Unity Linux 20.1060e / 20.1070e Security Update: kernel (UTSA-2026-003412)

high Nessus Plugin ID 287916

Synopsis

The Unity Linux host is missing one or more security updates.

Description

The Unity Linux 20 host has a package installed that is affected by a vulnerability as referenced in the UTSA-2026-003412 advisory.

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

Tenable has extracted the preceding description block directly from the Unity Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel package.

See Also

http://www.nessus.org/u?6de02872

http://rhn.redhat.com/errata/RHSA-2017-0293.html

http://rhn.redhat.com/errata/RHSA-2017-0294.html

http://rhn.redhat.com/errata/RHSA-2017-0295.html

http://rhn.redhat.com/errata/RHSA-2017-0316.html

http://rhn.redhat.com/errata/RHSA-2017-0323.html

http://rhn.redhat.com/errata/RHSA-2017-0324.html

http://rhn.redhat.com/errata/RHSA-2017-0345.html

http://rhn.redhat.com/errata/RHSA-2017-0346.html

http://rhn.redhat.com/errata/RHSA-2017-0347.html

http://rhn.redhat.com/errata/RHSA-2017-0365.html

http://rhn.redhat.com/errata/RHSA-2017-0366.html

http://rhn.redhat.com/errata/RHSA-2017-0403.html

http://rhn.redhat.com/errata/RHSA-2017-0501.html

http://www.debian.org/security/2017/dsa-3791

http://www.openwall.com/lists/oss-security/2017/02/22/3

http://www.nessus.org/u?50f36723

http://www.securityfocus.com/bid/96310

http://www.securitytracker.com/id/1037876

https://access.redhat.com/errata/RHSA-2017:0932

https://access.redhat.com/errata/RHSA-2017:1209

http://www.nessus.org/u?5b4b8f06

https://security-tracker.debian.org/tracker/CVE-2017-6074

https://source.android.com/security/bulletin/2017-07-01

https://www.exploit-db.com/exploits/41457/

https://www.exploit-db.com/exploits/41458/

https://www.tenable.com/security/tns-2017-07

Plugin Details

Severity: High

ID: 287916

File Name: unity_linux_UTSA-2026-003412.nasl

Version: 1.2

Type: local

Published: 1/15/2026

Updated: 1/16/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2017-6074

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/UOS-Server/release, Host/UOS-Server/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/15/2026

Vulnerability Publication Date: 2/18/2017

Reference Information

CVE: CVE-2017-6074