CVE-2017-6074

HIGH

Linux Kernel < 3.2.86 - Double Free

Title source: rule

Description

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

Exploits (6)

github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/kernel/EXP-CVE-2017-6074
nomisec WRITEUP 1 stars
by BimsaraMalinda · poc
https://github.com/BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
nomisec WORKING POC
by toanthang1842002 · poc
https://github.com/toanthang1842002/CVE-2017-6074
nomisec WORKING POC
by 34zY · poc
https://github.com/34zY/CVE-2017-6074-DOS
exploitdb WORKING POC
by Andrey Konovalov · clocallinux
https://www.exploit-db.com/exploits/41458
exploitdb WORKING POC
by Andrey Konovalov · cdoslinux
https://www.exploit-db.com/exploits/41457

References (25)

... and 5 more

Scores

CVSS v3 7.8
EPSS 0.2004
EPSS Percentile 95.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status draft

Affected Products (2)

linux/linux_kernel < 3.2.86
debian/debian_linux

Timeline

Published Feb 18, 2017
Tracked Since Feb 18, 2026