Executive brief
A vulnerability was identified in the Linux kernel's B.A.T.M.A.N. Advanced mesh networking protocol. A mathematical error in the throughput meter component can cause a system crash (divide-by-zero) when processing specific network congestion data. This could lead to a denial-of-service, impacting the availability of the mesh network.
Technical details
A divide-by-zero vulnerability exists in net/batman-adv/tp_meter.c within the batadv_tp_update_cwnd() function. The vulnerability is caused by an integer overflow when the congestion window (cwnd) reaches 0x20000000; a 3-bit left shift operation causes the 32-bit unsigned integer to wrap around to zero. When this zero value is subsequently used as a divisor in the dec_cwnd calculation, it triggers a kernel panic. The fix simplifies the arithmetic to (mss ** 2) * 8 / cwnd and adds a check to ensure the Maximum Segment Size (mss) does not exceed 16383 to prevent dividend overflow.
Affected products
- Linux Linux Kernel 33a3bb4a3345 to 35264c4d46067d6312871488c810cef387f8c1f6
Timeline
- 2026-06-26: patched: Initial patch authored by Sven Eckelmann
- 2026-07-19: disclosed: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/1381b021bf886b793fa5ffb895a8efae7ba0318f
- https://git.kernel.org/stable/c/33ccd52f3cc9ed46ce395199f89aa3234dc83314
- https://git.kernel.org/stable/c/35264c4d46067d6312871488c810cef387f8c1f6
- https://git.kernel.org/stable/c/585616dab0aa9c45bc11b2c8082ca78533bc00e9
- https://git.kernel.org/stable/c/7d2a44bc6bbe39aed03c68864aa0e54e04a50278
- https://git.kernel.org/stable/c/ac229c86e49fdb96d91f51bc2fa37a9c4f58c44f
- https://git.kernel.org/stable/c/cd74176cf1685f35a2e5f212d15748bbfecb53b6