Show patches with: Archived = No       |   31081 patches
« 1 2 3 4310 311 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[net,15/16] netfilter: nf_conntrack_expect: store master_tuple in expectation [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,14/16] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,13/16] netfilter: nf_reject: skip iphdr options when looking for icmp header [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,12/16] netfilter: nft_flow_offload: zero device address for non-ether case [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,11/16] netfilter: nft_meta_bridge: add validate callback for get operations [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 1 - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,10/16] netfilter: nft_payload: reject offsets exceeding 65535 bytes [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 1 - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,09/16] netfilter: ipset: make sure gc is properly stopped [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,08/16] netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,07/16] netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 2 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,06/16] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,05/16] netfilter: nfnetlink: make OOM conditions fatal [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,04/16] netfilter: flowtable: fix and simplify IP6IP6 tunnel handling [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,03/16] netfilter: xt_cluster: reject template conntracks in hash match [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,02/16] netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended [net,01/16] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[net,00/16] Netfilter fixes for net - - - - --- 2026-06-19 Pablo Neira Ayuso Changes Requested
[v6.1,3/3] netfilter: nf_tables: unconditionally bump set->nelems before insertion Fix CVE-2026-23272 - 1 - - --- 2026-06-19 Shivani Agarwal Awaiting Upstream
[v6.1,2/3] netfilter: nf_tables: fix set size with rbtree backend Fix CVE-2026-23272 - 1 - - --- 2026-06-19 Shivani Agarwal Awaiting Upstream
[v6.1,1/3] netfilter: nf_tables: always increment set element count Fix CVE-2026-23272 - - - - --- 2026-06-19 Shivani Agarwal Awaiting Upstream
[nf] netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak [nf] netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak - 1 - - --- 2026-06-18 Florian Westphal Accepted
[nf] netfilter: nf_conntrack_expect: store master_tuple in expectation [nf] netfilter: nf_conntrack_expect: store master_tuple in expectation - 1 - - --- 2026-06-18 Pablo Neira Ayuso Changes Requested
[nf,v6] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations [nf,v6] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations - 1 - - --- 2026-06-18 Pablo Neira Ayuso Accepted
[nft] tests: shell: Run tests with a fixed TZ [nft] tests: shell: Run tests with a fixed TZ - - - - --- 2026-06-18 Phil Sutter Accepted
[nf] netfilter: nf_reject: skip iphdr options when looking for icmp header [nf] netfilter: nf_reject: skip iphdr options when looking for icmp header - 1 - - --- 2026-06-18 Florian Westphal Accepted
[nf] netfilter: nft_flow_offload: zero device address for non-ether case [nf] netfilter: nft_flow_offload: zero device address for non-ether case - 1 - - --- 2026-06-18 Florian Westphal Accepted
[nf] netfilter: nft_meta_bridge: add validate callback for get operations [nf] netfilter: nft_meta_bridge: add validate callback for get operations - 1 1 - --- 2026-06-18 Florian Westphal Accepted
[nf] netfilter: nft_payload: reject offsets exceeding 65535 bytes [nf] netfilter: nft_payload: reject offsets exceeding 65535 bytes - 1 1 - --- 2026-06-18 Florian Westphal Accepted
[nf,v5] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations [nf,v5] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations - 1 - - --- 2026-06-17 Pablo Neira Ayuso Changes Requested
[nf,v4] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations [nf,v4] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations - 1 - - --- 2026-06-17 Pablo Neira Ayuso Changes Requested
[nf,v2,1/1] netfilter: nf_flow_table: separate tunnel route state from direct xmit [nf,v2,1/1] netfilter: nf_flow_table: separate tunnel route state from direct xmit - 1 - - --- 2026-06-17 Ren Wei Changes Requested
[nf,v3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations [nf,v3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations - 1 - - --- 2026-06-17 Pablo Neira Ayuso Changes Requested
[v3,5/7] netfilter: ipset: make sure gc is properly stopped netfilter: ipset fixes, second batch - - - - --- 2026-06-17 Jozsef Kadlecsik Accepted
[v3,3/7] netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() netfilter: ipset fixes, second batch - - - - --- 2026-06-17 Jozsef Kadlecsik Accepted
[v3,2/7] netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types netfilter: ipset fixes, second batch - - - - --- 2026-06-17 Jozsef Kadlecsik Accepted
[v3,1/7] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types netfilter: ipset fixes, second batch - - - - --- 2026-06-17 Jozsef Kadlecsik Accepted
