cbcvebase.
CVE-2017-6874
published 2017-03-14

CVE-2017-6874: Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or…

PriorityP427high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.26%
18.0th percentile
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.9.16-1 (bookworm)linux 4.9.16-1 (bookworm)
linuxlinux_kernel>= 0 < 4.9.16-14.9.16-1
linuxlinux_kernel>= 0 < 4.9.16-14.9.16-1
linuxlinux_kernel>= 0 < 4.9.16-14.9.16-1
linuxlinux_kernel>= 0 < 4.9.16-14.9.16-1
linuxlinux_kernel>= 4.10 < 4.10.44.10.4
linuxlinux_kernel>= 4.9 < 4.9.164.9.16

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.