PT-2025-8608 · Linux+4 · Linux Kernel+4

Published

2022-06-27

·

Updated

2025-04-14

·

CVE-2022-49675

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue arises from the combination of EXPORT SYMBOL and init annotations in the tick nohz full setup() function. This combination is problematic because the .init.text section is freed after initialization, and modules cannot use symbols annotated with init. Access to a freed symbol may result in a kernel panic. The modpost tool, which detects such issues, had been broken for a decade but was recently fixed, leading to the discovery of this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03998
CESA-2023_7077
CVE-2022-49675
RHSA-2023:7077
RHSA-2023_7077
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse