Executive brief
A vulnerability was identified in the Linux kernel's batman-adv mesh networking component. During the shutdown or teardown of a mesh network, the system failed to properly clear the currently selected gateway, leading to stale data. This could potentially cause issues or instability when attempting to recreate or restart the mesh network later.
Technical details
A flaw was discovered in the batadv_gw_node_free() function within the batman-adv subsystem of the Linux kernel. While the function correctly removes gateway list entries during mesh teardown, it fails to clear the 'bat_priv->gw.curr_gw' pointer. This results in a stale reference to the selected gateway persisting after cleanup. An attacker or system event triggering a teardown and subsequent recreation could encounter broken state or unexpected behavior. The fix involves using rcu_replace_pointer to nullify the current gateway and dropping the reference before walking the gateway list.
Affected products
- Linux Linux 3.1 to 5.10.258, 5.15.209, 6.1.175
Timeline
- 2026-06-24: advisory: CVE published by NVD
References
- https://git.kernel.org/stable/c/17e3a441111cd1a530cd6ee69a22f3161d80d810
- https://git.kernel.org/stable/c/30bda3ef4b0cac777f1a7c314cd08b8ff6437365
- https://git.kernel.org/stable/c/6de089b545db013433cf934bb4e4433dec2dd65f
- https://git.kernel.org/stable/c/9a1a8ed4facfe843bde6fdfcf7af0e9923eb2e17
- https://git.kernel.org/stable/c/a340a51ed801eab7bb454150c226323b865263cc
- https://git.kernel.org/stable/c/a3f3f1ec8aad84c5dd386c430b9c61cddd85b18f
- https://git.kernel.org/stable/c/ae7aeb0ce3c0ebbe357ed525779acac197a18086