CVE-2017-6874: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.

Affected products

  • Linux Linux Kernel: from 4.9, before 4.9.16 (fixed in 4.9.16); from 4.10, before 4.10.4 (fixed in 4.10.4)

Published 2017-03-14. Last modified 2026-06-17.