{"api_version":"1","generated_at":"2026-09-24T23:02:39+00:00","cve":"CVE-2026-97475","urls":{"html":"https://cve.report/CVE-2026-97475","api":"https://cve.report/api/cve/CVE-2026-97475.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97475","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97475"},"summary":{"title":"thermal/drivers/tegra/soctherma: Switch to devm cooling device registration","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/tegra/soctherma: Switch to devm cooling device registration\n\nUse devm_thermal_of_cooling_device_register() to simplify resource\nmanagement and avoid manual cleanup in error paths.\n\nAs a side effect this change has the benefit of solving an existing\nissue. Before, the function tegra_soctherm_remove() only called\ndebugfs_remove_recursive() and never called thermal_cooling_device_unregister()\nfor any of the cooling devices registered here.\n\nAfter the driver removal, the thermal framework's cdev list would\nstill hold references to thermal_cooling_device objects whose devdata\npointer (ts) pointed to memory already freed by the platform device's\ndevm cleanup.\n\nWith this change, the cooling device is unregistered when the driver\nis removed, thus fixing the issue above.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:24","updated_at":"2026-09-24 17:17:24"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/deaeb7be8e6b04c8b71080acba1bd88698f56b1d","name":"https://git.kernel.org/stable/c/deaeb7be8e6b04c8b71080acba1bd88698f56b1d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ee126267bc04bfb03816ae9d71ca24c5bf99e739","name":"https://git.kernel.org/stable/c/ee126267bc04bfb03816ae9d71ca24c5bf99e739","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6f2a863e7e9adf6088fe644259576181e60ee5e5","name":"https://git.kernel.org/stable/c/6f2a863e7e9adf6088fe644259576181e60ee5e5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97475","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97475","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 6f2a863e7e9adf6088fe644259576181e60ee5e5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 deaeb7be8e6b04c8b71080acba1bd88698f56b1d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ee126267bc04bfb03816ae9d71ca24c5bf99e739 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.111 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.53 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/thermal/tegra/soctherm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6f2a863e7e9adf6088fe644259576181e60ee5e5","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"deaeb7be8e6b04c8b71080acba1bd88698f56b1d","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"ee126267bc04bfb03816ae9d71ca24c5bf99e739","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6.12.111","status":"affected","version":"0","versionType":"semver"},{"lessThan":"6.18.53","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/thermal/tegra/soctherm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/tegra/soctherma: Switch to devm cooling device registration\n\nUse devm_thermal_of_cooling_device_register() to simplify resource\nmanagement and avoid manual cleanup in error paths.\n\nAs a side effect this change has the benefit of solving an existing\nissue. Before, the function tegra_soctherm_remove() only called\ndebugfs_remove_recursive() and never called thermal_cooling_device_unregister()\nfor any of the cooling devices registered here.\n\nAfter the driver removal, the thermal framework's cdev list would\nstill hold references to thermal_cooling_device objects whose devdata\npointer (ts) pointed to memory already freed by the platform device's\ndevm cleanup.\n\nWith this change, the cooling device is unregistered when the driver\nis removed, thus fixing the issue above."}],"providerMetadata":{"dateUpdated":"2026-09-24T16:04:17.604Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/6f2a863e7e9adf6088fe644259576181e60ee5e5"},{"url":"https://git.kernel.org/stable/c/deaeb7be8e6b04c8b71080acba1bd88698f56b1d"},{"url":"https://git.kernel.org/stable/c/ee126267bc04bfb03816ae9d71ca24c5bf99e739"}],"title":"thermal/drivers/tegra/soctherma: Switch to devm cooling device registration","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97475","datePublished":"2026-09-24T16:04:17.604Z","dateReserved":"2026-09-24T16:01:01.149Z","dateUpdated":"2026-09-24T16:04:17.604Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:24","lastModifiedDate":"2026-09-24 17:17:24","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97475","Ordinal":"1","Title":"thermal/drivers/tegra/soctherma: Switch to devm cooling device r","CVE":"CVE-2026-97475","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97475","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/tegra/soctherma: Switch to devm cooling device registration\n\nUse devm_thermal_of_cooling_device_register() to simplify resource\nmanagement and avoid manual cleanup in error paths.\n\nAs a side effect this change has the benefit of solving an existing\nissue. Before, the function tegra_soctherm_remove() only called\ndebugfs_remove_recursive() and never called thermal_cooling_device_unregister()\nfor any of the cooling devices registered here.\n\nAfter the driver removal, the thermal framework's cdev list would\nstill hold references to thermal_cooling_device objects whose devdata\npointer (ts) pointed to memory already freed by the platform device's\ndevm cleanup.\n\nWith this change, the cooling device is unregistered when the driver\nis removed, thus fixing the issue above.","Type":"Description","Title":"thermal/drivers/tegra/soctherma: Switch to devm cooling device r"}]}}}