Linux kernel vulnerability affecting a core OS component; kernel UAF can crash systems or enable local root; impacts virtually all Linux deployments and requires org-wide attention.
CVE-2026-74493
Local Linux kernel use-after-free in smc module enabling crash or local privilege escalation
Is CVE-2026-74493 being exploited?
Not confirmed. CVE-2026-74493 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.50% probability of exploitation in the next 30 days.
How severe is CVE-2026-74493?
CVE-2026-74493 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74493?
Yes. A fix has been recorded for CVE-2026-74493. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74493 affect?
CVE-2026-74493 affects Linux kernel (smc module), SMC sockets (smc). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74493?
Install vendor kernel updates with the smc fix and reboot; restrict untrusted local access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker can trigger kernel use-after-free causing system crashes or escalate to local root/kernel code execution.
Patch when possible
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < ff44f2df57fb5560bdc75eb977867643e764a262
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < 9fb17c95b8f0683570fca1fb2792264147af937a
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < bea8dc14de2d56aca749d368563e6888217710a5
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < 5a42f162b857019a4c10ff687dc3bcdf51831865
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < 281c103a8eaed59001ce952f231df1b07674215a
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < f807a63d0d95680c34f677700da9148a07d7c78f
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < f0541a775d04c88e90ba448e35ce0d743512822a
- affected>= 69318b5215f2dc32c345a3d65b98b4b1bf29c007 and < f621d6ebeebb6374342571e4ddf45fdbc420f6cd
- affected5.5
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.