PT-2025-8659 · Linux+4 · Linux Kernel+4

Stephen Rothwell

·

Published

2022-06-08

·

Updated

2025-10-24

·

CVE-2022-49726

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the hyper-v clocksource. The issue arises from the combination of EXPORT SYMBOL and init, which can lead to kernel panic when modules attempt to use symbols annotated init after the .init.text section is freed. The problem was previously undetected by modpost due to a decade-long bug, but after fixing modpost, the issue was identified in linux-next builds.
Recommendations Remove EXPORT SYMBOL from the hv init clocksource() function to prevent the vulnerability, as the only in-tree call-site is never compiled as modular.

Exploit

Fix

Use of Uninitialized Resource

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03714
CESA-2023_2951
CVE-2022-49726
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse