← back
CVE-2017-6074

CVE-2017-6074

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 6.0%
from disclosure to weapon8 days
Published on NVDFeb 18
1st PoC+8d
exploitation probability
6.0%top 7% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.