CVE-2026-89937
Last modified
CVE-2026-89937 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sgp30: Handle IAQ thread creation failure kthread_run() can fail and return an error pointer, but sgp_probe() stores it and returns success, so the device is registered without its IAQ thread and sgp_remove() later passes the error pointer to kthread_stop(). Return the error from probe instead..
Description
In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sgp30: Handle IAQ thread creation failure kthread_run() can fail and return an error pointer, but sgp_probe() stores it and returns success, so the device is registered without its IAQ thread and sgp_remove() later passes the error pointer to kthread_stop(). Return the error from probe instead.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < bffd0655a35402b2df8857699f8248e5a534d214; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < bae0316c087b1ef625844003fe37e803a13819f3; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < 3c6b52b258e65a584e3f5122ed7f406bc89a946e; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < 3462c13bb0f50dec09235adb7fd04b6f617cf0cc; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < a5aaea17a1834d7254ff597e4d5e1bc60dfc4800; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < 2d386efb4c37a50739db19c7c8e49564fd53a570; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < 44d52c8b1c6da7ac1b0dffeeff6de68370746775; >= ce514124161ac2ceb13d10b6c40cbf05c8f0cc91, < 1135d6875d2dbda3f6ec718f3421a6ce4378bd63 |
| Linux | Linux | 5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89937?
How severe is CVE-2026-89937?
How do I fix CVE-2026-89937?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89931In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89932In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89933In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89934In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89935In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89936In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89938In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89939In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8994The Login with NEAR plugin for WordPress is vulnerable to Au…8.1
- CVE-2026-89940In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89941In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89942In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-89937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
