U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-74636

Change History

New CVE Received from kernel.org 8/22/2026 12:16:36 PM

Action Type Old Value New Value
Added Description

                  
                
              
In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix race between update_event_fields and, event_define_fields

The following sequence may leads race between event_define_fields()
and update_event_fields():

 CPU0 (loads module A)                      CPU1 (loads module B)
 ===============================            ===============================
 load_module(A)                             load_module(B)
   notifier_call_chain                        notifier_call_chain
     trace_module_notify                        trace_module_notify
       mutex_lock(&event_mutex)                   trace_event_update_all()
         trace_module_add_events(A)                 down_write(&trace_event_sem)
            __register_event(call_A)
              __add_event_to_tracers(call_A)
                event_define_fields(call_A)
                  for each f:                         list_for_each_entry(field,
                    list_add(&f->link,                                    &class->fields, link)
                             &class->fields)            field = class->fields->next;

Where access to the class->fields is not protected by the event_mutex in
trace_event_update_all().

This produces the following panic:
   Unable to handle kernel access ... at virtual address 0000000000000018
   pc : update_event_fields+0xf8/0x368
   Call trace:
    update_event_fields+0xf8/0x368
    trace_event_update_all+0x7c/0x2b4
    trace_module_notify+0x4c/0x1dc
    notifier_call_chain+0x84/0x168
    blocking_notifier_call_chain_robust+0x64/0xd4
    load_module+0x10c8/0x123c
    __arm64_sys_finit_module+0x230/0x31c

Fix by taking event_mutex in trace_event_update_all() before
trace_event_sem.
Added Reference

                  
                
              
https://git.kernel.org/stable/c/4e39f7b4d9d36508c53e89e6cbc640728df870b5
Added Reference

                  
                
              
https://git.kernel.org/stable/c/a30d421468300b1e7b2f233136aeb2db8013f555
Added Reference

                  
                
              
https://git.kernel.org/stable/c/c3730b8373bb5059d735509b9e6a00d7eb337d7c
Added Reference

                  
                
              
https://git.kernel.org/stable/c/e5f1d301b4bdaa4206db251fdc691f623162b0a8
Added Reference

                  
                
              
https://git.kernel.org/stable/c/ed49684e69f846bf50b5050651ccdb87cfd152c0
Added Reference

                  
                
              
https://git.kernel.org/stable/c/f128740f39ab28d1f4ad5bdd10f3e117eec0c374
Added Reference

                  
                
              
https://git.kernel.org/stable/c/fdeb190b0905a6aaed1e5d6adfb8613214748d7d
Added Affected

                  
                
              
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c6bd60999f32138e3b73fd97ea11ef47a94de25","lessThan":"4e39f7b4d9d36508c53e89e6cbc640728df870b5","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"a30d421468300b1e7b2f233136aeb2db8013f555","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"e5f1d301b4bdaa4206db251fdc691f623162b0a8","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"fdeb190b0905a6aaed1e5d6adfb8613214748d7d","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"ed49684e69f846bf50b5050651ccdb87cfd152c0","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"f128740f39ab28d1f4ad5bdd10f3e117eec0c374","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"c3730b8373bb5059d735509b9e6a00d7eb337d7c","versionType":"git","status":"affected"},{"version":"55defdf935fab9f2989a197aae1042c082d9a343","versionType":"git","status":"affected"},{"version":"0c53a5c80e6e286733381a1d9f255ba4039e2e45","versionType":"git","status":"affected"},{"version":"5.15.33","lessThan":"5.15.216","versionType":"semver","status":"affected"},{"version":"5.16.19","lessThan":"5.17","versionType":"semver","status":"affected"},{"version":"5.17.2","lessThan":"5.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]