CVE-2026-97509
8.8 HIGHPublished 2026-09-24 · Updated 2026-09-28
AI risk analysis
- Summary
- This vulnerability in the Linux kernel allows an attacker to maintain a reference to a service ID during the lifetime of a Thunderbolt service, potentially leading to unauthorized access or manipulation of services.
- Exploitability
- Exploitation requires access to the Thunderbolt service and knowledge of the service ID, making it moderately difficult. Precondition is the presence of the Thunderbolt service and the ability to manipulate its lifecycle.
- Blast radius
- If exploited, the impact could be high, potentially leading to service disruption or unauthorized access to critical services.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of the affected Linux kernel, specifically version 5.19.0 or later.
kernelthunderboltservice-idprivilege-escalation
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Keep XDomain reference during the lifetime of a service This is needed because we release the service ID in tb_service_release() and the ID array is owned by the parent XDomain.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
All references
- https://git.kernel.org/stable/c/8ab12d015884b8aa85ea7ed58c5a0bae4264fe60
- https://git.kernel.org/stable/c/8b4060998637f06975fceee9b73845d8672d411e
- https://git.kernel.org/stable/c/a4567e5380e4e46d0ea9a28d2d675e5c6f013d54
- https://git.kernel.org/stable/c/daeaa6c7211d03ed061b0dd22a875fad9372b090
- https://git.kernel.org/stable/c/ea60ae6233ca0fc0d414e9c11f0d86c63b303fc7
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-17052PoC
- HIGHCVE-2026-64561PoC
- HIGHCVE-2026-89777
- CRITICALCVE-2026-89914
- CRITICALCVE-2026-89918
- HIGHCVE-2026-89995
- HIGHCVE-2026-90286
- HIGHCVE-2026-93284
Related by shared AI tags and CWE weakness class. Browse the full archive.