CVE-2023-6546
published 2023-12-21CVE-2023-6546: A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same…
PriorityP336high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.77%
51.8th percentile
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libreoffice | libreoffice | >= 0 < 1:6.4.7-0ubuntu0.20.04.9 | 1:6.4.7-0ubuntu0.20.04.9 |
| libreoffice | libreoffice | >= 0 < 1:7.3.7-0ubuntu0.22.04.4 | 1:7.3.7-0ubuntu0.22.04.4 |
| linux | linux_kernel | < 6.5 | 6.5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.13-1 | 6.4.13-1 |
| linux | linux_kernel | >= 0 < 6.4.13-1 | 6.4.13-1 |
| msrc | cbl2_kernel_5.15.148.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0 | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
kernel: GSM multiplexing race condition leads to privilege escalation
vendor_redhat·2023-12-21·CVSS 7.0
CVE-2023-6546 [HIGH] CWE-366 kernel: GSM multiplexing race condition leads to privilege escalation
kernel: GSM multiplexing race condition leads to privilege escalation
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a lo
Microsoft
Kernel: gsm multiplexing race condition leads to privilege escalation
vendor_msrc·2023-12-12·CVSS 7.0
CVE-2023-6546 [HIGH] CWE-362 Kernel: gsm multiplexing race condition leads to privilege escalation
Kernel: gsm multiplexing race condition leads to privilege escalation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Referenc
Debian
CVE-2023-6546: linux - A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. ...
vendor_debian·2023·CVSS 7.0
CVE-2023-6546 [HIGH] CVE-2023-6546: linux - A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. ...
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.4.13-1)
sid: resolved (fixed in 6.4.13-1)
trixie: resolved (fixed in 6.4.13-1)
GHSA
GHSA-v727-f437-6cxx: A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
ghsa_unreviewed·2023-12-21
CVE-2023-6546 [HIGH] CWE-362 GHSA-v727-f437-6cxx: A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
OSV
CVE-2023-6546: A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
osv·2023-12-21·CVSS 7.0
CVE-2023-6546 [HIGH] CVE-2023-6546: A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
OSV
libreoffice vulnerabilities
osv·2023-12-14·CVSS 8.8
CVE-2023-6185 libreoffice vulnerabilities
libreoffice vulnerabilities
USN-6546-1 fixed vulnerabilities in LibreOffice. This update provides the
corresponding updates for Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
Original advisory details:
Reginaldo Silva discovered that LibreOffice incorrectly handled filenames
when passing embedded videos to GStreamer. If a user were tricked into
opening a specially crafted file, a remote attacker could possibly use this
issue to execute arbitrary GStreamer plugins. (CVE-2023-6185)
Reginaldo Silva discovered that LibreOffice incorrectly handled certain
non-typical hyperlinks. If a user were tricked into opening a specially
crafted file, a remote attacker could possibly use this issue to execute
arbitrary scripts. (CVE-2023-6186)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:0930https://access.redhat.com/errata/RHSA-2024:0937https://access.redhat.com/errata/RHSA-2024:1018https://access.redhat.com/errata/RHSA-2024:1019https://access.redhat.com/errata/RHSA-2024:1055https://access.redhat.com/errata/RHSA-2024:1250https://access.redhat.com/errata/RHSA-2024:1253https://access.redhat.com/errata/RHSA-2024:1306https://access.redhat.com/errata/RHSA-2024:1607https://access.redhat.com/errata/RHSA-2024:1612https://access.redhat.com/errata/RHSA-2024:1614https://access.redhat.com/errata/RHSA-2024:2093https://access.redhat.com/errata/RHSA-2024:2394https://access.redhat.com/errata/RHSA-2024:2621https://access.redhat.com/errata/RHSA-2024:2697https://access.redhat.com/errata/RHSA-2024:4577https://access.redhat.com/errata/RHSA-2024:4729https://access.redhat.com/errata/RHSA-2024:4731https://access.redhat.com/errata/RHSA-2024:4970https://access.redhat.com/security/cve/CVE-2023-6546https://bugzilla.redhat.com/show_bug.cgi?id=2255498https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3https://www.zerodayinitiative.com/advisories/ZDI-CAN-20527http://www.openwall.com/lists/oss-security/2024/04/10/18http://www.openwall.com/lists/oss-security/2024/04/10/21http://www.openwall.com/lists/oss-security/2024/04/11/7http://www.openwall.com/lists/oss-security/2024/04/11/9http://www.openwall.com/lists/oss-security/2024/04/12/1http://www.openwall.com/lists/oss-security/2024/04/12/2http://www.openwall.com/lists/oss-security/2024/04/16/2http://www.openwall.com/lists/oss-security/2024/04/17/1https://access.redhat.com/errata/RHSA-2024:0930https://access.redhat.com/errata/RHSA-2024:0937https://access.redhat.com/errata/RHSA-2024:1018https://access.redhat.com/errata/RHSA-2024:1019https://access.redhat.com/errata/RHSA-2024:1055https://access.redhat.com/errata/RHSA-2024:1250https://access.redhat.com/errata/RHSA-2024:1253https://access.redhat.com/errata/RHSA-2024:1306https://access.redhat.com/errata/RHSA-2024:1607https://access.redhat.com/errata/RHSA-2024:1612https://access.redhat.com/errata/RHSA-2024:1614https://access.redhat.com/errata/RHSA-2024:2093https://access.redhat.com/errata/RHSA-2024:2394https://access.redhat.com/errata/RHSA-2024:2621https://access.redhat.com/errata/RHSA-2024:2697https://access.redhat.com/errata/RHSA-2024:4577https://access.redhat.com/errata/RHSA-2024:4729https://access.redhat.com/errata/RHSA-2024:4731https://access.redhat.com/security/cve/CVE-2023-6546https://bugzilla.redhat.com/show_bug.cgi?id=2255498https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3https://www.zerodayinitiative.com/advisories/ZDI-CAN-20527
2023-12-21
Published