Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perfeventopen system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6001.json"
[
{
"events": [
{
"introduced": "3.18.54"
},
{
"fixed": "3.18.92"
}
]
},
{
"events": [
{
"introduced": "4.0"
},
{
"fixed": "4.4.65"
}
]
},
{
"events": [
{
"introduced": "4.5"
},
{
"fixed": "4.9.7"
}
]
}
]