CVE-2017-6346: Race Condition
Last updated 29 November 2024
Other sources
Race condition in net/packet/afpacket.c in the Linux kerne allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKETFANOUT setsockopt system calls.
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d199fab63c11998a602205f7ee7ff7c05c97164b
References:
http://seclists.org/oss-sec/2017/q1/526
Race condition in net/packet/afpacket.c in the Linux kernel allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKETFANOUT setsockopt system calls.
Race condition in net/packet/afpacket.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKETFANOUT setsockopt system calls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Fixed in 4.9.13
Event History
Frequently Asked Questions
What is CVE-2017-6346?
CVE-2017-6346 is a vulnerability in the Linux kernel that allows local users to cause a denial of service or potentially have other unspecified impact.
How does CVE-2017-6346 affect the Linux kernel?
CVE-2017-6346 affects the Linux kernel versions before 4.9.13 and can be exploited by multithreaded applications making certain system calls.
What is the severity of CVE-2017-6346?
The severity of CVE-2017-6346 is high, with a CVSS score of 6.2.
How can I fix CVE-2017-6346?
To fix CVE-2017-6346, update your Linux kernel to version 4.9.13 or later.
Where can I find more information about CVE-2017-6346?
You can find more information about CVE-2017-6346 at the following references: [CVE-2017-6346](https://www.cve.org/CVERecord?id=CVE-2017-6346), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-6346), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1428487), [Red Hat Security](https://access.redhat.com/security/cve/CVE-2017-6346).