Description
In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: sgp30: Handle IAQ thread creation failure

kthread_run() can fail and return an error pointer, but sgp_probe() stores
it and returns success, so the device is registered without its IAQ thread
and sgp_remove() later passes the error pointer to kthread_stop(). Return
the error from probe instead.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel sgp30 sensor driver fails to check the return value of kthread_run during device probing. When thread creation fails, the probe function erroneously records the error pointer as a valid thread handle and reports success, resulting in the device being registered without its IAQ monitoring thread. Upon removal, the driver passes the same error pointer to kthread_stop, which attempts to stop a nonexistent thread and triggers a kernel panic. This flaw directly leads to a denial‑of‑service condition by crashing the kernel.

Affected Systems

All Linux kernel builds that compile the sgp30 driver without incorporating the upstream commit that propagates the kthread_run error from sgp_probe are vulnerable. This includes default distribution kernels as well as custom builds that intentionally enable the driver module. The problem therefore applies to any system running an affected kernel that has not yet applied the fix.

Risk and Exploitability

The EPSS score for this vulnerability is reported as <1 % and it is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. The bug requires the attacker to have local root access or the ability to load or unload kernel modules in order to trigger probe or removal. As the vector is limited to local, privileged interactions, the immediate risk in typical production environments is moderate; however, a successful exploit would cause an unavoidable kernel crash.

Generated by OpenCVE AI on September 18, 2026 at 08:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel that contains the sgp30 driver commit which reports kthread_run failures from sgp_probe().
  • If an immediate kernel upgrade is not possible, blacklist or disable the sgp30 driver at boot to prevent its buggy thread creation and removal logic from executing.
  • When the driver is in use, unload the sgp30 module with modprobe -r sgp30 before system shutdown or runtime to avoid the error pointer being passed to kthread_stop().

Generated by OpenCVE AI on September 18, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sgp30: Handle IAQ thread creation failure kthread_run() can fail and return an error pointer, but sgp_probe() stores it and returns success, so the device is registered without its IAQ thread and sgp_remove() later passes the error pointer to kthread_stop(). Return the error from probe instead.
Title iio: chemical: sgp30: Handle IAQ thread creation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:26.316Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:03.177

Modified: 2026-09-16T11:17:03.177

Link: CVE-2026-89937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses