Toggle navigation
Patchwork
Netfilter Development
Patches
Bundles
About this project
Login
Register
Mail settings
Show patches with
: State =
Action Required
| Archived =
No
| 150 patches
Series
Submitter
State
any
Action Required
New
Under Review
Accepted
Rejected
RFC
Not Applicable
Changes Requested
Awaiting Upstream
Superseded
Deferred
Needs Review / ACK
Handled Elsewhere
Search
Archived
No
Yes
Both
Delegate
------
Nobody
jgarzik
arnd
ymano
smfrench
jlayton
tseliot
ogasawara
amitk
awhitcroft
mst
dayangkun
jwboyer
jwboyer
colinking
colinking
azummo
dwmw2
rtg
sconklin
smb
aliguori
bradf
demarchi
ms
bhundven
chbs
kengyu
kadlec
regit
jabk
laforge
laforge
tonyb
alai
zecke
zecke
__damien__
luka
luka
prafulla@marvell.com
cyrus
PeterHuewe
kiho
jow
jow
ypwong
nico
dedeckeh
dedeckeh
yousong
yousong
tomcwarren
mb
mrchuck
vineetg76
computersforpeace
patrick_delaunay
Noltari
Noltari
ee07b291
ldir
ldir
stefanct
zhouhan
carldani
blp
ffainelli
ffainelli
regXboi
bbrezillon
pravin
mkp
jpettit
mkresin
mkresin
thess
thess
fbarrat
fbarrat
phil
linville
jesse
tjaalton
esben
abrodkin
abrodkin
diproiettod
tbot
stephenfin
ajd
darball1
sammj
jogo
jogo
bhelgaas
blogic
blogic
tagr
tagr
oohal
russellb
ptomsich
agraf
pchotard
joestringer
naveen
pepe2k
pepe2k
mwalle
arj
arj
davem
davem
davem
andmur01
jforissier
amitay
matttbe
pabeni
istokes
aparcar
martineau
maddy
Ansuel
danielschwierzeck
goliath
mkorpershoek
mariosix
dcaratti
aserdean
ovsrobot
ovsrobot
tpetazzoni
marex
khem
XiaoYang
apritzel
robimarko
danielhb
groug
npiggin
mmichelson
pareddja
liwang
atishp
netdrv
mkubecek
stintel
stintel
jkicinski
cpitchen
dsa
jstancek
bpf
shettyg
lorpie01
acelan
wigyori
wigyori
pm215
apopple
dja
alexhung
lynxis
lynxis
brgl
brgl
peda
akodanev
0andriy
981213
narmstrong
snowpatch_ozlabs
snowpatch_ozlabs
snowpatch_ozlabs
aivanov
atishp04
vigneshr
monstr
blocktrron
mraynal
shemminger
chunkeey
stewart
stewart
ukleinek
ukleinek
kabel
Jaehoon
ehristev
rfried
ivanhu
sjg
ag
xypron
jacmet
rsalvaterra
adrianschmutzler
hegdevasant
hegdevasant
horms
wsa
arbab
jagan
kevery
metan
rmilecki
rmilecki
bmeng
prom
akumar
freenix
abelloni
juju
wbx
apconole
legoater
legoater
legoater
trini
rw
rw
chleroy
pablo
pablo
svanheule
bjonglez
ynezz
xback
xback
pevik
sbabic
sbabic
richiejp
dangole
dangole
jonhunter
aik
Hauke
Hauke
forty
echaudron
anuppatel
anuppatel
next_ghost
amusil
benh
rgrimm
acer
passgat
segher
pratyush
jms
jms
jms
jk
jk
jk
jk
mans0n
ruscur
jmberg
Andes
numans
ymorin
festevam
xuyang
linusw
linusw
kubu
conchuod
matthias_bgg
tambarus
ltpci
tytso
krzk
spectrum
apalos
dceara
pbrobinson
strlen
strlen
imaximets
stroese
neocturne
cazzacarna
aldot
TIENFONG
tperale
mpe
galak
sfr
arnout
ktraynor
robh
nbd
nbd
kcxt
anguy11
paulus
jm
mwilczynski
hs
iTitou
Bubu
vfazio
jstephan
dlech
raymo200915
Apply
«
1
2
»
Patch
Series
A/F/R/T
S/W/F
Date
Submitter
Delegate
State
[1/2] netfilter fix u16 overflow in get_port()
[1/2] netfilter fix u16 overflow in get_port()
- - - -
-
-
-
2026-04-10
Cyber-JA
New
[2/2] netfilter: validate values parsed by try_number
[1/2] netfilter fix u16 overflow in get_port()
- - - -
-
-
-
2026-04-10
Cyber-JA
New
[4/3,nf,v4] netfilter: nf_conntrack_helper: call .destroy() when helper is unregistered
