Executive brief
A vulnerability in the Linux kernel's batman-adv mesh networking component could allow an attacker to cause a denial-of-service condition. By sending specifically crafted network messages, an attacker can force the system to consume excessive memory or CPU resources. This could lead to system instability, slow performance, or a complete crash, impacting the availability of the affected network node.
Technical details
A vulnerability in the 'tp_meter' component of the batman-adv module in the Linux kernel arises from an unbound 'unacked_list'. An attacker can send small network messages with specific sequence numbers and gaps to force the receiver to allocate an excessive number of list entries. This results in either an out-of-memory (OOM) condition or significant CPU overhead due to the management and searching of the large list. The fix introduces a limit (BATADV_TP_MAX_UNACKED) of 100 entries and ensures that the entry with the highest sequence number is dropped if the limit is exceeded, allowing the process to continue. The vulnerability was introduced in the initial throughput meter implementation (commit 33a3bb4a3345).
Affected products
- Linux Linux Kernel 33a3bb4a3345 to 7.1.y
Timeline
- 2026-06-26: other: Patch authored by Sven Eckelmann
- 2026-07-04: patched: Commits merged into stable branches by Greg Kroah-Hartman
- 2026-07-19: disclosed: CVE published and NVD record created
References
- https://git.kernel.org/stable/c/1111a3381bca2d1f084a07686bc783af5ab23df7
- https://git.kernel.org/stable/c/1c616b0be4bd8399d485e25e91859373b95d6013
- https://git.kernel.org/stable/c/1fb8762600a393d1caccd63be5d07e1756982d68
- https://git.kernel.org/stable/c/2233787658db859f0a9b83cb397cf783bb8be865
- https://git.kernel.org/stable/c/31a88792bfba142be3c9521538c1db805677381f
- https://git.kernel.org/stable/c/c6231d628d06d841bc1617b2f7034f5f39876b16
- https://git.kernel.org/stable/c/e7c775110e1858e5a7471a23a9c9658c0af9df89