Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74471

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> tracing: Check return value of __register_event() in trace_module_add_events()<br /> <br /> trace_module_add_events() ignores the return value of __register_event()<br /> and unconditionally calls __add_event_to_tracers() for each event.<br /> <br /> If __register_event() fails (for example, if event_init() fails), the<br /> trace_event_call is not added to ftrace_events list, but<br /> __add_event_to_tracers() still creates a trace_event_file pointing to it.<br /> If module loading subsequently fails and module memory is freed, tracing<br /> state retains a stale trace_event_call pointer in trace_event_file,<br /> leading to a use-after-free when tracefs or tracing subsystem operations<br /> are later executed.<br /> <br /> Fix this by checking the return value of __register_event() and only<br /> calling __add_event_to_tracers() if event registration succeeded.

Impacto