CVE-2026-89937
Published Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sgp30: Handle IAQ thread creation failure kthread_run() can fail and return an error pointer, but sgp_probe() stores it and returns success, so the device is registered without its IAQ thread and sgp_remove() later passes the error pointer to kthread_stop(). Return the error from probe instead.
Is your site exposed to CVE-2026-89937?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/1135d6875d2dbda3f6ec718f3421a6ce4378bd63
https://git.kernel.org/stable/c/2d386efb4c37a50739db19c7c8e49564fd53a570
https://git.kernel.org/stable/c/3462c13bb0f50dec09235adb7fd04b6f617cf0cc
https://git.kernel.org/stable/c/3c6b52b258e65a584e3f5122ed7f406bc89a946e
https://git.kernel.org/stable/c/44d52c8b1c6da7ac1b0dffeeff6de68370746775
https://git.kernel.org/stable/c/a5aaea17a1834d7254ff597e4d5e1bc60dfc4800
https://git.kernel.org/stable/c/bae0316c087b1ef625844003fe37e803a13819f3
https://git.kernel.org/stable/c/bffd0655a35402b2df8857699f8248e5a534d214
Frequently Asked Questions
What is CVE-2026-89937? +
In the Linux kernel, the following vulnerability has been resolved:
iio: chemical: sgp30: Handle IAQ thread creation failure
kthread_run() can fail and return an error pointer, but sgp_probe() stores
it and returns success, so the device is registered without its IAQ thread
and sgp_remove() later passes the error pointer to kthread_stop(). Return
the error from probe instead.
How do I check if I'm vulnerable to CVE-2026-89937? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.