CVE-2017-6874
published 2017-03-14CVE-2017-6874: Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or…
PriorityP427high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.26%
18.0th percentile
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.9.16-1 (bookworm) | linux 4.9.16-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 4.10 < 4.10.4 | 4.10.4 |
| linux | linux_kernel | >= 4.9 < 4.9.16 | 4.9.16 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pw64-74q3-2v7r: Race condition in kernel/ucount
ghsa_unreviewed·2022-05-17
CVE-2017-6874 [HIGH] CWE-362 GHSA-pw64-74q3-2v7r: Race condition in kernel/ucount
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
OSV
CVE-2017-6874: Race condition in kernel/ucount
osv·2017-03-14·CVSS 7.0
CVE-2017-6874 [HIGH] CVE-2017-6874: Race condition in kernel/ucount
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
Red Hat
kernel: Race condition in kernel/ucount.c
vendor_redhat·2017-03-06·CVSS 7.0
CVE-2017-6874 [HIGH] CWE-362 kernel: Race condition in kernel/ucount.c
kernel: Race condition in kernel/ucount.c
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux and Red Hat Enterprise MRG as they did not include the vulnerable code.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affec
Debian
CVE-2017-6874: linux - Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows loca...
vendor_debian·2017·CVSS 7.0
CVE-2017-6874 [HIGH] CVE-2017-6874: linux - Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows loca...
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
Scope: local
bookworm: resolved (fixed in 4.9.16-1)
bullseye: resolved (fixed in 4.9.16-1)
forky: resolved (fixed in 4.9.16-1)
sid: resolved (fixed in 4.9.16-1)
trixie: resolved (fixed in 4.9.16-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6874 kernel: Race condition in kernel/ucount.c [fedora-all]
bugzilla·2017-03-15·CVSS 7.0
CVE-2017-6874 [HIGH] CVE-2017-6874 kernel: Race condition in kernel/ucount.c [fedora-all]
CVE-2017-6874 kernel: Race condition in kernel/ucount.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2017-6874 kernel: Race condition in kernel/ucount.c
bugzilla·2017-03-15·CVSS 7.0
CVE-2017-6874 [HIGH] CVE-2017-6874 kernel: Race condition in kernel/ucount.c
CVE-2017-6874 kernel: Race condition in kernel/ucount.c
Race condition in kernel/ucount.c in the Linux kernel allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=040757f738e13caaa9c5078bca79aa97e11dde88
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1432430]
---
Statement:
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux and Red Hat Enterprise MRG as they did not include the vulnerable code.
---
k
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=040757f738e13caaa9c5078bca79aa97e11dde88http://www.securityfocus.com/bid/96856https://github.com/torvalds/linux/commit/040757f738e13caaa9c5078bca79aa97e11dde88http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=040757f738e13caaa9c5078bca79aa97e11dde88http://www.securityfocus.com/bid/96856https://github.com/torvalds/linux/commit/040757f738e13caaa9c5078bca79aa97e11dde88
2017-03-14
Published