The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
2017-02-18T21:59:00.237
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.2.86 | Yes |
Operating System | linux | linux_kernel | < 3.10.106 | Yes |
Operating System | linux | linux_kernel | < 3.12.71 | Yes |
Operating System | linux | linux_kernel | < 3.16.41 | Yes |
Operating System | linux | linux_kernel | < 3.18.49 | Yes |
Operating System | linux | linux_kernel | < 4.1.41 | Yes |
Operating System | linux | linux_kernel | < 4.4.52 | Yes |
Operating System | linux | linux_kernel | < 4.9.13 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |