It was found that the unlink and rename functionality in overlayfs did not verify the upper dentry for staleness. A local, unprivileged user could use the rename syscall on overlayfs on top of xfs to crash the system.
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1355651]
Name: CAI Qian (Red Hat)
This issue is not present in the Linux kernel packages as shipped with Red Hat Enterprise Linux versions 5 and 6.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. Future Linux kernel updates for the respective releases may address this issue.