Lucene search

K
redhatRedHatRHSA-2017:0324
HistoryFeb 24, 2017 - 3:03 p.m.

(RHSA-2017:0324) Important: kernel security update

2017-02-2415:03:48
access.redhat.com
87

0.0004 Low

EPSS

Percentile

0.4%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • A use-after-free flaw was found in the way the Linux kernel’s Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCP_PKT_REQUEST packet when the IPV6_RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important)

Red Hat would like to thank Andrey Konovalov (Google) for reporting this issue.