IT

Tracker / CVE-2017-6874

CVE-2017-6874

High 7.0

Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.

Affected products and versions

linux linux_kernel · 4.10 → 4.10.4
linux linux_kernel · 4.9 → 4.9.16

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References