---
id: CVE-2023-6546
title: A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
summary: >-
  A race condition was found in the GSM 0710 tty multiplexor in the Linux
  kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on
  the same tty file descriptor with the gsm line discipline enabled, and can
  lead to a u…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-366
  - CWE-362
vendor: linux
product: linux_kernel
affected:
  - linux_kernel < 6.5
  - linux_kernel = 6.5
  - fedora = 39
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
patched:
  - linux_kernel 6.5
published: '2023-12-21'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6546'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:0930'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0937'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1018'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1019'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1055'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1250'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1253'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1306'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1607'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1612'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1614'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2093'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2394'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2621'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2697'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4577'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4729'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4731'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4970'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6546'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2255498'
    label: secalert@redhat.com
  - url: >-
      https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3
    label: secalert@redhat.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-CAN-20527'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/10/18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/10/21'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/11/7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/11/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/12/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/12/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/16/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/17/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0930'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0937'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1018'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1019'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1055'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1250'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1253'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1306'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1607'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1612'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1614'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2093'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2394'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2621'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2697'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:4577'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:4729'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:4731'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6546'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2255498'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-CAN-20527'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.00735
epssPercentile: 0.52987
zeroDay: true
ingestedAt: '2026-08-06T23:06:28.927Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/harithlab/CVE-2023-6546'
  checkedAt: '2026-09-23T07:13:26.421Z'
exploitAvailable: true
---

## Overview

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.

## Affected

- `linux_kernel < 6.5`
- `linux_kernel = 6.5`
- `fedora = 39`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.5`
