RHSA-2017:0295: Important: kernel-rt security update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0295?
The severity of RHSA-2017:0295 is classified as important.
How do I fix RHSA-2017:0295?
To fix RHSA-2017:0295, update the kernel-rt packages to version 3.10.0-514.6.1.rt56.430.el7.
What is the vulnerability in RHSA-2017:0295?
RHSA-2017:0295 addresses a use-after-free flaw in the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation.
Which packages are affected by RHSA-2017:0295?
Affected packages include kernel-rt, kernel-rt-debug, kernel-rt-devel, and several of their related debug and trace packages.
When was RHSA-2017:0295 released?
RHSA-2017:0295 was released on February 22, 2017.