Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 2.6.17 | 2.6.17.x |
| linux / linux_kernel | 2.6.20 | 2.6.20.x |
| linux / linux_kernel | 2.6.19 | 2.6.19.x |
| linux / linux_kernel | 2.6.18 | 2.6.18.x |