{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97508","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T16:01:01.151Z","datePublished":"2026-09-24T16:04:58.740Z","dateUpdated":"2026-10-03T10:59:06.059Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:59:06.059Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Set tb->root_switch to NULL when domain is stopped\n\nSimilarly what we do with the firmware connection manager. This makes\ntb_xdp_handle_request() return error to the remote host. However, we\nneed to make sure we keep the uuid alive so that we can reply until the\nwhole domain is released."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - XDomain discovery packets (TB_CFG_PKG_XDOMAIN_REQ) from a connected Thunderbolt/USB4 peer enter via tb_ctl_rx_callback → tb_domain_event_cb → tb_xdomain_handle_request → tb_xdp_schedule_request and are handled in tb_xdp_handle_request, which then reads tb->root_switch after software-CM tb_stop(). This is a local Thunderbolt fabric, not a routable IP protocol.\nAC:H - The UAF requires software-CM tb_stop() to have already run tb_switch_remove(tb->root_switch) without clearing the pointer. tb_stop() is only called from tb_domain_remove() in nhi_pci_remove (NHI unbind/PCI removal), which a Thunderbolt peer cannot induce; UUID_REQUEST and other XDomain messages only queue system_wq work that then races that teardown.\nPR:N - tb_domain_event_cb dispatches TB_CFG_PKG_XDOMAIN_REQ to tb_xdomain_handle_request whenever tb_is_xdomain_enabled() (default-on xdomain module param plus ACPI OSC), with no device authorization or local credentials; UUID_REQUEST is answered even when tb_xdomain_find_by_route_locked() finds no xdomain.\nUI:N - Once a Thunderbolt/USB4 link exists, the peer injects XDomain control packets itself and tb_xdp_handle_request runs with no mount, sysfs write, or authorization dialog. Domain teardown is an attacker-independent condition and is scored as AC:H rather than a required victim UI step.\nS:U - The dangling tb->root_switch and sw->uuid accesses corrupt host kernel heap state inside the Thunderbolt driver; this does not cross a VM, IOMMU, or sandbox boundary.\nC:H - After tb_stop() frees the host switch, tb_xdp_handle_request still holds tb->root_switch->uuid and tb_xdp_uuid_response() uuid_copy()s those 16 bytes into a UUID_RESPONSE sent back to the peer; UAF of struct tb_switch is also a kernel disclosure primitive.\nI:H - tb_xdomain_find_by_route() calls switch_find_xdomain(tb->root_switch) which walks the freed host switch via tb_switch_for_each_port, and later request handlers may operate on a reallocated tb_xdomain; that slab UAF can be sprayed into an arbitrary write or control-flow hijack.\nA:H - Dereferencing the freed root switch in tb_xdp_handle_request (uuid load) or switch_find_xdomain (port walk) oopses the system_wq kworker, crashing the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/thunderbolt/tb.c","drivers/thunderbolt/xdomain.c"],"versions":[{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"d9a638e7bc87e0e6fe3a75517ac481e72fc0058c","status":"affected","versionType":"git"},{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"66b0fe27e277713c2b9f3c452c76330ed0bd7eaf","status":"affected","versionType":"git"},{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"54ad3415cc211ca0d64ae1bf3234d6eb5c6aedd0","status":"affected","versionType":"git"},{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"83d1af5b1b6e6c96ffa633ca2c9a77f6f4c93efa","status":"affected","versionType":"git"},{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"f06e9fbae78a51832211b4495a19412c7d49ecb4","status":"affected","versionType":"git"},{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"99f019d2e9eb79adc485fef8aa8ada2cd0c843e9","status":"affected","versionType":"git"},{"version":"d1ff70241a275133e1a0258b7c23588b122276c8","lessThan":"e56249d8a68e712f3b60e1f3fdbb5b4fea146468","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/thunderbolt/tb.c","drivers/thunderbolt/xdomain.c"],"versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d9a638e7bc87e0e6fe3a75517ac481e72fc0058c"},{"url":"https://git.kernel.org/stable/c/66b0fe27e277713c2b9f3c452c76330ed0bd7eaf"},{"url":"https://git.kernel.org/stable/c/54ad3415cc211ca0d64ae1bf3234d6eb5c6aedd0"},{"url":"https://git.kernel.org/stable/c/83d1af5b1b6e6c96ffa633ca2c9a77f6f4c93efa"},{"url":"https://git.kernel.org/stable/c/f06e9fbae78a51832211b4495a19412c7d49ecb4"},{"url":"https://git.kernel.org/stable/c/99f019d2e9eb79adc485fef8aa8ada2cd0c843e9"},{"url":"https://git.kernel.org/stable/c/e56249d8a68e712f3b60e1f3fdbb5b4fea146468"}],"title":"thunderbolt: Set tb->root_switch to NULL when domain is stopped","x_generator":{"engine":"bippy-1.2.0"}}}}