[nf] netfilter: nfnetlink: make OOM conditions fatal [nf] netfilter: nfnetlink: make OOM conditions fatal - 1 - - --- 2026-06-16 Florian Westphal Not Applicable
[nf-next,v3,3/4] netfilter: nf_sockopt: replace u_int8_t with u8 netfilter: replace u_int*_t with kernel int types - - - - --- 2026-06-16 Carlos Grillet Changes Requested
[nf-next,v3,2/4] netfilter: nf_nat_irc: replace u_int16_t with u16 netfilter: replace u_int*_t with kernel int types - - - - --- 2026-06-16 Carlos Grillet Changes Requested
[nf-next,v3,1/4] netfilter: nf_nat_ftp: replace u_int16_t with u16 netfilter: replace u_int*_t with kernel int types - - - - --- 2026-06-16 Carlos Grillet Changes Requested
[nf] netfilter: nft_compat: ebtables emulation must reject non-bridge targets [nf] netfilter: nft_compat: ebtables emulation must reject non-bridge targets - 1 - - --- 2026-06-15 Florian Westphal Accepted
[nf,v2] netfilter: flowtable: fix and simplify IP6IP6 tunnel handling [nf,v2] netfilter: flowtable: fix and simplify IP6IP6 tunnel handling - 1 - - --- 2026-06-15 Lorenzo Bianconi Accepted
[net-next] netfilter: x_tables.h: fix all kernel-doc warnings [net-next] netfilter: x_tables.h: fix all kernel-doc warnings - - - - --- 2026-06-14 Randy Dunlap Accepted
[nf,1/1] netfilter: xt_nat: reject unsupported target families netfilter: xt_nat: bridge nft_compat rule can trigger NULL-deref - 1 - - --- 2026-06-13 Ren Wei Not Applicable
[nf-next] netfilter: conntrack: add deprecation warnings for irc and pptp trackers [nf-next] netfilter: conntrack: add deprecation warnings for irc and pptp trackers - - - - --- 2026-06-12 Florian Westphal Accepted
[nf,v3] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test [nf,v3] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test 1 - - - --- 2026-06-11 Florian Westphal Accepted
[nft,v2] parser_bison: Fix for bison < 3.6 [nft,v2] parser_bison: Fix for bison < 3.6 - 1 - - --- 2026-06-11 Phil Sutter New
[nf,1/1] netfilter: xt_cluster: reject template conntracks in hash match [nf,1/1] netfilter: xt_cluster: reject template conntracks in hash match - 1 - - --- 2026-06-11 Ren Wei Accepted
[net] netfilter: nft_synproxy: stop bypassing the priv->info snapshot [net] netfilter: nft_synproxy: stop bypassing the priv->info snapshot - 1 1 - --- 2026-06-11 Runyu Xiao Accepted
[libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols [libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols - 1 - - --- 2026-06-10 Pablo Neira Ayuso Accepted
[libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols [libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols - 1 - - --- 2026-06-10 Pablo Neira Ayuso Changes Requested
[nft] profiling: Include unistd.h to avoid compiler warnings [nft] profiling: Include unistd.h to avoid compiler warnings - 1 - - --- 2026-06-10 Phil Sutter Accepted
[nf-next,v2] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them [nf-next,v2] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them - 2 - - --- 2026-06-10 Pablo Neira Ayuso Changes Requested
[nf-next,v2] netfilter: conntrack: check NULL when retrieving ct extension [nf-next,v2] netfilter: conntrack: check NULL when retrieving ct extension - - - - --- 2026-06-10 Pablo Neira Ayuso Changes Requested
[nf-next] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them [nf-next] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them - 1 - - --- 2026-06-09 Pablo Neira Ayuso Changes Requested
[nf-next,v2] netfilter: conntrack: check NULL when retrieving ct extension [nf-next,v2] netfilter: conntrack: check NULL when retrieving ct extension - - - - --- 2026-06-09 Pablo Neira Ayuso Changes Requested
[nf-next] netfilter: flowtable: bail out if forward path cannot be discovered [nf-next] netfilter: flowtable: bail out if forward path cannot be discovered - - - - --- 2026-06-09 Pablo Neira Ayuso Changes Requested
[2/2] netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register netfilter: fix two remaining stale-stack register leaks - 1 - - --- 2026-06-09 Davide Ornaghi Accepted
[1/2] netfilter: nft_fib: fix stale stack leak via the OIFNAME register netfilter: fix two remaining stale-stack register leaks - 1 - - --- 2026-06-09 Davide Ornaghi Accepted
[net-next] ipvs: fix doc syntax for conn_max sysctl [net-next] ipvs: fix doc syntax for conn_max sysctl - 1 - - --- 2026-06-08 Julian Anastasov Accepted
[nf-next] netfilter: conntrack: check NULL when calling nf_ct_ext_find() [nf-next] netfilter: conntrack: check NULL when calling nf_ct_ext_find() - 1 - - --- 2026-06-08 Pablo Neira Ayuso Changes Requested
[nf] netfilter: flowtable: use pskb_may_pull() in nf_flow_ip6_tunnel_proto() [nf] netfilter: flowtable: use pskb_may_pull() in nf_flow_ip6_tunnel_proto() - 1 - - --- 2026-06-08 Lorenzo Bianconi Accepted
netfilter: x_tables: avoid leaking percpu counter pointers netfilter: add restrictions/validations for packet rewrite - 1 - - --- 2026-06-08 Florian Westphal Accepted
[nf,v2] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() [nf,v2] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() - 1 - - --- 2026-06-08 Lorenzo Bianconi Accepted
[nf,v5,1/1] bridge: br_netfilter: pin bridge device while NFQUEUE holds fake dst [nf,v5,1/1] bridge: br_netfilter: pin bridge device while NFQUEUE holds fake dst - 1 - - --- 2026-06-08 Ren Wei Accepted
[net-next,15/15] netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() [net-next,01/15] ipvs: add conn_max sysctl to limit connections - - 1 - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,14/15] netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 1 - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,13/15] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,12/15] netfilter: conntrack: revert ct extension genid infrastructure [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,11/15] netfilter: nf_conntrack_helper: add refcounting from datapath [net-next,01/15] ipvs: add conn_max sysctl to limit connections - - - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,10/15] netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker [net-next,01/15] ipvs: add conn_max sysctl to limit connections - - - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,09/15] netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper [net-next,01/15] ipvs: add conn_max sysctl to limit connections - - - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,08/15] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 2 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,07/15] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,06/15] netfilter: synproxy: fix unaligned memory access in timestamp adjustment [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,05/15] netfilter: synproxy: adjust duplicate timestamp options [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,04/15] netfilter: synproxy: drop packets if timestamp adjustment fails [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,03/15] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,02/15] netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures [net-next,01/15] ipvs: add conn_max sysctl to limit connections - 1 - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,01/15] ipvs: add conn_max sysctl to limit connections [net-next,01/15] ipvs: add conn_max sysctl to limit connections - - - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[net-next,00/15] Netfilter/IPVS updates for net-next - - - - --- 2026-06-07 Pablo Neira Ayuso Accepted
[nf] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() [nf] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() - 1 - - --- 2026-06-05 Lorenzo Bianconi Changes Requested
[nf] netfilter: flowtable: fix IP6IP6 tunnel offset double-count with vlan/pppoe encap [nf] netfilter: flowtable: fix IP6IP6 tunnel offset double-count with vlan/pppoe encap 1 1 - - --- 2026-06-04 David Carlier Not Applicable
[nf-next,v5,7/7] netfilter: ctnetlink: call helper->destroy() when unhelping conntrack [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 1 - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v5,6/7] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 1 - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v5,5/7] netfilter: conntrack: revert ct extension genid infrastructure [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 1 - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v5,4/7] netfilter: nf_conntrack_helper: add refcounting from datapath [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - - - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v5,3/7] netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - - - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v5,2/7] netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - - - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount [nf-next,v5,1/7] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 2 - - --- 2026-06-04 Pablo Neira Ayuso Accepted
[nf-next,v4,6/6] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp [nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 1 - - --- 2026-06-03 Pablo Neira Ayuso Changes Requested
[nf-next,v4,5/6] netfilter: conntrack: revert ct extension genid infrastructure [nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 1 - - --- 2026-06-03 Pablo Neira Ayuso Changes Requested
[nf-next,v4,4/6] netfilter: nf_conntrack_helper: add refcounting from datapath [nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - - - - --- 2026-06-03 Pablo Neira Ayuso Changes Requested
[nf-next,v4,3/6] netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker [nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - - - - --- 2026-06-03 Pablo Neira Ayuso Changes Requested
[nf-next,v4,2/6] netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper [nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - - - - --- 2026-06-03 Pablo Neira Ayuso Changes Requested
[nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount [nf-next,v4,1/6] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount - 2 - - --- 2026-06-03 Pablo Neira Ayuso Changes Requested
[nft,6/6] netlink: Call tunnel getters unconditionally Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,5/6] src: Avoid variable declarations in switch cases Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,4/6] rule: Introduce tunnel_obj_print_data() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,3/6] rule: Turn obj_print_comment() into obj_print_header() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,2/6] parser_json: Introduce json_parse_tunnel() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
« 1 2 3 4310 311 »