← All Advisories

CVE-2026-97539

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97539

Key Details

CVECVE-2026-97539
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

usb: xusbatm: don't rely on id table pointer arithmetic

The current code is broken when dynamic ID is involved; in such cases

usb_device_id parameter of probe lives on the heap and the pointer

arithmetic will get an index that is wildly out of bound. xusbatm

initialize the USB device IDs dynamically so it can just use driver_info

too.

Even with conversion, xusbatm still cannot support dynamic IDs, so also set

no_dynamic_id. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97539
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97539