messages from 2026-07-17 10:39:20 to 2026-07-30 10:34:16 UTC [more...]
[PATCH nf v2 1/1] netfilter: validate L4 headers after userspace packet writes
2026-07-30 10:34 UTC (2+ messages)
[PATCH bpf] bpf: Fix netns reference imbalance in conntrack kfuncs
2026-07-30 9:52 UTC (6+ messages)
` [PATCH bpf v2] "
[PATCH nf] netfilter: nft_ct: postpone expectation creation to confirmed conntrack
2026-07-30 9:48 UTC
[conntrack-tools PATCH v2] conntrack.8: Document --stats counters
2026-07-30 9:18 UTC
Backport request: "netfilter: nf_conntrack_expect: restore helper propagation via expectation"
2026-07-29 23:07 UTC (2+ messages)
[PATCH nft v2] datatype: accept a numeric cgroupsv2 id on input
2026-07-29 17:37 UTC
[PATCH] netfilter: ebt_nflog: pin the NFLOG backend
2026-07-29 17:31 UTC
[PATCH nf-next] netfilter: conntrack: tcp: use UNACK timeout for non-closing RST packets
2026-07-29 15:51 UTC (4+ messages)
` "
` [PATCH v2 "
[PATCH nf 0/1] netfilter: fix TCP conntrack invalid-log deadlock
2026-07-29 15:28 UTC (4+ messages)
` [PATCH nf 1/1] netfilter: nf_conntrack_tcp: defer invalid logging until after unlock
[PATCH ipset 0/5] ipset test updates
2026-07-29 15:05 UTC
[PATCH nf 0/1] netfilter: h323: fix helper NAT mangling
2026-07-29 14:45 UTC (6+ messages)
` [PATCH nf 1/1] netfilter: h323: keep NAT mangling aligned with parsed transport
[nft PATCH 1/2] gitignore: Only ignore top level *.m4
2026-07-29 14:21 UTC (3+ messages)
` [nft PATCH 2/2] m4: Add missing AX_PROG_BISON macro
[PATCH nft] datatype: accept a numeric cgroupsv2 id on input
2026-07-29 14:19 UTC (11+ messages)
[PATCH nf v3 1/1] ipvs: stop estimator after disabled calc phase
2026-07-29 13:56 UTC
[PATCH nf,v2 1/2] netfilter: ctnetlink: reject expectation deletions on unconfirmed conntrack
2026-07-29 12:38 UTC (3+ messages)
` [PATCH nf,v2 2/2] netfilter: nf_conntrack: move expectation hlist_head on ct extension realloc
[PATCH nf-next,v5 1/6] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
2026-07-29 11:49 UTC (6+ messages)
` [PATCH nf-next,v5 2/6] netfilter: flowtable: consolidate flowtable device check
` [PATCH nf-next,v5 3/6] net: dsa: stop at the user device in .fill_forward_path
` [PATCH nf-next,v5 4/6] net: do not advance stack index from dev_fwd_path()
` [PATCH nf-next,v5 5/6] net: pass dst via net_device_path in dev_fill_forward_path()
` [PATCH nf-next,v5 6/6] netfilter: flowtable: release tunnel route on error when building forward path
[PATCH nf-next] netfilter: nf_tables: call skb_valid_dst() before skb_dst()
2026-07-29 9:45 UTC (3+ messages)
[PATCH nf] netfilter: conntrack: sctp: verify vtag before state changes
2026-07-29 4:56 UTC (3+ messages)
[PATCH nf 0/1] netfilter: ebtables: avoid unbounded counter allocations
2026-07-29 4:44 UTC (4+ messages)
` [PATCH nf 1/1] "
[PATCH nf] netfilter: nf_conntrack: move expectation hlist_head on ct extension realloc
2026-07-29 0:39 UTC (2+ messages)
[PATCH nf v2 0/2] ipvs: csum validations, part 2
2026-07-28 21:39 UTC (4+ messages)
` [PATCH nf v2 1/2] ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
` [PATCH nf v2 2/2] ipvs: return the csum validation for forward hook
[nft PATCH v2] parser_bison: Fix for bison < 3.6
2026-07-28 15:10 UTC (4+ messages)
[PATCH net-next v3] net: ip6_tunnel: use tunnel parameters for fill_forward_path route lookup
2026-07-28 14:10 UTC (3+ messages)
[PATCH nf v2 1/1] ipvs: stop estimator after disabled calc phase
2026-07-28 13:04 UTC (2+ messages)
[PATCH nf-next,v4 1/5] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
2026-07-28 12:26 UTC (5+ messages)
` [PATCH nf-next,v4 2/5] netfilter: flowtable: consolidate flowtable device check
` [PATCH nf-next,v4 3/5] net: do not advance stack index from dev_fwd_path()
` [PATCH nf-next,v4 4/5] net: pass dst via net_device_path in dev_fill_forward_path()
` [PATCH nf-next,v4 5/5] netfilter: flowtable: release tunnel route on error when building forward path
