PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97475 Linux CVE debrief

A Linux kernel vulnerability was resolved by switching to devm cooling device registration, simplifying resource management and avoiding manual cleanup in error paths. This change fixes an existing issue where thermal framework's cdev list held references to thermal_cooling_device objects whose devdata pointer pointed to memory already freed by the platform device's devm cleanup.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-28
Advisory published
2026-09-24
Advisory updated
2026-09-28

Who should care

Defenders responsible for Linux kernel systems, especially those using affected thermal drivers, should assess exposure and prioritize verification of Linux kernel versions. They must consider potential issues with thermal framework's cdev list and ensure proper resource management to avoid similar vulnerabilities.

Why it matters

Defenders should assess exposure and prioritize verification of Linux kernel versions, especially those using affected thermal drivers, as the vulnerability could lead to issues with thermal framework's cdev list.

  • Verification of Linux kernel versions is required to determine exposure
  • Defenders must assess thermal driver configurations for potential issues
  • Monitoring for updates on affected versions is necessary

Technical summary

The Linux kernel vulnerability was resolved by switching to devm cooling device registration. This change simplifies resource management and avoids manual cleanup in error paths, fixing an existing issue with thermal framework's cdev list holding references to thermal_cooling_device objects whose devdata pointer pointed to memory already freed. The vulnerability affects Linux kernel systems using the thermal drivers, and defenders should assess exposure and prioritize verification of Linux kernel versions, especially those using affected thermal drivers.

Defensive priority

Defenders should assess exposure and prioritize verification of Linux kernel versions, especially those using the affected thermal drivers.

Recommended defensive actions

  • Assess Linux kernel versions for exposure
  • Verify thermal driver configurations
  • Monitor for updates on affected versions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and its resolution. However, the corpus does not establish specific affected versions or exploitation details, requiring verification from official sources. Linux kernel versions and thermal driver configurations must be assessed for exposure. Official sources should be consulted for accurate information on affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97475 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97475

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97475 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97475

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6f2a863e7e9adf6088fe644259576181e60ee5e5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/deaeb7be8e6b04c8b71080acba1bd88698f56b1d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ee126267bc04bfb03816ae9d71ca24c5bf99e739

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.