跳转到帖子

Red Hat: CVE-2023-6546: kernel: GSM multiplexing race condition leads to privilege escalation (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2023-6546: kernel: GSM multiplexing race condition leads to privilege escalation (Multiple Advisories)

Severity
6
CVSS
(AV:L/AC:H/Au:S/C:C/I:C/A:C)
Published
12/21/2023
Created
02/23/2024
Added
02/22/2024
Modified
12/05/2024

Description

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.

Solution(s)

  • redhat-upgrade-kernel
  • redhat-upgrade-kernel-rt

References

  • CVE-2023-6546
  • RHSA-2024:0930
  • RHSA-2024:0937
  • RHSA-2024:1018
  • RHSA-2024:1019
  • RHSA-2024:1055
  • RHSA-2024:1250
  • RHSA-2024:1253
  • RHSA-2024:1306
  • RHSA-2024:1607
  • RHSA-2024:1612
  • RHSA-2024:1614
  • RHSA-2024:2394
  • RHSA-2024:2621
  • RHSA-2024:2697
View more
  • 查看数 705
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…