CVE-2017-6346: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKET_FANOUT setsockopt system calls.

Affected products

  • Linux Linux Kernel: from 3.1, before 3.2.87 (fixed in 3.2.87); from 3.3, before 3.10.106 (fixed in 3.10.106); from 3.11, before 3.12.71 (fixed in 3.12.71); from 3.13, before 3.16.42 (fixed in 3.16.42); from 3.17, before 4.1.49 (fixed in 4.1.49); from 4.2, before 4.4.52 (fixed in 4.4.52); …

Published 2017-03-01. Last modified 2026-06-17.