tracing: Fix race between update_event_fields and, event_define_fields

Summary

CVECVE-2026-74636
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-22 16:16:36 UTC
Updated2026-08-22 16:16:36 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: tracing: Fix race between update_event_fields and, event_define_fields The following sequence may leads race between event_define_fields() and update_event_fields(): CPU0 (loads module A) CPU1 (loads module B) =============================== =============================== load_module(A) load_module(B) notifier_call_chain notifier_call_chain trace_module_notify trace_module_notify mutex_lock(&event_mutex) trace_event_update_all() trace_module_add_events(A) down_write(&trace_event_sem) __register_event(call_A) __add_event_to_tracers(call_A) event_define_fields(call_A) for each f: list_for_each_entry(field, list_add(&f->link, &class->fields, link) &class->fields) field = class->fields->next; Where access to the class->fields is not protected by the event_mutex in trace_event_update_all(). This produces the following panic: Unable to handle kernel access ... at virtual address 0000000000000018 pc : update_event_fields+0xf8/0x368 Call trace: update_event_fields+0xf8/0x368 trace_event_update_all+0x7c/0x2b4 trace_module_notify+0x4c/0x1dc notifier_call_chain+0x84/0x168 blocking_notifier_call_chain_robust+0x64/0xd4 load_module+0x10c8/0x123c __arm64_sys_finit_module+0x230/0x31c Fix by taking event_mutex in trace_event_update_all() before trace_event_sem.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 7c6bd60999f32138e3b73fd97ea11ef47a94de25 4e39f7b4d9d36508c53e89e6cbc640728df870b5 git Not specified
CNA Linux Linux affected b3bc8547d3be60898818885f5bf22d0a62e2eb48 a30d421468300b1e7b2f233136aeb2db8013f555 git Not specified
CNA Linux Linux affected b3bc8547d3be60898818885f5bf22d0a62e2eb48 e5f1d301b4bdaa4206db251fdc691f623162b0a8 git Not specified
CNA Linux Linux affected b3bc8547d3be60898818885f5bf22d0a62e2eb48 fdeb190b0905a6aaed1e5d6adfb8613214748d7d git Not specified
CNA Linux Linux affected b3bc8547d3be60898818885f5bf22d0a62e2eb48 ed49684e69f846bf50b5050651ccdb87cfd152c0 git Not specified
CNA Linux Linux affected b3bc8547d3be60898818885f5bf22d0a62e2eb48 f128740f39ab28d1f4ad5bdd10f3e117eec0c374 git Not specified
CNA Linux Linux affected b3bc8547d3be60898818885f5bf22d0a62e2eb48 c3730b8373bb5059d735509b9e6a00d7eb337d7c git Not specified
CNA Linux Linux affected 55defdf935fab9f2989a197aae1042c082d9a343 git Not specified
CNA Linux Linux affected 0c53a5c80e6e286733381a1d9f255ba4039e2e45 git Not specified
CNA Linux Linux affected 5.15.33 5.15.216 semver Not specified
CNA Linux Linux affected 5.16.19 5.17 semver Not specified
CNA Linux Linux affected 5.17.2 5.18 semver Not specified
CNA Linux Linux affected 5.18 Not specified
CNA Linux Linux unaffected 5.18 semver Not specified
CNA Linux Linux unaffected 5.15.216 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.183 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.152 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.104 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.45 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.9 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/4e39f7b4d9d36508c53e89e6cbc640728df870b5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ed49684e69f846bf50b5050651ccdb87cfd152c0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e5f1d301b4bdaa4206db251fdc691f623162b0a8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c3730b8373bb5059d735509b9e6a00d7eb337d7c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a30d421468300b1e7b2f233136aeb2db8013f555 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f128740f39ab28d1f4ad5bdd10f3e117eec0c374 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fdeb190b0905a6aaed1e5d6adfb8613214748d7d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report