CVE-2023-52562 affects the Linux kernel slab allocator when a module destroys a kmem_cache while allocated objects still exist. If shutdown_cache() fails, kmem_cache_destroy() can release the cache object without removing its entry from the slab_caches list, leaving a stale reference that can corrupt the list and trigger kernel crashes or instability.
A local low-privileged user able to trigger the condition could cause denial of service through system hangs, crashes, or restarts. Red Hat rates the issue Low severity with a CVSS score of 5.5 and has released fixes for several RHEL 8 and RHEL 9 package streams; RHEL 8 kernel-rt and RHEL 9 kernel were listed as affected, while RHEL 7 is outside support scope. The flaw reflects a memory-lifecycle failure, where resources are released despite outstanding allocations, creating reliability and availability risk.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:7549 for the RHEL 8 kernel and RHSA-2023:7539 for the RHEL 8.8 Extended Update Support kernel, fixing the slab allocator flaw.
Red Hat published its CVE record for CVE-2023-52562, a CWE-401 slab allocator issue that can corrupt the slab_caches list and cause kernel crashes or instability.
Red Hat released RHBA-2024:0611, providing fixes for CVE-2023-52562 in the RHEL 9 Flatpak runtime and SDK streams.
Red Hat released RHSA-2024:0448 to fix CVE-2023-52562 in the RHEL 9.2 Extended Update Support kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.