Show patches with: Archived = No       |   31385 patches
« 1 2 3 4313 314 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf] netfilter: nft_dynset: missing .clone_destroy call when honoring set expression [nf] netfilter: nft_dynset: missing .clone_destroy call when honoring set expression - 1 - - --- 2026-08-18 Pablo Neira Ayuso New
[-stable,1/1] ipvs: separate destination availability state ipvs: backport cdcc4e46180d 1 1 - - --- 2026-08-18 Julian Anastasov New
netfilter: flowtable: publish HW_DEAD after worker is done netfilter: flowtable: publish HW_DEAD after worker is done - 1 - - --- 2026-08-18 Jérémy Jean New
[net,v3] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() [net,v3] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() - 1 - - --- 2026-08-18 Joas Antonio dos Santos New
[nf-next,4/4] netfilter: xt_cgroup: use pr_info_ratelimited() [nf-next,1/4] netfilter: x_tables: remove pr_debug in matches/targets - 1 2 - --- 2026-08-18 Pablo Neira Ayuso New
[nf-next,3/4] netfilter: x_tables: do not print specified table [nf-next,1/4] netfilter: x_tables: remove pr_debug in matches/targets - - - - --- 2026-08-18 Pablo Neira Ayuso New
[nf-next,2/4] netfilter: xt_CT: check for nul-terminated timeout and helper name [nf-next,1/4] netfilter: x_tables: remove pr_debug in matches/targets - 2 - - --- 2026-08-18 Pablo Neira Ayuso New
[nf-next,1/4] netfilter: x_tables: remove pr_debug in matches/targets [nf-next,1/4] netfilter: x_tables: remove pr_debug in matches/targets - - 1 - --- 2026-08-18 Pablo Neira Ayuso New
[nf] netfilter: nf_tables: fix device name and prefix match in hook lookup [nf] netfilter: nf_tables: fix device name and prefix match in hook lookup - 1 - - --- 2026-08-18 Fernando Fernandez Mancera New
[nf,1/1] netfilter: xt_IDLETIMER: validate label before debug logging in checkentry netfilter: xt_IDLETIMER: fix out-of-bounds heap read in checkentry - 2 1 - --- 2026-08-18 Ren Wei New
[net-next,8/8] ipvs: fix integer overflow in ftp helper port/address parsing [net-next,1/8] netfilter: validate L4 headers after userspace packet writes 1 1 - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,7/8] netfilter: nf_tables: call set ops .commit when building new ruleset blob [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - - - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,6/8] netfilter: nf_tables: move set_update_list to nftables per-netns [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - - - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,5/8] netfilter: ctnetlink: do not expose expectation DEAD flag [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - 1 - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,4/8] netfilter: nf_conntrack_expect: consolidate check for insertion of dead expectation [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - 1 - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,3/8] netfilter: nf_tables: don't queue packet path object notifications [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - 1 - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,2/8] netfilter: ipset: remove need to allocate memory on delete operations [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - 1 - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,1/8] netfilter: validate L4 headers after userspace packet writes [net-next,1/8] netfilter: validate L4 headers after userspace packet writes - - - - --- 2026-08-17 Pablo Neira Ayuso New
[net-next,0/8] Netfilter/IPVS fixes for net-next - - - - --- 2026-08-17 Pablo Neira Ayuso New
[nf,1/1] netfilter: xt_string: account textsearch configs netfilter: xt_string: account textsearch configs - 1 - - --- 2026-08-17 Zhiling@web.codeaurora.org, Zou@web.codeaurora.org, zhilinz@nebusec.ai New
[nf,1/1] netfilter: xt_TPROXY: require IPv6 protocol match netfilter: xt_TPROXY: require IPv6 protocol match - 1 1 - --- 2026-08-17 Zhiling@web.codeaurora.org, Zou@web.codeaurora.org, zhilinz@nebusec.ai New
