Impact
A flaw in the Hyper‑V VMBus kernel module allows the module to be loaded in the root partition while its initialization routine performs no work, yet it reports success. Subsequent unloading of the module triggers its exit routine, which attempts to clean up resources that were never allocated, causing memory faults and resulting in a kernel panic. This denial of service impacts the host operating system by bringing the kernel down.
Affected Systems
The issue targets the Linux kernel VMBus driver used on Hyper‑V virtual machines. It manifests in the root partition of a virtualized host when the system is not running as a nested VM. Any Linux kernel containing the unpatched hv_acpi_init and exit functions is vulnerable, regardless of specific version details.
Risk and Exploitability
The EPSS score is reported as less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the problem can be triggered by any entity that can unload the VMBus module on the host, typically requiring privileged access. If an attacker can force the module to unload, they can cause a kernel panic, potentially disrupting services unless mitigated by system resilience or monitoring.
OpenCVE Enrichment