summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)AuthorFilesLines
11 daysapparmor: fix race between freeing data and fs accessing itJohn Johansen7-101/+153
11 daysapparmor: fix race on rawdata dereferenceJohn Johansen4-57/+93
11 daysapparmor: fix differential encoding verificationJohn Johansen2-4/+20
11 daysapparmor: fix unprivileged local user can do privileged policy managementJohn Johansen3-9/+43
11 daysapparmor: Fix double free of ns_name in aa_replace_profiles()John Johansen1-0/+1
11 daysapparmor: fix missing bounds check on DEFAULT table in verify_dfa()Massimiliano Pellizzer1-2/+3
11 daysapparmor: fix side-effect bug in match_char() macro usageMassimiliano Pellizzer1-10/+20
11 daysapparmor: fix: limit the number of levels of policy namespacesJohn Johansen2-0/+4
11 daysapparmor: replace recursive profile removal with iterative approachMassimiliano Pellizzer1-3/+27
11 daysapparmor: fix memory leak in verify_headerMassimiliano Pellizzer1-1/+0
11 daysapparmor: validate DFA start states are in bounds in unpack_pdbMassimiliano Pellizzer1-1/+11
2026-03-04ima: verify the previous kernel's IMA buffer lies in addressable RAMHarshit Mogalapalli1-0/+35
2026-02-26apparmor: fix aa_label to return state from compount and component matchJohn Johansen1-6/+6
2026-02-26apparmor: fix invalid deref of rawdata when export_binary is unsetGeorgia Garcia1-0/+9
2026-02-26apparmor: avoid per-cpu hold underflow in aa_get_bufferZhengmian Hu1-1/+2
2026-02-26apparmor: make label_match return a consistent valueJohn Johansen1-11/+9
2026-02-26apparmor: remove apply_modes_to_perms from label_matchJohn Johansen1-3/+0
2026-02-26apparmor: fix rlimit for posix cpu timersJohn Johansen1-0/+5
2026-02-26apparmor: move check for aa_null file to cover all casesJohn Johansen2-6/+10
2026-02-26apparmor: account for in_atomic removal in common_file_permRyan Lee1-3/+2
2026-02-26apparmor: drop in_atomic flag in common_mmap, and common_file_permJohn Johansen1-12/+9
2026-02-26apparmor: fix boolean argument in apparmor_mmap_fileRyan Lee1-1/+1
2026-02-26apparmor: return -ENOMEM in unpack_perms_table upon alloc failureRyan Lee1-2/+4
2026-02-26apparmor: Fix & Optimize table creation from possibly unaligned memoryHelge Deller2-9/+10
2026-02-26AppArmor: Allow apparmor to handle unaligned dfa tablesHelge Deller1-7/+8
2026-02-26apparmor: fix NULL sock in aa_sock_file_permJohn Johansen1-2/+4
2026-02-26apparmor: fix NULL pointer dereference in __unix_needs_revalidationSystem Administrator1-0/+3
2026-02-26evm: Use ordered xattrs list to calculate HMAC in evm_init_hmac()Roberto Sassu1-4/+10
2026-02-26smack: /smack/doi: accept previously used valuesKonstantin Andreev1-26/+45
2026-02-26smack: /smack/doi must be > 0Konstantin Andreev1-5/+7
2026-01-30keys/trusted_keys: fix handle passed to tpm_buf_append_name during unsealSrish Srinivasan1-2/+2
2026-01-23landlock: Fix wrong type usageTingmao Wang1-1/+1
2026-01-23landlock: Fix TCP handling of short AF_UNSPEC addressesMatthieu Buffet1-51/+67
2026-01-08kernel/kexec: change the prototype of kimage_map_segment()Pingfan Liu1-3/+1
2026-01-02tpm2-sessions: Fix out of range indexing in name_sizeJarkko Sakkinen1-6/+23
2026-01-02KEYS: trusted: Fix a memory leak in tpm2_load_cmdJarkko Sakkinen1-2/+4
2025-12-18landlock: Fix handling of disconnected directoriesMickaël Salaün2-12/+44
2025-12-18ima: Handle error code returned by ima_filter_rule_match()Zhao Yipeng1-1/+1
2025-12-18ima: Attach CREDS_CHECK IMA hook to bprm_creds_from_file LSM hookRoberto Sassu1-9/+33
2025-12-18smack: fix bug: setting task label silently ignores input garbageKonstantin Andreev3-63/+148
2025-12-18smack: fix bug: unprivileged task can create labelsKonstantin Andreev1-14/+27
2025-12-18smack: fix bug: invalid label of unix socket fileKonstantin Andreev1-14/+44
2025-12-18smack: always "instantiate" inode in smack_inode_init_security()Konstantin Andreev1-3/+7
2025-12-18smack: deduplicate xattr setting in smack_inode_init_security()Konstantin Andreev1-27/+29
2025-12-18smack: deduplicate "does access rule request transmutation"Konstantin Andreev1-25/+32
2025-12-18smack: fix bug: SMACK64TRANSMUTE set on non-directoryKonstantin Andreev1-12/+14
2025-11-22Merge tag 'selinux-pr-20251121' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds2-129/+144
2025-11-20selinux: rename the cred_security_struct variables to "crsec"Paul Moore2-117/+117
2025-11-20selinux: move avdcache to per-task security structStephen Smalley2-15/+30
2025-11-20selinux: rename task_security_struct to cred_security_structStephen Smalley2-38/+38