Junglewise Threat Intelligence

CVE-2026-63836: Linux Kernel batman-adv divide-by-zero in tp_meter

CVE-2026-63836 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's B.A.T.M.A.N. Advanced mesh networking protocol. A mathematical error in the throughput meter component can cause a system crash (divide-by-zero) when processing specific network congestion data. This could lead to a denial-of-service, impacting the availability of the mesh network.

Technical details

A divide-by-zero vulnerability exists in net/batman-adv/tp_meter.c within the batadv_tp_update_cwnd() function. The vulnerability is caused by an integer overflow when the congestion window (cwnd) reaches 0x20000000; a 3-bit left shift operation causes the 32-bit unsigned integer to wrap around to zero. When this zero value is subsequently used as a divisor in the dec_cwnd calculation, it triggers a kernel panic. The fix simplifies the arithmetic to (mss ** 2) * 8 / cwnd and adds a check to ensure the Maximum Segment Size (mss) does not exceed 16383 to prevent dividend overflow.

Affected products

  • Linux Linux Kernel 33a3bb4a3345 to 35264c4d46067d6312871488c810cef387f8c1f6

Timeline

  • 2026-06-26: patched: Initial patch authored by Sven Eckelmann
  • 2026-07-19: disclosed: CVE published in NVD dataset

References

Related threats