PatchSiren cyber security CVE debrief
CVE-2026-97475 Linux CVE debrief
A Linux kernel vulnerability was resolved by switching to devm cooling device registration, simplifying resource management and avoiding manual cleanup in error paths. This change fixes an existing issue where thermal framework's cdev list held references to thermal_cooling_device objects whose devdata pointer pointed to memory already freed by the platform device's devm cleanup.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for Linux kernel systems, especially those using affected thermal drivers, should assess exposure and prioritize verification of Linux kernel versions. They must consider potential issues with thermal framework's cdev list and ensure proper resource management to avoid similar vulnerabilities.
Why it matters
Defenders should assess exposure and prioritize verification of Linux kernel versions, especially those using affected thermal drivers, as the vulnerability could lead to issues with thermal framework's cdev list.
- Verification of Linux kernel versions is required to determine exposure
- Defenders must assess thermal driver configurations for potential issues
- Monitoring for updates on affected versions is necessary
Technical summary
The Linux kernel vulnerability was resolved by switching to devm cooling device registration. This change simplifies resource management and avoids manual cleanup in error paths, fixing an existing issue with thermal framework's cdev list holding references to thermal_cooling_device objects whose devdata pointer pointed to memory already freed. The vulnerability affects Linux kernel systems using the thermal drivers, and defenders should assess exposure and prioritize verification of Linux kernel versions, especially those using affected thermal drivers.
Defensive priority
Defenders should assess exposure and prioritize verification of Linux kernel versions, especially those using the affected thermal drivers.
Recommended defensive actions
- Assess Linux kernel versions for exposure
- Verify thermal driver configurations
- Monitor for updates on affected versions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and its resolution. However, the corpus does not establish specific affected versions or exploitation details, requiring verification from official sources. Linux kernel versions and thermal driver configurations must be assessed for exposure. Official sources should be consulted for accurate information on affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97475 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97475
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97475 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97475
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6f2a863e7e9adf6088fe644259576181e60ee5e5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/deaeb7be8e6b04c8b71080acba1bd88698f56b1d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ee126267bc04bfb03816ae9d71ca24c5bf99e739
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.