The code in the net/core/skbuff.c in the Linux kernel allows local users to cause a denial of service (a system panic) or possibly have unspecified other impact via certain IPv6 socket operations. Reference (contains reproducer): http://seclists.org/oss-sec/2016/q3/8 An upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a612769774a3
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1353539]
This fix has been in Fedora for a long time now.
Note: Red Hat Enterprise Linux 7 is not vulnerable to this flaw as only a part of offending commit e6afc8ace6dd without the bug was backported. Other Red Hat products are not affected also, as either the bug is fully fixed or offending code is not present.