OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97509

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel related to Thunderbolt services allows for improper management of service IDs, potentially leading to unauthorized access or manipulation of services. This issue affects systems utilizing Thunderbolt technology, and organizations relying on Linux-based environments with Thunderbolt interfaces should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-97509
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Keep XDomain reference during the lifetime of a service This is needed because we release the service ID in tb_service_release() and the ID array is owned by the parent XDomain.