CVE-2022-49350 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: mdio: unexport __init-annotated mdio_bus_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text section is freed up after the initialization. Hence, modules cannot use symbols annotated __init. The access to a freed symbol may end up with kernel panic. modpost used to detect it, but it has been broken for a decade. Recently, I fixed modpost so it started to warn it again, then this showed up in linux-next builds. There are two ways to fix it: - Remove __init - Remove EXPORT_SYMBOL I chose the latter for this case because the only in-tree call-site, drivers/net/phy/phy_device.c is never compiled as modular. (CONFIG_PHYLIB is boolean)
A vulnerability in the Linux kernel's MDIO (Management Data Input/Output) subsystem has been addressed. The issue arose because the function 'mdio_bus_init' was incorrectly marked for export and initialization. This combination is problematic, as the initialization section of the code is cleared after use, leaving modules unable to access these symbols. Attempting to use a symbol from a freed section can cause a kernel panic. The problem was detected in 'linux-next' builds after the 'modpost' tool was fixed to issue warnings about this type of error, which had gone unaddressed for a decade.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/35b42dce619701f1300fb8498dae82c9bb1f0263 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5534bcd7c40299862237c4a8fd9c5031b3db1538 | kernel.org | Patch |
| https://git.kernel.org/stable/c/59fa94cddf9eef8d8dae587373eed8b8f4eb11d7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6a90a44d53428a3bf01bd80df9ba78b19959270c | kernel.org | Patch |
| https://git.kernel.org/stable/c/7759c3222815b945a94b212bc0c6cdec475cfec2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ab64ec2c75683f30ccde9eaaf0761002f901aa12 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f2f0f8c18b60ca64ff50892ed899cf1c77864755 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f5c68137f1191ba3fcf6260ec71b30be2e2bf4c3 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.12, < 4.14.283 >= 4.15, < 4.19.247 >= 4.20, < 5.4.198 >= 5.5, < 5.10.122 >= 5.11, < 5.15.47 >= 5.16, < 5.17.15 >= 5.18, < 5.18.4 5.19 rc1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Sep 22, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |