RHSA-2017:0346: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operatingsystem.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer)resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is seton the socket. A local, unprivileged user could use this flaw to alter thekernel memory, allowing them to escalate their privileges on the system.(CVE-2017-6074, Important) It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation used the IPv4-only inetskrebuildheader() function forboth IPv4 and IPv6 DCCP connections, which could result in memory corruptions. Aremote attacker could use this flaw to crash the system. (CVE-2017-2634,Moderate)Important: This update disables the DCCP kernel module at load time by using thekernel module blacklist method. The module is disabled in an attempt to reducefurther exposure to additional issues. (BZ#1426309)Red Hat would like to thank Andrey Konovalov (Google) for reportingCVE-2017-6074. The CVE-2017-2634 issue was discovered by Wade Mealing (Red HatProduct Security).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0346?
The severity of RHSA-2017:0346 is classified as important.
How do I fix RHSA-2017:0346?
To fix RHSA-2017:0346, you need to update the kernel packages to version 2.6.18-348.33.1.el5 or later.
What vulnerability does RHSA-2017:0346 address?
RHSA-2017:0346 addresses a use-after-free flaw in the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation.
Which versions are affected by RHSA-2017:0346?
RHSA-2017:0346 affects kernel packages prior to version 2.6.18-348.33.1.el5.
Is there a workaround for RHSA-2017:0346?
There is no official workaround for RHSA-2017:0346, and upgrading to the patched version is strongly recommended.