CVE-2026-89749
Received Received - Intake

Kernel Crash in Linux Kernel Due to Improper kthread_stop() Handling

Vulnerability report for CVE-2026-89749, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop() event_test_stuff() calls kthread_run() and unconditionally passes the returned task_struct pointer to kthread_stop(). kthread_run() returns an error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for example under memory pressure during the boot-time event self-test. kthread_stop() then dereferences the invalid pointer, crashing the kernel. Check the result of kthread_run() before passing it to kthread_stop(). Use WARN_ON() so that a failure to create the self-test thread does not go unnoticed, matching the ring-buffer self-test fix in commit 91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where event_test_stuff() calls kthread_run() and passes its result directly to kthread_stop() without checking for errors. If kthread_run() fails (e.g., due to memory pressure), it returns an error pointer like ERR_PTR(-ENOMEM). kthread_stop() then tries to dereference this invalid pointer, causing a kernel crash.

Detection Guidance

This vulnerability is specific to the Linux kernel and can be detected by checking kernel logs for crashes during boot-time event self-tests. Look for kernel oops or panic messages related to kthread_stop() or event_test_stuff().

Commands to check: dmesg | grep -i 'kthread_stop\|event_test_stuff\|kernel panic\|oops' or journalctl -k | grep -i 'kthread_stop\|event_test_stuff\|kernel panic\|oops'.

Impact Analysis

This vulnerability can cause a kernel crash if the system is under memory pressure during boot, especially when running the event self-test. A crash could lead to system instability, data loss, or denial of service.

Compliance Impact

This vulnerability is a kernel crash caused by improper error handling in the Linux tracing subsystem. It does not directly relate to data protection, privacy, or security controls required by GDPR or HIPAA. Compliance impact would depend on system stability and availability rather than data handling or access control.

Mitigation Strategies

Apply the latest Linux kernel update that includes the fix for this vulnerability. The patch ensures kthread_run() results are checked before passing to kthread_stop().

If immediate patching is not possible, consider disabling the event self-test feature if it is not critical for your system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89749. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart