Unchecked Return Value in Linux kernel - CVE-2026-89749
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an unchecked return value in event_test_stuff() when kthread creation fails. A local user can trigger a kthread creation failure that results in an error pointer being passed to kthread_stop() to cause a denial of service.
The failure can occur under memory pressure during the boot-time event self-test.