CVE-2026-89749: vulnerability in Linux
tracing: Fix crash passing ERR_PTR to kthread_stop()
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix crash passing ERR_PTR to kthread_stop()
event_test_stuff() calls kthread_run() and unconditionally passes the
returned task_struct pointer to kthread_stop(). kthread_run() returns an
error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for
example under memory pressure during the boot-time event self-test.
kthread_stop() then dereferences the invalid pointer, crashing the kernel.
Check the result of kthread_run() before passing it to kthread_stop(). Use
WARN_ON() so that a failure to create the self-test thread does not go
unnoticed, matching the ring-buffer self-test fix in commit
91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/12a499f741fc5be3731c8b0a0d909406575cc2ebhttps://git.kernel.org/stable/c/42ccb215ef0a552acbbd32f81009bfe4b278ba77https://git.kernel.org/stable/c/649bc7df3e5d7be6f7996a95084037dbf3cad1e5https://git.kernel.org/stable/c/98d06fb9865a490e12ebe32d65b9ffac6108614dhttps://git.kernel.org/stable/c/adadf4192f700bca82abfda9fa6d58c0bf37cc04https://git.kernel.org/stable/c/c1a4fb7aa290f158d50654d640292e49d9055fd1https://git.kernel.org/stable/c/c40e0b4fa365969e67011529eabdfb66d1022256https://git.kernel.org/stable/c/ceb1707aef5824cf024eb82d10787b7621e2ff35