FlawAtlas
Search the atlas
UBUNTU-CVE-2017-6074 High

UBUNTU-CVE-2017-6074

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

Exploit probability Not scored
Published February 23, 2017
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux

106 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

22 explicit affected versions

Ubuntu:16.04:LTS linux

42 explicit affected versions

Ubuntu:16.04:LTS linux-aws

2 explicit affected versions

Ubuntu:16.04:LTS linux-euclid

9 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

1 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

20 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

17 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3206-1
related USN-3207-2
related USN-3209-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-6074

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

View original source

05 / REFERENCES

Further evidence