CVE-2017-6074
moderate-risk
Published 2017-02-18
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
Do I need to act?
!
20.0% chance of exploitation in next 30 days
EPSS score — higher than 80% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (2)
References (50)
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0293.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0294.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0295.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0316.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0323.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0324.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0345.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0346.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0347.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0365.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0366.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0403.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0501.html
Third Party Advisory
http://www.debian.org/security/2017/dsa-3791
Third Party Advisory
http://www.securityfocus.com/bid/96310
Third Party Advisory
http://www.securitytracker.com/id/1037876
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:0932
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1209
and 30 more references
45
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
14/34 · Moderate
Exposure
7/34 · Low