kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.
https://www.openwall.com/lists/oss-security/2021/07/06/3
https://security.netapp.com/advisory/ntap-20210813-0004/
https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
http://www.openwall.com/lists/oss-security/2021/07/06/3