PT-2025-8608 · Linux+4 · Linux Kernel+4

Publicado

2022-06-27

·

Atualizado

2025-04-14

·

CVE-2022-49675

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue arises from the combination of EXPORT SYMBOL and init annotations in the tick nohz full setup() function. This combination is problematic because the .init.text section is freed after initialization, and modules cannot use symbols annotated with init. Access to a freed symbol may result in a kernel panic. The modpost tool, which detects such issues, had been broken for a decade but was recently fixed, leading to the discovery of this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Improper Initialization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-03998
CESA-2023_7077
CVE-2022-49675
RHSA-2023:7077
RHSA-2023_7077
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Produtos afetados

Astra Linux
Centos
Linux Kernel
Red Hat
Suse