The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. CVSS v2 Base Score: 7.8 HIGH (attack range: remote)

Upstream-commit and 3.2-backport are equal, so implementing in kernel-3.4 for jolla1 should be no problem ...

File affected: kernel-adaptation-sbj- lines 178-183

