UBUNTU-CVE-2017-6074
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
02 / AFFECTED SOFTWARE
Affected packages
106 explicit affected versions
22 explicit affected versions
42 explicit affected versions
2 explicit affected versions
9 explicit affected versions
1 explicit affected versions
20 explicit affected versions
17 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2017/02/26/2
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5edabca9d4cff7f1f2b68f0bac55ef99d9798ba4
- https://patchwork.ozlabs.org/patch/728808/
- https://ubuntu.com/security/CVE-2017-6074
- https://ubuntu.com/security/notices/USN-3206-1
- https://ubuntu.com/security/notices/USN-3207-1
- https://ubuntu.com/security/notices/USN-3207-2
- https://ubuntu.com/security/notices/USN-3208-1
- https://ubuntu.com/security/notices/USN-3208-2
- https://ubuntu.com/security/notices/USN-3209-1
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-6074
- https://www.cve.org/CVERecord?id=CVE-2017-6074