Race condition in Linux kernel - CVE-2026-74636
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in trace event field handling in the Linux kernel tracing subsystem when loading modules and updating trace event fields concurrently. A local user can load modules concurrently to trigger a kernel panic and cause a denial of service.
Exploitation requires the ability to initiate module loading.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74636
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/4e39f7b4d9d36508c53e89e6cbc640728df870b5
- https://git.kernel.org/stable/c/a30d421468300b1e7b2f233136aeb2db8013f555
- https://git.kernel.org/stable/c/c3730b8373bb5059d735509b9e6a00d7eb337d7c
- https://git.kernel.org/stable/c/e5f1d301b4bdaa4206db251fdc691f623162b0a8
- https://git.kernel.org/stable/c/ed49684e69f846bf50b5050651ccdb87cfd152c0
- https://git.kernel.org/stable/c/f128740f39ab28d1f4ad5bdd10f3e117eec0c374
- https://git.kernel.org/stable/c/fdeb190b0905a6aaed1e5d6adfb8613214748d7d