Answer in brief
CVE-2026-74471 records a Unknown severity vulnerability in tracing: Check return value of __register_event() in trace_module_add_events(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5 || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <22f954f7a8afe975e85517aff41b35defe05144b || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <000765dcdc3edf128990762790543adc4b868f6c || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <ac8719969e6c3c54e939834df812bc41f25453cf | d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5, 22f954f7a8afe975e85517aff41b35defe05144b, cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca, 000765dcdc3edf128990762790543adc4b868f6c, ac8719969e6c3c54e939834df812bc41f25453cf |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: tracing: Check return value of __register_event() in trace_module_add_events() trace_module_add_events() ignores the return value of __register_event() and unconditionally calls __add_event_to_tracers() for each event. If __register_event() fails (for example, if event_init() fails), the trace_event_call is not added to ftrace_events list, but __add_event_to_tracers() still creates a trace_event_file pointing to it. If module loading subsequently fails and module memory is freed, tracing state retains a stale trace_event_call pointer in trace_event_file, leading to a use-after-free when tracefs or tracing subsystem operations are later executed. Fix this by checking the return value of __register_event() and only calling __add_event_to_tracers() if event registration succeeded.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74471 records a Unknown severity vulnerability in tracing: Check return value of __register_event() in trace_module_add_events(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5 || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <22f954f7a8afe975e85517aff41b35defe05144b || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <000765dcdc3edf128990762790543adc4b868f6c || >=ae63b31e4d0e2ec09c569306ea46f664508ef717 <ac8719969e6c3c54e939834df812bc41f25453cf | d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5, 22f954f7a8afe975e85517aff41b35defe05144b, cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca, 000765dcdc3edf128990762790543adc4b868f6c, ac8719969e6c3c54e939834df812bc41f25453cf |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: tracing: Check return value of __register_event() in trace_module_add_events() trace_module_add_events() ignores the return value of __register_event() and unconditionally calls __add_event_to_tracers() for each event. If __register_event() fails (for example, if event_init() fails), the trace_event_call is not added to ftrace_events list, but __add_event_to_tracers() still creates a trace_event_file pointing to it. If module loading subsequently fails and module memory is freed, tracing state retains a stale trace_event_call pointer in trace_event_file, leading to a use-after-free when tracefs or tracing subsystem operations are later executed. Fix this by checking the return value of __register_event() and only calling __add_event_to_tracers() if event registration succeeded.
Quoted source text, attributed separately from HOL analysis.