Executive brief
A vulnerability was identified in the Linux kernel's batman-adv mesh networking component. When a mesh network interface is shut down, certain background throughput testing sessions (TP meter) may continue to run, attempting to access memory that is being freed. This can lead to a system crash or unstable behavior during network reconfiguration.
Technical details
A race condition exists in the batman-adv module of the Linux kernel during mesh interface teardown. TP meter sessions remain linked on the 'bat_priv->tp_list' even after netlink requests finish. When 'batadv_mesh_free()' is called to remove the interface, it fails to drain these active sessions. Consequently, a running sender thread or a late incoming tp_meter packet can continue processing against a mesh instance that is already being deallocated. The fix involves synchronizing tp_meter with the mesh lifetime by explicitly stopping all active sessions and waiting for sender threads to exit during 'batadv_mesh_free()'.
Affected products
- Linux Linux kernel Introduced in 33a3bb4a3345; fixed in various stable branches including 6.x
Timeline
- 2026-04-27: other: Patch authored
- 2026-05-28: advisory: CVE published
References
- https://git.kernel.org/stable/c/03660dab86f93319178a24667f6998526dc4355d
- https://git.kernel.org/stable/c/26dfeee8db81354bfdade155f27f9e16510ad196
- https://git.kernel.org/stable/c/3d3cf6a7314aca4df0a6dde28ce784a2a30d0166
- https://git.kernel.org/stable/c/79bc0eaeef2c5797317bf2da8e3159a74d62ec47
- https://git.kernel.org/stable/c/8634c1dbd73adb74d40533ebb7e914efb82e71fb