-05-15 Florian Westphal New
[V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl [V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl - - - - --- 2025-04-15 lvxiafei Under Review
[bpf-next,v6,1/6] net: move netfilter nf_reject_fill_skb_dst to core ipv4 bpf: add icmp_send kfunc - - - - --- 2026-05-18 Mahe Tardy New
[bpf-next,v6,2/6] net: move netfilter nf_reject6_fill_skb_dst to core ipv6 bpf: add icmp_send kfunc - - - - --- 2026-05-18 Mahe Tardy New
[bpf-next,v6,3/6] bpf: add bpf_icmp_send kfunc bpf: add icmp_send kfunc - - - - --- 2026-05-18 Mahe Tardy New
[bpf-next,v6,4/6] selftests/bpf: add bpf_icmp_send kfunc tests bpf: add icmp_send kfunc - - - - --- 2026-05-18 Mahe Tardy New
[bpf-next,v6,5/6] selftests/bpf: add bpf_icmp_send kfunc IPv6 tests bpf: add icmp_send kfunc - - - - --- 2026-05-18 Mahe Tardy New
[bpf-next,v6,6/6] selftests/bpf: add bpf_icmp_send recursion test bpf: add icmp_send kfunc - - - - --- 2026-05-18 Mahe Tardy New
[libnftnl,v4] expr: add support to math expression [libnftnl,v4] expr: add support to math expression - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[libnftnl] src: add connlimit stateful object support [libnftnl] src: add connlimit stateful object support - - - - --- 2025-11-04 Fernando Fernandez Mancera New
[net,00/12] Netfilter/IPVS fixes for net - - - - --- 2026-05-16 Pablo Neira Ayuso New
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,02/12] ipvs: avoid possible loop in ip_vs_dst_event on resizing [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,03/12] netfilter: ipset: fix a potential dump-destroy race [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - - - - --- 2026-05-16 Pablo Neira Ayuso New
[net,04/12] netfilter: nft_inner: Fix IPv6 inner_thoff desync [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 1 - --- 2026-05-16 Pablo Neira Ayuso New
[net,05/12] netfilter: ipset: stop hash:* range iteration at end [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,06/12] netfilter: nft_inner: release local_lock before re-enabling softirqs [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 1 - --- 2026-05-16 Pablo Neira Ayuso New
[net,07/12] netfilter: ip6t_hbh: reject oversized option lists [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,08/12] netfilter: ipset: Fix data race between add and list header in all hash types [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,09/12] netfilter: ipset: Fix data race between add and dump in all hash types [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,1/2] ipv4: raw: reject IP_HDRINCL packets with ihl < 5 ipv4: harden against ihl < 5 IP_HDRINCL packets - 1 - - --- 2026-05-12 Michael Bommarito New
[net,10/12] netfilter: ipset: annotate "pos" for concurrent readers/writers [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,11/12] netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 1 - --- 2026-05-16 Pablo Neira Ayuso New
[net,12/12] netfilter: nf_queue: hold bridge skb->dev while queued [net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-16 Pablo Neira Ayuso New
[net,2/2] ipv4: ah: harden ah_output options-copy guard against ihl < 5 ipv4: harden against ihl < 5 IP_HDRINCL packets - 1 - - --- 2026-05-12 Michael Bommarito New
[net,8/8] sched/isolation: Make HK_TYPE_KTHREAD an alias of HK_TYPE_DOMAIN [net,1/8] ipvs: fixes for the new ip_vs_status info - 1 - - --- 2026-05-05 Pablo Neira Ayuso New
[net,v2] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge() [net,v2] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge() - 1 - - --- 2026-05-11 Lorenzo Bianconi New
[net,v2] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test [net,v2] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test 1 - - - --- 2026-04-18 Yi Chen New
[net,v4] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge() [net,v4] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge() - 1 1 - --- 2026-05-14 Lorenzo Bianconi New
[net-next,2/2] ipvs: Replace use of system_unbound_wq with system_dfl_wq Untitled series #503729 - - - - --- 2026-05-11 Marco Crivellari New
[net-next,v3,1/4] netfilter: conntrack: add shared port and uint parsers for helpers netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 HACKE-RC New
[net-next,v3,2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 HACKE-RC New
[net-next,v3,3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 HACKE-RC New
[net-next,v3,4/4] netfilter: nf_conntrack_sip: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 HACKE-RC New
[net-next] netfilter: nf_conntrack_proto_tcp: fix typos in comments [net-next] netfilter: nf_conntrack_proto_tcp: fix typos in comments - - - - --- 2026-05-12 Avinash Duduskar New
[net] netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump [net] netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump - 1 - - --- 2026-05-05 Pratham Gupta New
[net] netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() [net] netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() - 1 - - --- 2026-04-28 Mathias Krause New
[net] xfrm: validate IPv4 header length before output transforms [net] xfrm: validate IPv4 header length before output transforms - - - - --- 2026-05-17 Michael Bommarito New
[nf,1/1] bridge: br_netfilter: give fake rtable its own lifetime [nf,1/1] bridge: br_netfilter: give fake rtable its own lifetime - 1 - - --- 2026-05-14 Ren Wei New
[nf,1/1] netfilter: ebtables: fix OOB read in compat_mtw_from_user [nf,1/1] netfilter: ebtables: fix OOB read in compat_mtw_from_user - 1 - - --- 2026-04-24 Ren Wei New
[nf,1/1] netfilter: ip6t_hbh: reject oversized option lists [nf,1/1] netfilter: ip6t_hbh: reject oversized option lists - 1 - - --- 2026-05-13 Ren Wei New
[nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize [nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize - 1 - 1 --- 2026-05-13 Ren Wei New
[nf,1/1] netfilter: ipset: keep comment extensions private on resize [nf,1/1] netfilter: ipset: keep comment extensions private on resize - 1 - - --- 2026-04-22 Ren Wei New
[nf,1/1] netfilter: nf_dup: preserve socket ownership on egress duplicates [nf,1/1] netfilter: nf_dup: preserve socket ownership on egress duplicates - 1 - - --- 2026-05-17 Ren Wei New
[nf,1/1] netfilter: nf_queue: hold bridge skb->dev while queued [nf,1/1] netfilter: nf_queue: hold bridge skb->dev while queued - 1 - 1 --- 2026-05-12 Ren Wei New
[nf,1/1] netfilter: xt_IDLETIMER: scope timer reuse to the owning netns [nf,1/1] netfilter: xt_IDLETIMER: scope timer reuse to the owning netns - 1 - 1 --- 2026-05-14 Ren Wei New
[nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end [nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end - 1 - - --- 2026-05-12 Ren Wei New
[nf,2/4] netfilter: ipset: stop hash:ip,port,ip range iteration at end [nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end - 1 - - --- 2026-05-12 Ren Wei New
[nf,3/4] netfilter: ipset: stop hash:ip,port range iteration at end [nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end - 1 - - --- 2026-05-12 Ren Wei New
[nf,4/4] netfilter: ipset: hash:ip,port,net: stop IPv4 range walk at upper bound [nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end - 1 - - --- 2026-05-12 Ren Wei New
[nf,v2,1/1] netfilter: ipset: preserve comment lifetime across resize and gc expiry [nf,v2,1/1] netfilter: ipset: preserve comment lifetime across resize and gc expiry - 1 - - --- 2026-05-17 Ren Wei New
[nf,v2,1/1] netfilter: nf_queue: hold bridge skb->dev while queued [nf,v2,1/1] netfilter: nf_queue: hold bridge skb->dev while queued - 1 - - --- 2026-05-15 Ren Wei New
[nf,v2] netfilter: conntrack: add dead flag to helpers [nf,v2] netfilter: conntrack: add dead flag to helpers - 1 - - --- 2026-05-14 Pablo Neira Ayuso New
[nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct [nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct - 1 - - --- 2026-05-14 Fernando Fernandez Mancera New
[nf,v2] netfilter: nf_queue: hold reference on skb->dev [nf,v2] netfilter: nf_queue: hold reference on skb->dev - - - - --- 2026-05-12 Pablo Neira Ayuso New
[nf,v3,1/2] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags [nf,v3,1/2] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - - - - --- 2026-05-14 Pablo Neira Ayuso New
[nf,v3,2/2] netfilter: conntrack: add dead flag to helpers [nf,v3,1/2] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - 1 - - --- 2026-05-14 Pablo Neira Ayuso New
[nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags [nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - - - - --- 2026-05-18 Pablo Neira Ayuso New
[nf,v4,2/3] netfilter: conntrack: add dead flag to helpers [nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - 1 - - --- 2026-05-18 Pablo Neira Ayuso New
[nf,v4,3/3] netfilter: nf_conntrack_helper: add null check in nfct_help_data() calls [nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - 1 - - --- 2026-05-18 Pablo Neira Ayuso New
[nf,v4] netfilter: nf_tables: fix dst corruption in same register operation [nf,v4] netfilter: nf_tables: fix dst corruption in same register operation 1 1 - - --- 2026-05-11 Fernando Fernandez Mancera New
[nf,v4] netfilter: nft_bitwise: fix dst corruption in same register shifts [nf,v4] netfilter: nft_bitwise: fix dst corruption in same register shifts - 1 - - --- 2026-04-27 Fernando Fernandez Mancera New
