summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2022-10-29selinux: enable use of both GFP_KERNEL and GFP_ATOMIC in convert_context()GONG, Ruiqi
2022-10-26ima: fix blocking of security.ima xattrs of unsupported algorithmsMimi Zohar
2022-10-26hardening: Remove Clang's enable flag for -ftrivial-auto-var-init=zeroKees Cook
2022-10-26hardening: Avoid harmless Clang option under CONFIG_INIT_STACK_ALL_ZEROKees Cook
2022-10-15efi: Correct Macmini DMI match in uefi cert quirkOrlando Chamberlain
2022-08-25apparmor: Fix memleak in aa_simple_write_to_buffer()Xiu Jianfeng
2022-08-25apparmor: fix reference count leak in aa_pivotroot()Xin Xiong
2022-08-25apparmor: fix overlapping attachment computationJohn Johansen
2022-08-25apparmor: fix setting unconfined mode on a loaded profileJohn Johansen
2022-08-25apparmor: fix aa_label_asxprint return checkTom Rix
2022-08-25apparmor: Fix failed mount permission check error messageJohn Johansen
2022-08-25apparmor: fix absroot causing audited secids to begin with =John Johansen
2022-08-25apparmor: fix quiet_denied for file rulesJohn Johansen
2022-08-17selinux: Add boundary check in put_entry()Xiu Jianfeng
2022-08-17selinux: fix memleak in security_read_state_kernel()Xiu Jianfeng
2022-07-29lockdown: Fix kexec lockdown bypass with ima policyEric Snowberg
2022-07-23x86/retbleed: Add fine grained Kconfig knobsPeter Zijlstra
2022-07-21ima: Fix potential memory leak in ima_init_crypto()Jianglei Nie
2022-07-21ima: force signature verification when CONFIG_KEXEC_SIG is configuredCoiby Xu
2022-07-21ima: Fix a potential integer overflow in ima_appraise_measurementHuaxin Lu
2022-07-21Revert "evm: Fix memleak in init_desc"Xiu Jianfeng
2022-07-02fs: support mapped mounts of mapped filesystemsChristian Brauner
2022-07-02fs: use low-level mapping helpersChristian Brauner
2022-07-02fs: move mapping helpersChristian Brauner
2022-06-14KEYS: trusted: tpm2: Fix migratable logicDavid Safford
2022-06-09ima: remove the IMA_TEMPLATE Kconfig optionGUO Zihua
2022-06-09landlock: Fix same-layer rule unionsMickaël Salaün
2022-06-09landlock: Create find_rule() from unmask_layers()Mickaël Salaün
2022-06-09landlock: Reduce the maximum number of layers to 16Mickaël Salaün
2022-06-09landlock: Define access_mask_t to enforce a consistent access mask sizeMickaël Salaün
2022-06-09landlock: Change landlock_restrict_self(2) check orderingMickaël Salaün
2022-06-09landlock: Change landlock_add_rule(2) argument check orderingMickaël Salaün
2022-06-09landlock: Fix landlock_add_rule(2) documentationMickaël Salaün
2022-06-09landlock: Format with clang-formatMickaël Salaün
2022-06-09landlock: Add clang-format exceptionsMickaël Salaün
2022-06-09efi: Do not import certificates from UEFI Secure Boot for T2 MacsAditya Garg
2022-05-25lockdown: also lock down previous kgdb useDaniel Thompson
2022-05-25selinux: fix bad cleanup on error in hashtab_duplicate()Ondrej Mosnacek
2022-04-08Fix incorrect type in assignment of ipv6 port for auditCasey Schaufler
2022-04-08selinux: allow FIOCLEX and FIONCLEX with policy capabilityRichard Haines
2022-04-08selinux: use correct type for context lengthChristian Göttsche
2022-04-08LSM: general protection fault in legacy_parse_paramCasey Schaufler
2022-04-08TOMOYO: fix __setup handlers return valuesRandy Dunlap
2022-04-08KEYS: trusted: Avoid calling null function trusted_key_exitDave Kleikamp
2022-04-08KEYS: trusted: Fix trusted key backends when building as moduleAndreas Rammhold
2022-04-08EVM: fix the evm= __setup handler return valueRandy Dunlap
2022-04-08selinux: Fix selinux_sb_mnt_opts_compat()Scott Mayhew
2022-04-08selinux: check return value of sel_make_avc_filesChristian Göttsche
2022-04-08selinux: access superblock_security_struct in LSM blob wayGONG, Ruiqi
2022-04-08landlock: Use square brackets around "landlock-ruleset"Christian Brauner