CVE-2023-6546

Updated: 2025-08-20 00:21:58.859665

Description:

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.0

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.0 HIGH Released CLSA-2025:1743193221 2024-08-01 14:40:02
CentOS 6 ELS kernel 2.6.32 7.0 HIGH Not Vulnerable 2024-02-15 10:09:26
CentOS 7 ELS kernel 3.10.0 7.0 HIGH Not Vulnerable 2024-07-02 11:19:38
CentOS 8.4 ELS kernel 4.18.0 7.0 HIGH Released CLSA-2024:1711026398 2024-03-21 09:54:16
CentOS 8.5 ELS kernel 4.18.0 7.0 HIGH Released CLSA-2024:1711026811 2024-03-21 09:54:17
CentOS Stream 8 ELS kernel 4.18.0 7.0 HIGH Already Fixed 2024-06-09 14:20:53
CloudLinux 6 ELS kernel 2.6.32 7.0 HIGH Not Vulnerable 2024-05-08 10:17:14
Oracle Linux 6 ELS kernel 2.6.32 7.0 HIGH Not Vulnerable 2024-02-15 10:09:26
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.0 HIGH Released CLSA-2024:1705079299 2024-01-12 13:09:02
Ubuntu 16.04 ELS linux 4.4.0 7.0 HIGH Released CLSA-2024:1705078045 2024-01-12 13:08:57
Total: 11