Hi Greg, please consider applying the following two patches to v4.4.y, v4.9.y, and v4.14.y 80055dab5de0 ("netfilter: x_tables: make xt_replace_table wait until old rules are not used anymore") 175e476b8cdf ("netfilter: x_tables: Use correct memory barriers.") to fix CVE-2021-29650 in those branches. Thanks, Guenter