---
cve: "CVE-2026-89749"
severity: "LOW"
cvss: 3.1
epss: "21%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-11 19:46:53"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-19T10:28:21+02:00"
---

# CVE-2026-89749

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix crash passing ERR_PTR to kthread_stop()

event_test_stuff() calls kthread_run() and unconditionally passes the
returned task_struct pointer to kthread_stop(). kthread_run() returns an
error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for
example under memory pressure during the boot-time event self-test.
kthread_stop() then dereferences the invalid pointer, crashing the kernel.

Check the result of kthread_run() before passing it to kthread_stop(). Use
WARN_ON() so that a failure to create the self-test thread does not go
unnoticed, matching the ring-buffer self-test fix in commit
91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.270
- Kernel ≥ 5.15.221
- Kernel ≥ 6.1.188
- Kernel ≥ 6.6.157
- Kernel ≥ 6.12.109
- Kernel ≥ 6.18.50
- Kernel ≥ 7.2.4

## Referenzen

- <https://git.kernel.org/stable/c/c1a4fb7aa290f158d50654d640292e49d9055fd1>
- <https://git.kernel.org/stable/c/42ccb215ef0a552acbbd32f81009bfe4b278ba77>
- <https://git.kernel.org/stable/c/98d06fb9865a490e12ebe32d65b9ffac6108614d>
- <https://git.kernel.org/stable/c/ceb1707aef5824cf024eb82d10787b7621e2ff35>
- <https://git.kernel.org/stable/c/12a499f741fc5be3731c8b0a0d909406575cc2eb>
- <https://git.kernel.org/stable/c/adadf4192f700bca82abfda9fa6d58c0bf37cc04>
- <https://git.kernel.org/stable/c/c40e0b4fa365969e67011529eabdfb66d1022256>
- <https://git.kernel.org/stable/c/649bc7df3e5d7be6f7996a95084037dbf3cad1e5>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89749) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