Untitled series #504819
- 1 - -
-
-
-
2026-05-18
Pablo Neira Ayuso
New
[BUG] KASAN: slab-use-after-free in hash_ipportip6_resize
[BUG] KASAN: slab-use-after-free in hash_ipportip6_resize
- - - -
-
-
-
2026-04-23
Eulgyu Kim
New
[RFC,net-next,1/4] net: flow_offload: let drivers report byte counter semantics
improve hw flow offload byte accounting
- - - -
-
-
-
2026-04-09
Daniel Golle
New
[RFC,net-next,2/4] nf_flow_table: track sub-interface and bridge ifindex in flow tuple
improve hw flow offload byte accounting
- - - -
-
-
-
2026-04-09
Daniel Golle
New
[RFC,net-next,3/4] nf_flow_table: convert hw byte counts and update sub-interface stats
improve hw flow offload byte accounting
- - - -
-
-
-
2026-04-09
Daniel Golle
New
[RFC,net-next,4/4] net: ethernet: mtk_eth_soc: report INGRESS_L2 byte_type in flow stats
improve hw flow offload byte accounting
- - - -
-
-
-
2026-04-09
Daniel Golle
New
[RFC] netfilter: disable payload mangling in userns
[RFC] netfilter: disable payload mangling in userns
- - - -
-
-
-
2026-05-15
Florian Westphal
New
[V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl
[V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl
- - - -
-
-
-
2025-04-15
lvxiafei
Under Review
[bpf-next,v6,1/6] net: move netfilter nf_reject_fill_skb_dst to core ipv4
bpf: add icmp_send kfunc
- - - -
-
-
-
2026-05-18
Mahe Tardy
New
[bpf-next,v6,2/6] net: move netfilter nf_reject6_fill_skb_dst to core ipv6
bpf: add icmp_send kfunc
- - - -
-
-
-
2026-05-18
Mahe Tardy
New
[bpf-next,v6,3/6] bpf: add bpf_icmp_send kfunc
bpf: add icmp_send kfunc
- - - -
-
-
-
2026-05-18
Mahe Tardy
New
[bpf-next,v6,4/6] selftests/bpf: add bpf_icmp_send kfunc tests
bpf: add icmp_send kfunc
- - - -
-
-
-
2026-05-18
Mahe Tardy
New
[bpf-next,v6,5/6] selftests/bpf: add bpf_icmp_send kfunc IPv6 tests
bpf: add icmp_send kfunc
- - - -
-
-
-
2026-05-18
Mahe Tardy
New
[bpf-next,v6,6/6] selftests/bpf: add bpf_icmp_send recursion test
bpf: add icmp_send kfunc
- - - -
-
-
-
2026-05-18
Mahe Tardy
New
[libnftnl,v4] expr: add support to math expression
[libnftnl,v4] expr: add support to math expression
- - - -
-
-
-
2026-04-21
Fernando Fernandez Mancera
New
[libnftnl] src: add connlimit stateful object support
[libnftnl] src: add connlimit stateful object support
- - - -
-
-
-
2025-11-04
Fernando Fernandez Mancera
New
[net,00/12] Netfilter/IPVS fixes for net
- - - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,02/12] ipvs: avoid possible loop in ip_vs_dst_event on resizing
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,03/12] netfilter: ipset: fix a potential dump-destroy race
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- - - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,04/12] netfilter: nft_inner: Fix IPv6 inner_thoff desync
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 1 -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,05/12] netfilter: ipset: stop hash:* range iteration at end
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,06/12] netfilter: nft_inner: release local_lock before re-enabling softirqs
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 1 -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,07/12] netfilter: ip6t_hbh: reject oversized option lists
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,08/12] netfilter: ipset: Fix data race between add and list header in all hash types
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,09/12] netfilter: ipset: Fix data race between add and dump in all hash types
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,1/2] ipv4: raw: reject IP_HDRINCL packets with ihl < 5
ipv4: harden against ihl < 5 IP_HDRINCL packets
- 1 - -
-
-
-
2026-05-12
Michael Bommarito
New
[net,10/12] netfilter: ipset: annotate "pos" for concurrent readers/writers
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,11/12] netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge()
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 1 -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,12/12] netfilter: nf_queue: hold bridge skb->dev while queued
[net,01/12] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-16
Pablo Neira Ayuso
New
[net,2/2] ipv4: ah: harden ah_output options-copy guard against ihl < 5
ipv4: harden against ihl < 5 IP_HDRINCL packets
- 1 - -
-
-
-
2026-05-12
Michael Bommarito
New
[net,8/8] sched/isolation: Make HK_TYPE_KTHREAD an alias of HK_TYPE_DOMAIN
[net,1/8] ipvs: fixes for the new ip_vs_status info
- 1 - -
-
-
-
2026-05-05
Pablo Neira Ayuso
New
[net,v2] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge()
[net,v2] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge()
- 1 - -
-
-
-
2026-05-11
Lorenzo Bianconi
New
[net,v2] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test
[net,v2] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test
1 - - -
-
-
-
2026-04-18
Yi Chen
New
[net,v4] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge()
[net,v4] net: neigh: Reallocate headroom if necessary in neigh_hh_bridge()
- 1 1 -
-
-
-
2026-05-14
Lorenzo Bianconi
New
[net-next,2/2] ipvs: Replace use of system_unbound_wq with system_dfl_wq
Untitled series #503729
- - - -
-
-
-
2026-05-11
Marco Crivellari
New
[net-next,v3,1/4] netfilter: conntrack: add shared port and uint parsers for helpers
netfilter: conntrack: shared port parser for helpers
- - - -
-
-
-
2026-05-03
HACKE-RC
New
[net-next,v3,2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port()
netfilter: conntrack: shared port parser for helpers
- 1 - -
-
-
-
2026-05-03
HACKE-RC
New
[net-next,v3,3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port()
netfilter: conntrack: shared port parser for helpers
- 1 - -
-
-
-
2026-05-03
HACKE-RC
New
[net-next,v3,4/4] netfilter: nf_conntrack_sip: use nf_ct_helper_parse_port()
netfilter: conntrack: shared port parser for helpers
- - - -
-
-
-
2026-05-03
HACKE-RC
New
[net-next] netfilter: nf_conntrack_proto_tcp: fix typos in comments
[net-next] netfilter: nf_conntrack_proto_tcp: fix typos in comments
- - - -
-
-
-
2026-05-12
Avinash Duduskar
New
[net] netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
[net] netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
- 1 - -
-
-
-
2026-05-05
Pratham Gupta
New
[net] netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
[net] netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
- 1 - -
-
-
-
2026-04-28