[PATCH nf-next,v3 1/5] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
2026-07-28 11:09 UTC (5+ messages)
` [PATCH nf-next,v3 2/5] netfilter: flowtable: consolidate flowtable device check
` [PATCH nf-next,v3 3/5] net: do not advance stack index from dev_fwd_path()
` [PATCH nf-next,v3 4/5] net: pass dst via net_device_path in dev_fill_forward_path()
` [PATCH nf-next,v3 5/5] netfilter: flowtable: release tunnel route on error when building forward path
nftables: regression/bug in interval set lookup in 6.18.14, still present in 7.1.5
2026-07-28 10:45 UTC (2+ messages)
[PATCH net-next 0/7] Netfilter/IPVS updates for net-next
2026-07-28 1:10 UTC (9+ messages)
` [PATCH net-next 1/7] ipvs: Move defense_work and est_reload_work to system_dfl_long_wq
` [PATCH net-next 2/7] netfilter: xt_tcpmss: extend checkentry to ipv6
` [PATCH net-next 3/7] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
` [PATCH net-next 4/7] netfilter: flowtable: tear down flow entries with stale dst from GC
` [PATCH net-next 5/7] netfilter: conntrack_helper: pass master conntrack to helper functions
` [PATCH net-next 6/7] netfilter: nf_conntrack_expect: store event cache in expectation
` [PATCH net-next 7/7] ipvs: use type-safe allocation helpers in ip_vs_rht_alloc
[PATCH 00/36] treewide: remove conditional returns with no effect
2026-07-27 12:59 UTC (10+ messages)
` [PATCH 11/36] ipvs: remove conditional return "
` (subset) [PATCH 00/36] treewide: remove conditional returns "
[PATCH nf 0/2] ipvs: csum validations, part 2
2026-07-27 20:29 UTC (4+ messages)
` [PATCH nf 1/2] ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
` [PATCH nf 2/2] ipvs: return the per-proto csum validations
[PATCH nf-next] netfilter: conncount: normalize tuple and zone on successful ct lookup
2026-07-27 19:41 UTC
[PATCH nf 0/1] ipvs: guard estimator enqueue until limits are set
2026-07-27 18:48 UTC (3+ messages)
` [PATCH nf 1/1] "
[PATCH nf-next,v2 1/5] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
2026-07-27 14:25 UTC (7+ messages)
` [PATCH nf-next,v2 2/5] netfilter: flowtable: consolidate flowtable device check
` [PATCH nf-next,v2 3/5] net: do not advance stack index from dev_fwd_path()
` [PATCH nf-next,v2 4/5] net: pass dst via net_device_path in dev_fill_forward_path()
` [PATCH nf-next,v2 5/5] netfilter: flowtable: release tunnel route on error when building forward path
[PATCH nft] mergesort: use lhs expression when sorting concatenation
2026-07-27 14:21 UTC
[PATCH net v2] net: flow_offload: serialize driver callback lists
2026-07-26 12:03 UTC
[PATCH nf] netfilter: ipset: fix refcount race between list:set GC and swap
2026-07-25 21:59 UTC (3+ messages)
[PATCH nf-next 0/4] flowtable: pass dst_entry from ipip tunnel
2026-07-25 11:05 UTC (9+ messages)
` [PATCH nf-next 1/4] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
` [PATCH nf-next 2/4] netfilter: flowtable: consolidate flowtable device check
` [PATCH nf-next 3/4] net: pass dst via net_device_path in dev_fill_forward_path()
` [PATCH nf-next 4/4] netfilter: flowtable: release tunnel route on error when building forward path
[PATCH net,v2 00/13] Netfilter/IPVS fixes for net
2026-07-25 0:20 UTC (15+ messages)
` [PATCH net 01/13] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
` [PATCH net 02/13] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests
` [PATCH net 03/13] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
` [PATCH net 04/13] netfilter: ipset: do not update comments from kernel-side hash adds
` [PATCH net 05/13] ipvs: do not propagate one-packet flag to synced conns
` [PATCH net 06/13] ipvs: adjust double hashing when fwd method changes
` [PATCH net 07/13] netfilter: nf_tables: make nft_object rhltable per table
` [PATCH net 08/13] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
` [PATCH net 09/13] ipvs: fix the checksum validations
