The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.
Exploitability
AV:LAC:MAu:NImpact
C:NI:NA:C4.7/AV:L/AC:M/Au:N/C:N/I:N/A:C