Mathias Krause
New
[net] xfrm: validate IPv4 header length before output transforms
[net] xfrm: validate IPv4 header length before output transforms
- - - -
-
-
-
2026-05-17
Michael Bommarito
New
[nf,1/1] bridge: br_netfilter: give fake rtable its own lifetime
[nf,1/1] bridge: br_netfilter: give fake rtable its own lifetime
- 1 - -
-
-
-
2026-05-14
Ren Wei
New
[nf,1/1] netfilter: ebtables: fix OOB read in compat_mtw_from_user
[nf,1/1] netfilter: ebtables: fix OOB read in compat_mtw_from_user
- 1 - -
-
-
-
2026-04-24
Ren Wei
New
[nf,1/1] netfilter: ip6t_hbh: reject oversized option lists
[nf,1/1] netfilter: ip6t_hbh: reject oversized option lists
- 1 - -
-
-
-
2026-05-13
Ren Wei
New
[nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize
[nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize
- 1 - 1
-
-
-
2026-05-13
Ren Wei
New
[nf,1/1] netfilter: ipset: keep comment extensions private on resize
[nf,1/1] netfilter: ipset: keep comment extensions private on resize
- 1 - -
-
-
-
2026-04-22
Ren Wei
New
[nf,1/1] netfilter: nf_dup: preserve socket ownership on egress duplicates
[nf,1/1] netfilter: nf_dup: preserve socket ownership on egress duplicates
- 1 - -
-
-
-
2026-05-17
Ren Wei
New
[nf,1/1] netfilter: nf_queue: hold bridge skb->dev while queued
[nf,1/1] netfilter: nf_queue: hold bridge skb->dev while queued
- 1 - 1
-
-
-
2026-05-12
Ren Wei
New
[nf,1/1] netfilter: xt_IDLETIMER: scope timer reuse to the owning netns
[nf,1/1] netfilter: xt_IDLETIMER: scope timer reuse to the owning netns
- 1 - 1
-
-
-
2026-05-14
Ren Wei
New
[nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end
[nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end
- 1 - -
-
-
-
2026-05-12
Ren Wei
New
[nf,2/4] netfilter: ipset: stop hash:ip,port,ip range iteration at end
[nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end
- 1 - -
-
-
-
2026-05-12
Ren Wei
New
[nf,3/4] netfilter: ipset: stop hash:ip,port range iteration at end
[nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end
- 1 - -
-
-
-
2026-05-12
Ren Wei
New
[nf,4/4] netfilter: ipset: hash:ip,port,net: stop IPv4 range walk at upper bound
[nf,1/4] netfilter: ipset: stop hash:ip,mark range iteration at end
- 1 - -
-
-
-
2026-05-12
Ren Wei
New
[nf,v2,1/1] netfilter: ipset: preserve comment lifetime across resize and gc expiry
[nf,v2,1/1] netfilter: ipset: preserve comment lifetime across resize and gc expiry
- 1 - -
-
-
-
2026-05-17
Ren Wei
New
[nf,v2,1/1] netfilter: nf_queue: hold bridge skb->dev while queued
[nf,v2,1/1] netfilter: nf_queue: hold bridge skb->dev while queued
- 1 - -
-
-
-
2026-05-15
Ren Wei
New
[nf,v2] netfilter: conntrack: add dead flag to helpers
[nf,v2] netfilter: conntrack: add dead flag to helpers
- 1 - -
-
-
-
2026-05-14
Pablo Neira Ayuso
New
[nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
[nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
- 1 - -
-
-
-
2026-05-14
Fernando Fernandez Mancera
New
[nf,v2] netfilter: nf_queue: hold reference on skb->dev
[nf,v2] netfilter: nf_queue: hold reference on skb->dev
- - - -
-
-
-
2026-05-12
Pablo Neira Ayuso
New
[nf,v3,1/2] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
[nf,v3,1/2] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
