PT-2024-11221 · Linux+1 · Linux Kernel+1

Arturo Borrero Gonzalez

·

Published

2021-05-14

·

Updated

2024-08-19

·

CVE-2021-47174

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 5.10.0-0.bpo.5-amd64
Description A vulnerability has been resolved in the Linux kernel, specifically in the netfilter component. The issue was related to the nft set pipapo avx2 function, where an irq fpu usable() check was added, and a fallback to a non-AVX2 version was implemented. The vulnerability was reported by Arturo, who provided a backtrace showing a warning message related to the kernel fpu begin mask function. The backtrace also listed various modules linked in, including nft nat, nft chain nat, and nf tables. The vulnerability appears to be related to a CPU and PID issue, but no further details are provided.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, for Linux kernel version 5.10.0-0.bpo.5-amd64, update to a newer version that includes the irq fpu usable() check and fallback to non-AVX2 version in the nft set pipapo avx2 function.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13711
CVE-2021-47174
OPENSUSE-SU-2024_1489-1
SUSE-SU-2024:1465-1
SUSE-SU-2024:1489-1

Affected Products

Linux Kernel
Suse