The dccprcvstateprocess function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCPPKTREQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6RECVPKTINFO setsockopt system call.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6074.json"
[
{
"id": "CVE-2017-6074-22f50688",
"deprecated": false,
"target": {
"file": "net/dccp/input.c",
"function": "dccp_rcv_state_process"
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/5edabca9d4cff7f1f2b68f0bac55ef99d9798ba4",
"digest": {
"function_hash": "180602064360365984284020031322082380597",
"length": 2207.0
},
"signature_type": "Function"
},
{
"id": "CVE-2017-6074-d99102cf",
"deprecated": false,
"target": {
"file": "net/dccp/input.c"
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/5edabca9d4cff7f1f2b68f0bac55ef99d9798ba4",
"digest": {
"line_hashes": [
"51699821363819783944777538915561591228",
"287157093675138264898095941819855000529",
"107615567005359438278692316765651777953",
"183614538055235991710157128450839007871"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]