RHSA-2017:0403: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important) Red Hat would like to thank Andrey Konovalov (Google) for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0403?
The severity of RHSA-2017:0403 is considered important due to a use-after-free vulnerability in the Linux kernel's Datagram Congestion Control Protocol implementation.
How do I fix RHSA-2017:0403?
To fix RHSA-2017:0403, you should update to kernel version 3.10.0-229.49.1.el7 or later.
What systems are affected by RHSA-2017:0403?
RHSA-2017:0403 affects various versions of the Linux kernel and related packages on Red Hat Enterprise Linux 7 systems.
When was the issue associated with RHSA-2017:0403 discovered?
The vulnerability addressed in RHSA-2017:0403 was reported in early 2017.
Is there a risk of exploitation with RHSA-2017:0403 if not addressed?
Yes, there is a potential risk of remote exploitation if the vulnerability in RHSA-2017:0403 is not patched.