CVE-2022-49345 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: xfrm: unexport __init-annotated xfrm4_protocol_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text section is freed up after the initialization. Hence, modules cannot use symbols annotated __init. The access to a freed symbol may end up with kernel panic. modpost used to detect it, but it has been broken for a decade. Recently, I fixed modpost so it started to warn it again, then this showed up in linux-next builds. There are two ways to fix it: - Remove __init - Remove EXPORT_SYMBOL I chose the latter for this case because the only in-tree call-site, net/ipv4/xfrm4_policy.c is never compiled as modular. (CONFIG_XFRM is boolean)
A vulnerability in the Linux kernel's handling of the XFRM (IPsec) module has been identified. The issue arises because the function 'xfrm4_protocol_init' was incorrectly marked for export and initialization, allowing access to a freed symbol after the initialization process. This mismanagement can lead to a kernel panic. The problem was detected in 'linux-next' builds after the 'modpost' tool was fixed to recognize such issues, which had gone undetected for a decade.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2b253fbc9f7b5db18d716436bdcf8ecef09fd63d | kernel.org | Patch |
| https://git.kernel.org/stable/c/31f3c6a4dcd3260a386e62cef2d5b36e902600a1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4a388f08d8784af48f352193d2b72aaf167a57a1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/85a055c03691e51499123194a14a0c249cf33227 | kernel.org | Patch |
| https://git.kernel.org/stable/c/be3884d5cd04ccd58294b83a02d70b7c5fca19d3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c58d82a1264813e69119c13e9804e2e60b664ad5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e04d59cfe0c0129df7aba7ef7bb17b96be2a64f2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e53cd3814504b2cadaba4d5a8a07eeea9ddacd03 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ef6d2354de238b065d8799c80da4be9a6af18e39 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.15, < 4.9.318 >= 4.10, < 4.14.283 >= 4.15, < 4.19.247 >= 4.20, < 5.4.198 >= 5.5, < 5.10.122 >= 5.11, < 5.15.47 >= 5.16, < 5.17.15 >= 5.18, < 5.18.4 5.19 rc1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Sep 22, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |