CVE-2026-89749

Summary

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix crash passing ERR_PTR to kthread_stop()

event_test_stuff() calls kthread_run() and unconditionally passes the returned task_struct pointer to kthread_stop(). kthread_run() returns an error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for example under memory pressure during the boot-time event self-test. kthread_stop() then dereferences the invalid pointer, crashing the kernel.

Check the result of kthread_run() before passing it to kthread_stop(). Use WARN_ON() so that a failure to create the self-test thread does not go unnoticed, matching the ring-buffer self-test fix in commit 91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe6187007d6c365b551c69ea3df46f06fd1c8bd19 < 12a499f741fc5be3731c8b0a0d909406575cc2ebaffected
LinuxLinuxe6187007d6c365b551c69ea3df46f06fd1c8bd19 < adadf4192f700bca82abfda9fa6d58c0bf37cc04affected
LinuxLinuxe6187007d6c365b551c69ea3df46f06fd1c8bd19 < c40e0b4fa365969e67011529eabdfb66d1022256affected
LinuxLinuxe6187007d6c365b551c69ea3df46f06fd1c8bd19 < 649bc7df3e5d7be6f7996a95084037dbf3cad1e5affected
LinuxLinux2.6.31affected
LinuxLinux0 < 2.6.31unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References