Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-6074

39
FAUCET Score

CVE-2017-6074 is a high-severity double-free vulnerability in the Linux kernel's DCCP implementation (net/dccp/input.c), affecting versions through 4.9.11, including Debian and Ubuntu distributions. A local attacker can exploit this flaw by making an IPV6_RECVPKTINFO setsockopt system call, leading to root privilege escalation or denial of service. While not listed on the KEV catalog, public exploit code exists (e.g., ExploitDB EDB-41458), and it has garnered significant community discussion and media attention, indicating a high potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.86CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.10.106CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.71CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.16.41CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.17, < 3.18.49CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
5.96%
Probability of exploitation in next 30 days
EPSS Percentile
92.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-41457 · Feb 26, 2017
This CVE's current EPSS score of 0.0596 is in the 98th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

github_advisorypatch availablevia nvd_reference
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 Long LifeFixed in: kernel-0:2.6.18-238.58.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Long LifeFixed in: kernel-0:2.6.18-348.33.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-642.13.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.70.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Advanced Update SupportFixed in: kernel-0:2.6.32-358.77.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.78.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Telco Extended Update SupportFixed in: kernel-0:2.6.32-431.78.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Telco Extended Update SupportFixed in: kernel-0:2.6.32-504.57.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.40.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-514.6.1.rt56.430.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-514.6.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.1 Extended Update SupportFixed in: kernel-0:3.10.0-229.49.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Extended Update SupportFixed in: kernel-0:3.10.0-327.49.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-514.rt56.219.el6rt
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor7-0:7.3-20170425.0.el6ev
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-7Fixed in: rhev-hypervisor7-0:7.3-20170425.0.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Advanced Update SupportFixed in: kernel-0:2.6.32-504.57.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-419.el5
View patch
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: distribution

Vendor Advisories (1)

redhatCVE-2017-6074Important

kernel: use after free in dccp protocol

Feb 22, 2017

References

rhn.redhat.com / errata/RHSA-2017-0293.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0294.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0295.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0316.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0323.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0324.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0345.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0346.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0347.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0365.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0366.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0403.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0501.html
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0932
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1209
Third Party Advisory
github.com / torvalds/linux/commit/5edabca9d4cff7f1f2b68f0bac55ef99d9798ba4
Issue TrackingPatchThird Party Advisory
source.android.com / security/bulletin/2017-07-01
Third Party Advisory
exploit-db.com / exploits/41457
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/41458
Third Party AdvisoryVDB Entry
tenable.com / security/tns-2017-07
Third Party Advisory
debian.org / security/2017/dsa-3791
Third Party Advisory
openwall.com / lists/oss-security/2017/02/22/3
Mailing ListThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2018-4258247.html
PatchThird Party Advisory
securityfocus.com / bid/96310
Third Party AdvisoryVDB Entry
securitytracker.com / id/1037876
Third Party AdvisoryVDB Entry