Status: UPDATED | Advisory ID: CVE-2026-97508
| CVE | CVE-2026-97508 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-10-03 |
| CVSS Vector | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is adjacent; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Linux Linux |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Linux | Linux |
| Subsystems | General OT |
| Sectors | Multiple |
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Set tb->root_switch to NULL when domain is stopped
Similarly what we do with the firmware connection manager. This makes
tb_xdp_handle_request() return error to the remote host. However, we
need to make sure we keep the uuid alive so that we can reply until the
whole domain is released. (NVD)
Monitor Linux's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-97508 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-97508 |