Answer in brief
CVE-2026-89749 records a Unknown severity vulnerability in tracing: Fix crash passing ERR_PTR to kthread_stop(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e6187007d6c365b551c69ea3df46f06fd1c8bd19 <12a499f741fc5be3731c8b0a0d909406575cc2eb || >=e6187007d6c365b551c69ea3df46f06fd1c8bd19 <adadf4192f700bca82abfda9fa6d58c0bf37cc04 || >=e6187007d6c365b551c69ea3df46f06fd1c8bd19 <c40e0b4fa365969e67011529eabdfb66d1022256 || >=e6187007d6c365b551c69ea3df46f06fd1c8bd19 <649bc7df3e5d7be6f7996a95084037dbf3cad1e5 | 12a499f741fc5be3731c8b0a0d909406575cc2eb, adadf4192f700bca82abfda9fa6d58c0bf37cc04, c40e0b4fa365969e67011529eabdfb66d1022256, 649bc7df3e5d7be6f7996a95084037dbf3cad1e5 |
| Linux/Linuxgeneric | 2.6.31 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop() event_test_stuff() calls kthread_run() and unconditionally passes the returned task_struct pointer to kthread_stop(). kthread_run() returns an error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for example under memory pressure during the boot-time event self-test. kthread_stop() then dereferences the invalid pointer, crashing the kernel. Check the result of kthread_run() before passing it to kthread_stop(). Use WARN_ON() so that a failure to create the self-test thread does not go unnoticed, matching the ring-buffer self-test fix in commit 91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").
Quoted source text, attributed separately from HOL analysis.