- - - -
-
-
-
2026-05-14
Pablo Neira Ayuso
New
[nf,v3,2/2] netfilter: conntrack: add dead flag to helpers
[nf,v3,1/2] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
- 1 - -
-
-
-
2026-05-14
Pablo Neira Ayuso
New
[nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
[nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
- - - -
-
-
-
2026-05-18
Pablo Neira Ayuso
New
[nf,v4,2/3] netfilter: conntrack: add dead flag to helpers
[nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
- 1 - -
-
-
-
2026-05-18
Pablo Neira Ayuso
New
[nf,v4,3/3] netfilter: nf_conntrack_helper: add null check in nfct_help_data() calls
[nf,v4,1/3] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
- 1 - -
-
-
-
2026-05-18
Pablo Neira Ayuso
New
[nf,v4] netfilter: nf_tables: fix dst corruption in same register operation
[nf,v4] netfilter: nf_tables: fix dst corruption in same register operation
1 1 - -
-
-
-
2026-05-11
Fernando Fernandez Mancera
New
[nf,v4] netfilter: nft_bitwise: fix dst corruption in same register shifts
[nf,v4] netfilter: nft_bitwise: fix dst corruption in same register shifts
- 1 - -
-
-
-
2026-04-27
Fernando Fernandez Mancera
New
[nf-next,1/4] net: netfilter: Add ether_type to net_device_path_ctx
Add IPv4 over IPv6 flowtable SW acceleration
- - - -
-
-
-
2026-05-05
Lorenzo Bianconi
New
[nf-next,2/4] net: netfilter: Add encap_proto to flow_offload_tunnel
Add IPv4 over IPv6 flowtable SW acceleration
- - - -
-
-
-
2026-05-05
Lorenzo Bianconi
New
[nf-next,3/4] net: netfilter: Add IPv4 over IPv6 tunnel flowtable acceleration
Add IPv4 over IPv6 flowtable SW acceleration
- - - -
-
-
-
2026-05-05
Lorenzo Bianconi
New
[nf-next,4/4] selftests: netfilter: nft_flowtable.sh: Add IPv4 over IPv6 flowtable selftest
Add IPv4 over IPv6 flowtable SW acceleration
- - - -
-
-
-
2026-05-05
Lorenzo Bianconi
New
[nf-next,v2,1/2] netfilter: flowtable: update netdev stats with HW_OFFLOAD flows
Update (DSA) netdev stats with offloaded flows
- - - -
-
-
-
2026-03-24
Ahmed Zaki
Needs Review / ACK
[nf-next,v2,1/6] net: netfilter: Add ether_type to net_device_path_ctx
Add IPv4 over IPv6 and SIT flowtable SW acceleration
- - - -
-
-
-
2026-05-06
Lorenzo Bianconi
New
[nf-next,v2,2/2] net: dsa: update net_device stats with HW offloaded flows stats
Update (DSA) netdev stats with offloaded flows
- - - -
-
-
-
2026-03-24
Ahmed Zaki
Needs Review / ACK
[nf-next,v2,2/6] net: netfilter: Add encap_proto to flow_offload_tunnel
Add IPv4 over IPv6 and SIT flowtable SW acceleration
- - - -
-
-
-
2026-05-06
Lorenzo Bianconi
New
[nf-next,v2,3/6] net: netfilter: Add IPv4 over IPv6 tunnel flowtable acceleration
Add IPv4 over IPv6 and SIT flowtable SW acceleration
- - - -
-
-
-
2026-05-06
Lorenzo Bianconi
New
[nf-next,v2,4/6] selftests: netfilter: nft_flowtable.sh: Add IPv4 over IPv6 flowtable selftest
Add IPv4 over IPv6 and SIT flowtable SW acceleration
- - - -
-
-
-
2026-05-06
Lorenzo Bianconi
New
[nf-next,v2,5/6] net: netfilter: Add SIT tunnel flowtable acceleration
Add IPv4 over IPv6 and SIT flowtable SW acceleration
- - - -
-
-
-
2026-05-06
Lorenzo Bianconi
New
[nf-next,v2,6/6] selftests: netfilter: nft_flowtable.sh: Add SIT flowtable selftest
