CVE-2026-89749 is a vulnerability in Linux Kernel
Published on September 11, 2026
tracing: Fix crash passing ERR_PTR to kthread_stop()
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix crash passing ERR_PTR to kthread_stop()
event_test_stuff() calls kthread_run() and unconditionally passes the
returned task_struct pointer to kthread_stop(). kthread_run() returns an
error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for
example under memory pressure during the boot-time event self-test.
kthread_stop() then dereferences the invalid pointer, crashing the kernel.
Check the result of kthread_run() before passing it to kthread_stop(). Use
WARN_ON() so that a failure to create the self-test thread does not go
unnoticed, matching the ring-buffer self-test fix in commit
91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").
Products Associated with CVE-2026-89749
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version e6187007d6c365b551c69ea3df46f06fd1c8bd19 and below 12a499f741fc5be3731c8b0a0d909406575cc2eb is affected.
- Version e6187007d6c365b551c69ea3df46f06fd1c8bd19 and below adadf4192f700bca82abfda9fa6d58c0bf37cc04 is affected.
- Version e6187007d6c365b551c69ea3df46f06fd1c8bd19 and below c40e0b4fa365969e67011529eabdfb66d1022256 is affected.
- Version e6187007d6c365b551c69ea3df46f06fd1c8bd19 and below 649bc7df3e5d7be6f7996a95084037dbf3cad1e5 is affected.
- Version 2.6.31 is affected.
- Before 2.6.31 is unaffected.
- Version 6.12.109, <= 6.12.* is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.