Lucene search

K
redhatcveRedhat.comRH:CVE-2017-9075
HistoryOct 10, 2019 - 4:24 a.m.

CVE-2017-9075

2019-10-1004:24:41
redhat.com
access.redhat.com
31

EPSS

0.001

Percentile

32.6%

The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890. An unprivileged local user could use this flaw to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.