[nf,v2,1/1] ipvs: bound LBLCR and LBLC cache growth ipvs: bound LBLCR and LBLC cache growth - 1 - - --- 2026-08-17 Zhiling Zou New
[nf,1/1] ipvs: bound LBLCR cache growth ipvs: bound LBLCR cache growth - 1 - - --- 2026-08-16 Zhiling Zou New
[6/6] netfilter: nft_set_pipapo_avx2: add missing vzeroupper x86: add missing vzeroupper instructions - 1 1 - --- 2026-08-15 Eric Biggers New
[nft,v2] evaluate: reject negative values for unsigned datatypes [nft,v2] evaluate: reject negative values for unsigned datatypes - 1 - - --- 2026-08-14 Avinash Duduskar New
[net,v2] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() [net,v2] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() - - - - --- 2026-08-14 Joas Antonio dos Santos New
[ipset] tests: runtest.sh: do kmemleak scan if available [ipset] tests: runtest.sh: do kmemleak scan if available - - - - --- 2026-08-13 Florian Westphal New
[nft,2/2] tests: shell: add JSON delete test for ct stateful objects parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nft,1/2] parser_json: fix CMD_OBJ/NFT_OBJECT mismatch in delete path parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress [nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress - 1 - - --- 2026-08-10 David Lee New
[nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers [nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers - - - - --- 2026-08-07 Zhixing Chen New
[nft] netlink_linearize: size nat register allocation by address expression [nft] netlink_linearize: size nat register allocation by address expression - - - - --- 2026-08-06 Adrian Moisey New
selftests: netfilter: add functional test for nft ct timeout policies selftests: netfilter: add functional test for nft ct timeout policies - - - - --- 2026-08-05 Valery Borovsky New
[net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path [net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path - - - - --- 2026-08-04 Alexandre Ferrieux New
[nf-next] netfilter: conntrack: sctp: validate vtag before state changes [nf-next] netfilter: conntrack: sctp: validate vtag before state changes - - - - --- 2026-07-31 Yizhou Zhao New
ipvs: clear IPv4 options after rebasing tunnel ICMP errors ipvs: clear IPv4 options after rebasing tunnel ICMP errors - 1 - - --- 2026-07-31 David Lee New
[conntrack-tools,v2] conntrack.8: Document --stats counters [conntrack-tools,v2] conntrack.8: Document --stats counters - - - - --- 2026-07-30 Phil Sutter New
[nf,1/1] netfilter: ebtables: avoid unbounded counter allocations netfilter: ebtables: avoid unbounded counter allocations - 1 - - --- 2026-07-27 Ren Wei New
[nf,1/1] ipvs: guard estimator enqueue until limits are set ipvs: guard estimator enqueue until limits are set - 1 - - --- 2026-07-27 Ren Wei New
[net,v2] net: flow_offload: serialize driver callback lists [net,v2] net: flow_offload: serialize driver callback lists - 1 - - --- 2026-07-26 Weiming Shi New
[nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay [nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay - 1 - - --- 2026-07-13 Weiming Shi New
[nf-next,v5] netfilter: flowtable: initial bridge support [nf-next,v5] netfilter: flowtable: initial bridge support - - - - --- 2026-07-13 Pablo Neira Ayuso New
[nf-next,v3,4/4] netfilter: nfnetlink_hook: Fix for concurrent NAT hooks dump and change Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,3/4] netfilter: nfnetlink_hook: Handle multipart NAT hook dumps Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,2/4] netfilter: nfnetlink_hook: Address hook ops using READ_ONCE() Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,1/4] netfilter: nfnetlink_hook: Pass cb object to nfnl_hook_dump_nat() Address Sashiko review of NAT hook dump code - - - - --- 2026-07-10 Phil Sutter New
[net,v3] netfilter: nf_nat: recalculate TCP TS offset after SNAT port rewrite [net,v3] netfilter: nf_nat: recalculate TCP TS offset after SNAT port rewrite - 1 - - --- 2026-07-10 xietangxin New
[nf,1/1] netfilter: xt_time: reject pre-epoch calendar matching [nf,1/1] netfilter: xt_time: reject pre-epoch calendar matching - 1 2 - --- 2026-07-03 Ren Wei New
