]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/history - security
tuntap: add sanity checks about msg_controllen in sendmsg
[mirror_ubuntu-focal-kernel.git] / security /
2022-05-20 Casey SchauflerFix incorrect type in assignment of ipv6 port for audit
2022-05-20 Christian Göttscheselinux: use correct type for context length
2022-05-20 Casey SchauflerLSM: general protection fault in legacy_parse_param
2022-05-20 Randy DunlapTOMOYO: fix __setup handlers return values
2022-05-20 Eric BiggersKEYS: fix length validation in keyctl_pkey_params_get_2()
2022-04-14 Stefan Bergerima: Do not print policy rule with inactive LSM labels
2022-04-14 Roberto Sassuima: Allow template selection with ima_template[_fmt...
2022-04-14 Stefan Bergerima: Remove ima_policy file before directory
2022-04-14 Xiaoke Wangintegrity: check the return value of audit_log_start()
2022-03-07 Bernard Zhaoselinux: fix potential memleak in selinux_add_opt()
2022-03-07 Tom Rixselinux: initialize proto variable in selinux_ip_postro...
2022-03-07 Dmitry Vyukovtomoyo: Check exceeded quota early in tomoyo_domain_quo...
2022-03-07 Ondrej Mosnacekselinux: fix race condition when computing ocontext...
2022-01-13 Kees Cookfortify: Explicitly disable Clang support
2022-01-13 Tom Rixapparmor: fix error check
2022-01-13 Tetsuo Handasmackfs: use netlbl_cfg_cipsov4_del() for deleting...
2022-01-13 Tetsuo Handasmackfs: use __GFP_NOFAIL for smk_cipso_doi()
2022-01-13 Pawan Guptasmackfs: Fix use-after-free in netlbl_catmap_walk()
2022-01-13 Austin Kimevm: mark evm_fixmode as __ro_after_init
2022-01-13 Todd Kjosbinder: use cred instead of task for selinux checks
2021-11-24 Dimitri John LedkovUBUNTU: SAUCE: integrity: add informational messages...
2021-11-24 Dimitri John LedkovUBUNTU: SAUCE: integrity: Load mokx certs from the...
2021-11-24 Eric Snowbergintegrity: Load mokx variables into the blacklist keyring
2021-11-24 Lenny Szubowiczintegrity: Load certs from the EFI MOK config table
2021-11-24 Lenny Szubowiczintegrity: Move import of MokListRT certs to a separate...
2021-11-24 Dimitri John LedkovRevert "UBUNTU: SAUCE: (lockdown) Make get_cert_list...
2021-10-27 Andy Shevchenkoapparmor: remove duplicate macro list_entry_is_head()
2021-10-12 Tianjia ZhangSmack: Fix wrong semantics in smk_access_entry()
2021-10-11 THOBY SimonIMA: remove the dependency on CRYPTO_MD5
2021-10-11 Austin KimIMA: remove -Wmissing-prototypes warning
2021-09-20 John Johansenapparmor: Fix memory leak of profile proxy
2021-08-13 Tetsuo Handasmackfs: restrict bytes count in smk_set_cipso()
2021-08-13 Minchan Kimselinux: use __GFP_NOWARN with GFP_NOWAIT in the AVC
2021-08-13 Mimi Zoharevm: fix writing <securityfs>/evm overflow
2021-08-13 Roberto Sassuevm: Refuse EVM_ALLOW_METADATA_WRITES only if an HMAC...
2021-08-13 Roberto Sassuevm: Execute evm_inode_init_security() only when an...
2021-08-13 Eric Snowbergcerts: Add EFI_CERT_X509_GUID support for dbx entries
2021-05-19 Arnd Bergmannsecurity: commoncap: fix -Wstringop-overread warning
2021-04-23 Mimi Zoharintegrity: double check iint_cache was initialized
2021-04-14 Eric W. BiedermanRevert 95ebabde382c ("capabilities: Don't allow writing...
2021-04-14 Sabyrzhan Tasbolatovsmackfs: restrict bytes count in smackfs write functions
2021-04-14 Jarkko SakkinenKEYS: trusted: Fix migratable=1 failing
2021-04-14 David Howellscerts: Fix blacklist flag type confusion
2021-04-14 Eric W. Biedermancapabilities: Don't allow writing ambiguous v3 file...
2021-04-14 Lakshmi Ramasubram... ima: Free IMA measurement buffer after kexec syscall
2021-04-14 Lakshmi Ramasubram... ima: Free IMA measurement buffer on error
2021-04-14 Dinghao Liuevm: Fix memleak in init_desc
2021-04-12 Miklos Szeredivfs: move cap_convert_nscap() call into vfs_setxattr()
2021-03-24 Miklos Szeredicap: fix conversions on getxattr
2021-02-19 Al Virodump_common_audit_data(): fix racy accesses to ->d_name
2021-01-20 Roberto Sassuima: Don't modify file descriptor mode on the fly
2021-01-20 Paul Mooreselinux: fix inode_doinit_with_dentry() LABEL_INVALID...
2021-01-20 Tianyue Renselinux: fix error initialization in inode_doinit_with_...
2021-01-20 Maurizio Droccoima: extend boot_aggregate with kernel measurements
2020-12-10 Chen Zhouselinux: Fix error return code in sel_ib_pkey_sid_slow()
2020-12-10 Roberto Sassuevm: Check size of security.evm before using it
2020-11-09 Roberto Sassuima: Don't ignore errors from crypto_shash_update()
2020-11-09 Amol Groverdevice_cgroup: Fix RCU list debugging warning
2020-11-09 Vasily Averinselinux: sel_avc_get_stat_idx should increase position...
2020-11-09 Jonathan Lebonselinux: allow labeling before policy is loaded
2020-09-30 Miklos Szerediovl: call secutiry hook in ovl_real_ioctl()
2020-09-04 Dan CarpenterSmack: prevent underflow in smk_set_cipso()
2020-09-04 Dan CarpenterSmack: fix another vsscanf out of bounds
2020-09-04 Tyler Hicksima: Have the LSM free its audit rule
2020-09-04 Bruno Menegueleima: move APPRAISE_BOOTPARAM dependency on ARCH_POLICY...
2020-09-04 Eric BiggersSmack: fix use-after-free in smk_write_relabel_self()
2020-08-08 Tom Rixselinux: fix double free
2020-08-08 John Johansenapparmor: fix introspection of of task mode for unconfi...
2020-08-08 Krzysztof Struczynskiima: Set again build_ima_appraise variable
2020-08-08 Krzysztof Struczynskiima: Remove redundant policy rule set in add_rules()
2020-08-08 Roberto Sassuevm: Fix possible memory leak in evm_calc_hmac_or_hash()
2020-08-08 Roberto Sassuima: Remove __init annotation from ima_pcrread()
2020-08-08 Roberto Sassuima: Call ima_calc_boot_aggregate() in ima_eventdigest_...
2020-08-08 Roberto Sassuima: Directly assign the ima_default_policy pointer...
2020-08-08 Roberto Sassuima: Evaluate error in init_ima()
2020-08-08 Roberto Sassuima: Switch to ima_hash_algo for boot aggregate
2020-08-08 Krzysztof Struczynskiima: Fix ima digest hash table key calculation
2020-08-08 Wei Yongjunselinux: fix error return code in policydb_read()
2020-08-08 Jeremy Clinelockdown: Allow unprivileged users to see lockdown...
2020-08-08 Casey SchauflerSmack: slab-out-of-bounds in vsscanf
2020-08-08 Waiman Longmm: add kvfree_sensitive() for freeing sensitive data...
2020-08-08 Arnd Bergmannsmack: avoid unused 'sip' variable warning
2020-08-08 Mauricio Faria de... apparmor: check/put label on apparmor_sk_clone_security()
2020-08-08 Madhuparna Bhowmikevm: Fix RCU list related warnings
2020-06-22 Eric W. Biedermanexec: Always set cap_ambient in cap_bprm_set_creds
2020-06-22 Xiyu Yangapparmor: Fix aa_label refcnt leak in policy_update
2020-06-22 Dan Carpenterevm: Fix a small race in init_desc()
2020-06-22 Roberto Sassuima: Fix return value of ima_write_policy()
2020-06-22 Roberto Sassuevm: Check also if *tfm is an error pointer in init_desc()
2020-06-22 Roberto Sassuima: Set file->f_mode instead of file->f_flags in ima_c...
2020-05-25 Paul Mooreselinux: properly handle multiple messages in selinux_n...
2020-05-25 Waiman LongKEYS: Avoid false positive ENOMEM error on key read
2020-05-25 Waiman LongKEYS: Don't write out to userspace while holding key...
2020-05-05 Vasily Averinkeys: Fix proc_keys_next to increase position index
2020-04-09 Mateusz NosekUBUNTU: SAUCE: security/apparmor/label.c: Clean code...
2020-04-09 Xiyu YangUBUNTU: SAUCE: apparmor: fix potential label refcnt...
2020-04-09 John JohansenUBUNTU: SAUCE: apparmor: ensure that dfa state tables...
2020-04-09 John JohansenUBUNTU: SAUCE: aapparmor: fail unpack if profile mode...
2020-04-09 John JohansenUBUNTU: SAUCE: aapparmor: remove useless aafs_create_sy...
2020-04-09 John JohansenUBUNTU: SAUCE: aapparmor: add consistency check between...
next