CVE-2017-6074

HIGH

Linux Kernel < 3.2.86 - Double Free

Title source: rule

Description

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

Exploits (6)

exploitdb WORKING POC
by Andrey Konovalov · clocallinux
https://www.exploit-db.com/exploits/41458
exploitdb WORKING POC
by Andrey Konovalov · cdoslinux
https://www.exploit-db.com/exploits/41457
github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/kernel/EXP-CVE-2017-6074
nomisec WRITEUP 1 stars
by BimsaraMalinda · poc
https://github.com/BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
nomisec WORKING POC
by 34zY · poc
https://github.com/34zY/CVE-2017-6074-DOS
nomisec WORKING POC
by toanthang1842002 · poc
https://github.com/toanthang1842002/CVE-2017-6074

References (25)

... and 5 more

Scores

CVSS v3 7.8
EPSS 0.2004
EPSS Percentile 95.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (2)
debian/debian_linux 8.0
linux/linux_kernel < 3.2.86
Published Feb 18, 2017
Tracked Since Feb 18, 2026