Executive brief
A race condition vulnerability was identified in the Linux kernel's batman-adv networking module, which is used for managing mesh networks. Under specific conditions, the system might miscalculate the memory needed for network configuration data, potentially leading to a system crash or memory corruption. This could impact the stability and availability of devices using mesh networking.
Technical details
A TOCTOU race condition exists in net/batman-adv/translation-table.c within the batadv_tt_prepare_tvlv_local_data function. The code first counts VLANs with active Translation Table (TT) entries to determine buffer size, then drops a lock and later populates the buffer. If a VLAN gains its first TT entry between the check and the allocation, the buffer may be too small for the resulting data, leading to a heap out-of-bounds write. The fix involves overestimating the buffer size by including all VLANs initially and then refining the count during population.
Affected products
- Linux Linux Kernel 16116dac2339 to e4236bf3ec8d6bb15d0d8d825dcf9933a7d6666b
Timeline
- 2026-07-19: advisory: CVE-2026-64091 published by NVD
- 2026-06-19: patched: Fix committed to Linux stable tree
References
- https://git.kernel.org/stable/c/211ea59988e1cba43cb0367ad65d379b56f9c3bd
- https://git.kernel.org/stable/c/4cc85aec8d3c9ab4dc716dc9f1ed36fca16b227f
- https://git.kernel.org/stable/c/65a1e67339aa8c95ac544b796946af388930ee23
- https://git.kernel.org/stable/c/724a8eb4155669797c96b70d70e354284ae3b5a8
- https://git.kernel.org/stable/c/94d27005016be15ffc638b2ecbc4d58805ad7b48
- https://git.kernel.org/stable/c/9a9c859457bc440a55773e01ff18b1bb5bab6836
- https://git.kernel.org/stable/c/b4d4efd4e351593c81e9293d4b4408d244fa5ee7