CVE-2026-97509
Published Sep 24, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Keep XDomain reference during the lifetime of a service This is needed because we release the service ID in tb_service_release() and the ID array is owned by the parent XDomain.
Is your site exposed to CVE-2026-97509?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/8ab12d015884b8aa85ea7ed58c5a0bae4264fe60
https://git.kernel.org/stable/c/8b4060998637f06975fceee9b73845d8672d411e
https://git.kernel.org/stable/c/a4567e5380e4e46d0ea9a28d2d675e5c6f013d54
https://git.kernel.org/stable/c/daeaa6c7211d03ed061b0dd22a875fad9372b090
https://git.kernel.org/stable/c/ea60ae6233ca0fc0d414e9c11f0d86c63b303fc7
Frequently Asked Questions
What is CVE-2026-97509? +
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Keep XDomain reference during the lifetime of a service
This is needed because we release the service ID in tb_service_release()
and the ID array is owned by the parent XDomain.
How do I check if I'm vulnerable to CVE-2026-97509? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.