PT-2025-8659 · Linux+4 · Linux Kernel+4
Stephen Rothwell
·
Published
2022-06-08
·
Updated
2025-10-24
·
CVE-2022-49726
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, related to the hyper-v clocksource. The issue arises from the combination of EXPORT SYMBOL and init, which can lead to kernel panic when modules attempt to use symbols annotated init after the .init.text section is freed. The problem was previously undetected by modpost due to a decade-long bug, but after fixing modpost, the issue was identified in linux-next builds.
Recommendations
Remove EXPORT SYMBOL from the hv init clocksource() function to prevent the vulnerability, as the only in-tree call-site is never compiled as modular.
Exploit
Fix
Use of Uninitialized Resource
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse