CVE-2026-97508

Summary

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Set tb->root_switch to NULL when domain is stopped

Similarly what we do with the firmware connection manager. This makes tb_xdp_handle_request() return error to the remote host. However, we need to make sure we keep the uuid alive so that we can reply until the whole domain is released.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f06e9fbae78a51832211b4495a19412c7d49ecb4affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 99f019d2e9eb79adc485fef8aa8ada2cd0c843e9affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e56249d8a68e712f3b60e1f3fdbb5b4fea146468affected
LinuxLinux0 < 6.12.111affected
LinuxLinux0 < 6.18.53affected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References