CVE
- Id
- 102894
- CVE No.
- CVE-2017-6074
- Status
- Candidate
- Description
- The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
- Phase
- Assigned (20170217)
- Votes
- None (candidate not yet proposed)
- Comments