{"id":"CVE-2026-74471","summary":"tracing: Check return value of __register_event() in trace_module_add_events()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Check return value of __register_event() in trace_module_add_events()\n\ntrace_module_add_events() ignores the return value of __register_event()\nand unconditionally calls __add_event_to_tracers() for each event.\n\nIf __register_event() fails (for example, if event_init() fails), the\ntrace_event_call is not added to ftrace_events list, but\n__add_event_to_tracers() still creates a trace_event_file pointing to it.\nIf module loading subsequently fails and module memory is freed, tracing\nstate retains a stale trace_event_call pointer in trace_event_file,\nleading to a use-after-free when tracefs or tracing subsystem operations\nare later executed.\n\nFix this by checking the return value of __register_event() and only\ncalling __add_event_to_tracers() if event registration succeeded.","modified":"2026-08-21T03:30:14.227897888Z","published":"2026-08-15T12:27:08.128Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74471.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/000765dcdc3edf128990762790543adc4b868f6c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/22f954f7a8afe975e85517aff41b35defe05144b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3bf965a2827c44f03294107703e7ba53fbd0a69a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/54b7a358f6399c1242d2fb7f4f96085af34baa5e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9d6d79744f01eacaf3d5522f4fcd59939581abfd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ac8719969e6c3c54e939834df812bc41f25453cf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74471.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74471"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ae63b31e4d0e2ec09c569306ea46f664508ef717"},{"fixed":"3bf965a2827c44f03294107703e7ba53fbd0a69a"},{"fixed":"9d6d79744f01eacaf3d5522f4fcd59939581abfd"},{"fixed":"54b7a358f6399c1242d2fb7f4f96085af34baa5e"},{"fixed":"d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5"},{"fixed":"22f954f7a8afe975e85517aff41b35defe05144b"},{"fixed":"cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca"},{"fixed":"000765dcdc3edf128990762790543adc4b868f6c"},{"fixed":"ac8719969e6c3c54e939834df812bc41f25453cf"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74471.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.10.0"},{"fixed":"5.10.265"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.216"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.183"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.151"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.103"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.44"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74471.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}