Impact
The Linux kernel sgp30 sensor driver fails to check the return value of kthread_run during device probing. When thread creation fails, the probe function erroneously records the error pointer as a valid thread handle and reports success, resulting in the device being registered without its IAQ monitoring thread. Upon removal, the driver passes the same error pointer to kthread_stop, which attempts to stop a nonexistent thread and triggers a kernel panic. This flaw directly leads to a denial‑of‑service condition by crashing the kernel.
Affected Systems
All Linux kernel builds that compile the sgp30 driver without incorporating the upstream commit that propagates the kthread_run error from sgp_probe are vulnerable. This includes default distribution kernels as well as custom builds that intentionally enable the driver module. The problem therefore applies to any system running an affected kernel that has not yet applied the fix.
Risk and Exploitability
The EPSS score for this vulnerability is reported as <1 % and it is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. The bug requires the attacker to have local root access or the ability to load or unload kernel modules in order to trigger probe or removal. As the vector is limited to local, privileged interactions, the immediate risk in typical production environments is moderate; however, a successful exploit would cause an unavoidable kernel crash.
OpenCVE Enrichment
Debian DLA
Debian DSA