CVE-2026-97509

Source
https://cve.org/CVERecord?id=CVE-2026-97509
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-97509.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-97509
Downstream
Published
2026-09-24T16:05:04Z
Modified
2026-10-05T02:30:42Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
thunderbolt: Keep XDomain reference during the lifetime of a service
Details

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Keep XDomain reference during the lifetime of a service

This is needed because we release the service ID in tb_service_release() and the ID array is owned by the parent XDomain.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97509.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d1ff70241a275133e1a0258b7c23588b122276c8
Fixed
a4567e5380e4e46d0ea9a28d2d675e5c6f013d54
Fixed
daeaa6c7211d03ed061b0dd22a875fad9372b090
Fixed
cca72fe513f3d6b1279fe83483f8a8990adbe0c6
Fixed
57359bb31526c2f1bb0a7b9b69d8b8a6bd3f0e9f
Fixed
8ab12d015884b8aa85ea7ed58c5a0bae4264fe60
Fixed
ea60ae6233ca0fc0d414e9c11f0d86c63b303fc7
Fixed
8b4060998637f06975fceee9b73845d8672d411e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-97509.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-97509.json"