summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2022-03-02selinux: fix misuse of mutex_is_locked()Ondrej Mosnacek
2022-02-16ima: Do not print policy rule with inactive LSM labelsStefan Berger
2022-02-16ima: Allow template selection with ima_template[_fmt]= after ima_hash=Roberto Sassu
2022-02-16ima: Remove ima_policy file before directoryStefan Berger
2022-02-16ima: fix reference leak in asymmetric_verify()Eric Biggers
2022-02-16integrity: check the return value of audit_log_start()Xiaoke Wang
2022-02-08selinux: fix double free of cond_list on error pathsVratislav Bendel
2022-01-27selinux: fix potential memleak in selinux_add_opt()Bernard Zhao
2022-01-05selinux: initialize proto variable in selinux_ip_postroute_compat()Tom Rix
2022-01-05tomoyo: use hwight16() in tomoyo_domain_quota_is_ok()Tetsuo Handa
2022-01-05tomoyo: Check exceeded quota early in tomoyo_domain_quota_is_ok().Dmitry Vyukov
2021-12-22selinux: fix sleeping function called from invalid contextScott Mayhew
2021-11-25selinux: fix NULL-pointer dereference when hashtab allocation failsOndrej Mosnacek
2021-11-21fortify: Explicitly disable Clang supportKees Cook
2021-11-18apparmor: fix error checkTom Rix
2021-11-18smackfs: use netlbl_cfg_cipsov4_del() for deleting cipso_v4_doiTetsuo Handa
2021-11-18ima: fix deadlock when traversing "ima_default_rules".liqiong
2021-11-18smackfs: use __GFP_NOFAIL for smk_cipso_doi()Tetsuo Handa
2021-11-18smackfs: Fix use-after-free in netlbl_catmap_walk()Pawan Gupta
2021-11-18evm: mark evm_fixmode as __ro_after_initAustin Kim
2021-11-18selinux: fix race condition when computing ocontext SIDsOndrej Mosnacek
2021-11-12binder: use cred instead of task for selinux checksTodd Kjos
2021-10-21Merge branch 'ucount-fixes-for-v5.15' of git://git.kernel.org/pub/scm/linux/k...Linus Torvalds
2021-10-20ucounts: Move get_ucounts from cred_alloc_blank to key_change_session_keyringEric W. Biederman
2021-10-07Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/David S. Miller
2021-09-23selinux,smack: fix subjective/objective credential use mixupsPaul Moore
2021-09-14include/uapi/linux/xfrm.h: Fix XFRM_MSG_MAPPING ABI breakageEugene Syromiatnikov
2021-09-03Merge tag 'kbuild-v5.15' of git://git.kernel.org/pub/scm/linux/kernel/git/mas...Linus Torvalds
2021-09-03Merge branch 'akpm' (patches from Andrew)Linus Torvalds
2021-09-03mm/pagemap: add mmap_assert_locked() annotations to find_vma*()Luigi Rizzo
2021-09-03security: remove unneeded subdir-$(CONFIG_...)Masahiro Yamada
2021-09-02Merge tag 'integrity-v5.15' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds
2021-09-02Merge tag 'hardening-v5.15-rc1' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds
2021-08-31Merge tag 'net-next-5.15' of git://git.kernel.org/pub/scm/linux/kernel/git/ne...Linus Torvalds
2021-08-31Merge tag 'for-5.15/dm-changes' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds
2021-08-31Merge tag 'Smack-for-5.15' of git://github.com/cschaufler/smack-nextLinus Torvalds
2021-08-31Merge tag 'selinux-pr-20210830' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds
2021-08-30Merge tag 'efi-core-2021-08-30' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds
2021-08-27efi: Don't use knowledge about efi_guid_t internalsAndy Shevchenko
2021-08-23IMA: reject unknown hash algorithms in ima_get_hash_algoTHOBY Simon
2021-08-16IMA: prevent SETXATTR_CHECK policy rules with unavailable algorithmsTHOBY Simon
2021-08-16IMA: introduce a new policy option func=SETXATTR_CHECKTHOBY Simon
2021-08-16IMA: add a policy option to restrict xattr hash algorithms on appraisalTHOBY Simon
2021-08-16IMA: add support to restrict the hash algorithms used for file appraisalTHOBY Simon
2021-08-16IMA: block writes of the security.ima xattr with unsupported algorithmsTHOBY Simon
2021-08-16IMA: remove the dependency on CRYPTO_MD5THOBY Simon
2021-08-13Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
2021-08-10dm ima: measure data on table loadTushar Sugandhi
2021-08-10bpf: Add lockdown check for probe_write_user helperDaniel Borkmann
2021-08-09bpf: Add _kernel suffix to internal lockdown_bpf_readDaniel Borkmann