CVE-2021-29650: Medium severity IBM DRM vulnerability
A denial-of-service (DoS) flaw was identified in the Linux kernel due to an incorrect memory barrier in xtreplacetable in net/netfilter/xtables.c in the netfilter subsystem.
Other sources
A flaw was found in the Linux kernel in the netfilter subsystem, Where a local attacker may cause a denial of service (panic) because net/netfilter/xtables.c and include/linux/netfilter/xtables.h lack a full memory barrier upon the assignment of a new table value.
Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=175e476b8cdf2a4de7432583b49c871345e4f8a1
— Red Hat
An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/xtables.c and include/linux/netfilter/xtables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.
Linux Kernel is vulnerable to a denial of service, caused by the lack of a full memory barrier upon the assignment of a new table value in the netfilter subsystem. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause the system to crash.
— IBM
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-29650?
CVE-2021-29650 has been classified as a medium-severity vulnerability due to its potential to cause denial-of-service conditions.
How do I fix CVE-2021-29650?
To fix CVE-2021-29650, upgrade your Linux kernel to the recommended version specified by your distribution.
What systems are affected by CVE-2021-29650?
CVE-2021-29650 affects various versions of the Linux kernel across different distributions including Red Hat, Debian, and Fedora.
What kind of attack is associated with CVE-2021-29650?
CVE-2021-29650 is associated with a denial-of-service (DoS) attack that can be executed by a local attacker.
Is there a known exploit for CVE-2021-29650?
As of now, there are no publicly available exploits specifically targeting CVE-2021-29650.