Description
In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix crash passing ERR_PTR to kthread_stop()

event_test_stuff() calls kthread_run() and unconditionally passes the
returned task_struct pointer to kthread_stop(). kthread_run() returns an
error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for
example under memory pressure during the boot-time event self-test.
kthread_stop() then dereferences the invalid pointer, crashing the kernel.

Check the result of kthread_run() before passing it to kthread_stop(). Use
WARN_ON() so that a failure to create the self-test thread does not go
unnoticed, matching the ring-buffer self-test fix in commit
91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s tracing subsystem contains a flaw where event_test_stuff() unconditionally passes the task_struct pointer returned by kthread_run() to kthread_stop() without validating the return value. When kthread_run() fails, it returns an error pointer such as ERR_PTR(-ENOMEM). Passing this error pointer into kthread_stop() causes a dereference of an invalid pointer and results in a kernel crash. The weakness is a classic unchecked return value leading to a null pointer dereference. An attacker exploiting this flaw would trigger a kernel panic, thereby denying service to the system. This flaw is a classic example of CWE-476: Unchecked Return Value Leading to Null Pointer Dereference.

Affected Systems

All Linux kernel releases that do not contain the patch adding a null-pointer check before calling kthread_stop() are potentially vulnerable. The CNA data associates the defect with the Linux kernel as a whole; specific version ranges are not provided, so any kernel prior to the commit that implements the fix is at risk.

Risk and Exploitability

With a CVSS score of 4.4 and an EPSS score of less than 1%, the exploitation likelihood is low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local privileged access that can trigger the boot-time self-test or otherwise execute the vulnerable path. An attacker would need to force a pressure during boot, or reach event_test_stuff(). The impact, if exploited, would result in a kernel panic and denial of service.

Generated by OpenCVE AI on September 15, 2026 at 19:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the commit adding the null-pointer check before calling kthread_stop(), such as the release that includes commit 91542863abad.
  • If a kernel upgrade is not immediately feasible, apply the same source change manually by patching the tracing subsystem and rebuilding the kernel.
  • Disable the tracing self-test path by disabling CONFIG_EVENT_TEST or removing the associated sysfs entries so that the vulnerable code path is never executed.

Generated by OpenCVE AI on September 15, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-690

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CWE-690

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop() event_test_stuff() calls kthread_run() and unconditionally passes the returned task_struct pointer to kthread_stop(). kthread_run() returns an error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for example under memory pressure during the boot-time event self-test. kthread_stop() then dereferences the invalid pointer, crashing the kernel. Check the result of kthread_run() before passing it to kthread_stop(). Use WARN_ON() so that a failure to create the self-test thread does not go unnoticed, matching the ring-buffer self-test fix in commit 91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").
Title tracing: Fix crash passing ERR_PTR to kthread_stop()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:28.892Z

Reserved: 2026-09-11T19:38:34.762Z

Link: CVE-2026-89749

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:05.757

Modified: 2026-09-14T13:19:23.513

Link: CVE-2026-89749

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:53Z

Links: CVE-2026-89749 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses