Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.9 | 4.9.16 |
| linux / linux_kernel | 4.10 | 4.10.4 |