Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
2017-02-07T07:59:00.183
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | linux | linux_kernel | < 3.10.45 | Yes |
| Operating System | linux | linux_kernel | < 3.12.23 | Yes |
| Operating System | linux | linux_kernel | < 3.14.9 | Yes |
| Operating System | linux | linux_kernel | < 3.15.2 | Yes |
| Operating System | android | ≤ 7.1.1 | Yes |