Kernel: gsm multiplexing race condition leads to privilege escalation
Summary
| CVE | CVE-2023-6546 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-12-21 20:15:08 UTC |
| Updated | 2026-08-06 22:16:38 UTC |
| Description | A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system. |
Risk And Classification
Primary CVSS: v3.1 7 HIGH from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.007670000 probability, percentile 0.521190000 (date 2026-08-09)
Problem Types: CWE-366 | CWE-362 | CWE-366 Race Condition within a Thread
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 39 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | 6.5 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 6.5 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 6.5 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 6.5 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 6.5 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 6.5 | rc6 | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 9.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:4.18.0-513.24.1.rt7.326.el8_9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:4.18.0-513.24.1.el8_9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 0:4.18.0-193.136.1.el8_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 0:4.18.0-305.134.1.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 0:4.18.0-305.134.1.rt7.210.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 0:4.18.0-305.134.1.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | unaffected 0:4.18.0-305.134.1.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | unaffected 0:4.18.0-372.93.1.el8_6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | unaffected 0:4.18.0-477.55.1.el8_8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-427.13.1.el9_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-427.13.1.el9_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:5.14.0-70.93.2.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:5.14.0-70.93.1.rt21.165.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 0:5.14.0-284.55.1.el9_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 0:5.14.0-284.55.1.rt14.340.el9_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Virtualization 4 For Red Hat Enterprise Linux 8 | unaffected 0:4.18.0-372.93.1.el8_6 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-16 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-7 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v6.8.1-408 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-19 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v1.0.0-480 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-9 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v0.4.0-248 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v1.14.6-215 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v6.8.1-431 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v1.1.0-228 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.8.1-471 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v2.9.6-15 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-3 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-27 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v5.7.13-12 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v0.1.0-527 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v0.1.0-225 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.7-RHEL-8 | unaffected v0.28.1-57 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2024:1614 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:1612 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:4577 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:4731 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:1018 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0937 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:1250 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:4970 | [email protected] | access.redhat.com | |
| www.openwall.com/lists/oss-security/2024/04/17/1 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2024:1607 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| www.zerodayinitiative.com/advisories/ZDI-CAN-20527 | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| www.openwall.com/lists/oss-security/2024/04/12/1 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2024:2621 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| www.openwall.com/lists/oss-security/2024/04/12/2 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| www.openwall.com/lists/oss-security/2024/04/10/18 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2024:1306 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| www.openwall.com/lists/oss-security/2024/04/10/21 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3 | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| www.openwall.com/lists/oss-security/2024/04/11/9 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2024:1055 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| www.openwall.com/lists/oss-security/2024/04/11/7 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2024:4729 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| www.openwall.com/lists/oss-security/2024/04/16/2 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2024:0930 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:2394 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2023-6546 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1019 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:2093 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:1253 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:2697 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-12-18T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-12-21T00:00:00.000Z | Made public. |
Workarounds
CNA: This flaw can be mitigated by preventing the affected `n_gsm` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
Legacy QID Mappings
- 161479 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-1607)
- 242941 Red Hat Update for kernel (RHSA-2024:0930)
- 242942 Red Hat Update for kpatch-patch (RHSA-2024:0937)
- 242985 Red Hat Update for kernel (RHSA-2024:1018)
- 242986 Red Hat Update for kernel-rt (RHSA-2024:1019)
- 242994 Red Hat Update for kpatch-patch (RHSA-2024:1055)
- 243050 Red Hat Update for kernel (RHSA-2024:1250)
- 243053 Red Hat Update for kernel live patch module (RHSA-2024:1253)
- 243062 Red Hat Update for kernel-rt (RHSA-2024:1306)
- 243160 Red Hat Update for kernel security (RHSA-2024:1607)
- 243163 Red Hat Update for kpatch-patch (RHSA-2024:1612)
- 243167 Red Hat Update for kernel-rt (RHSA-2024:1614)
- 357089 Amazon Linux Security Advisory for kernel : ALAS2-2024-2443
- 673321 EulerOS Security Update for kernel (EulerOS-SA-2024-1337)
- 673547 EulerOS Security Update for kernel (EulerOS-SA-2024-1315)
- 673714 EulerOS Security Update for kernel (EulerOS-SA-2024-1196)
- 673723 EulerOS Security Update for kernel (EulerOS-SA-2024-1237)
- 673902 EulerOS Security Update for kernel (EulerOS-SA-2024-1176)
- 673992 EulerOS Security Update for kernel (EulerOS-SA-2024-1215)
- 673995 EulerOS Security Update for kernel (EulerOS-SA-2024-1275)
- 755604 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0129-1)
- 755607 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0115-1)
- 907788 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (32284)
- 907967 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (32284-1)
- 941650 AlmaLinux Security Update for kernel (ALSA-2024:1607)
- 961147 Rocky Linux Security Update for kernel (RLSA-2024:1607)
- 961150 Rocky Linux Security Update for kernel-rt (RLSA-2024:1614)