Answer in brief
CVE-2026-74284 records a Unknown severity vulnerability in net/sched: sch_hfsc: Don't make class passive twice. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.