CVE-2021-29650. The netfilter subsystem allows attackers to cause a denial of service.

Brocade Fabric OS

2 more products

21250

13 September 2022

13 September 2022

Closed

Medium

Base Score: 5.5 MEDIUM - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

N/A

CVE-2021-29650

Summary

Security Advisory ID : BSA-2022-1462

Component : Kernel

Revision : 1.0

A denial-of-service (DoS) flaw was identified in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.

Affected Products

  • Brocade Fabric OS versions after v9.0.0 and before v9.0.1e.
  • Brocade Active Support Connectivity Gateway (ASC-G) before v.2.0.0

Products Confirmed Not Vulnerable

  • Brocade Fabric OS versions before v9.0.0
  • Brocade ASCG versions after v.2.0.0

No other Brocade Fibre Channel Products from Broadcom products are known to be affected by this vulnerability.

Solution

Security update provided in Brocade Fabric OS v9.0.1e, v9.1.0, Brocade ASCG v.2.0.0, and all later versions.

Revision History

Version

Change

Date

1.0

Initial Publication

Sept 13, 2022