RHSA-2017:0294: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0294?
The severity of RHSA-2017:0294 is classified as important.
How do I fix RHSA-2017:0294?
To fix RHSA-2017:0294, update to the kernel package version 3.10.0-514.6.2.el7.
What systems are affected by RHSA-2017:0294?
RHSA-2017:0294 affects systems running the 3.10.0 kernel version prior to 3.10.0-514.6.2.el7.
What type of vulnerability is addressed in RHSA-2017:0294?
RHSA-2017:0294 addresses a use-after-free vulnerability in the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation.
Are there any known exploits for RHSA-2017:0294?
As of now, there have been no publicly disclosed exploits specifically targeting the vulnerability detailed in RHSA-2017:0294.