UBUNTU-CVE-2017-8824
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-8824
UBUNTU-CVE-2017-8824
Summary:
Details: The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
References: https://ubuntu.com/security/CVE-2017-8824, http://lists.openwall.net/netdev/2017/12/04/224, http://www.openwall.com/lists/oss-security/2017/12/05/1, https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=69c64866ce072dea1d1e59a0d61e0f66c0dffb76, https://ubuntu.com/security/notices/USN-3581-1, https://ubuntu.com/security/notices/USN-3581-2, https://ubuntu.com/security/notices/USN-3582-1, https://ubuntu.com/security/notices/USN-3582-2, https://ubuntu.com/security/notices/USN-3581-3, https://ubuntu.com/security/notices/USN-3583-1, https://ubuntu.com/security/notices/USN-3583-2, https://www.cve.org/CVERecord?id=CVE-2017-8824
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
