Red Hat released Important-security-impact updates for CVE-2023-6546, a Linux kernel race condition in the GSM 07.10 (n_gsm) TTY multiplexer. Concurrent GSMIOC_SETCONF calls by a low-privileged local user on the same TTY file descriptor can trigger a use-after-free of struct gsm_dlci during GSM multiplexer restart, potentially enabling local privilege escalation. Red Hat assigns the flaw a CVSS 3.1 score of 7.0.
Affected RHEL 8 deployments should install the applicable kernel updates and reboot to activate them; RHEL Server 8.2 AUS on x86_64 received kernel version 4.18.0-193.136.1.el8_2 in RHSA-2024:4577. RHSA-2024:1612 also provides a kpatch-patch live-kernel module for RHEL 8 x86_64 and ppc64le, including RHEL 8.10 ELS, which loads after RPM installation to patch running kernels. Organizations unable to patch immediately can mitigate exposure by preventing the n_gsm kernel module from loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:4970, an Important-rated update for the kpatch-patch-4_18_0-305_120_1 live kernel patch module. It fixes CVE-2023-6546 for specified RHEL 8.4 SAP Solutions and Extended Life Cycle Long Life deployments on x86_64 and ppc64le without requiring an immediate reboot.
Red Hat issued RHSA-2024:4731, an Important-rated update providing kernel 4.18.0-305.134.1.el8_4 for RHEL 8.4 Extended Life Cycle Long Life, Advanced Update Support, Telecommunications Update Service, and SAP Solutions offerings. The update fixes CVE-2023-6546 and CVE-2024-21823; affected systems must be rebooted after installation.
Red Hat issued RHSA-2024:4729 for RHEL 8.4 Real Time ELC Long Life and telecommunications offerings on x86_64, providing kernel-rt 4.18.0-305.134.1.rt7.210.el8_4 to remediate CVE-2023-6546 and CVE-2024-21823. Systems must be rebooted after installation for the kernel fixes to take effect.
Red Hat issued RHSA-2024:4577 for Red Hat Enterprise Linux Server 8.2 Advanced Update Support on x86_64, fixing CVE-2023-6546 with kernel version 4.18.0-193.136.1.el8_2. Systems require a reboot after installation for the kernel fix to take effect.
Red Hat issued RHSA-2024:1614, supplying fixed Red Hat Enterprise Linux 8 kernel-rt packages for CVE-2023-6546.
RHSA-2024:1612 delivered an Important-rated kpatch-patch update for RHEL 8 on x86_64 and ppc64le, including RHEL 8.10 Extended Life Cycle releases. The live-patch module is loaded after RPM installation to apply the fix to a running kernel.
Red Hat issued RHSA-2024:1607, providing fixed Red Hat Enterprise Linux 8 kernel packages for CVE-2023-6546.
Red Hat issued RHSA-2024:0930 to fix CVE-2023-6546 in Red Hat Enterprise Linux 8.6 Extended Update Support kernel packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.