{
  "threat_severity" : "Moderate",
  "public_date" : "2026-08-26T00:00:00Z",
  "bugzilla" : {
    "description" : "kernel: rseq: Prevent hard lockup on granted time slice extension",
    "id" : "2524421",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2524421"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-366",
  "details" : [ "In the Linux kernel, the following vulnerability has been resolved:\nrseq: Prevent hard lockup on granted time slice extension\n__exit_to_user_mode_loop() invokes rseq_grant_timeslice_extension() with\ninterrupts enabled. If the extension is granted it invokes\nhrtimer_rearm_deferred_tif() to ensure that a pending deferred hrtimer\nrearm is handled before exiting to user space.\nThough this invokes __hrtimer_rearm_deferred() which expects to be invoked\nwith interrupts disabled as it takes hrtimer_cpu_base::lock with\nraw_spin_lock(). That's a livelock waiting to happen and caught by lockdep:\nWARNING: ./include/linux/hrtimer_rearm.h:17 at irqentry_exit, CPU#1: slice_test\nWARNING: inconsistent lock state\ninconsistent {IN-HARDIRQ-W} -> {HARDIRQ-ON-W} usage.\nPrevent this by disabling interrupts around the invocation of\nhrtimer_rearm_deferred_tif() in rseq_grant_timeslice_extension().\n[ tglx: Massaged change log ]", "A flaw was found in the Linux kernel's restartable sequences (rseq) mechanism. An inconsistency in the handling of lock states during time slice extensions can occur when interrupts are enabled. This can lead to a system livelock or hard lockup, effectively causing a Denial of Service (DoS) for the affected system." ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-74749\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-74749\nhttps://lore.kernel.org/linux-cve-announce/2026082659-CVE-2026-74749-2cf1@gregkh/T" ],
  "name" : "CVE-2026-74749",
  "csaw" : false
}