CVE-2026-97510
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() If tb_cfg_request() fails setting up the request (for example the control channel is shut down already) it returns an error without calling the callback. To avoid leaking that memory, call tb_cfg_request_put() if tb_cfg_request() fails.
- Published Sep 24, 2026
- Not yet scored
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available