[nf-next,1/4] net: netfilter: Add ether_type to net_device_path_ctx Add IPv4 over IPv6 flowtable SW acceleration - - - - --- 2026-05-05 Lorenzo Bianconi New
[nf-next,2/4] net: netfilter: Add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 flowtable SW acceleration - - - - --- 2026-05-05 Lorenzo Bianconi New
[nf-next,3/4] net: netfilter: Add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 flowtable SW acceleration - - - - --- 2026-05-05 Lorenzo Bianconi New
[nf-next,4/4] selftests: netfilter: nft_flowtable.sh: Add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 flowtable SW acceleration - - - - --- 2026-05-05 Lorenzo Bianconi New
[nf-next,v2,1/2] netfilter: flowtable: update netdev stats with HW_OFFLOAD flows Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nf-next,v2,1/6] net: netfilter: Add ether_type to net_device_path_ctx Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-06 Lorenzo Bianconi New
[nf-next,v2,2/2] net: dsa: update net_device stats with HW offloaded flows stats Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nf-next,v2,2/6] net: netfilter: Add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-06 Lorenzo Bianconi New
[nf-next,v2,3/6] net: netfilter: Add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-06 Lorenzo Bianconi New
[nf-next,v2,4/6] selftests: netfilter: nft_flowtable.sh: Add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-06 Lorenzo Bianconi New
[nf-next,v2,5/6] net: netfilter: Add SIT tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-06 Lorenzo Bianconi New
[nf-next,v2,6/6] selftests: netfilter: nft_flowtable.sh: Add SIT flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-06 Lorenzo Bianconi New
[nf-next,v2] netfilter: add option for GCOV profiling [nf-next,v2] netfilter: add option for GCOV profiling 1 - - - --- 2026-05-12 Florian Westphal New
[nf-next,v2] netfilter: nfnetlink_hook: Dump nat type chains [nf-next,v2] netfilter: nfnetlink_hook: Dump nat type chains - - - - --- 2026-03-20 Phil Sutter Under Review
[nf-next,v2] netfilter: nft_set_rbtree: remove dead conditional [nf-next,v2] netfilter: nft_set_rbtree: remove dead conditional - - - - --- 2026-04-11 Florian Westphal New
[nf-next,v5] netfilter: nf_tables: add math expression support [nf-next,v5] netfilter: nf_tables: add math expression support - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[nf-next] netfilter: allow nfnetlink built-in only [nf-next] netfilter: allow nfnetlink built-in only - - 1 - --- 2026-04-15 Pablo Neira Ayuso New
[nf-next] netfilter: flowtable_offload: propagate CT mark to hardware offload path [nf-next] netfilter: flowtable_offload: propagate CT mark to hardware offload path - - - - --- 2026-04-29 Lorenzo Bianconi New
[nf-next] netfilter: nf_conncount: use per-rule hash initval [nf-next] netfilter: nf_conncount: use per-rule hash initval - - - - --- 2026-04-29 Florian Westphal New
[nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces [nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-04-29 Florian Westphal New
[nf] ipvs: avoid possible loop in ip_vs_dst_event on resizing [nf] ipvs: avoid possible loop in ip_vs_dst_event on resizing - 1 - - --- 2026-05-06 Julian Anastasov New
[nf] netfilter: conntrack: add dead flag to helpers [nf] netfilter: conntrack: add dead flag to helpers - 1 - - --- 2026-05-12 Pablo Neira Ayuso New
[nf] netfilter: conntrack: correct sequence on reinitialized TCP connection [nf] netfilter: conntrack: correct sequence on reinitialized TCP connection - 1 - - --- 2025-02-20 Pablo Neira Ayuso New
[nf] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check [nf] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 - - --- 2026-05-11 Hamza Mahfooz New
[nf] netfilter: disable payload mangling in userns [nf] netfilter: disable payload mangling in userns - - - 1 --- 2026-05-16 Qi Tang New
[nf] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct [nf] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct - 1 - - --- 2026-05-13 Fernando Fernandez Mancera New
[nf] netfilter: nf_conntrack_helper: fix possible null deref during error log [nf] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-09 Florian Westphal New
[nf] netfilter: nft_inner: release local_lock before re-enabling softirqs [nf] netfilter: nft_inner: release local_lock before re-enabling softirqs - 1 1 - --- 2026-05-12 Florian Westphal New
[nf] netfilter: xt_TCPMSS: check skb_dst before path-MTU clamping [nf] netfilter: xt_TCPMSS: check skb_dst before path-MTU clamping - 1 - - --- 2026-04-18 Weiming Shi Under Review
[nft,1/2] parser_json: Accept non-RHS expressions in binop RHS A bit of non-constant binop follow-up - 1 - - --- 2026-04-02 Phil Sutter New
« 1 2 »