CVE-2023-1252 is a use-after-free flaw in the Linux kernel’s OverlayFS asynchronous I/O path that can be triggered when OverlayFS performs direct asynchronous reads against an underlying Ext4 filesystem. I/O completion on a separate thread can free the embedded iocb in ovl_aio_req before the lower filesystem returns from its read/write iterator, creating a system-crash and potential local privilege-escalation condition for low-privileged users.
The upstream fix adds reference counting to ovl_aio_req, retaining the I/O control block until vfs_read_iter() or vfs_write_iter() returns. The affected OverlayFS AIO implementation was introduced in Linux 5.6, and the correction was backported to the stable 5.15 series. Red Hat rated the issue Moderate (CVSS 7.0), released fixes for affected RHEL 8 and RHEL 9 kernel streams, including applicable EUS and kernel-rt packages, and listed RHEL 6 and 7 as unaffected.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:6901 for RHEL 8 kernel-rt and RHSA-2023:7077 for the RHEL 8 kernel, addressing CVE-2023-1252.
Red Hat released RHSA-2023:6583 to fix CVE-2023-1252 in the Red Hat Enterprise Linux 9 kernel stream.
Linux stable 5.15 patch 138 incorporated upstream commit 9a254403760041528bc8f69fe2f5e1ef86950991, adding reference counting to ovl_aio_req to prevent its embedded iocb from being freed before the underlying read/write operation returns.
Red Hat released RHSA-2024:8613 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:8614 for its kernel-rt package, fixing CVE-2023-1252.
Red Hat released RHSA-2024:8107 to address CVE-2023-1252 in the RHEL 8.8 Extended Update Support kernel.
RHSA-2024:0724 fixed CVE-2023-1252 in the RHEL 8.6 Extended Update Support kernel and the Red Hat Virtualization 4 for RHEL 8 kernel.
Commit 2406a307ac7 introduced OverlayFS asynchronous I/O routines containing a use-after-free condition in ovl_aio_req. The affected implementation has been present since Linux kernel 5.6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.