[nft,v2,5/5] libnftables: support for several reset commands support for several list and reset commands - 1 - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,4/5] src: allow reset commands in batch with list and get commands only support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,3/5] libnftables: use nft_run_cmds() in nft_run_cmd_from_filename() support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,2/5] libnftables: split nft_run_cmd_from_buffer() in helper functions support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,1/5] libnftables: add nft_run_cmd_release() helper and use it support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nf-next] netfilter: flowtable: remove inline segmentation [nf-next] netfilter: flowtable: remove inline segmentation - - - - --- 2026-06-03 Qingfang Deng New
[9/9,nf-next] netfilter: conncount: use DEBUG_NET_WARN_ON_ONCE on reaching count limit netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[8/9,nf-next] netfilter: flowtable: use DEBUG_NET_WARN_ON_ONCE in offload path netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[7/9,nf-next] netfilter: bpf: use DEBUG_NET_WARN_ON_ONCE for missing BTF structures netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[6/9,nf-next] netfilter: tproxy: use DEBUG_NET_WARN_ON_ONCE for protocol fallbacks netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[5/9,nf-next] netfilter: nat: use DEBUG_NET_WARN_ON_ONCE in core and helper paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[4/9,nf-next] netfilter: conntrack: use DEBUG_NET_WARN_ON_ONCE on packet paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[3/9,nf-next] netfilter: nfnetlink: use DEBUG_NET_WARN_ON_ONCE for attribute validation netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[1/9,nf-next] netfilter: xtables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh [v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,2/2] netfilter: bridge: Add conntrack double vlan and pppoe conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,1/2] netfilter: utils: nf_ip(6)_checksum(_partial) correct data!=networkheader conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[net-next,v3,4/4] netfilter: nf_conntrack_sip: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 Rahul New
[net-next,v3,3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 Rahul New
[net-next,v3,2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 Rahul New
[net-next,v3,1/4] netfilter: conntrack: add shared port and uint parsers for helpers netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 Rahul New
[libnftnl,v4] expr: add support to math expression [libnftnl,v4] expr: add support to math expression - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[nf-next,v5] netfilter: nf_tables: add math expression support [nf-next,v5] netfilter: nf_tables: add math expression support - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[nft] json: output set/map element count [nft] json: output set/map element count - - - - --- 2026-04-19 Niklas Fiekas New
[nft,2/2] parser_bison: Accept non-constant binop on LHS of relationals A bit of non-constant binop follow-up - - - - --- 2026-04-02 Phil Sutter New
[nft,1/2] parser_json: Accept non-RHS expressions in binop RHS A bit of non-constant binop follow-up - 1 - - --- 2026-04-02 Phil Sutter New
[nft] cache: Fix for multiple commands in a single batch [nft] cache: Fix for multiple commands in a single batch - 1 - - --- 2026-03-11 Phil Sutter New
[nft] datatype: Accept IPv4 addresses for ip6addr_type [nft] datatype: Accept IPv4 addresses for ip6addr_type - - - - --- 2025-12-10 Phil Sutter New
[nft,v2] src: Convert ip {s,d}addr to IPv4-mapped as needed [nft,v2] src: Convert ip {s,d}addr to IPv4-mapped as needed - - - - --- 2025-12-10 Phil Sutter New
[nft,v3] src: add connlimit stateful object support [nft,v3] src: add connlimit stateful object support - - 1 - --- 2025-11-24 Fernando Fernandez Mancera New
