CVE-2026-89937

Source
https://cve.org/CVERecord?id=CVE-2026-89937
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89937.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89937
Downstream
Published
2026-09-16T10:32:26Z
Modified
2026-09-17T03:47:26Z
Summary
iio: chemical: sgp30: Handle IAQ thread creation failure
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: sgp30: Handle IAQ thread creation failure

kthread_run() can fail and return an error pointer, but sgp_probe() stores it and returns success, so the device is registered without its IAQ thread and sgp_remove() later passes the error pointer to kthread_stop(). Return the error from probe instead.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89937.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ce514124161ac2ceb13d10b6c40cbf05c8f0cc91
Fixed
bffd0655a35402b2df8857699f8248e5a534d214
Fixed
bae0316c087b1ef625844003fe37e803a13819f3
Fixed
3c6b52b258e65a584e3f5122ed7f406bc89a946e
Fixed
3462c13bb0f50dec09235adb7fd04b6f617cf0cc
Fixed
a5aaea17a1834d7254ff597e4d5e1bc60dfc4800
Fixed
2d386efb4c37a50739db19c7c8e49564fd53a570
Fixed
44d52c8b1c6da7ac1b0dffeeff6de68370746775
Fixed
1135d6875d2dbda3f6ec718f3421a6ce4378bd63

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89937.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89937.json"