CVE-2026-74636

Kernel panic via unprotected tracing field list

Published Aug 22, 2026 · Updated Aug 22, 2026

Race condition in Linux kernel tracing allows privileged local users to crash the kernel by loading modules concurrently. trace_event_update_all iterates class->fields without event_mutex while event_define_fields adds entries to the same list. Triggering the race requires CAP_SYS_MODULE and concurrent module loads; the resulting panic interrupts all service on the host.

CVSS severityUnavailable
Unscored
EPSS probability0.17%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Race condition in Linux kernel tracing allows privileged local users to crash the kernel by loading modules concurrently. trace_event_update_all iterates class->fields without event_mutex while event_define_fields adds entries to the same list. Triggering the race requires CAP_SYS_MODULE and concurrent module loads; the resulting panic interrupts all service on the host.

The record

CVE
CVE-2026-74636
Published
Aug 22, 2026
Updated
Aug 22, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-362, T1499
Attack vector
local
Privileges
admin

Timeline

How it unfolded

  1. Aug 22, 2026CVE publishedPublication date reported by the CVE source.
  2. Aug 22, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0c53a5c80e6e286733381a1d9f255ba4039e2e45
  2. Affected versionversion=5.15.33 <5.15.216
  3. Affected versionversion=5.16.19 <5.17
  4. Affected versionversion=5.17.2 <5.18
  5. Affected versionversion=5.18
  6. Affected versionversion=55defdf935fab9f2989a197aae1042c082d9a343
  7. Affected versionversion=7c6bd60999f32138e3b73fd97ea11ef47a94de25 <4e39f7b4d9d36508c53e89e6cbc640728df870b5
  8. Affected versionversion=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <a30d421468300b1e7b2f233136aeb2db8013f555
  9. Affected versionversion=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <c3730b8373bb5059d735509b9e6a00d7eb337d7c
  10. Affected versionversion=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <e5f1d301b4bdaa4206db251fdc691f623162b0a8
  11. Affected versionversion=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <ed49684e69f846bf50b5050651ccdb87cfd152c0
  12. Affected versionversion=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <f128740f39ab28d1f4ad5bdd10f3e117eec0c374
  13. Affected versionversion=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <fdeb190b0905a6aaed1e5d6adfb8613214748d7d

What conditions does exploitation require?

Attack vectorlocal
Required privilegesadmin

What is affected?

The Linux Kernel Organization · Linuxversion=0c53a5c80e6e286733381a1d9f255ba4039e2e45; version=5.15.33 <5.15.216; version=5.16.19 <5.17; version=5.17.2 <5.18; version=5.18; version=55defdf935fab9f2989a197aae1042c082d9a343; version=7c6bd60999f32138e3b73fd97ea11ef47a94de25 <4e39f7b4d9d36508c53e89e6cbc640728df870b5; version=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <a30d421468300b1e7b2f233136aeb2db8013f555; version=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <c3730b8373bb5059d735509b9e6a00d7eb337d7c; version=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <e5f1d301b4bdaa4206db251fdc691f623162b0a8; version=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <ed49684e69f846bf50b5050651ccdb87cfd152c0; version=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <f128740f39ab28d1f4ad5bdd10f3e117eec0c374; version=b3bc8547d3be60898818885f5bf22d0a62e2eb48 <fdeb190b0905a6aaed1e5d6adfb8613214748d7d

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesadmin
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
T1499Endpoint Denial of Service

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo