{"id":"CVE-2026-97509","published":"2026-09-24T17:17:28.767","lastModified":"2026-09-28T06:16:36.890","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Keep XDomain reference during the lifetime of a service\n\nThis is needed because we release the service ID in tb_service_release()\nand the ID array is owned by the parent XDomain.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/8ab12d015884b8aa85ea7ed58c5a0bae4264fe60","tags":[]},{"url":"https://git.kernel.org/stable/c/8b4060998637f06975fceee9b73845d8672d411e","tags":[]},{"url":"https://git.kernel.org/stable/c/a4567e5380e4e46d0ea9a28d2d675e5c6f013d54","tags":[]},{"url":"https://git.kernel.org/stable/c/daeaa6c7211d03ed061b0dd22a875fad9372b090","tags":[]},{"url":"https://git.kernel.org/stable/c/ea60ae6233ca0fc0d414e9c11f0d86c63b303fc7","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability in the Linux kernel allows an attacker to maintain a reference to a service ID during the lifetime of a Thunderbolt service, potentially leading to unauthorized access or manipulation of services.","exploitability":"Exploitation requires access to the Thunderbolt service and knowledge of the service ID, making it moderately difficult. Precondition is the presence of the Thunderbolt service and the ability to manipulate its lifecycle.","blast_radius":"If exploited, the impact could be high, potentially leading to service disruption or unauthorized access to critical services.","remediation":"Upgrade to the latest version of the affected Linux kernel, specifically version 5.19.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","thunderbolt","service-id","privilege-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:00:59.104Z"}}