CVE•Published 2023-12-21•Modified 2026-08-06•0 articles on news•6 live references•NVD data
CVE-2023-6546Linux · Linux_kernel
Vulnerability data via NVD (ingested)
CVSS v3.1
7.0
HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
52
Exploit Prediction Scoring System · top 48% of all CVEs
Weaknesses (CWE)
Description
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
Timeline
Published 2023-12-21
Modified 2026-08-06
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2023-6546Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · OS
os:"Linux Kernel"Hosts Shodan identified as running Linux Kernel.
More intel sources (5)
Shodan report
vuln:CVE-2023-6546Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2023-6546Censys host search filtered to this CVE id.
grep.app
CVE-2023-6546Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2023-6546GitHub code search for direct mentions.
Google dork
"CVE-2023-6546" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (4)
CVE-2023-65464 repos
xairy/linux-kernel-exploitationunknown
A collection of links related to Linux kernel security and exploitation
zerozenxlabs/ZDI-24-020C
harithlab/CVE-2023-6546C
jaschadub/compromised-packages-checkPython
Scan a repository for known-malicious npm, cratres, and PyPI package versions from recent supply-chain compromises (Mini Shai-Hulud, TanStack, @cap-js/mbt, etc). UPDATED 6 TIMES A …
We haven't classified any articles referencing CVE-2023-6546 yet. The external references above still apply.