Thunderbolt Service ID Reference Issue in Linux Kernel
CVE-2026-97509

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-97509?

In the Linux kernel, a vulnerability exists in the Thunderbolt subsystem concerning the handling of service IDs. It occurs because the service ID is released prematurely during the execution of the tb_service_release() function while the ID array remains tied to its parent XDomain. This oversight can potentially lead to issues in service management and stability, highlighting the need for improved tracking of references throughout the service lifecycle.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8ab12d015884b8aa85ea7ed58c5a0bae4264fe60

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.