tracing: Fix crash passing ERR_PTR to kthread_stop()
Summary
| CVE | CVE-2026-89749 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:20:05 UTC |
| Updated | 2026-09-11 20:20:05 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix crash passing ERR_PTR to kthread_stop()
event_test_stuff() calls kthread_run() and unconditionally passes the
returned task_struct pointer to kthread_stop(). kthread_run() returns an
error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for
example under memory pressure during the boot-time event self-test.
kthread_stop() then dereferences the invalid pointer, crashing the kernel.
Check the result of kthread_run() before passing it to kthread_stop(). Use
WARN_ON() so that a failure to create the self-test thread does not go
unnoticed, matching the ring-buffer self-test fix in commit
91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()"). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected e6187007d6c365b551c69ea3df46f06fd1c8bd19 12a499f741fc5be3731c8b0a0d909406575cc2eb git |
Not specified |
| CNA |
Linux |
Linux |
affected e6187007d6c365b551c69ea3df46f06fd1c8bd19 adadf4192f700bca82abfda9fa6d58c0bf37cc04 git |
Not specified |
| CNA |
Linux |
Linux |
affected e6187007d6c365b551c69ea3df46f06fd1c8bd19 c40e0b4fa365969e67011529eabdfb66d1022256 git |
Not specified |
| CNA |
Linux |
Linux |
affected e6187007d6c365b551c69ea3df46f06fd1c8bd19 649bc7df3e5d7be6f7996a95084037dbf3cad1e5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.31 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.31 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/c40e0b4fa365969e67011529eabdfb66d1022256 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/12a499f741fc5be3731c8b0a0d909406575cc2eb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/adadf4192f700bca82abfda9fa6d58c0bf37cc04 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/649bc7df3e5d7be6f7996a95084037dbf3cad1e5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.