summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2025-06-27selinux: fix selinux_xfrm_alloc_user() to set correct ctx_lenStephen Smalley
2025-06-04smack: recognize ipv4 CIPSO w/o categoriesKonstantin Andreev
2025-04-25landlock: Add the errata interfaceMickaël Salaün
2025-04-10smack: dont compile ipv6 code unless ipv6 is configuredKonstantin Andreev
2025-02-21tomoyo: don't emit warning in tomoyo_write_control()Tetsuo Handa
2025-02-21safesetid: check size of policy writesLeo Stone
2025-02-21landlock: Handle weird filesMickaël Salaün
2025-01-09selinux: ignore unknown extended permissionsThiébaud Weksteen
2024-12-14apparmor: test: Fix memory leak for aa_unpack_strdup()Jinjie Ruan
2024-12-14apparmor: fix 'Do simple duplicate message elimination'chao liu
2024-11-22ima: fix buffer overrun in ima_eventdigest_init_commonSamasth Norway Ananda
2024-11-14security/keys: fix slab-out-of-bounds in key_task_permissionChen Ridong
2024-11-01selinux: improve error checking in sel_write_load()Paul Moore
2024-10-17tomoyo: fallback to realpath if symlink's pathname does not existTetsuo Handa
2024-10-17proc: add config & param to block forcing mem writesAdrian Ratiu
2024-10-17bpf: lsm: Set bpf_lsm_blob_sizes.lbs_task to 0Song Liu
2024-10-17selinux,smack: don't bypass permissions check in inode_setsecctx hookScott Mayhew
2024-10-17smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipsoJiawei Ye
2024-09-12smack: unix sockets: fix accept()ed socket labelKonstantin Andreev
2024-09-08smack: tcp: ipv4, fix incorrect labelingCasey Schaufler
2024-09-08apparmor: fix possible NULL pointer dereferenceLeesoo Ahn
2024-09-04apparmor: fix policy_unpack_test on big endian systemsGuenter Roeck
2024-08-29selinux: fix potential counting error in avc_add_xperms_decision()Zhen Lei
2024-08-03apparmor: Fix null pointer deref when receiving skb during sock creationXiao Liang
2024-08-03task_work: s/task_work_cancel()/task_work_cancel_func()/Frederic Weisbecker
2024-08-03apparmor: use kvfree_sensitive to free data->dataFedor Pchelkin
2024-08-03landlock: Don't lose track of restrictions on cred_transferJann Horn
2024-07-11ima: Avoid blocking in RCU read-side critical sectionGUO Zihua
2024-07-05ima: Fix use-after-free on a dentry's dname.nameStefan Berger
2024-06-21landlock: Fix d_parent walkMickaël Salaün
2024-05-25KEYS: trusted: Do not use WARN when encode failsJarkko Sakkinen
2024-05-25KEYS: trusted: Fix memory leak in tpm2_key_encode()Jarkko Sakkinen
2024-05-17keys: Fix overwrite of key expiration on instantiationSilvio Gissi
2024-04-03landlock: Warn once if a Landlock action is requested while disabledMickaël Salaün
2024-04-03smack: Handle SMACK64TRANSMUTE in smack_inode_setsecurity()Roberto Sassu
2024-04-03smack: Set SMACK64TRANSMUTE only for dirs in smack_inode_setxattr()Roberto Sassu
2024-03-06landlock: Fix asymmetric private inodes referringMickaël Salaün
2024-03-06tomoyo: fix UAF write bug in tomoyo_write_control()Tetsuo Handa
2024-02-23apparmor: Free up __cleanup() namePeter Zijlstra
2024-02-23lsm: fix the logic in security_inode_getsecctx()Ondrej Mosnacek
2024-01-31lsm: new security_file_ioctl_compat() hookAlfred Piccioni
2024-01-25Revert "KEYS: encrypted: Add check for strsep"Mimi Zohar
2024-01-25apparmor: avoid crash when parsed profile name is emptyFedor Pchelkin
2024-01-25selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socketMickaël Salaün
2024-01-25KEYS: encrypted: Add check for strsepChen Ni
2024-01-01keys, dns: Allow key types (eg. DNS) to be reclaimed immediately on expiryDavid Howells
2023-11-28ima: detect changes to the backing overlay fileMimi Zohar
2023-11-28ima: annotate iint mutex to avoid lockdep false positive warningsAmir Goldstein
2023-11-28KEYS: trusted: Rollback init_trusted() consistentlyJarkko Sakkinen
2023-11-28KEYS: trusted: tee: Refactor register SHM usageSumit Garg