CVE-2022-49098 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix potential crash on module unload The vmbus driver relies on the panic notifier infrastructure to perform some operations when a panic event is detected. Since vmbus can be built as module, it is required that the driver handles both registering and unregistering such panic notifier callback. After commit 74347a99e73a ("x86/Hyper-V: Unload vmbus channel in hv panic callback") though, the panic notifier registration is done unconditionally in the module initialization routine whereas the unregistering procedure is conditionally guarded and executes only if HV_FEATURE_GUEST_CRASH_MSR_AVAILABLE capability is set. This patch fixes that by unconditionally unregistering the panic notifier in the module's exit routine as well.
A vulnerability in the Linux kernel's VMBus driver module can lead to a potential crash when the module is unloaded. This issue arises because the VMBus driver, which can be built as a module, improperly manages the registration and unregistration of panic notifier callbacks. The vulnerability is present in the VMBus driver of the Linux kernel.
The vulnerability has been addressed by modifying the VMBus driver to unconditionally unregister the panic notifier in the module's exit routine.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2133c422a103cf7c7768c37b9ac382e73b691892 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3d0078f8bddd58d9bb1ad40bbe929f8633abb276 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5ea98d0f5f035c1bcf1517ccec0e024ae35a48b2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6b4c0149a56147b29169e07000d566162892722a | kernel.org | Patch |
| https://git.kernel.org/stable/c/792f232d57ff28bbd5f9c4abe0466b23d5879dc8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cf580d2e3884dbafd6b90269b03a24d661578624 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dcd6b1a624c0ffa21034d8b1e02e9d068458f596 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.19.118, < 4.19.238 >= 5.4.35, < 5.4.189 >= 5.6.7, < 5.7 >= 5.7.1, < 5.10.111 >= 5.11, < 5.15.34 >= 5.16, < 5.16.20 >= 5.17, < 5.17.3 5.7 - 5.7 rc2 5.7 rc3 5.7 rc4 5.7 rc5 5.7 rc6 5.7 rc7 5.18 rc1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 14, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |