The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to execute code and gain privileges.
4.4.0-1014.144.4.0-116.140~14.04.14.4.0-116.1404.4.0-1052.614.13.0-1011.144.4.0-9025.274.13.0-1011.154.13.0-41.46~16.04.14.4.0-1019.244.13.0-1021.23Exploitability
AV:LAC:HPR:LUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H