{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3olinuxlinux_kernel6.5rc4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.5:rc1:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.5:rc2:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.5:rc3:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.5:rc4:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.5:rc5:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:6.5:rc6:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2023-6546"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Linux kernel"],"_cs_severities":["medium"],"_cs_tags":["privilege-escalation","linux","kernel"],"_cs_type":"advisory","_cs_vendors":["Linux"],"content_html":"\u003cp\u003eThis threat involves a local privilege escalation vulnerability in the Linux kernel, specifically within the GSM 0710 tty multiplexor module (n_gsm). The vulnerability, tracked as CVE-2023-6546, arises from a race condition triggered when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor while the gsm line discipline is active. An unprivileged local attacker can leverage this race condition to gain root privileges. Defense teams should monitor for anomalous kernel module management and shell execution patterns that coincide with the loading or unloading of the n_gsm kernel module.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the Linux system as an unprivileged user.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a local exploit payload targeting the GSM 0710 tty multiplexor.\u003c/li\u003e\n\u003cli\u003eAttacker initiates multiple threads attempting to trigger the race condition using the GSMIOC_SETCONF ioctl.\u003c/li\u003e\n\u003cli\u003eAttacker forces the unloading of the \u003ccode\u003en_gsm\u003c/code\u003e kernel module using \u003ccode\u003ermmod\u003c/code\u003e to manipulate the module state.\u003c/li\u003e\n\u003cli\u003eAttacker executes shell commands (e.g., \u003ccode\u003e/bin/bash\u003c/code\u003e or \u003ccode\u003e/bin/sh\u003c/code\u003e) following the successful race condition exploitation.\u003c/li\u003e\n\u003cli\u003eAttacker confirms privilege escalation to root.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full local privilege escalation, allowing an unprivileged attacker to obtain root-level access on the affected system. This compromise permits the attacker to bypass access controls, install persistence mechanisms, exfiltrate sensitive data, or deploy further malicious payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to detect suspicious process activity associated with GSM module manipulation. Ensure that kernel auditing and Sysmon for Linux are configured to log process creation events. Restrict the ability of unprivileged users to load or unload kernel modules using \u003ccode\u003ermmod\u003c/code\u003e.\u003c/p\u003e\n","date_modified":"2026-08-07T15:16:26Z","date_published":"2026-08-07T15:16:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linux-gsm-privilege-escalation/","summary":"An unprivileged local user can escalate privileges to root by exploiting a race condition in the Linux kernel GSM 0710 tty multiplexor (CVE-2023-6546).","title":"Exploitation of Linux Kernel GSM 0710 TTY Multiplexor Race Condition","url":"https://feed.craftedsignal.io/briefs/2026-08-linux-gsm-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:linux:linux_kernel:6.5:rc4:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}