Related Vulnerabilities: CVE-2021-29650  

An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.

Severity Low

Remote Yes

Type Denial of service

Description

An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.

AVG-1748 linux-hardened 5.11.10.hardened1-1 Medium Vulnerable

AVG-1750 linux-lts 5.10.26-1 5.10.27-1 Medium Fixed

AVG-1749 linux-zen 5.11.10.zen1-1 5.11.11.zen1-1 Medium Fixed

AVG-1747 linux 5.11.10.arch4-1 5.11.11.arch4-1 Medium Fixed

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.11&id=4c2d548cefe0d5defa2750f128712c00912a975a
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.27&id=3fdebc2d8e7965f946a3d716ffdd482e66c1f46c