CVE-2026-97509

Published: Set 24, 2026 Last Modified: Set 25, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Keep XDomain reference during the lifetime of a service

This is needed because we release the service ID in tb_service_release()
and the ID array is owned by the parent XDomain.

https://git.kernel.org/stable/c/8ab12d015884b8aa85ea7ed58c5a0bae4264fe60
https://git.kernel.org/stable/c/8b4060998637f06975fceee9b73845d8672d411e
https://git.kernel.org/stable/c/a4567e5380e4e46d0ea9a28d2d675e5c6f013d54
https://git.kernel.org/stable/c/daeaa6c7211d03ed061b0dd22a875fad9372b090
https://git.kernel.org/stable/c/ea60ae6233ca0fc0d414e9c11f0d86c63b303fc7