Unchecked Return Value in Linux kernel - CVE-2026-89937
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of an error return in the SGP30 driver sgp_probe() and sgp_remove() functions when IAQ thread creation fails. A local user can cause IAQ thread creation to fail and subsequently trigger device removal to cause a denial of service.
Affected software
How to mitigate CVE-2026-89937
External References
- https://git.kernel.org/stable/c/1135d6875d2dbda3f6ec718f3421a6ce4378bd63
- https://git.kernel.org/stable/c/2d386efb4c37a50739db19c7c8e49564fd53a570
- https://git.kernel.org/stable/c/3462c13bb0f50dec09235adb7fd04b6f617cf0cc
- https://git.kernel.org/stable/c/3c6b52b258e65a584e3f5122ed7f406bc89a946e
- https://git.kernel.org/stable/c/44d52c8b1c6da7ac1b0dffeeff6de68370746775
- https://git.kernel.org/stable/c/a5aaea17a1834d7254ff597e4d5e1bc60dfc4800
- https://git.kernel.org/stable/c/bae0316c087b1ef625844003fe37e803a13819f3
- https://git.kernel.org/stable/c/bffd0655a35402b2df8857699f8248e5a534d214