OpenSSH 7.4p1 is affected by CVE-2017-15906.
... unless the distributor of that OpenSSH package has patched it.
An example of a distributor patching this particular CVE in an affected OpenSSH package may be found in this changelog entry for 7.5p1 on Ubuntu (they have not distributed a patched 7.4p1 as far as I could see after only a brief look):
openssh (1:7.5p1-10ubuntu0.1) artful-security; urgency=medium
* SECURITY UPDATE: DoS via zero-length file creation in readonly mode
- debian/patches/CVE-2017-15906.patch: disallow creation of empty files
in sftp-server.c.
- CVE-2017-15906
-- Marc Deslauriers <[email protected]> Tue, 16 Jan 2018 08:28:47 -0500
Similarly for Fedora (7.4p1).
Unfortunately, CentOS does not seem to have an easily accessible database of package updates (that I could find).