summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2024-12-05apparmor: fix 'Do simple duplicate message elimination'chao liu
2024-11-17security/keys: fix slab-out-of-bounds in key_task_permissionChen Ridong
2024-11-08selinux: improve error checking in sel_write_load()Paul Moore
2024-11-08tomoyo: fallback to realpath if symlink's pathname does not existTetsuo Handa
2024-11-08smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipsoJiawei Ye
2024-09-12smack: unix sockets: fix accept()ed socket labelKonstantin Andreev
2024-09-12smack: tcp: ipv4, fix incorrect labelingCasey Schaufler
2024-09-12apparmor: fix possible NULL pointer dereferenceLeesoo Ahn
2024-09-04selinux: fix potential counting error in avc_add_xperms_decision()Zhen Lei
2024-04-13smack: Handle SMACK64TRANSMUTE in smack_inode_setsecurity()Roberto Sassu
2024-04-13smack: Set SMACK64TRANSMUTE only for dirs in smack_inode_setxattr()Roberto Sassu
2024-02-23lsm: new security_file_ioctl_compat() hookAlfred Piccioni
2024-01-25apparmor: avoid crash when parsed profile name is emptyFedor Pchelkin
2024-01-25selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socketMickaël Salaün
2023-12-08ima: detect changes to the backing overlay fileMimi Zohar
2023-12-08ima: annotate iint mutex to avoid lockdep false positive warningsAmir Goldstein
2023-10-10smack: Record transmuting in smk_transmutedRoberto Sassu
2023-10-10smack: Retrieve transmuting information in smack_inode_getsecurity()Roberto Sassu
2023-10-10Smack:- Use overlay inode label in smack_inode_copy_up()Vishal Goel
2023-09-23smackfs: Prevent underflow in smk_set_cipso()Dan Carpenter
2023-09-23security: keys: perform capable check only on privileged operationsChristian Göttsche
2023-08-30IMA: allow/fix UML buildsRandy Dunlap
2023-08-11integrity: Fix possible multiple allocation in integrity_inode_get()Tianjia Zhang
2023-08-11evm: Complete description of evm_inode_setattr()Roberto Sassu
2023-06-09selinux: don't use make's grouped targets feature yetPaul Moore
2023-05-17selinux: ensure av_permissions.h is built when neededPaul Moore
2023-05-17selinux: fix Makefile dependencies of flask.hOndrej Mosnacek
2023-03-11ima: Align ima_file_mmap() parameters with mmap_file LSM hookRoberto Sassu
2023-02-06tomoyo: fix broken dependency on *.conf.defaultMasahiro Yamada
2023-01-18device_cgroup: Roll back to original exceptions after copy failureWang Weiyang
2023-01-18ima: Fix a potential NULL pointer access in ima_restore_measurement_listHuaxin Lu
2023-01-18apparmor: Fix abi check to include v8 abiJohn Johansen
2023-01-18apparmor: fix lockdep warning when removing a namespaceJohn Johansen
2023-01-18apparmor: fix a memleak in multi_transaction_new()Gaosheng Cui
2023-01-18ima: Fix misuse of dereference of pointer in template_desc_init_fields()Xiu Jianfeng
2022-11-10capabilities: fix potential memleak on error path from vfs_getxattr_alloc()Gaosheng Cui
2022-10-05ima: Free the entire rule if it fails to parseTyler Hicks
2022-10-05ima: Free the entire rule when deleting a list of rulesTyler Hicks
2022-10-05ima: Have the LSM free its audit ruleTyler Hicks
2022-08-25apparmor: Fix memleak in aa_simple_write_to_buffer()Xiu Jianfeng
2022-08-25apparmor: fix reference count leak in aa_pivotroot()Xin Xiong
2022-08-25apparmor: fix overlapping attachment computationJohn Johansen
2022-08-25apparmor: fix aa_label_asxprint return checkTom Rix
2022-08-25apparmor: Fix failed mount permission check error messageJohn Johansen
2022-08-25apparmor: fix absroot causing audited secids to begin with =John Johansen
2022-08-25apparmor: fix quiet_denied for file rulesJohn Johansen
2022-08-25selinux: Add boundary check in put_entry()Xiu Jianfeng
2022-07-29ima: remove the IMA_TEMPLATE Kconfig optionGUO Zihua
2022-04-15Fix incorrect type in assignment of ipv6 port for auditCasey Schaufler
2022-04-15selinux: use correct type for context lengthChristian Göttsche