Junglewise Threat Intelligence

CVE-2026-64088: Linux Kernel information disclosure in batman-adv module

CVE-2026-64088 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's batman-adv module, which is used for managing mobile ad-hoc networks. A technical error in how the system tracks network update sizes could lead to the transmission of uninitialized memory over the network. This could potentially expose sensitive information from the system's memory to other devices on the same network.

Technical details

A vulnerability exists in the batman-adv module due to the 'tt_buff_len' field in 'struct batadv_orig_node' being declared as a signed 16-bit integer (s16). When a value exceeds 32767, it wraps to a negative value. In 'batadv_send_other_tt_response()', this value is widened to a signed 32-bit integer (s32), causing sign extension. This leads 'batadv_tt_prepare_tvlv_global_data()' to allocate a full-sized buffer but only populate a small portion, leaving the remainder of the buffer containing uninitialized kernel memory which is then transmitted over the network. The fix changes the field type to an unsigned 16-bit integer (u16).

Affected products

  • Linux Linux Kernel 3.1 to 7.1.y

Timeline

  • 2026-05-02: disclosed: Vulnerability reported by Sven Eckelmann
  • 2026-06-01: patched: Fix committed to stable kernel trees
  • 2026-07-19: advisory: CVE published in NVD dataset

References

Related threats