Lucene search

K
redhatRedHatRHSA-2017:0365
HistoryMar 01, 2017 - 3:21 p.m.

(RHSA-2017:0365) Important: kernel security update

2017-03-0115:21:18
access.redhat.com
116

0.0004 Low

EPSS

Percentile

0.4%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • A use-after-free flaw was found in the way the Linux kernel’s Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCP_PKT_REQUEST packet when the IPV6_RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important)

Red Hat would like to thank Andrey Konovalov (Google) for reporting this issue.