CVE-2017-6074: Debian Linux

High severity, CVSS 7.8. EPSS: 6% chance of exploitation in the next 30 days.

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 3.2.86 (fixed in 3.2.86); from 3.3, before 3.10.106 (fixed in 3.10.106); from 3.11, before 3.12.71 (fixed in 3.12.71); from 3.13, before 3.16.41 (fixed in 3.16.41); from 3.17, before 3.18.49 (fixed in 3.18.49); from 3.19, before 4.1.41 (fixed in 4.1.41); …

Published 2017-02-18. Last modified 2026-06-17.