← All Advisories

CVE-2026-97987

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97987

Key Details

CVECVE-2026-97987
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

virtio_input: reset device if input_register_device() fails

Probe marks the device DRIVER_OK with virtio_device_ready() before

calling input_register_device(). If registration fails, the error path

cleared vi->ready and called del_vqs() while the device was still live,

so the device could keep DMA to queues that were already torn down.

Match remove/freeze: call virtio_reset_device() on that path before

tearing down the virtqueues. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97987
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97987