Add IPv4 over IPv6 and SIT flowtable SW acceleration
- - - -
-
-
-
2026-05-06
Lorenzo Bianconi
New
[nf-next,v2] netfilter: add option for GCOV profiling
[nf-next,v2] netfilter: add option for GCOV profiling
1 - - -
-
-
-
2026-05-12
Florian Westphal
New
[nf-next,v2] netfilter: nfnetlink_hook: Dump nat type chains
[nf-next,v2] netfilter: nfnetlink_hook: Dump nat type chains
- - - -
-
-
-
2026-03-20
Phil Sutter
Under Review
[nf-next,v2] netfilter: nft_set_rbtree: remove dead conditional
[nf-next,v2] netfilter: nft_set_rbtree: remove dead conditional
- - - -
-
-
-
2026-04-11
Florian Westphal
New
[nf-next,v5] netfilter: nf_tables: add math expression support
[nf-next,v5] netfilter: nf_tables: add math expression support
- - - -
-
-
-
2026-04-21
Fernando Fernandez Mancera
New
[nf-next] netfilter: allow nfnetlink built-in only
[nf-next] netfilter: allow nfnetlink built-in only
- - 1 -
-
-
-
2026-04-15
Pablo Neira Ayuso
New
[nf-next] netfilter: flowtable_offload: propagate CT mark to hardware offload path
[nf-next] netfilter: flowtable_offload: propagate CT mark to hardware offload path
- - - -
-
-
-
2026-04-29
Lorenzo Bianconi
New
[nf-next] netfilter: nf_conncount: use per-rule hash initval
[nf-next] netfilter: nf_conncount: use per-rule hash initval
- - - -
-
-
-
2026-04-29
Florian Westphal
New
[nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces
[nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces
- - - -
-
-
-
2026-04-29
Florian Westphal
New
[nf] ipvs: avoid possible loop in ip_vs_dst_event on resizing
[nf] ipvs: avoid possible loop in ip_vs_dst_event on resizing
- 1 - -
-
-
-
2026-05-06
Julian Anastasov
New
[nf] netfilter: conntrack: add dead flag to helpers
[nf] netfilter: conntrack: add dead flag to helpers
- 1 - -
-
-
-
2026-05-12
Pablo Neira Ayuso
New
[nf] netfilter: conntrack: correct sequence on reinitialized TCP connection
[nf] netfilter: conntrack: correct sequence on reinitialized TCP connection
- 1 - -
-
-
-
2025-02-20
Pablo Neira Ayuso
New
[nf] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
[nf] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
- 1 - -
-
-
-
2026-05-11
Hamza Mahfooz
New
[nf] netfilter: disable payload mangling in userns
[nf] netfilter: disable payload mangling in userns
- - - 1
-
-
-
2026-05-16
Qi Tang
New
[nf] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
[nf] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
- 1 - -
-
-
-
2026-05-13
Fernando Fernandez Mancera
New
[nf] netfilter: nf_conntrack_helper: fix possible null deref during error log
[nf] netfilter: nf_conntrack_helper: fix possible null deref during error log
- 1 - -
-
-
-
2026-05-09
Florian Westphal
New
[nf] netfilter: nft_inner: release local_lock before re-enabling softirqs
[nf] netfilter: nft_inner: release local_lock before re-enabling softirqs
- 1 1 -
-
-
-
2026-05-12
Florian Westphal
New
[nf] netfilter: xt_TCPMSS: check skb_dst before path-MTU clamping
[nf] netfilter: xt_TCPMSS: check skb_dst before path-MTU clamping
- 1 - -
-
-
-
2026-04-18
Weiming Shi
Under Review
[nft,1/2] parser_json: Accept non-RHS expressions in binop RHS
A bit of non-constant binop follow-up
- 1 - -
-
-
-
2026-04-02
Phil Sutter
New
«
1
2
»