SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74471

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the tracing subsystem, where the function trace_module_add_events() fails to properly handle the return value of __register_event(). This oversight can lead to a use-after-free condition, potentially allowing an attacker to exploit stale pointers in trace_event_file, which may compromise system stability or security. Organizations utilizing Linux kernel versions that include this flaw should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-74471
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: tracing: Check return value of __register_event() in trace_module_add_events() trace_module_add_events() ignores the return value of __register_event() and unconditionally calls __add_event_to_tracers() for each event. If __register_event() fails (for example, if event_init() fails), the trace_event_call is not added to ftrace_events list, but __add_event_to_tracers() still creates a trace_event_file pointing to it. If module loading subsequently fails and module memory is freed, tracing state retains a stale trace_event_call pointer in trace_event_file, leading to a use-after-free when tracefs or tracing subsystem operations are later executed. Fix this by checking the return value of __register_event() and only calling __add_event_to_tracers() if event registration succeeded.