` [PATCH net 10/13] ipvs: fix places with wrong packet offsets
` [PATCH net 11/13] ipvs: do not mangle ICMP replies for non-first fragments
` [PATCH net 12/13] ipvs: clear the nfct flag under lock
` [PATCH net 13/13] netfilter: nft_payload: fix mask build for partial field offload
[nf-next PATCH v3 0/4] Address Sashiko review of NAT hook dump code
2026-07-24 10:54 UTC (3+ messages)
[PATCH net 00/13] Netfilter/IPVS fixes for net
2026-07-23 19:40 UTC (18+ messages)
` [PATCH net 01/13] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
` [PATCH net 02/13] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests
` [PATCH net 03/13] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
` [PATCH net 04/13] netfilter: ipset: do not update comments from kernel-side hash adds
` [PATCH net 05/13] ipvs: do not propagate one-packet flag to synced conns
` [PATCH net 06/13] ipvs: adjust double hashing when fwd method changes
` [PATCH net 07/13] netfilter: nf_tables: make nft_object rhltable per table
` [PATCH net 08/13] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
` [PATCH net 09/13] ipvs: fix the checksum validations
` [PATCH net 10/13] ipvs: fix places with wrong packet offsets
` [PATCH net 11/13] ipvs: do not mangle ICMP replies for non-first fragments
` [PATCH net 12/13] ipvs: clear the nfct flag under lock
` [PATCH net 13/13] netfilter: nft_payload: fix mask build for partial field offload
[nft PATCH 0/6] Eliminate variable declarations in switch cases
2026-07-22 16:57 UTC (5+ messages)
` [nft PATCH 6/6] netlink: Call tunnel getters unconditionally
[PATCH net] netfilter: nf_conntrack_h323: fix get_bitmap() overread
2026-07-22 12:57 UTC
[PATCH nf v3 0/3] ipvs: csum validations and data offsets
2026-07-22 11:56 UTC (5+ messages)
` [PATCH nf v3 1/3] ipvs: fix the checksum validations
` [PATCH nf v3 2/3] ipvs: fix places with wrong packet offsets
` [PATCH nf v3 3/3] ipvs: do not mangle ICMP replies for non-first fragments
[PATCH nf] ipvs: clear the nfct flag under lock
2026-07-22 10:25 UTC
[PATCH nf-next] ipvs: use type-safe allocation helpers in ip_vs_rht_alloc
2026-07-22 10:23 UTC (3+ messages)
[PATCH net-next v2] net: ip6_tunnel: use tunnel parameters for fill_forward_path route lookup
2026-07-22 7:12 UTC
[PATCH nf,v3] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
2026-07-22 5:56 UTC (2+ messages)
[PATCH nf,v2] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
2026-07-21 20:32 UTC
[PATCH nf] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
2026-07-21 20:20 UTC
[PATCH net-next] net: ip6_tunnel: use tunnel parameters for fill_forward_path route lookup
2026-07-21 10:54 UTC (2+ messages)
[PATCH net-next] net: ipip: use tunnel parameters for fill_forward_path route lookup
2026-07-21 10:40 UTC (2+ messages)
[SECURITY] net/netfilter/xt_hashlimit: Uninitialized rateinfo.burst read via shared table mode confusion (CWE-457)
2026-07-21 7:56 UTC
[PATCH] netfilter: xt_hashlimit: fix uninitialized rateinfo.burst read on shared table
2026-07-21 7:46 UTC
[PATCH nf v2 0/2] ipvs: csum validations and data offsets
2026-07-21 6:19 UTC (4+ messages)
` [PATCH nf v2 1/2] ipvs: fix the checksum validations
` [PATCH nf v2 2/2] ipvs: fix places with wrong packet offsets
[PATCH nf] netfilter: nft_payload: fix mask build for partial field offload
2026-07-19 22:15 UTC
[PATCH iptables] nft: fix out-of-bounds read listing an old-revision match
2026-07-17 18:59 UTC
[PATCH iptables] nft: bridge: fix among buffer overflow when set has no size
2026-07-17 18:56 UTC
[PATCH net 0/9] netfilter: updates for net
2026-07-17 17:41 UTC (4+ messages)
` [PATCH net 8/9] ipvs: fix more places with wrong ipv6 transport offsets
[PATCH nf,v3] netfilter: nf_tables: make nft_object rhltable per table
2026-07-17 11:06 UTC
page: next (older) | prev (newer) | latest
- recent:[subjects (threaded)|topics (new)|topics (active)]
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox