Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-6546— Kernel: gsm multiplexing race condition leads to privilege escalation

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 8
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于GSM 多路复用竞争条件导致权限升级,当两个线程在启用 gsm 行规则的情况下在同一个 tty 文件描述符上执行 GSMIOC_SETCONF ioctl 时,会出现此问题,并且可能会导致在重新启动 gsm mux 时在 struct gsm_dlci 上出现释放后重用问题。

CVSS 7.0 · High EPSS 0.73% · P53

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 44

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 6 any unaffected
Red Hat Red Hat Enterprise Linux 7 any unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-513.24.1.rt7.326.el8_9< * unaffected
0:4.18.0-513.24.1.el8_9< * unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:4.18.0-193.136.1.el8_2< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:4.18.0-305.134.1.el8_4< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.134.1.rt7.210.el8_4< * unaffected
0:4.18.0-305.134.1.el8_4< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions 0:4.18.0-305.134.1.el8_4< * unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support 0:4.18.0-372.93.1.el8_6< * unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support 0:4.18.0-477.55.1.el8_8< * unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-427.13.1.el9_4< * unaffected
0:5.14.0-427.13.1.el9_4< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.93.2.el9_0< * unaffected
0:5.14.0-70.93.1.rt21.165.el9_0< * unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:5.14.0-284.55.1.el9_2< * unaffected
0:5.14.0-284.55.1.rt14.340.el9_2< * unaffected
any unaffected
Red Hat Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 0:4.18.0-372.93.1.el8_6< * unaffected
Red Hat RHOL-5.7-RHEL-8 v5.7.13-16< * unaffected
v5.7.13-7< * unaffected
v6.8.1-408< * unaffected
v5.7.13-19< * unaffected
v1.0.0-480< * unaffected
v5.7.13-9< * unaffected
v0.4.0-248< * unaffected
v1.14.6-215< * unaffected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-6546

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kernel: gsm multiplexing race condition leads to privilege escalation
Source: CVE Program / CVE List V5
Vulnerability Description
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
单线程内的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于GSM 多路复用竞争条件导致权限升级,当两个线程在启用 gsm 行规则的情况下在同一个 tty 文件描述符上执行 GSMIOC_SETCONF ioctl 时,会出现此问题,并且可能会导致在重新启动 gsm mux 时在 struct gsm_dlci 上出现释放后重用问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-513.24.1.rt7.326.el8_9 ~ * cpe:/a:redhat:enterprise_linux:8::nfv
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-513.24.1.el8_9 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8::baseos
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:4.18.0-193.136.1.el8_2 ~ * cpe:/o:redhat:rhel_aus:8.2::baseos
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:4.18.0-305.134.1.el8_4 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.134.1.rt7.210.el8_4 ~ * cpe:/a:redhat:rhel_tus:8.4::nfv
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.134.1.el8_4 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions 0:4.18.0-305.134.1.el8_4 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions - cpe:/o:redhat:rhel_e4s:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support 0:4.18.0-372.93.1.el8_6 ~ * cpe:/a:redhat:rhel_eus:8.6::crb
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support - cpe:/o:redhat:rhel_eus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support 0:4.18.0-477.55.1.el8_8 ~ * cpe:/a:redhat:rhel_eus:8.8::crb
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support - cpe:/o:redhat:rhel_eus:8.8::baseos
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-427.13.1.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-427.13.1.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.93.2.el9_0 ~ * cpe:/a:redhat:rhel_eus:9.0::appstream
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.93.1.rt21.165.el9_0 ~ * cpe:/a:redhat:rhel_eus:9.0::nfv
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support - cpe:/o:redhat:rhel_eus:9.0::baseos
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:5.14.0-284.55.1.el9_2 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:5.14.0-284.55.1.rt14.340.el9_2 ~ * cpe:/a:redhat:rhel_eus:9.2::nfv
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support - cpe:/o:redhat:rhel_eus:9.2::baseos
Red Hat Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 0:4.18.0-372.93.1.el8_6 ~ * cpe:/a:redhat:rhel_eus:8.6::crb
Red Hat RHOL-5.7-RHEL-8 v5.7.13-16 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v5.7.13-7 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v6.8.1-408 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v5.7.13-19 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v1.0.0-480 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v5.7.13-9 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v0.4.0-248 ~ * cpe:/a:redhat:logging:5.7::el8
Red Hat RHOL-5.7-RHEL-8 v1.14.6-215 ~ * cpe:/a:redhat:logging:5.7::el8

II. Public POCs for CVE-2023-6546

# POC Description Source Link Shenlong Link
1 None https://github.com/harithlab/CVE-2023-6546 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-6546

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-6546 (1)

Vendor Advisories for CVE-2023-6546 (19)

Mailing List Discussions for CVE-2023-6546 (8)

Same Patch Batch · Red Hat · 2023-12-21 · 3 CVEs total

CVE-2023-7042 4.4 MEDIUM Kernel: null pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
CVE-2023-2585 3.5 LOW Keycloak: client access via device auth request spoof

IV. Related Vulnerabilities

V. Comments for CVE-2023-6546

No comments yet


Leave a comment