Linux Netfilter development
 help / color / mirror / Atom feed
 messages from 2026-09-18 11:28:55 to 2026-09-25 07:52:48 UTC [more...]

[PATCH 6.18.y 0/2] netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
 2026-09-25  7:52 UTC  (2+ messages)
` [PATCH 6.18.y 2/2] "

[PATCH request stable 6.12 6.6 6.1] netfilter: nf_tables_netdev_event UAF of binding chain
 2026-09-25  7:51 UTC  (7+ messages)
    ` [PATCH 6.12 1/2] netfilter: nf_tables: Tolerate chains with no remaining hooks
    ` [PATCH 6.12 2/2] netfilter: nf_tables: Simplify chain netdev notifier
    ` [PATCH 6.6 6.1 1/2] netfilter: nf_tables: Tolerate chains with no remaining hooks
    ` [PATCH 6.6 6.1 2/2] netfilter: nf_tables: Simplify chain netdev notifier

[PATCH net-next] netfilter: nf_flow_table_bpf: populate VLAN encap in XDP flowtable lookup
 2026-09-24 20:25 UTC 

[PATCH nf v3] netfilter: nft_reject: prevent unbounded recursion in output hooks
 2026-09-24 20:13 UTC 

[PATCH nf,v4] netfilter: flowtable: generalize pending status bit
 2026-09-24 20:11 UTC 

[ANNOUNCE] New mirrors to public git.netfilter.org repositories
 2026-09-24 18:19 UTC 

[PATCH net v6 0/2] net: prevent partial checksums from modifying network headers
 2026-09-24 17:18 UTC  (13+ messages)
` [PATCH net v6 1/2] net: validate virtio checksum start after network header
` [PATCH net v6 2/2] ip: reject partial checksums covering network headers

[PATCH net 0/6] ovs, net/sched: fixes for UAF after conntrack extension realloc
 2026-09-24 17:10 UTC  (31+ messages)
` [PATCH net 1/6] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry
` [PATCH net 2/6] net: openvswitch: conntrack: remove 'add_helper' dead code
` [PATCH net 3/6] net: openvswitch: conntrack: fix helper UAF due to extensions realloc
` [PATCH net 4/6] net/sched: act_ct: avoid modifying shared unconfirmed ct entry
` [PATCH net 5/6] net/sched: act_ct: remove 'add_helper' dead code
` [PATCH net 6/6] net/sched: act_ct: fix helper UAF due to extensions realloc

[PATCH nf v4 0/3] ipvs: avoid stack overflow from recursive connection expiration
 2026-09-24 12:11 UTC  (5+ messages)
` [PATCH nf v4 1/3] ipvs: wait the running timer cb on conn deletion
` [PATCH nf v4 2/3] ipvs: avoid stack overflow from recursive connection expiration
` [PATCH nf v4 3/3] ipvs: reject FTP control ports as data ports

conntrack extension preallocation problems
 2026-09-24 10:46 UTC 

[PATCH net v5 0/2] net: prevent partial checksums from modifying network headers
 2026-09-24  8:54 UTC  (9+ messages)
  ` [PATCH net v5 1/2] net: validate virtio checksum start after network header
  ` [PATCH net v5 2/2] ip: reject partial checksums covering network headers

[BUG] netfilter: nf_tables_netdev_event UAF of JUMP binding chain
 2026-09-24  7:05 UTC  (2+ messages)

[PATCH v2] netfilter: nf_nat: Fix stale outer UDP checksum on VXLAN encapsulated packets
 2026-09-24  7:04 UTC  (2+ messages)

[PATCH nf,v2] netfilter: flowtable: restore wireless forward path
 2026-09-23 22:22 UTC 

[PATCH nf v2] netfilter: nft_reject: prevent unbounded recursion in output hooks
 2026-09-23 22:06 UTC  (4+ messages)

[PATCH nf,v3] netfilter: nfnetlink_queue: hash queue instance by portid too
 2026-09-23 20:04 UTC  (2+ messages)

[PATCH nf] netfilter: flowtable: restore wireless forward path
 2026-09-23 19:50 UTC 

[PATCH nf-next v4 0/4] netfilter: conntrack: shared port parser for helpers
 2026-09-23 17:15 UTC  (5+ messages)
` [PATCH nf-next v4 1/4] netfilter: conntrack: add shared uint and port parsers "
` [PATCH nf-next v4 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port()
` [PATCH nf-next v4 3/4] netfilter: nf_conntrack_amanda: "
` [PATCH nf-next v4 4/4] netfilter: nf_conntrack_sip: use shared helper parsers

