race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
18 Feb 2026, 18:24
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-366 |
21 Nov 2024, 08:44
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://access.redhat.com/errata/RHSA-2024:0930 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:0937 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1018 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1019 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1055 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1250 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1253 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1306 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1607 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1612 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:1614 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2093 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2394 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2621 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2697 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:4577 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:4729 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:4731 - | |
| References | () https://access.redhat.com/security/cve/CVE-2023-6546 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2255498 - Issue Tracking, Patch, Third Party Advisory | |
| References | () https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3 - Patch | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-CAN-20527 - |
14 Sep 2024, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Aug 2024, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Jul 2024, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Jul 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 May 2024, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Apr 2024, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Apr 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Published : 2023-12-21 20:15
Updated : 2026-02-18 18:24
NVD link : CVE-2023-6546
Mitre link : CVE-2023-6546
CVE.ORG link : CVE-2023-6546
JSON object : View