The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
Product | Vendor | Version |
---|---|---|
Linux kernel through 4.14.3 | n/a | 6.0(2)U6(7) |