Linux Kernel VMBus Driver Panic Notifier Unloading Vulnerability

Vulnerability

A vulnerability in the Linux kernel's VMBus driver module can lead to a potential crash when the module is unloaded. This issue arises because the VMBus driver, which can be built as a module, improperly manages the registration and unregistration of panic notifier callbacks. The vulnerability is present in the VMBus driver of the Linux kernel.

Impact

Improper handling of panic notifier callbacks in the VMBus driver can lead to a module unload crash.

Remediation

The vulnerability has been addressed by modifying the VMBus driver to unconditionally unregister the panic notifier in the module's exit routine.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.