CVE-2017-9076: High severity Google Android vulnerability
Last updated 29 November 2024
Other sources
The dccpv6requestrecvsock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
— Launchpad
The IPv6 DCCP implementation in the Linux kernel mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
Upstream patch:
https://github.com/torvalds/linux/commit/83eaddab4378db256d00d295bda6ca997cd13a52
References:
https://patchwork.ozlabs.org/patch/760370/
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-9076.
What is the severity level of CVE-2017-9076?
CVE-2017-9076 has a severity level of high (7 out of 10).
How does CVE-2017-9076 impact the Linux kernel?
CVE-2017-9076 allows local users to cause a denial of service or possibly have other unspecified impacts via crafted system calls.
Which versions of the Linux kernel are affected by CVE-2017-9076?
Linux kernel versions through 4.11.1 are affected by CVE-2017-9076.
How can I fix the vulnerability identified in CVE-2017-9076?
To fix the vulnerability, update your Linux kernel to version 4.12 or higher.