[PATCH v2 nf-next] netfilter: conntrack: add and use nf_ct_get_real()
 2026-09-23 12:27 UTC 

[PATCH nf,v3] netfilter: flowtable: generalize pending status bit
 2026-09-23 10:56 UTC 

[PATCH nf-next] netfilter: conntrack: add and use nf_ct_get_real()
 2026-09-23 10:54 UTC 

[PATCH net 0/2] netfilter: nf_conntrack_h323: fixes for NAT bypass and ASN.1 decode
 2026-09-23 10:46 UTC  (5+ messages)
` [PATCH net 1/2] netfilter: nf_conntrack_h323: do not bypass NAT helpers when tuple source matches reply destination
` [PATCH net 2/2] netfilter: nf_conntrack_h323: check extension bitmap before decoding components

[PATCH nf 0/1] netfilter: ecache: bound destroy event redelivery
 2026-09-22 21:03 UTC  (3+ messages)
` [PATCH nf 1/1] "

[PATCH nf] netfilter: bpf: reject invalid NAT manipulation types
 2026-09-22 19:18 UTC 

[PATCH v5 nf-next 0/3] ipvs: add per-service secure_tcp
 2026-09-22 17:12 UTC  (7+ messages)
` [PATCH v5 nf-next 1/3] ipvs: add flags for per-service secure TCP state table
` [PATCH v5 nf-next 2/3] ipvs: tcp: enable per-connection secure_tcp in state machine
` [PATCH v5 nf-next 3/3] selftests: netfilter: ipvs: add per-service secure_tcp test
    ` [PATCH v5 nf-next 3/3] selftests: netfilter: ipvs: add per-service secure_tcp test (David Dull)

[PATCH] ipvs: skip committing sync_threshold when proc_dointvec fails
 2026-09-22 16:52 UTC  (2+ messages)

[PATCH nf-next] netfilter: nft_nat: use the right enum members for nat type switch
 2026-09-22 16:51 UTC  (2+ messages)

[PATCH nf v3 0/1] netfilter: nf_dup: disable duplication in user namespaces
 2026-09-22  9:52 UTC  (2+ messages)
` [PATCH nf v3 1/1] "

[PATCH nf] netfilter: nft_reject: prevent unbounded recursion in output hooks
 2026-09-22  9:05 UTC  (3+ messages)

[PATCH] netfilter: nf_nat: Fix stale outer UDP checksum on VXLAN encapsulated packets
 2026-09-21 13:01 UTC  (3+ messages)

[PATCH net 1/8] netfilter: flowtable: publish HW_DEAD after worker is done
 2026-09-21 22:20 UTC  (4+ messages)

[PATCH net 01/10] netfilter: flowtable: publish HW_DEAD after worker is done
 2026-09-21 20:56 UTC  (5+ messages)
    ` my summary of LLM judgement in this PR [was Re: [PATCH net 01/10] netfilter: flowtable: publish HW_DEAD after worker is done]

[PATCH nf] netfilter: nft_set_rbtree: skip transaction elements during GC
 2026-09-21 20:48 UTC  (4+ messages)

[PATCH nft] payload: restore is_raw flag for th expressions parsed from udata
 2026-09-21 18:50 UTC  (2+ messages)

[BUG] netfilter: unbounded nftables reject recursion on inet OUTPUT
 2026-09-21 10:32 UTC  (3+ messages)

[PATCH net v2 0/2] ipvs: avoid stack overflow from recursive connection expiration
 2026-09-21  7:10 UTC  (10+ messages)
` [PATCH net v2 1/2] "
` [PATCH net v2 2/2] ipvs: reject FTP control ports as data ports

[PATCH v4 nf-next 0/3] ipvs: add per-service secure_tcp
 2026-09-21  5:50 UTC  (7+ messages)
` [PATCH v4 nf-next 1/3] ipvs: add flags for per-service secure TCP state table
` [PATCH v4 nf-next 2/3] ipvs: tcp: enable per-connection secure_tcp in state machine
` [PATCH v4 nf-next 3/3] selftests: netfilter: ipvs: add per-service secure_tcp test

[PATCH 6.12.y 0/3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
 2026-09-20 17:50 UTC  (5+ messages)
` [PATCH 6.12.y 1/3] netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
` [PATCH 6.12.y 2/3] netfilter: conntrack: check NULL when retrieving ct extension
` [PATCH 6.12.y 3/3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations

[PATCH net 0/1] ipvs: bound twos scheduler destination walks
 2026-09-20 14:09 UTC  (8+ messages)

[PATCH nf v3 0/1] netfilter: x_tables: avoid holding mutex over faultable user copies
 2026-09-20 11:58 UTC  (2+ messages)
` [PATCH nf v3 1/1] "

[PATCH nf v3 0/2] ipvs: avoid stack overflow from recursive connection expiration
 2026-09-20  9:31 UTC  (3+ messages)
` [PATCH nf v3 1/2] "
` [PATCH nf v3 2/2] ipvs: reject FTP control ports as data ports

[PATCH] netfilter: nf_nat: fix unsigned range_size underflow for ICMP and GRE when max < min
 2026-09-19 21:52 UTC 

[PATCH] netfilter: nfnetlink_log: fix config error handling, SIT headroom OOB read, and nlmsg rollback
 2026-09-19 21:52 UTC 

[PATCH v2 nf 0/2] ipvs: filter some connection flags
 2026-09-19 18:07 UTC  (3+ messages)
` [PATCH v2 nf 1/2] ipvs: do not create invisible templates
` [PATCH v2 nf 2/2] ipvs: filter some flags received in the backup server

[PATCH net,v2 0/8] Netfilter/IPVS fixes for net
 2026-09-19 15:02 UTC  (11+ messages)
` [PATCH net 3/8] netfilter: ip6t_rpfilter: reject routes without inet6_dev
` [PATCH net 4/8] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read
` [PATCH net 5/8] netfilter: nft_synproxy: use the family-aware checksum helper
` [PATCH net 6/8] ipvs: revalidate ihl before icmp_send
` [PATCH net 7/8] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name
` [PATCH net 8/8] netfilter: nf_tables: skip expired catchall elements on insert and delete

[PATCH nf 0/1] netfilter: nf_ip6_checksum: validate checksum offset
 2026-09-19 14:35 UTC  (5+ messages)

[PATCH nf-next] selftests: netfilter: nft_queue.sh: only queue icmp echo request/reply
 2026-09-19  6:24 UTC  (2+ messages)

[PATCH] netfilter: nf_tables: defer object destruction on abort past commit_mutex
 2026-09-19  3:34 UTC  (2+ messages)
` [PATCH v2] "

[PATCH net] selftests: net: update netfilter netlink config
 2026-09-19  0:30 UTC  (2+ messages)

[PATCH 6.1.y 0/3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
 2026-09-18 18:24 UTC  (4+ messages)
` [PATCH 6.1.y 1/3] netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
` [PATCH 6.1.y 2/3] netfilter: conntrack: check NULL when retrieving ct extension
` [PATCH 6.1.y 3/3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations

[PATCH 6.6.y 0/3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
 2026-09-18 18:23 UTC  (4+ messages)
` [PATCH 6.6.y 1/3] netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
` [PATCH 6.6.y 2/3] netfilter: conntrack: check NULL when retrieving ct extension
` [PATCH 6.6.y 3/3] netfilter: nf_conntrack_expect: use conntrack GC to reap expectations

[PATCH nf v3 0/6] netfilter: harden conntrack vs ingress pipeline rewrites
 2026-09-18 14:58 UTC  (7+ messages)
` [PATCH v3 nf 1/6] netfilter: nf_conntrack: validate skb->_nfct and packet headers
` [PATCH v3 nf 2/6] netfilter: nf_conntrack: refactor helper call logic in nf_confirm()
` [PATCH v3 nf 3/6] netfilter: nf_conntrack: verify L4 protocol before calling helper
` [PATCH v3 nf 4/6] netfilter: conntrack: replace open-coded helper invocation
` [PATCH v3 nf 5/6] netfilter: nf_conntrack: harden helper invocation with tuple revalidation
` [PATCH v3 nf 6/6] netfilter: nft_ct: validate timeout object protocol

[PATCH nf,v2] netfilter: flowtable: generalize pending status bit
 2026-09-18 12:45 UTC 

[PATCH nf] netfilter: flowtable: generalize pending status bit
 2026-09-18 11:53 UTC 


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox