CVE-2026-97508 is a vulnerability in Linux Kernel
Published on September 24, 2026
thunderbolt: Set tb->root_switch to NULL when domain is stopped
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Set tb->root_switch to NULL when domain is stopped
Similarly what we do with the firmware connection manager. This makes
tb_xdp_handle_request() return error to the remote host. However, we
need to make sure we keep the uuid alive so that we can reply until the
whole domain is released.
Products Associated with CVE-2026-97508
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below f06e9fbae78a51832211b4495a19412c7d49ecb4 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 99f019d2e9eb79adc485fef8aa8ada2cd0c843e9 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below e56249d8a68e712f3b60e1f3fdbb5b4fea146468 is affected.
- Before 6.12.111 is affected.
- Before 6.18.53 is affected.
- Version 6.12.111, <= 6.12.* is unaffected.
- Version 6.18.53, <= 6.18.* is unaffected.
- Version 7.2, <= * is unaffected.