Executive brief
A vulnerability in the Linux kernel's batman-adv networking module could cause a system to hang or crash during certain network operations. This occurs when the throughput meter component fails to properly track its shutdown state, leading to a 'zombie' process that continues to run after its resources have been removed. This could result in a service outage or system instability for devices using this specific mesh networking protocol.
Technical details
A race condition exists in the batman-adv module's throughput meter implementation (tp_meter.c). The function batadv_tp_sender_shutdown() unconditionally decrements the 'sending' atomic counter; if multiple execution paths (such as a timeout and a user cancellation) trigger simultaneously, the counter underflows to -1. Because the sender logic interprets any non-zero value as an active state, the sender kernel thread enters an infinite loop. When the associated network interface is subsequently removed, the active 'zombie' thread attempts to access freed memory, resulting in a use-after-free. The fix replaces atomic_dec_and_test() with atomic_xchg() to ensure the state transition from 1 to 0 occurs exactly once.
Affected products
- Linux Linux Kernel 4.8 to 5.10.258
Timeline
- 2026-05-11: disclosed: Vulnerability reported and patch authored
- 2026-06-01: patched: Patch committed to stable trees
- 2026-06-24: advisory: CVE published and NVD record created
References
- https://git.kernel.org/stable/c/01cefc5923889e29dbb5f281c3d457714ceb9c00
- https://git.kernel.org/stable/c/90ae3eae06b7b8ab9f6250b9497c860915b4c17b
- https://git.kernel.org/stable/c/94f3b133168d1c49895e7cc6afbcf1cc0b354602
- https://git.kernel.org/stable/c/abae88fa254f2981d39ac003a7b302528a22af64
- https://git.kernel.org/stable/c/aeae11c5dad9cd0d50723890bdd866f8e6db2e7d
- https://git.kernel.org/stable/c/c1bac194733aabd731aafa6a01350c229e187dba
- https://git.kernel.org/stable/c/c66d20a3ff095e3f000551d208ec2606616db15c