[nf] netfilter: conntrack: correct sequence on reinitialized TCP connection [nf] netfilter: conntrack: correct sequence on reinitialized TCP connection - 1 - - --- 2025-02-20 Pablo Neira Ayuso New
[nftables] include: fix for musl with iptables v1.8.11 [nftables] include: fix for musl with iptables v1.8.11 - - - - --- 2024-12-19 Alyssa Ross New
[nft] limit: Support arbitrary unit values [nft] limit: Support arbitrary unit values - - - - --- 2024-04-13 Phil Sutter New
[4/4] lib/ts_fsm: document that a match must consume the remaining data lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - - - - --- 2026-08-16 Bernard Ladenthin Under Review
[3/4] textsearch: align ts_state.cb like skb->cb lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - - - - --- 2026-08-16 Bernard Ladenthin Under Review
[2/4] lib/tests: add KUnit tests for the textsearch infrastructure lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - - - - --- 2026-08-16 Bernard Ladenthin Under Review
[1/4] lib/ts_bm: advance state->offset past the reported match lib/textsearch: fix ts_bm resume offset, add tests, two small cleanups - 1 - - --- 2026-08-16 Bernard Ladenthin Under Review
netfilter: nf_conntrack: validate template helper protocol netfilter: nf_conntrack: validate template helper protocol - 1 - - --- 2026-08-10 Kyle Zeng Under Review
[BUG] KASAN: slab-use-after-free in hash_ipportip6_resize [BUG] KASAN: slab-use-after-free in hash_ipportip6_resize - - - - --- 2026-04-23 Eulgyu Kim Under Review
netfilter: ipset: harden payload calculation in call_ad() netfilter: ipset: harden payload calculation in call_ad() 1 - - - --- 2026-03-13 David Baum kadlec Under Review
[V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl [V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl - - - - --- 2025-04-15 lvxiafei Under Review
[v2,ipvs] ipvs: fix integer overflow in ftp helper port/address parsing [v2,ipvs] ipvs: fix integer overflow in ftp helper port/address parsing 1 1 - - --- 2026-08-13 Joas Antonio dos Santos Accepted
[nf,v2,2/2] netfilter: nf_tables: call set ops .commit when building new ruleset blob [nf,v2,1/2] netfilter: nf_tables: move set_update_list to nftables per-netns - - - - --- 2026-08-13 Pablo Neira Ayuso Accepted
[nf,v2,1/2] netfilter: nf_tables: move set_update_list to nftables per-netns [nf,v2,1/2] netfilter: nf_tables: move set_update_list to nftables per-netns - - - - --- 2026-08-13 Pablo Neira Ayuso Accepted
[nft,2/2] tests: shell: Convert dumps to numeric protocols tests: shell: Keep dumps with numeric protocol values - - - - --- 2026-08-13 Phil Sutter Accepted
[nft,1/2] tests: shell: Use --numeric-protocol for dumps tests: shell: Keep dumps with numeric protocol values - - - - --- 2026-08-13 Phil Sutter Accepted
[nf,RESEND] netfilter: nf_tables: move hardware offload step after building the chain blob [nf,RESEND] netfilter: nf_tables: move hardware offload step after building the chain blob - 1 - - --- 2026-08-13 Pablo Neira Ayuso Accepted
[nf-next] netfilter: ctnetlink: do not expose expectation DEAD flag [nf-next] netfilter: ctnetlink: do not expose expectation DEAD flag - 1 - - --- 2026-08-12 Pablo Neira Ayuso Accepted
[net-next,12/12] selftests: netfilter: conntrack_dump_flush: remove unused variables and fix typo [net-next,01/12] netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct() - - 2 - --- 2026-08-10 Pablo Neira Ayuso Accepted
[net-next,11/12] netfilter: nf_conntrack_expect: bail out on insert dead expectations [net-next,01/12] netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct() - - - - --- 2026-08-10 Pablo Neira Ayuso Accepted
[net-next,10/12] netfilter: conntrack: always lower timeout for non-closing RST packets [net-next,01/12] netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct() - 1 - - --- 2026-08-10 Pablo Neira Ayuso Accepted
[net-next,09/12] netfilter: nft_ct: move custom expectation support to helper [net-next,01/12] netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct() - 1 - - --- 2026-08-10 Pablo Neira Ayuso Accepted
« 1 2 3 4313 314 »