← All Advisories

CVE-2026-97540

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97540

Key Details

CVECVE-2026-97540
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: usb: pegasus: don't rely on id table pointer arithmetic

The current code is broken when dynamic ID is involved; in such cases

usb_device_id parameter of probe lives on the heap and the pointer

arithmetic will get an index that is wildly out of bound. Instead of

keeping a side table for additional information, use driver_info field of

the usb_device_id.

The dynamic ID parsing code needs to be updated for this; convert it to

just write to the reserved entry for dynamic ID and remove the weird loop. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97540
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97540