Red Hat disclosed and patched CVE-2023-52922, an Important use-after-free flaw in the Linux kernel's CAN Broadcast Manager (CAN BCM) subsystem that could let local, unprivileged users disclose kernel memory on RHEL 9. The bug stemmed from bcm_release() freeing bcm_op objects before removing their procfs entries, allowing bcm_proc_show() to read freed memory concurrently through /proc/net/can-bcm. Red Hat rated the issue CVSS 7.8 and warned it could lead to information disclosure, denial of service, memory corruption, and potentially code execution; fixes were shipped in March 2025 through RHEL 9 kernel advisories including RHSA-2025:2627 and kernel version 5.14.0-503.31.1.el9_5.
Research published by Allele Security showed the flaw could be exploited in environments where unprivileged user and network namespaces are enabled and a CAN interface can be created, such as with VXCAN, to leak encoded SLUB freelist pointers and slab addresses useful for bypassing kernel mitigations. The upstream Linux fix, commit 55c3b96, reordered CAN BCM cleanup so the procfs entry is removed earlier, and the researchers later released proof-of-concept code and noted the subsystem contained additional procfs-related memory-safety issues, including CVE-2025-38003 and CVE-2025-38004; a later upstream patch, commit dac5e62, added missing RCU read protection for CAN BCM procfs handling.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
A later Linux kernel commit added missing RCU read protection for CAN BCM procfs content, reflecting further memory-safety remediation in the same subsystem. The research ties this later fix to additional CAN BCM vulnerabilities found during review.
Red Hat released RHSA-2025:2627 for RHEL 9, backporting the fix for CVE-2023-52922 in kernel 5.14.0-503.31.1.el9_5 as part of an Important kernel security update.
Red Hat issued Important-rated RHSA-2025:2488 for RHEL 9.0 Update Services for SAP Solutions, updating kernel packages to 5.14.0-70.125.1.el9_0. The advisory remediates CVE-2023-52922 alongside CVE-2024-50302 and CVE-2024-53197 for x86_64, ppc64le, aarch64, and s390x systems.
Red Hat issued Important-rated RHSA-2025:2528 for supported non-Real-Time RHEL 8.4 variants, updating x86_64 and ppc64le kernel packages to 4.18.0-305.151.1.el8_4. The advisory remediates CVE-2023-52922 alongside CVE-2024-50302 and CVE-2024-53197.
Red Hat issued Important-rated RHSA-2025:2524 for specified RHEL 8.4 Real Time offerings, updating kernel-rt to 4.18.0-305.151.1.rt7.228.el8_4. The update remediates CVE-2023-52922 alongside CVE-2024-50302 and CVE-2024-53197.
Red Hat issued Important-rated RHSA-2025:2517 for RHEL 6 Extended Lifecycle Support Extension, updating the kernel to 2.6.32-754.56.1.el6. The advisory remediates CVE-2023-52922 for x86_64, i386, and s390x deployments, alongside CVE-2024-50302 and CVE-2024-53197.
Red Hat issued RHSA-2025:2489, an Important advisory updating selected RHEL 8.6 support channels for x86_64 and ppc64le to kernel 4.18.0-372.141.1.el8_6. The update fixes CVE-2023-52922 along with CVE-2024-50302 and CVE-2024-53197.
Red Hat issued RHSA-2025:2510, an Important advisory updating the RHEL for Real Time 7 x86_64 kernel-rt package to 3.10.0-1160.133.1.rt56.1285.el7. The update remediates CVE-2023-52922 alongside CVE-2024-50302 and CVE-2024-53197.
Red Hat published its CVE page for CVE-2023-52922, rating the Linux kernel flaw Important with a CVSS v3.1 score of 7.8 and crediting Anderson Nascimento of Allele Security Intelligence for reporting it.
Red Hat's CVE record lists additional fixed packages for CVE-2023-52922 across supported kernel streams, including RHEL 8 kernel and kernel-rt advisories issued on March 19 and March 20, 2025.
Red Hat's CVE record states that CVE-2023-52922 was publicly disclosed on this date. The issue was described as an Important Linux kernel CAN BCM use-after-free vulnerability.
Allele Security researchers reported the CAN BCM use-after-free vulnerability to Red Hat. Red Hat initially said upstream had declined a CVE, but later assigned CVE-2023-52922 after receiving a detailed report and proof of concept.
A Linux kernel commit changed bcm_release() so the procfs entry is removed before BCM operations are freed, fixing the use-after-free in bcm_proc_show() tracked as CVE-2023-52922.
Red Hat lists fixes for CVE-2023-52922 in RHEL 8 kernel packages through RHSA-2025:2646. The CVE page identifies March 11, 2025 as the fix date for RHEL 8.2 Advanced Update Support kernel packages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourcegithub.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.