CVE-2026-89937

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: sgp30: Handle IAQ thread creation failure

kthread_run() can fail and return an error pointer, but sgp_probe() stores it and returns success, so the device is registered without its IAQ thread and sgp_remove() later passes the error pointer to kthread_stop(). Return the error from probe instead.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < bffd0655a35402b2df8857699f8248e5a534d214affected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < bae0316c087b1ef625844003fe37e803a13819f3affected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < 3c6b52b258e65a584e3f5122ed7f406bc89a946eaffected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < 3462c13bb0f50dec09235adb7fd04b6f617cf0ccaffected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < a5aaea17a1834d7254ff597e4d5e1bc60dfc4800affected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < 2d386efb4c37a50739db19c7c8e49564fd53a570affected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < 44d52c8b1c6da7ac1b0dffeeff6de68370746775affected
LinuxLinuxce514124161ac2ceb13d10b6c40cbf05c8f0cc91 < 1135d6875d2dbda3f6ec718f3421a6ce4378bd63affected
LinuxLinux5.1affected
LinuxLinux0 < 5.1unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References