# CVE-2026-89749

## Summary

- **CVE ID:** CVE-2026-89749
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix crash passing ERR_PTR to kthread_stop()

event_test_stuff() calls kthread_run() and unconditionally passes the
returned task_struct pointer to kthread_stop(). kthread_run() returns an
error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for
example under memory pressure during the boot-time event self-test.
kthread_stop() then dereferences the invalid pointer, crashing the kernel.

Check the result of kthread_run() before passing it to kthread_stop(). Use
WARN_ON() so that a failure to create the self-test thread does not go
unnoticed, matching the ring-buffer self-test fix in commit
91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").

## Affected Products

- Linux — Linux (e6187007d6c365b551c69ea3df46f06fd1c8bd19)
- Linux — Linux (2.6.31)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/12a499f741fc5be3731c8b0a0d909406575cc2eb)
- [CNA](https://git.kernel.org/stable/c/adadf4192f700bca82abfda9fa6d58c0bf37cc04)
- [CNA](https://git.kernel.org/stable/c/c40e0b4fa365969e67011529eabdfb66d1022256)
- [CNA](https://git.kernel.org/stable/c/649bc7df3e5d7be6f7996a95084037dbf3cad1e5)
- [CNA](https://git.kernel.org/stable/c/c1a4fb7aa290f158d50654d640292e49d9055fd1)
- [CNA](https://git.kernel.org/stable/c/42ccb215ef0a552acbbd32f81009bfe4b278ba77)
- [CNA](https://git.kernel.org/stable/c/98d06fb9865a490e12ebe32d65b9ffac6108614d)
- [CNA](https://git.kernel.org/stable/c/ceb1707aef5824cf024eb82d10787b7621e2ff35)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._