CVE-2026-74471

Source
https://cve.org/CVERecord?id=CVE-2026-74471
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74471.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74471
Downstream
Published
2026-08-15T12:27:08Z
Modified
2026-08-21T03:30:14Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
tracing: Check return value of __register_event() in trace_module_add_events()
Details

In the Linux kernel, the following vulnerability has been resolved:

tracing: Check return value of __register_event() in trace_module_add_events()

trace_module_add_events() ignores the return value of __register_event() and unconditionally calls __add_event_to_tracers() for each event.

If __register_event() fails (for example, if event_init() fails), the trace_event_call is not added to ftrace_events list, but __add_event_to_tracers() still creates a trace_event_file pointing to it. If module loading subsequently fails and module memory is freed, tracing state retains a stale trace_event_call pointer in trace_event_file, leading to a use-after-free when tracefs or tracing subsystem operations are later executed.

Fix this by checking the return value of __register_event() and only calling __add_event_to_tracers() if event registration succeeded.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74471.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ae63b31e4d0e2ec09c569306ea46f664508ef717
Fixed
3bf965a2827c44f03294107703e7ba53fbd0a69a
Fixed
9d6d79744f01eacaf3d5522f4fcd59939581abfd
Fixed
54b7a358f6399c1242d2fb7f4f96085af34baa5e
Fixed
d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5
Fixed
22f954f7a8afe975e85517aff41b35defe05144b
Fixed
cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca
Fixed
000765dcdc3edf128990762790543adc4b868f6c
Fixed
ac8719969e6c3c54e939834df812bc41f25453cf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74471.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74471.json"